Cavuno
  • Features
  • Examples
  • Documentation
  • Blog
  • Tools
  • Pricing
  • Contact
Sign InSign Up
Cavuno

AI job board software that runs itself

Product
  • Features
  • Integrations
  • Examples
  • Documentation
  • Tools
  • Blog
Compare
  • Alternatives
  • Comparisons
Company
  • About Us
  • Contact
  • Trust Center
  • Status

© Copyright 2026 Cavuno. All Rights Reserved.

Terms of ServicePrivacy PolicyCookie PolicySecuritySubprocessorsData Processing Agreement

Data Processing Agreement

How we process data on behalf of our customers

Last updated: 1 March 2026

Introduction

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Wollemia Pty Ltd (ABN 35 692 226 323) ("Processor", "we", "us") and the customer ("Controller", "you") who uses the Cavuno platform to operate a job board. By using Cavuno, you agree to the terms of this DPA.

This DPA governs the processing of personal data that you collect from end users of your job board and that we process on your behalf to provide the Cavuno platform.

Definitions

The following terms have the meanings set out below. Where not defined here, terms have the meanings given in the Australian Privacy Act 1988, the EU General Data Protection Regulation (GDPR), or our Terms of Service.

  • "Controller" means the customer who determines the purposes and means of processing personal data — that is, you, the job board operator.
  • "Processor" means Wollemia Pty Ltd, which processes personal data on behalf of the Controller to provide the Cavuno platform.
  • "Personal data" means any information relating to an identified or identifiable natural person, including names, email addresses, IP addresses, and device identifiers.
  • "Data subject" means an identified or identifiable natural person whose personal data is processed — for example, a job seeker who subscribes to job alerts on your board.
  • "Subprocessor" means a third party engaged by the Processor to process personal data on behalf of the Controller.
  • "Data breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.

Scope and purpose of processing

We process personal data solely to provide and maintain the Cavuno platform on your behalf. This includes hosting your job board, delivering job alert emails, processing search queries, generating analytics, and any other functionality available through the platform.

The types of personal data we process on your behalf include:

  • Job alert subscriber data — email addresses, consent records, and subscription preferences (job functions, locations, salary filters, frequency)
  • Candidate profile data — email addresses, hashed passwords, display names, biographies, avatars, headlines, locations, job search status, work experience, education history, skills, and language proficiency
  • Authentication and session data — session tokens, IP addresses and user-agent strings collected at login, OAuth provider identifiers and email addresses for social sign-in
  • Job poster contact data — contact names and email addresses submitted with job listing orders
  • Visitor analytics — pseudonymised page views, referral sources, and event data collected through first-party analytics. No personally identifiable visitor data is stored in our database.

The categories of data subjects whose data we process include job seekers, candidate profile holders, job alert subscribers, job posters, and visitors to your job board. Cavuno does not process or store job application data — job listings redirect applicants to external application URLs controlled by the employer.

Processing instructions

We process personal data only on your documented instructions, which are defined by your use of the Cavuno platform and the features you enable. We will not process personal data for any purpose other than providing the service to you.

If we believe an instruction from you infringes applicable data protection law, we will inform you without delay.

Processor obligations

We commit to the following obligations when processing personal data on your behalf:

  • Process personal data only in accordance with your documented instructions and this DPA
  • Ensure that persons authorised to process personal data are bound by obligations of confidentiality
  • Implement appropriate technical and organisational security measures as described in our Security page
  • Assist you in responding to data subject requests (access, rectification, erasure, portability, restriction, and objection) using the tools available in the Cavuno platform
  • Assist you in meeting your obligations regarding data breach notification, data protection impact assessments, and prior consultation with supervisory authorities
  • Delete or return all personal data to you upon termination of the service, at your choice, and delete existing copies unless retention is required by law

Subprocessors

You authorise us to engage the subprocessors listed on our Subprocessors page to process personal data on your behalf. This page is maintained as the current list of approved subprocessors.

We will notify you of any intended changes to the list of subprocessors by updating the Subprocessors page. You may object to a new subprocessor by contacting us within 14 days of the update. If we cannot reasonably accommodate your objection, either party may terminate the affected service.

International data transfers

Personal data processed on your behalf may be transferred to and processed in countries outside your jurisdiction, including the United States and Germany, as detailed on our Subprocessors page.

Where personal data is transferred outside the European Economic Area or the United Kingdom, we ensure that appropriate safeguards are in place. We can provide EU Standard Contractual Clauses (SCCs) or UK International Data Transfer Agreement upon request.

For transfers from Australia, we take reasonable steps to ensure that overseas recipients comply with the Australian Privacy Principles, consistent with our obligations under APP 8.

Security measures

We implement and maintain appropriate technical and organisational measures to protect personal data against unauthorised or unlawful processing, accidental loss, destruction, or damage. A detailed description of our security measures is available on our Security page. These measures include encryption in transit and at rest, multi-tenant data isolation using row-level security, access controls governed by the principle of least privilege, and automated vulnerability scanning.

Data breach notification

In the event of a data breach affecting personal data processed on your behalf, we will notify you without undue delay and in any event within 72 hours of becoming aware of the breach.

Our notification will include the nature of the breach, the categories and approximate number of data subjects affected, the likely consequences, and the measures taken or proposed to address the breach.

We will cooperate with you and provide reasonable assistance in investigating the breach and meeting your notification obligations to supervisory authorities and data subjects.

Data subject rights

We will assist you in fulfilling your obligations to respond to data subject requests. The Cavuno platform provides tools to access, export, and delete subscriber and applicant data. Where a data subject contacts us directly with a request relating to your job board, we will promptly refer them to you unless otherwise instructed.

Audits

We will make available to you the information necessary to demonstrate compliance with this DPA and allow for and contribute to audits and inspections conducted by you or an auditor mandated by you.

Audit requests must be submitted in writing with reasonable notice. We may charge a reasonable fee for audits that go beyond reviewing our existing documentation and certifications. We will cooperate in good faith to address any findings.

Duration and termination

This DPA takes effect when you begin using the Cavuno platform and remains in effect for the duration of our provision of the service to you.

Upon termination of the service, we will delete all personal data processed on your behalf within 30 days, unless retention is required by applicable law (for example, billing records retained under Australian tax law). Backup copies may persist for up to 30 days after deletion from primary systems.

You may request a copy of your data before termination using the export tools available in the platform, or by contacting us directly.

Return and deletion of data

Upon termination or expiry of the service, and at your written request, we will either return all personal data to you in a structured, commonly used, and machine-readable format, or delete it. The choice is yours.

We will confirm deletion in writing upon request. Any personal data that we are required to retain by law will be isolated and protected from further processing.

Governing law

This DPA is governed by the laws of New South Wales, Australia, consistent with our Terms of Service. For data subjects in the European Economic Area, this DPA is also subject to the GDPR. For data subjects in the United Kingdom, this DPA is also subject to the UK GDPR.

Contact

For questions about this DPA or to exercise any rights under it, please contact us:

  • Email: hi@cavuno.com
  • Entity: Wollemia Pty Ltd (ABN 35 692 226 323)
  • Location: Sydney, New South Wales, Australia