On this page
- Introduction and scope
- Personal information we collect
- How we collect personal information
- Purposes for collection and use
- Our proprietary AI in recruitment
- Disclosure of personal information
- Data security and storage
- Cookies, tracking, and analytics
- Direct marketing and communications
- Your privacy rights
- Privacy complaints
1. Introduction and scope
37Talent Pty Ltd (we, us, our) is a specialist recruitment agency based in Sydney, Australia, providing talent acquisition services across media, marketing, technology, digital, eCommerce, and retail media.
This policy applies to all personal information we handle through our website, recruitment services, client engagements, candidate interactions, AI-assisted tools, and any other means. It applies to candidates, clients, referees, contractors, and website visitors.
We handle personal information in accordance with:
- The Privacy Act 1988 (Cth)
- The Australian Privacy Principles (APPs) contained in Schedule 1 of the Privacy Act
- The Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act
- Any other applicable Australian or State/Territory privacy laws
2. Personal information we collect
2.1 Candidate information
- Identity and contact: Name, home address, email, phone, date of birth (where required), and professional profiles (e.g. LinkedIn).
- Professional information: Resume/CV, employment history, qualifications, certifications, skills, memberships, and work samples.
- Compensation and preferences: Current and expected salary, work arrangement preferences, location, availability, and notice period.
- Assessment data: Interview notes, recruiter assessments, reference check outcomes, test results, video interview recordings, and suitability ratings.
- Verification data: Right-to-work documentation, identity documents, visa status, and other legally required checks.
- Diversity data (voluntary): Gender, cultural background, disability status — collected only with explicit consent and used solely for reporting or reasonable adjustments.
2.2 Client and employer information
- Business contacts: Name, title, business email, phone, and employer.
- Organisational details: Company name, ABN, billing address, and invoicing contacts.
- Talent requirements: Job descriptions, role briefs, salary bands, and hiring preferences.
2.3 Sensitive information
Sensitive information is afforded higher protection under the APPs. We collect it only with your explicit consent, or where required or authorised by law. This may include health information (for workplace adjustments), criminal record history (for specific roles), or voluntarily disclosed demographic information.
We will always inform you of the purpose before collecting sensitive information.
2.4 Technical and website data
- IP address and geolocation data
- Browser type, version, and device information
- Pages visited, time on site, and navigation patterns
- Cookie and tracking data (see Section 8)
3. How we collect personal information
3.1 Directly from you
- Resume or application submissions via our website or email
- Contact forms, salary guide requests, or other online forms
- Phone calls, video interviews, or in-person meetings
- Email correspondence or job alert registrations
3.2 From third parties
- Referees and former employers (after obtaining your consent)
- Professional networks and job boards (e.g. LinkedIn, Seek, Indeed)
- Background check and screening providers
- Clients who provide referrals or information about internal candidates
- Publicly available professional sources
3.3 Automatically via technology
- Cookies and tracking technologies on our website
- Our applicant tracking system (ATS) and CRM platforms
- Our proprietary AI systems when processing resumes and profiles (see Section 5)
Where we collect your information from a third party or public source, we will take reasonable steps to notify you at or before our first contact with you.
4. Purposes for collection and use
We collect and use personal information only for purposes directly related to our functions as a recruitment agency. We will not use your information for a secondary purpose without your consent, unless an APP exception applies.
4.1 For candidates
- Assessing suitability and eligibility for current and future roles
- Matching your skills and preferences with client requirements
- Conducting screening, reference checks, and background verification
- Communicating about opportunities, interviews, and outcomes
- Maintaining a talent pool for future opportunities (with ongoing consent)
- Complying with right-to-work and other legal obligations
- Sending industry news, salary guides, or career resources (where opted in)
4.2 For clients
- Delivering recruitment and talent acquisition services
- Understanding role requirements to ensure quality placements
- Invoicing and managing commercial relationships
- Reporting on placement activity and market insights
4.3 General operational purposes
- Improving our website, services, and internal processes
- Conducting data analytics, market research, and business planning
- Training staff and AI systems (using de-identified or aggregated data only)
- Responding to enquiries, complaints, or legal requests
5. Our proprietary AI in recruitment
37Talent has developed and operates proprietary AI systems to enhance the quality, efficiency, and consistency of our recruitment processes. These systems are built, hosted, and controlled entirely by 37Talent — giving us full governance over how your data is processed.
5.1 What our AI does
- Resume and profile parsing: Extracting and structuring information from CVs and professional profiles.
- Skills matching: Analysing candidate profiles against role requirements to generate suitability scores.
- Candidate ranking: Generating ranked shortlists based on defined criteria.
- Interview preparation: Generating tailored interview questions from a candidate's background and role requirements.
- Talent pool insights: Identifying patterns to support workforce planning and market intelligence.
- Predictive matching: Recommending candidates for roles based on historical placement data.
5.2 Safeguards
Human oversight
All AI outputs — rankings, shortlists, assessments — are reviewed by a qualified recruiter before any action is taken. Our AI is a decision-support tool, not a decision-maker.
No solely automated decisions with significant effects
We do not make final decisions about shortlisting, interviewing, offering, or rejecting candidates based solely on automated processing. A human is always involved in material outcomes.
Bias monitoring
We regularly review AI outputs for patterns that may indicate bias based on gender, age, cultural background, or other protected attributes. Where bias is detected, we take corrective action.
Data minimisation
Our AI systems use only the minimum personal information necessary for each task. We do not feed sensitive information into AI processes without explicit consent and clear justification.
No external model training
Your personal information is never used to train external AI models or shared with third-party AI providers for training purposes. All AI development uses de-identified or synthetic data.
