About this policy
RecDial Pty Ltd ABN 56 698 654 232 (RecDial, we, us, or our) is an Australian company based in New South Wales. We provide voice and messaging infrastructure designed for recruitment agencies.
This policy applies to recdial.com, recdial.app, our desktop application, and the calling, messaging, recording, transcription, AI, integration, support, marketing, and billing services we provide together as the Services.
We are committed to handling personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles, whether those requirements apply to us directly or we adopt them as our operating standard. If you are outside Australia, local privacy laws may give you additional rights. Nothing in this policy limits rights that cannot lawfully be limited.
Our role and agency-controlled data
We handle some personal information for our own business purposes, such as account, billing, enquiry, and support information. We also process information for recruitment agencies that use the Services.
An agency controls the candidate, contractor, client, contact, call, messaging, and recruitment system data that it provides or connects to RecDial. We process that information on the agency's instructions to provide the configured Services. Questions about an agency's collection or use of that information should usually be directed to the agency first.
Agencies and their users must have authority to provide personal information to RecDial. They are responsible for giving any privacy notices and obtaining any permissions or consents required by law, including for call recording, transcription, messaging, and connected recruitment systems.
Personal information we handle
The information we handle depends on how a person or agency uses the Services. It may include:
- Account and identity information: name, work email address, employer, role, group membership, account status, authentication records, and Google or Microsoft sign-in identifiers.
- Recruitment and address book information: candidate, contractor, client, contact, job title, employer, phone number, record identifiers, status, notes, and related details entered by an agency or synced from a connected recruitment system.
- Calling information: phone numbers, call history, timestamps, routing information, call outcomes, recordings, voicemail, transcripts, summaries, notes, action items, and related metadata.
- Messaging information: SMS content, participants, timestamps, and delivery records where messaging is enabled.
- Presence information: Microsoft Teams presence, linked account identifiers, and related status information where that integration is enabled.
- Website and enquiry information: name, work email address, agency, recruitment system, team size, message, and security check information submitted through our website.
- Support information: correspondence, support requests, call quality reports, and information supplied to diagnose or resolve an issue.
- Billing information: account details, invoices, payment status, and transaction references received from Ezidebit. RecDial does not store complete payment card or bank account credentials processed by Ezidebit.
- Technical and diagnostic information: IP address, approximate location, device and operating system details, browser or application version, network provider, microphone and audio diagnostics, connection events, logs, and security information.
- Product usage information: stable user and agency identifiers, application screens and features used, feature outcomes, call connection timing and duration, integration provider, safe failure stages and codes, application version, operating system, and device architecture.
Call content and agency-controlled recruitment records may incidentally contain sensitive information, such as health, racial or ethnic, professional membership, or other protected information. RecDial does not ask agencies to provide sensitive information unless it is reasonably necessary for a configured Service and lawfully collected.
You may choose not to provide personal information to us. This may prevent us from creating an account, responding to an enquiry, or providing some or all of the Services.
How we collect information
We may collect personal information:
- directly from you when you create or use an account, contact us, request a demonstration, submit a report, or communicate with us;
- from your agency, its account administrators, and other authorised users;
- from call and message participants as communications pass through the Services;
- from connected services such as Recruit Wizard, JobAdder, Microsoft, Google, and other identity or recruitment platforms authorised by an agency; and
- automatically from devices, browsers, telephony systems, applications, security services, and service logs.
Why we handle information
We collect, hold, use, and disclose personal information where reasonably necessary to:
- create, secure, administer, and authenticate accounts;
- provide calling, messaging, recording, voicemail, transcription, summarisation, action items, and recruitment system synchronisation;
- route communications, provide real-time features, and maintain service reliability;
- provide support, investigate call quality, troubleshoot faults, prevent fraud, protect security, and respond to incidents;
- measure product activation, feature adoption, reliability, and retention, and use those insights to improve the Services;
- invoice customers, process payments through Ezidebit, maintain accounting records, and recover amounts owed;
- respond to enquiries, arrange demonstrations, conduct sales follow-up, and send relevant product updates;
- comply with laws, respond to lawful requests, exercise or defend legal rights, and enforce our agreements;
- analyse de-identified or aggregated information to understand and improve the Services; and
- support a proposed or completed sale, merger, financing, restructure, or transfer of all or part of our business.
