Privacy Policy
Privacy contact: matt@reprofile.com.au
1. Who we are and this policy
ReProfile is a product of SpokeCV Pty Ltd (ACN 697 934 884, ABN 23 697 934 884) (ReProfile, we, us or our). ReProfile is a business software service that reformats candidate CVs into recruitment agencies’ configured document templates.
This policy explains how we handle personal information in connection with the ReProfile service, website and related business activities. We handle personal information in accordance with applicable privacy laws and, as a matter of practice, consistently with the Australian Privacy Principles (APPs). Nothing in this policy reduces any right available under applicable law.
2. Our different roles
We handle personal information in different capacities depending on the information and activity:
- For agency account holders, website visitors, billing contacts and people who contact or book meetings with us, we determine why and how that information is used to operate our business and service.
- For Candidate Content submitted by an agency, the agency determines why the information is collected and submitted. We process that information to provide the service on the agency’s instructions.
Australian privacy law does not use the terms controller and processor in exactly the same way as some overseas laws. Where those terms are used in customer contracts, they are contractual shorthand and do not change either party’s obligations under applicable law.
Candidates should ordinarily contact the recruitment agency that holds and submitted their CV about access, correction, deletion or use of candidate information. We will assist the agency where required.
3. Personal information we handle
3.1 Agency users and account holders
We may collect:
- identity and contact details, including display name, work email address and, where supplied for a document cover page, a phone number;
- account data, including user ID, organisation membership, role, account status and authentication events. Passwords are managed by our authentication provider and are not stored by ReProfile in readable form;
- usage and operational metadata, including when a reformat job was run, the user and organisation, template, success or failure, file size, processing time, a sanitised error code, the CV source (an upload or a connected applicant tracking system) and, for a job sourced from a connected system, whether the Output was written back;
- applicant tracking system connection data, where an agency connects its JobAdder account as described in section 5.7: the agency’s JobAdder account identifiers, connection status, the user who connected it, timestamps, a sanitised error code and the agency’s authorisation credentials for that system, held in encrypted form;
- six optional placement-detail fields entered for the cover page: position title, notice period, availability, charge rate, pre-booked leave and client company;
- billing and transaction information, including business name, billing contact, invoices, payment status and records required for accounting; and
- support and communication information, including enquiries and correspondence.
3.2 Candidate Content
A CV may contain a candidate’s name, contact details, employment history, education, qualifications, skills, licences, professional memberships and any other information included by the candidate or agency. It may also identify referees, managers, colleagues or other people. A CV may incidentally contain sensitive information even though the Service does not request it.
3.3 Website and technical information
When someone visits or uses our website or application, we and our infrastructure providers may collect standard technical information such as IP address, browser and device information, requested pages, timestamps, security events and performance information. We do not currently use third-party advertising cookies. If this changes, we will update this policy and provide any required notice or consent mechanism.
3.4 Enquiries, support and bookings
If a person contacts us or books a call, we collect the information they provide, such as name, work email, organisation, booking details and message content. We ask customers not to email candidate CVs or unnecessary candidate information to our general support address unless a secure support method has been agreed.
4. How we use personal information
We use agency, account, website and business contact information to:
- create, administer and secure accounts, organisations, seats and templates;
- provide, operate, support and improve the Service;
- authenticate users and investigate security or service issues;
- send transactional communications, including account confirmation and password-reset messages;
- respond to enquiries, arrange demonstrations and provide customer support;
- issue invoices, manage subscriptions and maintain accounting records;
- analyse de-identified or aggregated operational performance;
- enforce our agreements and protect our rights and users; and
- comply with legal, regulatory and accounting obligations.
We use Candidate Content only to provide, secure and support the reformatting requested by the agency, comply with law and respond to an authorised support or security need. We do not sell Candidate Content, use it for advertising or opt in to using it to train Anthropic’s models.
5. How candidate CV data is handled
5.1 Upload and extraction
The uploaded file is processed in memory by the ReProfile application. ReProfile does not intentionally write the original CV file or original filename to its own persistent file or object storage. Text is extracted in memory for the reformatting process.
5.2 AI processing
Extracted CV text is sent to Anthropic’s commercial API in the United States to perform the reformatting step. Anthropic states that commercial API inputs and outputs are not used to train its models by default. ReProfile does not opt in to model training or intentionally submit Candidate Content as product feedback.
