Privacy Policy
Our privacy policy and how we use your data
Last updated: 4 August 2026
Introduction
Wollemia Pty Ltd (ABN 35 692 226 323) ("we", "us", "our") operates Cavuno (cavuno.com). This policy explains how we collect, use, and protect personal information in accordance with the Australian Privacy Act 1988 and the Australian Privacy Principles (APPs). This policy also covers data collected on job boards operated by Cavuno customers on behalf of their organisations. For information about cookies and tracking technologies, please see our Cookie Policy.
Data controller and processor roles
Wollemia Pty Ltd is the data controller for personal information collected through the Cavuno platform, including account data, billing information, and usage analytics.
For personal information collected from visitors to customer-operated job boards, including candidate profiles, job applications, CVs, subscriptions, and marketing permissions, the customer is generally the data controller and Wollemia Pty Ltd acts as a data processor. Customers are responsible for ensuring they have an appropriate legal basis, configuring their job board and disclosures, informing end users, and selecting any webhook endpoint or other recipient to which they instruct Cavuno to send that data.
Information we collect
Account information
When you create an account, we collect your name, email address, and password. If you create or join a team account, we also collect your team or organisation name.
Job board configuration
We collect information related to your job board setup, including site name, domain, branding preferences, configuration settings, analytics tracking IDs, custom domain settings, and SEO metadata.
Job and company data
We store job listings and company profiles that you create or upload to the platform, including AI-enriched content, vector embeddings derived from this data, and associated metadata.
AI builder attachments
When you attach files or images to the AI website builder, they are stored privately in your workspace and are accessible only to members of your team. The contents of attachments are shared with our AI model providers to process your build requests — see our Subprocessors page. We remove photo metadata, including location data, from images when they are attached, and attachments that are never sent with a message are deleted automatically.
AI builder dictation
When you use the microphone in the AI website builder, your voice is streamed directly from your browser to xAI (our speech-to-text provider) and transcribed into editable text. The audio never passes through Cavuno's servers and is not stored by Cavuno. xAI processes the audio in the United States and does not retain it (zero data retention) or use it to train models — see our Subprocessors page.
Subscriptions and marketing permissions
When a person subscribes to job alerts or a Board-enabled email-marketing purpose, we process their email address, optional display name, subscription preferences, the Board's purpose and disclosure version, and the request, grant, or withdrawal record needed to operate the feature. We may also process request metadata and use a protected keyed identifier to enforce unsubscribe and erasure suppression. The Board decides whether to enable email-marketing capture, supplies its disclosure and privacy-policy link, and is responsible for its lawful use.
Candidate profiles and resumes
When a job seeker creates a candidate profile, we may store their name, email address, headline, biography, location, social links, work authorisation, job search status, skills, languages, work experience, education, and an uploaded resume or CV. Resume files may be parsed into structured profile data.
Job applications
When a job board uses Cavuno's native application feature, we store application data such as the candidate's name and email address, headline, location, cover note, application status and history, employer notes, and an uploaded CV or resume. Some listings instead direct applicants to an external employer website, whose privacy practices are controlled by that employer.
Billing information
Payment details are processed and stored by Stripe. Stripe stores your payment method details, billing address, and transaction history. We store a reference to your Stripe customer ID and subscription status. We do not store full credit card numbers.
Usage and analytics data
We collect information about how you use the platform, including pages visited, features used, device information, IP address, browser type, referral source, geographic region (derived from IP address), session duration, and interactions with specific features. For signed-in product analytics, a provider may also receive an account user ID or email address. Analytics data is pseudonymised or aggregated where the applicable feature and provider allow it.
Location data
When you use location-based features such as job location search, we process location queries through Mapbox. We do not store precise geolocation data.
