Data Processing Agreement
How we process data on behalf of our customers
Last updated: 4 August 2026
Introduction
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Wollemia Pty Ltd (ABN 35 692 226 323) ("Processor", "we", "us") and the customer ("Controller", "you") who uses the Cavuno platform to operate a job board. By using Cavuno, you agree to the terms of this DPA.
This DPA governs the processing of personal data that you collect from end users of your job board and that we process on your behalf to provide the Cavuno platform.
Definitions
The following terms have the meanings set out below. Where not defined here, terms have the meanings given in the Australian Privacy Act 1988, the EU General Data Protection Regulation (GDPR), or our Terms of Service.
- "Controller" means the customer who determines the purposes and means of processing personal data — that is, you, the job board operator.
- "Processor" means Wollemia Pty Ltd, which processes personal data on behalf of the Controller to provide the Cavuno platform.
- "Personal data" means any information relating to an identified or identifiable natural person, including names, email addresses, IP addresses, and device identifiers.
- "Data subject" means an identified or identifiable natural person whose personal data is processed — for example, an applicant, candidate profile holder, job alert subscriber, employer user, or job board visitor.
- "Subprocessor" means a third party engaged by the Processor to process personal data on behalf of the Controller.
- "Data breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.
Scope and purpose of processing
We process personal data solely to provide and maintain the Cavuno platform on your behalf and on your documented instructions. This includes hosting your job board, operating candidate profiles and native job applications, storing CVs, parsing resumes when that feature is used, delivering transactional, job-alert, and authorised marketing emails, delivering selected webhook events, processing search queries, generating analytics, and generating customer-authorised data exports.
The types of personal data we process on your behalf include:
- Subscription and marketing-permission data — email addresses, optional display names, subscription preferences, Board-defined purposes and disclosure versions, confirmation-request state and token hashes, grant or withdrawal state and evidence, and protected keyed identifiers used to enforce suppression after withdrawal, provider feedback, or erasure
- Candidate profile data — email addresses, hashed passwords, display names, biographies, avatars, headlines, locations, job search status, work authorisation, social links, work experience, education history, skills, language proficiency, uploaded resumes, and structured data extracted from resumes
- Authentication and session data — session tokens, IP addresses and user-agent strings collected at login, OAuth provider identifiers and email addresses for social sign-in
- Job poster contact data — contact names and email addresses submitted with job listing orders
- Visitor and account analytics — page views, referral sources, event data, IP and device information and, for signed-in product analytics, account user identifiers or email addresses
- Application data — candidate names and email addresses, headlines, locations, cover notes, an uploaded CV or resume, application stage and source, timestamps, employer notes, and application activity history
The categories of data subjects whose data we process include applicants, job seekers, candidate profile holders, job alert subscribers, job posters, employer users, and visitors to your job board. Cavuno processes and stores application data when the native application feature is used. Listings configured with an external application URL instead direct applicants to a service controlled by the employer.
Processing instructions
We process personal data only on your documented instructions, which are defined by your use of the Cavuno platform and the features you enable. We will not process personal data for any purpose other than providing the service to you.
You decide whether to enable marketing-permission capture and which webhook endpoints or providers receive your data. You are responsible for your disclosure, privacy-policy link, lawful basis, recipients, and instructions. Cavuno records and enforces the configured workflow but does not approve or warrant your copy or use.
Processor obligations
We commit to the following obligations when processing personal data on your behalf:
- Process personal data only in accordance with your documented instructions and this DPA
- Ensure that persons authorised to process personal data are bound by obligations of confidentiality
- Implement appropriate technical and organisational security measures as described in our Security page
- Assist you in responding to data subject requests (access, rectification, erasure, portability, restriction, and objection) using the tools available in the Cavuno platform
- Assist you in meeting your obligations regarding data breach notification, data protection impact assessments, and prior consultation with supervisory authorities
- On your documented instruction at termination, provide the available self-service deletion controls and manually coordinate any separate return request or deletion assistance within an agreed scope, format, and timeframe, unless retention is required by law
Subprocessors
You authorise us to engage the subprocessors listed on our Subprocessors page to process personal data on your behalf. This page is maintained as the current list of approved subprocessors.
We will notify you of any intended changes to the list of subprocessors by updating the Subprocessors page. You may object to a new subprocessor by contacting us within 14 days of the update. If we cannot reasonably accommodate your objection, either party may terminate the affected service.