Anthropic ordinarily deletes commercial API inputs and outputs from its backend within 30 days, subject to limited exceptions described in Anthropic’s terms and privacy materials, including legal requirements, usage-policy enforcement or an alternative retention arrangement.
5.3 Output download window
The completed Output is stored encrypted at rest in ReProfile’s active application database for a short download window and is automatically deleted from active application storage within 20 minutes of completion.
The current Service uses organisation-scoped access. During that window, active members of the submitting agency’s organisation account may be able to access the Output. The agency is responsible for managing its organisation membership. In ordinary operation, the Output is returned to the user who submitted the job.
Authorised ReProfile personnel could technically access an Output during the window using administrative access, but such access is restricted to circumstances reasonably necessary for support, security, legal compliance or service operation and is not part of ordinary processing.
5.4 Deletion and residual systems
After the download window, the Output is not available through the Service. Residual encrypted copies may persist temporarily if unavoidably captured in infrastructure backups, security records or provider systems. Those copies are not available through the ordinary product interface and are subject to access controls and the relevant provider’s retention cycle.
Anthropic’s retention of API inputs and outputs is separate from ReProfile’s 20-minute Output window and is described in section 5.2.
5.5 Information retained for operations
ReProfile retains limited operational records: organisation and user identifiers, template, timestamps, job state, input file size, processing time, sanitised error code, the CV source and, for a job sourced from a connected applicant tracking system, the write-back outcome, together with, where entered, the six placement-detail fields described in section 3.1. ReProfile does not intentionally retain the CV body, original uploaded filename or completed Output in active application storage beyond the periods described above.
5.6 Generated content and human review
The Service may generate an optional short consultant summary or, where an agency has expressly enabled the setting, draft content for a missing template section. The Service does not make recruitment or employment decisions. Agency users must review every Output before relying on or disclosing it.
5.7 Connected applicant tracking systems (JobAdder)
An agency’s owner or administrator may connect the agency’s JobAdder account to the Service. JobAdder is a system the agency already uses and controls. By connecting it, the agency authorises us to retrieve a CV from a candidate record the agency selects and to return the completed Output to that record, on the agency’s instruction.
When a consultant uses the connection, the selected CV is retrieved into memory and handled in the same way as an uploaded file under sections 5.1 to 5.5. Once the Output is complete, it is written to the candidate record in JobAdder and the record’s action is marked complete. The copy in JobAdder is the agency’s own record: it is controlled by the agency under the agency’s agreement with JobAdder and is not subject to the Output window described in section 5.3.
We hold the agency’s JobAdder authorisation credentials in encrypted form for as long as the connection is active, renew them while the account remains connected, and erase them when the agency disconnects or when JobAdder finally rejects them. For each job we record that the CV came from JobAdder and whether the Output was written back. We do not retain the JobAdder candidate identifier, attachment identifiers, file names or the CV content beyond the processing periods described above.
6. Service providers and disclosures
We do not sell personal information. We disclose it only as reasonably necessary to provide and secure the Service, operate our business, comply with law or complete a corporate transaction subject to appropriate protections.
| Provider | Purpose and information | Typical processing location |
|---|---|---|
| Supabase, Inc. | Database, authentication and serverless functions. May process account data, operational metadata, placement fields and the encrypted Output during the short download window. | Core ReProfile project configured in Sydney, Australia. |
| Vercel, Inc. | Web application hosting and reformatting worker. May transiently process uploaded files and extracted content to provide the Service. | Core ReProfile workloads configured in Sydney, Australia. |
| Anthropic, PBC | Commercial AI API used for the reformatting step. Receives extracted CV text and returns processed text. | United States. |
| Resend, Inc. | Transactional emails such as account confirmation and password reset. Candidate CV content is not intentionally included. | United States. |
| Google LLC - Workspace | Business email and support correspondence. Candidate CV content is not intentionally provided, but information a person includes in an email may be processed. | United States and other locations under Google’s terms. |
| Google LLC - Calendar | Appointment scheduling for demonstrations and support calls. Processes booking details entered by the person booking. | United States and other locations under Google’s terms. |
| Xero Limited | Invoicing, subscription administration and accounting records. Processes business and billing contact information, not Candidate Content. | Australia and other locations under Xero’s terms. |
Connected systems. JobAdder is not a service provider we engage to operate the Service and does not appear in the table above. Where an agency connects its JobAdder account (JobAdder Operations Pty Ltd, ACN 167 597 953, Australia; hosted on Amazon Web Services in the region matching the agency’s location), it is a system the agency has authorised us to retrieve a CV from and return the Output to, on the agency’s instruction, as described in section 5.7. We hold only the agency’s authorisation credentials for it. JobAdder’s handling of the agency’s records is governed by the agency’s own agreement with JobAdder.