Calls, recordings, and messages
Call recording is configurable by each agency. An agency and its users decide when recording is enabled and are responsible for complying with the laws that apply to each call. Those laws may depend on the location of every participant, the purpose of the communication, and the circumstances in which it is recorded.
Agencies and users must notify participants and obtain any consent required before recording, transcribing, summarising, or otherwise processing a communication. RecDial may process recordings, voicemail, transcripts, summaries, SMS, and related metadata only to provide the Services, meet legal obligations, or for another purpose authorised by the agency or individual.
AI processing
RecDial uses automated tools to transcribe calls and produce summaries, action items, call outcomes, and prompts. These features assist users. They do not make employment, recruitment, contracting, client, or other decisions that significantly affect an individual without human review.
We do not use identifiable customer call content to train general AI models. Customer content is sent to our AI providers only as needed to deliver the requested feature. Call audio is transcribed by a provider that processes RecDial requests in Australia, and the resulting transcript is sent to our summarisation provider in the United States to generate summaries, action items, and related outputs. See Overseas processing and our subprocessors page for details. We may use information that has been de-identified or aggregated to monitor performance and improve the operation of the Services.
AI-generated content can be incomplete or inaccurate. Users should review an output against the underlying communication and apply their own judgement before relying on it.
Product analytics and diagnostics
We use product analytics in the customer-facing application to understand activation, feature adoption, reliability, and retention. After an authenticated account loads, analytics may be associated with the user's stable identifier and agency identifier and include the user's name, work email address, role, agency name, application version, operating system, device architecture, internal-user status, and allowlisted feature events and outcomes. We do not send phone numbers, message content, candidate or contact information, call session identifiers, recordings, transcripts, or free-form error messages to our product analytics provider.
We use application diagnostics to detect errors and crashes, investigate regressions, and monitor sampled performance. Diagnostic events may include stable user and agency identifiers, request, job, and call session identifiers, normalised routes, status codes, release information, application and device details, and sanitised error and stack information. We configure diagnostics not to include names, email addresses, authorisation data, cookies, tokens, phone numbers, recordings, transcripts, message content, or candidate and contact details.
PostHog provides product analytics and Sentry provides application diagnostics. Both process RecDial data in the United States. We do not use either service for behavioural advertising, and session replay is not enabled. See our subprocessors page for more information.
Who receives information
We may make personal information available to:
- authorised users and administrators within the relevant agency;
- authorised RecDial personnel who require limited access for requested support, service operation, security, legal compliance, or incident response;
- our current subprocessors, which provide hosting, telephony, AI, email, payment, security, product analytics, application diagnostics, and other infrastructure;
- customer-directed services and integrations enabled by an agency;
- professional advisers, insurers, auditors, and contractors subject to appropriate confidentiality obligations;
- regulators, courts, law enforcement, or other parties where disclosure is required or authorised by law; and
- an actual or proposed purchaser, investor, financier, or successor in connection with a corporate transaction.
RecDial does not sell or rent personal information.
Overseas processing
RecDial takes an Australia-first approach to hosting and storage. Our production database and primary object storage are located in Australia, and call transcription for RecDial requests uses an Australian endpoint. Delivering the Services still requires some personal information to be processed outside Australia, including call content, recordings, message content, and transcripts.
The main overseas processing locations are the United States, Japan, and Singapore. In particular, our telephony provider carries calls and messages across Australian, United States, and global networks; our AI provider generates call summaries and action items from transcripts in the United States; our product analytics, application diagnostics, webhook routing, and network diagnostic providers operate in the United States; our email delivery provider operates in Japan; and our real-time event provider operates in Singapore. Our website and application hosting and object storage are located in Australia, though content delivery and automated security checks may be served from a provider's global edge network. Optional identity providers and customer-directed integrations may also process information in countries described in their own agreements and privacy terms. Our subprocessors page lists each current provider and its likely processing location.
