Be Recruitment Group is committed to respecting privacy and protecting the personal information entrusted to us by candidates, workseekers, on-hired workers, employees, clients, referees, suppliers and other people with whom we interact.
This policy explains how Be Recruitment Group (ABN 82 626 742 505), operating under the registered business names Be Recruitment Company, Be Workforce Services and Solutions, and Be Executive (collectively, “Be”, “we”, “us” or “our”), collects, holds, uses and discloses personal information.
We manage personal information in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), the Notifiable Data Breaches scheme and other applicable privacy, employment, workplace, surveillance and recordkeeping laws.
This policy applies to our recruitment, executive search, labour-hire, workforce-management, employment, marketing and related services, including our websites, applications, communication channels and digital platforms.
This policy applies to personal information relating to:
Information about a company or organisation is not personal information unless it identifies, or is reasonably capable of identifying, an individual.
The information we collect depends on the nature of a person’s relationship and interactions with Be. It may include:
Some information handled by Be may be sensitive information under the Privacy Act. Depending on the role, placement, employment relationship or legal requirements, this may include:
We collect sensitive information only where it is reasonably necessary for our functions or activities and with the person’s consent, unless collection is otherwise authorised or required by law. People are not required to provide voluntary diversity information and will not be disadvantaged for choosing not to provide it.
We generally collect personal information directly from the person, including through applications, registration and onboarding forms, interviews, telephone and video calls, email, websites, portals, mobile applications, timesheets and other service interactions.
We may also collect information from:
If we receive personal information that we did not request, we will determine whether we could lawfully have collected it. If not, we will take reasonable steps to destroy or de-identify it, provided it is lawful and reasonable to do so.
We may collect, hold, use and disclose personal information for purposes including:
Where practicable, we will explain the main purpose of collection at or before the time information is collected through an appropriate privacy collection notice.
People may choose not to provide personal information. However, without information that is reasonably required, Be may be unable to assess an application, conduct mandatory checks, present a person for work, employ or pay a worker, meet client or legal requirements, investigate an issue or provide the requested service.
Be may use approved technology, including artificial intelligence (AI), automated matching tools and embedded software features, to support recruitment, administration, communications, transcription, compliance, skills matching, information organisation and service improvement.
Computer programs may assist Be personnel to:
Be does not use solely automated processing to make final decisions to hire, place, reject, discipline or terminate a person. Appropriately authorised personnel remain responsible for reviewing material outputs, considering relevant evidence and making final decisions. AI output is not treated as independent evidence about a candidate or worker.
Where a computer program uses personal information to make, or undertake something substantially and directly related to making, a decision that could reasonably be expected to significantly affect a person’s rights or interests, Be will provide the transparency required by applicable law. A person may contact our Privacy Coordinator to ask about material automated processing involving their information, raise a concern or request human review where appropriate.
AI may assist our staff with tasks such as drafting, summarising, searching, sourcing, matching, administration and workflow support. AI is an assistant, not a decision-maker. We do not permit an AI system to make final decisions about a person’s application, suitability, employment, engagement or access to our services, and we do not use AI to make solely automated decisions that have a legal or similarly significant effect on a person.
Recruiters and other authorised staff remain responsible for applying job-related criteria, checking the accuracy and relevance of AI-assisted outputs, considering context, managing bias and making the final decision. We do not permit personal, sensitive, candidate-identifiable, client-confidential or proprietary information to be entered into an unapproved AI system or workflow.
Material AI uses are assessed and governed under our Artificial Intelligence Use Policy and AI Use Register. These controls include approval before use, privacy and security assessment, defined permitted and prohibited uses, human oversight and override, transparency or consent where appropriate, testing and monitoring, incident and complaint handling, and review when a tool, integration, data flow or use materially changes.
We prohibit unapproved automated candidate rejection or ranking, emotion or personality inference from voice, image or video, covert recording or transcription, and the use of free or public AI tools to process candidate or client information. If an AI-assisted process materially affects you, you may contact us to request information, raise a concern or ask for human review.
Be may record or transcribe approved telephone calls, video meetings or interviews for quality assurance, training, compliance, dispute resolution, accurate recordkeeping and service improvement.
Participants will be notified before recording or transcription begins. Where consent is required, Be will obtain consent from all participants. A participant may ask for recording or transcription to be stopped, and an alternative method of taking notes will be offered where reasonably practicable.
Approved technology may create recordings, transcripts, summaries, topics or action items. These records may contain personal or sensitive information and will be subject to appropriate purpose limitations, human review, access restrictions, security, retention and deletion controls.
We may disclose personal information where reasonably necessary for the purposes described in this policy, including to:
We will not ordinarily provide an identifiable candidate résumé or profile to a client without the candidate’s authority, except where otherwise permitted by law. We limit disclosure to information reasonably necessary for the relevant purpose.
Be primarily uses systems that store core recruitment, workforce and compliance information in Australia. Some technology, communication, recruitment, payroll, reference-checking, artificial-intelligence, hosting and support providers may process, access or store personal information outside Australia.
Overseas recipients are likely to be located in countries including the United States, United Kingdom, New Zealand, Singapore, India, the Philippines, Sri Lanka, South Africa, Canada, Germany, Ireland, Malaysia and other countries in which our service providers and their authorised subprocessors operate. The particular countries involved may vary according to the service, integration, check, communication method and support arrangement used.
Before disclosing personal information to an overseas recipient, Be will take reasonable steps in the circumstances to ensure that the recipient handles the information consistently with the APPs, unless an exception under the Privacy Act applies. Measures may include due diligence, contractual privacy and confidentiality obligations, access controls, security requirements, breach-notification obligations and restrictions on further disclosure.
Where permitted by law, Be may use personal information to communicate relevant employment opportunities, industry information, events and information about our services. We will not use sensitive information for direct marketing without consent.
A person may opt out at any time, free of charge, by using the unsubscribe facility in an electronic message or contacting us. Electronic marketing unsubscribe requests will be actioned within five working days. A person may also ask us to identify the source of personal information used for direct marketing where required by law.
Be will not disclose personal information to a partner for that partner’s independent marketing without appropriate consent or another lawful basis.
When a person visits a Be website or uses an online form, portal or application, we and our authorised providers may collect technical information including IP address, device and browser information, pages visited, referral source, form interactions and general usage data.
We may use cookies, pixels and similar technologies to operate and secure our websites, remember preferences, understand website use, measure communications and improve our services. Where advertising or remarketing technologies are used, appropriate notices and choices will be provided. Browser settings may be used to block or delete cookies, although this may affect website functionality.
Be takes reasonable steps to ensure that personal information it collects, uses and discloses is accurate, up to date, complete and relevant, having regard to the purpose of the handling. We may ask individuals, clients, referees or authorised third parties to verify or update information.
Be takes reasonable technical and organisational measures to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. Depending on the circumstances, these measures may include:
No method of electronic storage or transmission is completely secure. People should avoid sending highly sensitive documents through unapproved or insecure channels and should notify Be promptly if they suspect unauthorised access or disclosure.
Be retains personal information only for as long as reasonably necessary for the purpose for which it was collected, or as required by employment, taxation, superannuation, workers compensation, safety, child-protection, contractual, insurance, dispute and other legal obligations.
Retention periods vary according to the information and the person’s relationship with Be. Candidate information may be retained to consider the person for future opportunities where permitted and reasonably expected. When information is no longer required, Be will take reasonable steps to securely destroy or de-identify it, subject to any legal hold, dispute, complaint, claim, investigation or recordkeeping requirement.
Suspected breaches will be reported internally, contained, investigated and assessed promptly. Where Be has reasonable grounds to believe that an eligible data breach has occurred, Be will notify the Office of the Australian Information Commissioner and affected individuals in accordance with the Notifiable Data Breaches scheme.
Be may also notify clients, insurers, law-enforcement bodies, regulators or other parties where required or appropriate. We will take reasonable steps to reduce harm, remediate the incident and prevent recurrence.