How we use information
We use the information we collect for the following purposes:
- Providing and operating the Cavuno platform
- AI-powered enrichment of job listings and company profiles (via OpenAI, Anthropic, and Voyage AI)
- Powering semantic search functionality (via Qdrant vector database)
- Sending transactional emails and job alerts (via Resend)
- Analytics and service improvement (via Tinybird)
- Processing payments and managing subscriptions (via Stripe)
- Communicating service updates, changes, and support responses
- Generating logos and brand assets using AI (via OpenAI)
- Geocoding and location search for job listings (via Mapbox)
- Managing custom domains and TLS certificates (via Caddy on Hetzner)
We process data using artificial intelligence services from OpenAI and Anthropic. When an AI feature is used, relevant content may be sent to the provider used for that feature. Cavuno currently uses OpenAI for resume parsing and OCR, which may require sending resume text or images for structured extraction. Anthropic is used for other content features, not resume parsing. We do not send account passwords to AI providers. OpenAI states that API data is not used to train its models by default; however, its standard abuse-monitoring logs may retain prompts and outputs for up to 30 days unless different approved data controls apply. AI providers may process this data on servers outside Australia.
Legal basis for processing
We process personal information on the following legal bases:
- Contractual necessity — to provide and operate the Cavuno platform, manage your account, process payments, and deliver the services you have subscribed to.
- Legitimate interest — for analytics and service improvement, error monitoring, security measures, and fraud prevention, where these interests are not overridden by your rights.
- Consent — for marketing cookies, advertising tracking, and optional communications. You may withdraw consent at any time.
- Legal obligation — to retain billing records as required by Australian tax law and to comply with the Notifiable Data Breaches scheme.
Third-party services
We share data with third-party service providers to operate and improve Cavuno. Each provider processes data under the applicable contract and its privacy terms. For our current public list of identified subprocessors, their purposes, and their processing regions, see our Subprocessors page.
Bot and abuse prevention
To protect our support chat and public forms from spam and automated abuse, we use Cloudflare Turnstile. Turnstile runs invisibly and may collect device and connection information, including your IP address and browser characteristics, to distinguish real visitors from bots. Cloudflare processes this information as a data processor on our behalf, as described in the Cloudflare Turnstile Privacy Addendum.
Data retention and deletion
Account data is retained while your account is active and until an applicable deletion request has been completed, except where we must retain information for legal, security, fraud-prevention, or dispute-resolution purposes.
Job board content (listings, company profiles, and blog posts) is retained while the service is active and until it is deleted by the customer or as part of a supported termination or deletion request.
Job-alert subscriptions and marketing-permission records are retained with the Board account until they are deleted or a valid erasure request is completed. Marketing confirmation links expire after 24 hours. On erasure, we withdraw permission and remove the raw email address, display name, permission evidence, and opt-in request, while retaining a protected keyed identifier and minimum state needed to prevent accidental re-entry or comply with applicable law.
Structured candidate profile data is retained until the profile or account is deleted. If a candidate chooses not to keep an uploaded resume on file, the original profile resume is deleted after successful parsing; the structured profile information extracted from it remains until the profile is updated or deleted. After successful parsing, a resume the candidate chose to keep remains until it is replaced or deleted. Resume files are also deleted when parsing permanently fails.
Candidates can withdraw and delete an application while it remains editable. Deleting a job board also starts deletion of its applications, notes, activity history, and uploaded application resumes. Other applicant-specific deletion requests may require support assistance. Job board operators are responsible for defining and documenting their applicant-retention process and using the available deletion controls.
AI providers may retain service or abuse-monitoring records under their own contractual data controls. OpenAI's standard API abuse-monitoring logs may retain inputs and outputs for up to 30 days unless different approved controls apply.
Analytics and usage-data retention varies by provider, data type, and configured feature. Aggregated reports may be retained for service measurement, while identifiable account analytics is retained according to the applicable provider settings and deletion process.
Billing records may be retained for up to 7 years as required by Australian tax law.
Vector embeddings derived from your content are deleted when the source content is deleted.
Where a customer enables outbound webhooks, the event payload and per-attempt delivery record are retained for 30 days from the event, so deliveries remain inspectable and replayable. At that point the stored payload and attempt detail are deleted and only narrow delivery metadata, which contains no payload or response body, is kept.
Deleted data may remain temporarily in provider-managed backups for the period required by the applicable provider's backup and disaster-recovery processes. Backup copies are not used for ordinary product processing and are overwritten or deleted in the normal backup lifecycle.
You may request deletion of your data at any time by contacting us at hi@cavuno.com.