Where personal information is handled outside Australia, we take reasonable steps appropriate to the service and risk, which may include contractual privacy and security terms, restricted access, protected transmission, and provider due diligence.
Security
We use reasonable administrative, technical, and organisational measures to protect personal information from misuse, interference, loss, and unauthorised access, modification, or disclosure. These measures include access controls, protected transmission, private storage, restricted administrative access, credential and token protection, logging, and monitoring appropriate to the information and Service.
No method of transmission or storage is completely secure. Users are responsible for keeping their account credentials confidential, using appropriate device security, and telling us promptly if they suspect unauthorised access.
Retention and deletion
We generally retain service data while an agency's account is active. After account closure, we delete or de-identify active service data within 90 days unless a law, legal claim, fraud or security investigation, or agreed contract requires us to keep it for longer.
Encrypted backups expire through our normal rotation within 180 days after account closure. Call routing and network diagnostics are retained for 30 days by default. Billing, legal, audit, and security records may be retained for longer where reasonably required. Information that has been irreversibly de-identified may be retained without a fixed time limit.
An agency may have its own retention settings or contractual obligations. A customer-directed integration may retain information after it has been removed from RecDial, subject to that service's own terms.
Product analytics and application diagnostic data are retained only for as long as reasonably required to analyse product use, investigate faults, monitor releases, and improve the Services, within the retention periods configured with each provider. Where an approved user or agency deletion requires removal of linked analytics data, we delete or request deletion of the corresponding PostHog person and agency group records. Sentry diagnostic events expire under the configured event-retention period and are not used as a durable account record.
Direct marketing
We may use business contact details to respond to enquiries, follow up a demonstration request, and send relevant RecDial product updates. You can opt out of marketing emails by using the unsubscribe facility provided or contacting privacy@recdial.com.
Opting out of marketing does not prevent us from sending operational, security, billing, account, or legal notices that are necessary for the Services or our relationship with an agency.
Access, correction, deletion, and complaints
You may ask to access personal information we hold about you, correct information that is inaccurate, or delete information where the law provides that right. Send your request to privacy@recdial.com or write to our Privacy Officer at the address below. We may take reasonable steps to verify your identity before acting on a request.
Access or deletion may be limited where required by law, where it would unreasonably affect another person's privacy, where information must be preserved for security or a legal claim, or where RecDial processes the information on behalf of an agency. If an agency controls the information, we may refer the request to that agency or assist it in responding.
If you believe we have mishandled personal information, please describe the issue and include any supporting information. We will acknowledge a privacy complaint within 10 business days and aim to resolve it within 30 calendar days. If we need more time, we will explain why and provide an updated timeframe.
If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner. Individuals outside Australia may also have a right to contact their local privacy or data protection authority.
Data breaches
We assess and respond to suspected data breaches in accordance with our legal obligations. Where the Australian Notifiable Data Breaches scheme applies and a breach is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner as required. More information is available from the OAIC's Notifiable Data Breaches guidance.
Third-party services and links
Agencies may connect RecDial to services they select, including recruitment, identity, presence, and communication platforms. Information sent to a customer-directed service is also handled under that service's agreement and privacy practices. RecDial is not responsible for the privacy practices of an external service or website that we do not control.
Changes and contact details
We may update this policy to reflect changes to the Services, our providers, our information handling practices, or applicable law. The revised policy takes effect when published unless it states otherwise. Where a change is material, we will take reasonable steps to notify affected agencies or users.
Privacy Officer
RecDial Pty LtdABN 56 698 654 232
Suite 703, Level 7, The Trust Building, 155 King Street, Sydney NSW 2000
Email: privacy@recdial.com