AI Resume Generator and JobAdder integration
Our AI Resume Generator uses a leading enterprise-grade large language model, accessed through a US-based AI infrastructure provider, to rewrite your CV. Only the information you submit to the generator is sent to the provider. The provider does not retain the content or use it to train its models. A full list of subprocessors is available on request.
If you tick the "Share my profile with 37Talent recruiters" box on the generator, your resume data, contact details, and the generated PDF will be added to our recruitment database, which is hosted on JobAdder (operated by Job Adder Operations Pty Ltd, Sydney, Australia). Ticking the box is optional. Untick it and your resume will be generated and downloaded without any data being shared with our recruiters.
If you later want your profile deleted from our JobAdder database, email info@37talent.com.au and we will remove it within 14 days.
Privacy by design
Privacy-by-design principles are embedded into the development lifecycle of all our AI systems. Privacy impact assessments are conducted before introducing new AI capabilities.
5.3 Your rights regarding AI
You have the right to:
- Request information about whether and how your data has been processed by our AI
- Request a human review of any AI-generated assessment that has affected you
- Ask us to explain the criteria or logic used to generate a particular outcome
- Object to the use of your data in AI-assisted processes (subject to limitations where this would prevent us from providing services to you)
6. Disclosure of personal information
6.1 Who we share with
- Clients and potential employers: We share candidate information with clients as part of the recruitment process, with your consent. Clients receive only information necessary to assess your suitability.
- Technology and service providers: Cloud infrastructure, ATS platforms, background screening, and communication tools — all bound by contractual data protection obligations.
- Referees and verification providers: With your consent, we contact referees and professional bodies to verify information you have provided.
- Professional advisers: Legal, financial, or insurance advisers where necessary, subject to professional confidentiality.
- Regulators and government agencies: Where required or authorised by law (e.g. ATO, Department of Home Affairs, OAIC).
- Successors: In the event of a sale, merger, or restructure, information may transfer to a successor entity under equivalent privacy protections.
6.2 Overseas disclosure
37Talent primarily stores and processes data in Australia. Where information is disclosed to overseas recipients, we take reasonable steps to ensure they are bound by privacy obligations substantially similar to the APPs through contractual agreements, verification of comparable laws, or your explicit consent.
6.3 What we will never do
- Sell, rent, or trade your personal information for commercial purposes
- Share your information with third parties for their direct marketing without your consent
- Use your sensitive information for purposes unrelated to why it was collected
7. Data security and storage
7.1 Security measures
- Encryption of data in transit (TLS/HTTPS) and at rest
- Role-based access controls limiting access to authorised personnel only
- Multi-factor authentication for internal systems
- Regular security assessments, penetration testing, and vulnerability management
- Employee training on data handling and privacy obligations
- Incident response procedures to detect, contain, and respond to data breaches
7.2 Retention periods
| Active candidates | 3 years from last interaction |
| Placed candidates | 7 years from placement date |
| Unsuccessful applicants | 12 months unless in talent pool |
| Client records | 7 years (commercial/tax obligations) |
When information is no longer required, it is securely destroyed or permanently deleted and de-identified.
7.3 Data breach response
In the event of a breach likely to result in serious harm, we will comply with our obligations under the Notifiable Data Breaches (NDB) scheme, including notifying affected individuals and the OAIC as soon as practicable, and taking remedial action to contain the breach.
8. Cookies, tracking, and analytics
8.1 What we use
- Essential cookies: Required for the website to function (session management, form submissions). These cannot be disabled.
- Analytics cookies: Used to understand how visitors interact with our site (e.g. Google Analytics).
- Functional cookies: Enable personalisation features such as saved preferences.
- Marketing pixels: Where used, these help measure the effectiveness of advertising or job board integrations.
8.2 Managing your preferences
You can manage or disable cookies through your browser settings. Disabling certain cookies may affect website functionality. For more information, visit allaboutcookies.org.
8.3 Third-party links
Our website may link to third-party websites, job boards, or social platforms. We are not responsible for their privacy practices. We encourage you to review their privacy policies before providing personal information.
9. Direct marketing and communications
We may contact you with relevant job opportunities, salary guides, industry reports, and 37Talent updates where you have engaged with us as a candidate or client, or explicitly opted in to marketing communications.
Every marketing communication includes a clear opt-out. To unsubscribe at any time:
- Click the unsubscribe link in any email, or
- Email info@37talent.com.au with the subject line "Unsubscribe"
We will process opt-out requests within 5 business days at no charge.
10. Your privacy rights
Right of access
Request a copy of the personal information we hold about you, including any AI-generated assessments or scores.
Right of correction
Request correction of inaccurate, incomplete, or outdated information. We will respond within 30 days.
Right to withdraw consent
Withdraw consent for processing at any time, including removal from our talent pool. This does not affect past processing.
Right to object
Object to direct marketing, AI processing of your data, or retention in our talent pool.
Right to anonymity
Where lawful and practicable, interact with us anonymously or using a pseudonym.
AI-specific rights
Request human review, explanation of AI logic, or details of how your data was used in AI processes.
To exercise any of these rights, email info@37talent.com.au with the subject line: Privacy Request — [Access / Correction / Withdrawal / Objection].
We will acknowledge within 5 business days and respond fully within 30 days.
11. Privacy complaints
11.1 Internal process
If you believe we have mishandled your personal information, email info@37talent.com.au with the subject line "Privacy Complaint". We will acknowledge within 5 business days and respond with our findings within 30 days.
11.2 External escalation
If unsatisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC):