Privacy Policy

Last Updated: 7 October 2026

1. About this policy

Be Recruitment Group is committed to respecting privacy and protecting the personal information entrusted to us by candidates, workseekers, on-hired workers, employees, clients, referees, suppliers and other people with whom we interact.

This policy explains how Be Recruitment Group (ABN 82 626 742 505), operating under the registered business names Be Recruitment Company, Be Workforce Services and Solutions, and Be Executive (collectively, “Be”, “we”, “us” or “our”), collects, holds, uses and discloses personal information.

We manage personal information in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), the Notifiable Data Breaches scheme and other applicable privacy, employment, workplace, surveillance and recordkeeping laws.

This policy applies to our recruitment, executive search, labour-hire, workforce-management, employment, marketing and related services, including our websites, applications, communication channels and digital platforms.

2. Who this policy applies to

This policy applies to personal information relating to:

  • candidates, prospective candidates and workseekers;
  • on-hired workers, contractors and other people engaged through Be;
  • current and former employees, noting that the Privacy Act employee-records exemption may apply to some records directly related to an employment relationship;
  • client contacts, prospective clients and client representatives;
  • referees, emergency contacts and nominated representatives;
  • suppliers, professional advisers and business partners; and
  • website visitors and other people who communicate or interact with us.

Information about a company or organisation is not personal information unless it identifies, or is reasonably capable of identifying, an individual.

3. The kinds of personal information we collect

The information we collect depends on the nature of a person’s relationship and interactions with Be. It may include:

  • Identity and contact information: name, previous names, date of birth, address, email address, telephone number, photograph, signature, identity documents, visa and work-right information.
  • Employment and professional information: résumés, employment history, qualifications, skills, licences, accreditations, professional memberships, work samples, career interests, remuneration expectations, availability, preferred work type and location.
  • Recruitment and assessment information: applications, interview notes, screening responses, assessment results, referee details, references, background-check outcomes, candidate submissions, client feedback and recruitment decisions.
  • Workforce and employment information: contracts, placements, rosters, availability, timesheets, attendance, leave, training, supervision, performance, conduct, complaints, investigations, disciplinary matters and termination information.
  • Payroll and financial information: bank-account details, tax file number, superannuation information, pay rates, allowances, deductions, payroll, invoices and payment information.
  • Safety and insurance information: workplace incidents, hazards, injuries, workers compensation, insurance, fitness for work, rehabilitation and return-to-work information.
  • Communication records: emails, messages, call notes, recordings, video recordings, transcripts, meeting notes and AI-generated summaries where applicable.
  • Technical and website information: IP address, device and browser information, login and audit records, cookies, website activity, form interactions and communication preferences.
  • Client and business-contact information: position, employer, reporting relationships, workforce needs, role briefs, recruitment feedback, service information and relevant professional interactions.

3.1 Sensitive information

Some information handled by Be may be sensitive information under the Privacy Act. Depending on the role, placement, employment relationship or legal requirements, this may include:

  • health, disability, injury, medical, vaccination and reasonable-adjustment information;
  • criminal-record and police-check information;
  • racial or ethnic origin, including Aboriginal or Torres Strait Islander identity;
  • religious beliefs or affiliations where relevant and lawfully required;
  • professional or trade-association membership and trade-union membership;
  • sexual orientation or gender identity where voluntarily provided for a lawful diversity purpose;
  • biometric information used for identity verification; and
  • other information classified as sensitive under applicable law.

We collect sensitive information only where it is reasonably necessary for our functions or activities and with the person’s consent, unless collection is otherwise authorised or required by law. People are not required to provide voluntary diversity information and will not be disadvantaged for choosing not to provide it.

4. How we collect personal information

We generally collect personal information directly from the person, including through applications, registration and onboarding forms, interviews, telephone and video calls, email, websites, portals, mobile applications, timesheets and other service interactions.

We may also collect information from:

  • clients, referees, previous employers and nominated representatives;
  • job boards, recruitment platforms and publicly available professional sources, including LinkedIn and SEEK;
  • government agencies, regulatory databases and identity or work-right verification services;
  • police-check, reference-check, credential, medical and other screening providers;
  • insurers, claims managers, medical practitioners and rehabilitation providers;
  • our related entities, suppliers, contractors and authorised offshore service partners;
  • technology integrations and platforms selected or authorised by Be; and
  • other sources with consent or where authorised or required by law.

If we receive personal information that we did not request, we will determine whether we could lawfully have collected it. If not, we will take reasonable steps to destroy or de-identify it, provided it is lawful and reasonable to do so.

5. Why we collect, use and disclose personal information

We may collect, hold, use and disclose personal information for purposes including:

  • providing recruitment, executive search, labour-hire, workforce and related services;
  • assessing suitability, qualifications, experience, availability and work preferences;
  • matching and presenting candidates for roles, assignments and opportunities;
  • conducting interviews, reference checks, screening, probity and compliance checks;
  • employing, onboarding, rostering, supporting, paying and managing workers and employees;
  • meeting workplace health and safety, child-safety, safeguarding and client-compliance obligations;
  • managing incidents, complaints, investigations, conduct, performance, workers compensation and return to work;
  • communicating with candidates, workers, clients, referees and other stakeholders;
  • managing contracts, service delivery, quality, training, audits, insurance, reporting and business administration;
  • operating, securing, improving and integrating our systems, websites and services;
  • using approved technology and artificial intelligence as described in this policy;
  • preventing fraud, misuse, unauthorised access and security incidents;
  • sending relevant employment opportunities, industry information or service communications where permitted by law;
  • complying with legal, regulatory, taxation, employment and contractual obligations; and
  • establishing, exercising or defending legal rights and claims.

Where practicable, we will explain the main purpose of collection at or before the time information is collected through an appropriate privacy collection notice.

6. If personal information is not provided

People may choose not to provide personal information. However, without information that is reasonably required, Be may be unable to assess an application, conduct mandatory checks, present a person for work, employ or pay a worker, meet client or legal requirements, investigate an issue or provide the requested service.

7. Artificial intelligence and automated processing

Be may use approved technology, including artificial intelligence (AI), automated matching tools and embedded software features, to support recruitment, administration, communications, transcription, compliance, skills matching, information organisation and service improvement.

Computer programs may assist Be personnel to:

  • search for and identify people who may be relevant to an opportunity;
  • match information against documented role or assignment criteria;
  • organise, classify, summarise or retrieve information;
  • prepare draft communications, interview materials, notes or administrative records;
  • transcribe calls or meetings and prepare summaries or action items; and
  • support compliance, security, quality-assurance and workflow activities.

Be does not use solely automated processing to make final decisions to hire, place, reject, discipline or terminate a person. Appropriately authorised personnel remain responsible for reviewing material outputs, considering relevant evidence and making final decisions. AI output is not treated as independent evidence about a candidate or worker.

Where a computer program uses personal information to make, or undertake something substantially and directly related to making, a decision that could reasonably be expected to significantly affect a person’s rights or interests, Be will provide the transparency required by applicable law. A person may contact our Privacy Coordinator to ask about material automated processing involving their information, raise a concern or request human review where appropriate.

AI may assist our staff with tasks such as drafting, summarising, searching, sourcing, matching, administration and workflow support. AI is an assistant, not a decision-maker. We do not permit an AI system to make final decisions about a person’s application, suitability, employment, engagement or access to our services, and we do not use AI to make solely automated decisions that have a legal or similarly significant effect on a person.

Recruiters and other authorised staff remain responsible for applying job-related criteria, checking the accuracy and relevance of AI-assisted outputs, considering context, managing bias and making the final decision. We do not permit personal, sensitive, candidate-identifiable, client-confidential or proprietary information to be entered into an unapproved AI system or workflow.

Material AI uses are assessed and governed under our Artificial Intelligence Use Policy and AI Use Register. These controls include approval before use, privacy and security assessment, defined permitted and prohibited uses, human oversight and override, transparency or consent where appropriate, testing and monitoring, incident and complaint handling, and review when a tool, integration, data flow or use materially changes.

We prohibit unapproved automated candidate rejection or ranking, emotion or personality inference from voice, image or video, covert recording or transcription, and the use of free or public AI tools to process candidate or client information. If an AI-assisted process materially affects you, you may contact us to request information, raise a concern or ask for human review.

8. Call recording, transcription and monitoring

Be may record or transcribe approved telephone calls, video meetings or interviews for quality assurance, training, compliance, dispute resolution, accurate recordkeeping and service improvement.

Participants will be notified before recording or transcription begins. Where consent is required, Be will obtain consent from all participants. A participant may ask for recording or transcription to be stopped, and an alternative method of taking notes will be offered where reasonably practicable.

Approved technology may create recordings, transcripts, summaries, topics or action items. These records may contain personal or sensitive information and will be subject to appropriate purpose limitations, human review, access restrictions, security, retention and deletion controls.

