Privacy Policy
CV Matcher is built for recruitment agencies. We take the privacy of your candidate data seriously. This policy explains clearly what we collect, why, and how it is protected — and our obligations under Australian privacy law.
1. Who we are
CV Matcher ("we", "our", "us") operates the platform available at cvmatcher.work. We provide AI-powered CV screening software to recruitment agencies and individual recruiters. We are an Australian business (ABN: 65 366 917 788).
CV Matcher is subject to the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) contained in Schedule 1 of that Act. This policy sets out how we meet our obligations under the APPs.
For questions about this policy, contact us at: [email protected]
2. What data we collect
We collect the following categories of data:
- Account data: Your name, email address, company name, and password (stored as a one-way hash) when you register.
- Job description data: Job descriptions you upload or import to use for candidate matching.
- CV data: CVs and resumes you upload for screening. This includes candidate names, contact details, employment history, skills, and qualifications contained within those documents.
- Usage data: Log data including IP addresses, browser type, pages visited, and timestamps — collected automatically for security and performance monitoring.
- Payment data: If you subscribe to a paid plan, payment is processed by our third-party payment provider (Stripe). We do not store your card details.
3. How we use your data
We use your data only for the following purposes:
- Providing the CV matching and screening service you signed up for
- Authenticating your account and maintaining session security
- Processing your subscription payments via Stripe
- Sending transactional emails (account confirmation, password reset)
- Monitoring for security incidents and preventing abuse
- Improving the platform based on aggregated, anonymised usage patterns
We do not sell your data. We do not use candidate CV data to train AI models. We do not share your data with third parties for marketing purposes.
4. Data isolation and security
Each agency account operates in a completely isolated data environment. Your uploaded CVs and job descriptions are never accessible to or shared with any other agency or user on the platform. This is consistent with our obligations under APP 11 (security of personal information).
We apply the following security measures:
- All data is encrypted in transit using TLS 1.2 or higher
- Stored files and database records are encrypted at rest
- Passwords are stored as one-way cryptographic hashes (bcrypt) — we cannot recover your password
- Access to production systems is restricted to authorised personnel only
- Session tokens are HTTP-only and protected against CSRF attacks
- Failed login attempts are rate-limited and accounts are temporarily locked after repeated failures
5. Notifiable data breaches
CV Matcher is subject to the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act 1988 (Cth). If we become aware of a data breach that is likely to result in serious harm to any individual whose personal information is involved, we will:
- Contain the breach and assess its likely impact as quickly as possible
- Notify the Office of the Australian Information Commissioner (OAIC) as soon as practicable
- Notify all affected individuals directly, unless the OAIC directs otherwise
- Notify you as the account holder if your agency's candidate data is involved
To report a suspected data breach or security issue, contact [email protected] immediately.
6. Candidate data — your responsibilities
When you upload CVs to CV Matcher, you are the data controller for the personal data of those candidates. As a recruitment agency operating in Australia, you are also subject to the Privacy Act 1988 (Cth) and the APPs in your own right. Your responsibilities include:
- Ensuring you have a lawful basis to collect and process each candidate's personal data (typically: the candidate applied for a role, or has given explicit consent)
- Only uploading CVs of candidates who have applied for roles or given consent for their details to be processed by third-party tools
- Responding to any access, correction, or deletion requests from candidates regarding their personal data (APP 12 and APP 13)
- Not uploading CVs of candidates for roles they have not consented to be considered for
CV Matcher acts as a data processor on your behalf for candidate data. We process it only to provide the screening service and do not use it for any other purpose, consistent with APP 6 (use or disclosure of personal information).
7. Data retention
We retain personal data only for as long as necessary for the purposes described in this policy, consistent with APP 11.2 (destruction or de-identification of personal information).
- Uploaded CVs: Retained for as long as your account is active. You can delete individual CVs at any time from your dashboard. CVs are permanently deleted within 30 days of account closure.
- Job descriptions: Retained for as long as your account is active. You can delete them at any time.
- Account data: Retained until you request account deletion, then permanently deleted within 30 days.
- Usage logs: Retained for up to 90 days for security monitoring, then permanently deleted.
- Payment records: Retained for 7 years as required by Australian tax law. Payment data is held by Stripe; we retain only transaction references.
To request full account and data deletion, email [email protected]. We will action deletion requests within 30 days.
8. Third-party services
We use the following third-party services to operate the platform:
- Stripe — payment processing. Stripe Privacy Policy
- Umami Analytics — privacy-preserving, cookieless website analytics. No personal data or cross-site tracking.
We do not use Google Analytics, Facebook Pixel, or any advertising trackers.
9. Cookies
We use a single session cookie to keep you logged in. This cookie contains no personal information — only an encrypted session identifier. It is deleted when you log out or after 7 days of inactivity.
We do not use advertising cookies, tracking cookies, or third-party cookies.
10. Your rights under the Australian Privacy Principles
Under the Privacy Act 1988 (Cth) and the APPs, you have the following rights regarding your personal data:
- APP 12 — Access: Request a copy of the personal information we hold about you. We will respond within 30 days.
- APP 13 — Correction: Request that inaccurate, out-of-date, incomplete, or misleading information be corrected.
- Deletion: Request that your account and all associated data be permanently deleted. We will action this within 30 days.
- Complaint: If you believe we have breached the APPs, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au. We ask that you contact us first so we can attempt to resolve the matter directly.
To exercise any of these rights, contact [email protected]. We will respond within 30 days.
11. Changes to this policy
We may update this privacy policy from time to time. We will notify you of material changes by email or by displaying a notice on the platform. The "last updated" date at the top of this page reflects the most recent revision.
12. Contact and complaints
For any privacy-related questions, access requests, or complaints: [email protected]
If you are not satisfied with our response to a complaint, you may contact the Office of the Australian Information Commissioner (OAIC):
- Website: oaic.gov.au
- Phone: 1300 363 992
- Post: GPO Box 5218, Sydney NSW 2001