International data transfers
Personal data processed on your behalf is currently processed primarily in the United States, including through infrastructure in AWS us-east-1, Ashburn, Virginia, and other US regions detailed on our Subprocessors page. Cavuno does not currently offer EU-only data residency.
Before processing personal data subject to EEA or UK transfer restrictions, you must contact us to confirm and execute the transfer mechanism applicable to your use. EU Standard Contractual Clauses (SCCs) or a UK transfer addendum are not incorporated automatically into this online DPA unless we provide and execute them with you.
For transfers from Australia, we take reasonable steps to ensure that overseas recipients comply with the Australian Privacy Principles, consistent with our obligations under APP 8.
Security measures
We implement and maintain appropriate technical and organisational measures to protect personal data against unauthorised or unlawful processing, accidental loss, destruction, or damage. A detailed description of our security measures is available on our Security page. These measures include TLS encryption in transit, provider-managed encryption at rest, multi-tenant data isolation enforced through account-scoped authorisation checks, role-based access controls, least-privilege production access, and vulnerability monitoring.
Data breach notification
In the event of a data breach affecting personal data processed on your behalf, we will notify you without undue delay and in any event within 72 hours of becoming aware of the breach.
Our notification will include the nature of the breach, the categories and approximate number of data subjects affected, the likely consequences, and the measures taken or proposed to address the breach.
We will cooperate with you and provide reasonable assistance in investigating the breach and meeting your notification obligations to supervisory authorities and data subjects.
Data subject rights
We will provide reasonable assistance so that you can fulfil data subject requests for access, rectification, erasure, portability, restriction, and objection. Available Cavuno workflows can delete or update subscriber, profile, and application records, and deleting a job board starts deletion of its applicant data. Self-service exports cover jobs, companies, employers, candidates, subscribers, blog posts, authors, and tags; candidate resumes are retrieved separately through an authenticated route, and applications are not included in those exports. Some applicant-specific requests therefore still require support assistance. Where a data subject contacts us directly about your job board, we will promptly refer the request to you unless applicable law or your documented instruction requires otherwise.
Audits
We will make available to you the information necessary to demonstrate compliance with this DPA and allow for and contribute to audits and inspections conducted by you or an auditor mandated by you.
Audit requests must be submitted in writing with reasonable notice. We may charge a reasonable fee for audits that go beyond reviewing our existing documentation and certifications. We will cooperate in good faith to address any findings.
Duration and termination
This DPA takes effect when you begin using the Cavuno platform and remains in effect for the duration of our provision of the service to you.
Upon termination of the service, self-service account and job-board deletion removes access and starts a tracked asynchronous purge of tenant data and configured provider resources. The process retries failures and records completion internally. It is subject to legal-retention exceptions and provider backup lifecycles.
Before termination, self-service CSV exports are available for jobs, companies, employers, candidates, subscribers, blog posts, authors, and tags. Candidate resumes are downloaded separately through an authenticated route, and applications are excluded. Asynchronous export files are kept in protected existing storage and deleted 30 days after the export operation reaches a terminal state, subject to the backup lifecycle described in this DPA. You may contact us to coordinate a return request with a different available scope or format.
Return and deletion of data
Account and job-board deletion is available as a self-service control that initiates a tracked asynchronous purge. A separately coordinated return request remains available through support. Self-service exports are category-specific rather than a single whole-account package, and they do not include applications; candidate resumes are downloaded separately through an authenticated route.
Deletion completion is recorded internally after required local and configured-provider steps succeed. The direct requester identity is removed from a completed deletion receipt, and that receipt is deleted after one year. Limited personal data that applicable law requires us to retain will be isolated from ordinary product processing and protected for the required retention period. Retained security evidence is de-identified, and deleted data may remain temporarily in protected provider backups until the applicable backup lifecycle expires.
Governing law
This DPA is governed by the laws of New South Wales, Australia, consistent with our Terms of Service. For data subjects in the European Economic Area, this DPA is also subject to the GDPR. For data subjects in the United Kingdom, this DPA is also subject to the UK GDPR.
Contact
For questions about this DPA or to exercise any rights under it, please contact us:
- Email: hi@cavuno.com
- Entity: Wollemia Pty Ltd (ABN 35 692 226 323)
- Location: Sydney, New South Wales, Australia