9. Disclosure of personal information

We may disclose personal information where reasonably necessary for the purposes described in this policy, including to:

  • clients and prospective clients considering a person for a role or assignment;
  • referees and previous employers;
  • related entities and authorised Be personnel;
  • payroll, superannuation, banking, accounting, insurance and professional-advisory providers;
  • recruitment, job-board, workforce-management, communication, cloud, AI and IT-service providers;
  • identity, work-right, reference, police, credential, medical and compliance-checking providers;
  • insurers, claims managers, rehabilitation providers and medical practitioners;
  • government agencies, regulators, law-enforcement bodies, courts and tribunals;
  • auditors, legal advisers and other professional advisers; and
  • other persons where the individual has consented or disclosure is authorised or required by law.

We will not ordinarily provide an identifiable candidate résumé or profile to a client without the candidate’s authority, except where otherwise permitted by law. We limit disclosure to information reasonably necessary for the relevant purpose.

10. Overseas disclosures and access

Be primarily uses systems that store core recruitment, workforce and compliance information in Australia. Some technology, communication, recruitment, payroll, reference-checking, artificial-intelligence, hosting and support providers may process, access or store personal information outside Australia.

Overseas recipients are likely to be located in countries including the United States, United Kingdom, New Zealand, Singapore, India, the Philippines, Sri Lanka, South Africa, Canada, Germany, Ireland, Malaysia and other countries in which our service providers and their authorised subprocessors operate. The particular countries involved may vary according to the service, integration, check, communication method and support arrangement used.

Before disclosing personal information to an overseas recipient, Be will take reasonable steps in the circumstances to ensure that the recipient handles the information consistently with the APPs, unless an exception under the Privacy Act applies. Measures may include due diligence, contractual privacy and confidentiality obligations, access controls, security requirements, breach-notification obligations and restrictions on further disclosure.

11. Direct marketing and opportunity communications

Where permitted by law, Be may use personal information to communicate relevant employment opportunities, industry information, events and information about our services. We will not use sensitive information for direct marketing without consent.

A person may opt out at any time, free of charge, by using the unsubscribe facility in an electronic message or contacting us. Electronic marketing unsubscribe requests will be actioned within five working days. A person may also ask us to identify the source of personal information used for direct marketing where required by law.

Be will not disclose personal information to a partner for that partner’s independent marketing without appropriate consent or another lawful basis.

12. Websites, cookies and analytics

When a person visits a Be website or uses an online form, portal or application, we and our authorised providers may collect technical information including IP address, device and browser information, pages visited, referral source, form interactions and general usage data.

We may use cookies, pixels and similar technologies to operate and secure our websites, remember preferences, understand website use, measure communications and improve our services. Where advertising or remarketing technologies are used, appropriate notices and choices will be provided. Browser settings may be used to block or delete cookies, although this may affect website functionality.

13. Information quality

Be takes reasonable steps to ensure that personal information it collects, uses and discloses is accurate, up to date, complete and relevant, having regard to the purpose of the handling. We may ask individuals, clients, referees or authorised third parties to verify or update information.

14. Security of personal information

Be takes reasonable technical and organisational measures to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. Depending on the circumstances, these measures may include:

  • role-based access and least-privilege permissions;
  • multi-factor authentication and password controls;
  • encryption and secure transmission methods;
  • approved-system, device and software requirements;
  • staff privacy, confidentiality and security training;
  • supplier due diligence and contractual controls;
  • logging, monitoring, backups and incident-response processes;
  • secure disposal and data-culling processes; and
  • periodic review of access, systems, risks and controls.

No method of electronic storage or transmission is completely secure. People should avoid sending highly sensitive documents through unapproved or insecure channels and should notify Be promptly if they suspect unauthorised access or disclosure.

15. Retention and disposal

Be retains personal information only for as long as reasonably necessary for the purpose for which it was collected, or as required by employment, taxation, superannuation, workers compensation, safety, child-protection, contractual, insurance, dispute and other legal obligations.

Retention periods vary according to the information and the person’s relationship with Be. Candidate information may be retained to consider the person for future opportunities where permitted and reasonably expected. When information is no longer required, Be will take reasonable steps to securely destroy or de-identify it, subject to any legal hold, dispute, complaint, claim, investigation or recordkeeping requirement.

16. Data breaches

Suspected breaches will be reported internally, contained, investigated and assessed promptly. Where Be has reasonable grounds to believe that an eligible data breach has occurred, Be will notify the Office of the Australian Information Commissioner and affected individuals in accordance with the Notifiable Data Breaches scheme.

Be may also notify clients, insurers, law-enforcement bodies, regulators or other parties where required or appropriate. We will take reasonable steps to reduce harm, remediate the incident and prevent recurrence.

17. Access and correction

A person may request access to personal information Be holds about them or ask us to correct information that is inaccurate, out of date, incomplete, irrelevant or misleading. Requests should be made to the Privacy Coordinator using the details in section 20.

We may need to verify identity before responding. We will respond within a reasonable period, ordinarily within 30 days. Be does not charge for making an access or correction request. If a reasonable cost is proposed for providing access, we will explain it before proceeding.

Access may be refused or limited where permitted by law, including where disclosure would unreasonably affect another person’s privacy, reveal confidential evaluative material, prejudice an investigation or legal proceeding, or be otherwise unlawful. Where required, we will provide written reasons and information about available complaint mechanisms.

If we decline to correct information, the person may ask us to associate a statement with the record indicating that the information is disputed.

18. Anonymity and pseudonymity

Where lawful and practicable, people may make a general enquiry or interact with Be anonymously or using a pseudonym. Identification will ordinarily be required where Be needs to assess, represent, employ, place or pay a person, perform compliance checks, manage an incident or meet legal and client requirements.

19. Privacy complaints

A person who believes Be has mishandled their personal information may submit a written complaint to the Privacy Coordinator. The complaint should describe the concern, relevant dates or interactions and the outcome sought.

We will acknowledge the complaint, investigate it fairly and aim to provide a response within 30 days. If more time is reasonably required, we will explain the reason and provide an updated timeframe.

If the person is not satisfied with our response, they may contact the Office of the Australian Information Commissioner at www.oaic.gov.au. Depending on the matter, an individual may also be able to raise a concern with another regulator or professional body, including RCSA.

20. Contact us

Privacy Coordinator
Be Recruitment Group
Level 1, 50 Miller Street, North Sydney NSW 2060
Email: [email protected]
Telephone: 1300 912 153

21. Changes to this policy

We may update this policy to reflect changes in law, technology, services and information-handling practices. The current version will be published on our website and will state its effective date. Material changes may also be communicated through other appropriate channels.

22. Related documents

  • Artificial Intelligence Use Policy and AI Use Register;
  • Data Breach Response Plan;
  • Data Retention and Disposal Schedule;
  • Information Security and IT Security policies;
  • Candidate and On-Hired Worker Privacy Collection Notices;
  • Call Recording and AI Transcription Notice; and
  • Third-Party Provider and Overseas Data Register.

Schedule 1 – Key systems and likely data locations

This schedule provides a high-level summary for transparency. It does not replace Be’s internal supplier register. Locations may vary by account configuration, feature, integration, support request and provider subprocessor arrangements.

SystemPrimary locationOther likely processing or access
JobAdderAustralia (AWS Sydney)Singapore may be used for some AI processing; other approved subprocessors may process information internationally.
Entire OnHireAustralia (AWS Sydney)India may have authorised development or support access. Rackspace is also used; applicable location requires contractual confirmation.
Astute PayrollAustralia (AWS and Australian backups)Astute contemplates overseas recipients; current applicable access and subprocessor countries require written confirmation.
WorkProAustraliaSome checks, information sources and integrations may involve overseas recipients; locations depend on the service used.
ReferooAustralia appears to be the primary environmentHosting, backup, support and complete subprocessor locations require written confirmation.
Google WorkspaceDistributed Google infrastructure; Australian data-region controls only if available, purchased and configuredSupport and maintenance may involve numerous countries, including Australia, US, India, Philippines and others.
AircallAustralia for recordings/voicemails where Be’s APAC account configuration qualifiesOther account and analytics data may be hosted in the US; authorised support and AI processing may involve Australia, India, US and Microsoft infrastructure.
LinkedIn Recruiter and Hiring AssistantUnited States / global infrastructureInternational suppliers and support locations include the US, India, Ireland, Malaysia, China, Spain, Greece, the Netherlands and others.
XeroAccount- and service-dependent; not represented as Australia-onlyXero group companies and subprocessors operate in Australia, New Zealand, US, UK, Singapore, Canada, South Africa, India and other locations.
Wyzed LMSAustralian provider; hosting is not represented as Australia-onlyWyzed states that data may be hosted or processed in Australia, the United States, Europe and Asia. Its listed subprocessors include providers based in the United States.


Version 6.1 – Reviewed 7 October 2026. Comprehensive rewrite covering expanded data categories, AI and automated processing, recordings and transcription, overseas access, marketing, website technologies, security, retention and breach response.