We may also disclose information to professional advisers, insurers, auditors, regulators, courts, law enforcement or transaction counterparties where reasonably necessary and lawful. Where a business sale or reorganisation occurs, the recipient must continue to handle transferred personal information subject to applicable law and this policy or an equivalent policy.
7. Overseas processing
The core ReProfile application database and processing workloads are configured in Sydney, Australia. Some providers process information overseas:
- Anthropic processes extracted CV text in the United States for the AI step;
- Resend stores and processes transactional email information in the United States;
- Google and Xero may process business contact, booking, support or billing information in overseas locations under their terms; and
- JobAdder hosts a connected agency’s account in the region matching that agency’s location, under the agency’s agreement with JobAdder.
Where applicable, we take reasonable steps appropriate to the circumstances to ensure overseas recipients handle personal information consistently with applicable privacy requirements. Recruitment agencies are responsible for ensuring their own candidate-facing notices appropriately describe the technologies and overseas processing they authorise.
8. Security
We take reasonable technical and organisational steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. Measures include, as appropriate:
- encryption in transit using TLS and encryption at rest provided by infrastructure providers;
- individual user accounts, organisation-scoped access controls and database row-level security;
- restricted administrative and service credentials stored in provider secret-management systems;
- data minimisation, a short Output download window and sanitised operational errors;
- dependency and secret scanning, security updates and secure-development review processes; and
- incident assessment and response procedures.
No method of transmission or storage is completely secure. We cannot guarantee absolute security.
9. Retention
| Information | Purpose | General retention approach |
|---|---|---|
| Uploaded CV file | Processed in memory; not intentionally written to ReProfile’s persistent file or object storage. | Processing session only, subject to provider security systems. |
| Extracted CV text at Anthropic | Used for the AI reformatting step. | Ordinarily deleted within 30 days, subject to Anthropic’s stated exceptions. |
| Completed Output | Available in active application storage for download. | Deleted from active application storage within 20 minutes; residual provider backups may expire later. |
| Operational metadata and placement fields | Used for account operation, billing, support, audit and security. | For the subscription term and ordinarily deleted within 30 days after organisation deletion or termination, except where law or a dispute requires longer retention. |
| Agency user and billing data | Account administration, support, invoicing and legal records. | While the relationship is active and for a reasonable period afterwards, including any legally required accounting period. |
| JobAdder authorisation credentials | Used to retrieve a CV from, and return the Output to, a candidate record in the agency’s connected JobAdder account (section 5.7). | Held in encrypted form while the connection is active and erased when the agency disconnects or JobAdder finally rejects them. |
10. Access, correction, deletion and complaints
10.1 Agency users and business contacts
A person may request access to or correction of personal information we hold about them. They may also ask us to delete information. We will consider a deletion request subject to legal, accounting, security, dispute and operational retention requirements. We may need to verify identity and authority before acting.
10.2 Candidates and other people named in CVs
The recruitment agency that collected and submitted the CV is ordinarily the first point of contact. Because ReProfile does not maintain a candidate database and generally does not retain CV content after the processing periods described above, we may hold only limited metadata or placement-detail fields. We will provide reasonable assistance to the relevant agency where required.
10.3 Complaints
Privacy concerns should first be sent to matt@reprofile.com.au. We will investigate and respond within a reasonable period. Where the Privacy Act applies, a person may also be entitled to complain to the Office of the Australian Information Commissioner at oaic.gov.au.
11. Children and people under 18
ReProfile accounts are intended for adult recruitment professionals. Candidate Content may concern a person under 18 where an agency is lawfully handling that information, for example for an apprenticeship or junior role. The agency remains responsible for ensuring that collection and processing are appropriate and lawful.
12. Changes to this policy
We may update this policy to reflect changes to the Service, law or providers. We will publish the updated version with a revised date. Where a change is material, we will take reasonable steps to notify agency account holders before or shortly after it takes effect.
13. Contact
SpokeCV Pty Ltd - ReProfile
Privacy contact: Matt Cameron
Email: matt@reprofile.com.au
Website: reprofile.com.au