A person may request access to personal information Be holds about them or ask us to correct information that is inaccurate, out of date, incomplete, irrelevant or misleading. Requests should be made to the Privacy Coordinator using the details in section 20.
We may need to verify identity before responding. We will respond within a reasonable period, ordinarily within 30 days. Be does not charge for making an access or correction request. If a reasonable cost is proposed for providing access, we will explain it before proceeding.
Access may be refused or limited where permitted by law, including where disclosure would unreasonably affect another person’s privacy, reveal confidential evaluative material, prejudice an investigation or legal proceeding, or be otherwise unlawful. Where required, we will provide written reasons and information about available complaint mechanisms.
If we decline to correct information, the person may ask us to associate a statement with the record indicating that the information is disputed.
Where lawful and practicable, people may make a general enquiry or interact with Be anonymously or using a pseudonym. Identification will ordinarily be required where Be needs to assess, represent, employ, place or pay a person, perform compliance checks, manage an incident or meet legal and client requirements.
A person who believes Be has mishandled their personal information may submit a written complaint to the Privacy Coordinator. The complaint should describe the concern, relevant dates or interactions and the outcome sought.
We will acknowledge the complaint, investigate it fairly and aim to provide a response within 30 days. If more time is reasonably required, we will explain the reason and provide an updated timeframe.
If the person is not satisfied with our response, they may contact the Office of the Australian Information Commissioner at www.oaic.gov.au. Depending on the matter, an individual may also be able to raise a concern with another regulator or professional body, including RCSA.
Privacy Coordinator
Be Recruitment Group
Level 1, 50 Miller Street, North Sydney NSW 2060
Email: [email protected]
Telephone: 1300 912 153
We may update this policy to reflect changes in law, technology, services and information-handling practices. The current version will be published on our website and will state its effective date. Material changes may also be communicated through other appropriate channels.
This schedule provides a high-level summary for transparency. It does not replace Be’s internal supplier register. Locations may vary by account configuration, feature, integration, support request and provider subprocessor arrangements.
| System | Primary location | Other likely processing or access |
|---|---|---|
| JobAdder | Australia (AWS Sydney) | Singapore may be used for some AI processing; other approved subprocessors may process information internationally. |
| Entire OnHire | Australia (AWS Sydney) | India may have authorised development or support access. Rackspace is also used; applicable location requires contractual confirmation. |
| Astute Payroll | Australia (AWS and Australian backups) | Astute contemplates overseas recipients; current applicable access and subprocessor countries require written confirmation. |
| WorkPro | Australia | Some checks, information sources and integrations may involve overseas recipients; locations depend on the service used. |
| Referoo | Australia appears to be the primary environment | Hosting, backup, support and complete subprocessor locations require written confirmation. |
| Google Workspace | Distributed Google infrastructure; Australian data-region controls only if available, purchased and configured | Support and maintenance may involve numerous countries, including Australia, US, India, Philippines and others. |
| Aircall | Australia for recordings/voicemails where Be’s APAC account configuration qualifies | Other account and analytics data may be hosted in the US; authorised support and AI processing may involve Australia, India, US and Microsoft infrastructure. |
| LinkedIn Recruiter and Hiring Assistant | United States / global infrastructure | International suppliers and support locations include the US, India, Ireland, Malaysia, China, Spain, Greece, the Netherlands and others. |
| Xero | Account- and service-dependent; not represented as Australia-only | Xero group companies and subprocessors operate in Australia, New Zealand, US, UK, Singapore, Canada, South Africa, India and other locations. |
| Wyzed LMS | Australian provider; hosting is not represented as Australia-only | Wyzed states that data may be hosted or processed in Australia, the United States, Europe and Asia. Its listed subprocessors include providers based in the United States. |
Version 6.1 – Reviewed 7 October 2026. Comprehensive rewrite covering expanded data categories, AI and automated processing, recordings and transcription, overseas access, marketing, website technologies, security, retention and breach response.