Data security
We implement reasonable security measures to protect your information, including:
- Encryption of data in transit using TLS
- Encryption of data at rest
- Logical data isolation between tenants
- Role-based access controls
- Regular security reviews
- Multi-factor authentication support for Cavuno customer and operator accounts
- Automated vulnerability monitoring
- Signature verification on webhooks Cavuno receives, and HMAC-SHA256 signing of every outbound webhook Cavuno sends, so you can verify each delivery came from us
We require our third-party service providers to maintain appropriate security measures. Access to production systems is restricted to authorised personnel and governed by the principle of least privilege.
However, no method of electronic transmission or storage is completely secure, and we cannot guarantee absolute security.
International data transfers
Our service is hosted and operated using third-party providers that may process your data outside of Australia, including in the United States. Where your data is transferred internationally, we take reasonable steps to ensure that the recipients of your information maintain data protection standards consistent with Australian Privacy Principle 8.
Cavuno's current primary data processing is in the United States, including Convex on AWS us-east-1, Hetzner in Ashburn, Virginia, Qdrant in US East, and Tinybird in US East. Other US-based providers also process data as described on our Subprocessors page. Cavuno does not currently offer EU-only data residency; a provider's corporate location in Germany or elsewhere in the EU does not mean that Cavuno customer data is processed there.
We take reasonable steps to ensure that overseas recipients of your personal information comply with the Australian Privacy Principles, including assessing each provider's data protection practices and contractual commitments (APP 8).
Notifiable data breaches
In accordance with the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act 1988, we will notify you and the Office of the Australian Information Commissioner (OAIC) if we become aware of a data breach that is likely to result in serious harm to any individual whose personal information is involved. Notification will be provided as soon as practicable after we become aware of the breach.
Your rights
Under the Australian Privacy Act 1988, you have the right to:
- Access the personal information we hold about you (APP 12)
- Request correction of inaccurate or outdated information (APP 13)
- Request deletion of your personal information where we no longer need it for the purpose for which it was collected
- Lodge a complaint with the Office of the Australian Information Commissioner (OAIC) if you believe your privacy has been breached
To exercise any of these rights, please contact us at hi@cavuno.com. We will respond to your request within 30 days.
You may also contact the OAIC at www.oaic.gov.au (opens in new tab) or by phone at 1300 363 992.
International users
If you are located in the European Economic Area (EEA), you may have additional rights under the General Data Protection Regulation (GDPR), including the right to:
- Request erasure of your personal data (right to be forgotten)
- Request portability of your personal data in a structured, commonly used, machine-readable format
- Object to processing of your personal data based on legitimate interests
- Request restriction of processing of your personal data
- Lodge a complaint with a supervisory authority in your country of residence
To exercise any of these rights, please contact us at hi@cavuno.com. We will respond within the timeframes required by applicable law.
California residents
If you are a California resident, the California Consumer Privacy Act (CCPA) provides you with additional rights regarding your personal information:
- Right to know — you may request details about the categories and specific pieces of personal information we have collected about you.
- Right to delete — you may request that we delete personal information we have collected from you, subject to certain exceptions.
- Right to opt out of sale or sharing — we do not sell personal information. However, certain advertising cookies (such as those set by Google AdSense) may constitute "sharing" under the CCPA. You can opt out of personalised advertising via your cookie preferences.
- Right to non-discrimination — we will not discriminate against you for exercising any of your CCPA rights.
To exercise any of these rights, please contact us at hi@cavuno.com. We will verify your identity before processing your request and respond within 45 days.
Children's privacy
Cavuno is not intended for use by individuals under the age of 16. We do not knowingly collect personal information from children under 16. If we become aware that we have inadvertently collected information from a child under 16, we will take steps to delete that information promptly.
Changes to this policy
We may update this privacy policy from time to time to reflect changes in our practices or for legal and regulatory reasons. We will notify you of material changes by posting the updated policy on our website and updating the "Last updated" date at the top of this page. Your continued use of the service after any changes constitutes acceptance of the updated policy.
Contact us
If you have any questions or concerns about this privacy policy or our data practices, please contact us at:
- Email: hi@cavuno.com
- Entity: Wollemia Pty Ltd (ABN 35 692 226 323)
- Location: Sydney, New South Wales, Australia