V 0.1
This privacy policy explains how we, Skill Scanner Pty Ltd trading as Haga.Pro (HAGA, we, us, our), handle your personal information (i.e. information about you that identifies you) in the course of our activities including when you use our platform.
Our platform connects Australian employers and international job candidates. Our users may engage a third party immigration consultant and then update their HAGA account with information about their immigration visa status and sponsorship eligibility.
The policy applies to our platform users, customers, partners, service providers, individuals applying to work at HAGA, members of the public or others who visit us or interact with us online or offline (each referred to as, you, your). This policy applies to you as an individual even if you act as a representative of an organisation (e.g. your employer).
This policy shall be interpreted in accordance with the law and shall not grant you greater rights or impose on us greater obligations that than those afforded or imposed by law. It provides information only as may be required under data privacy laws and it is not intended, and must not be relied on by you, as a representation, warranty, contract or an acknowledgement of a duty of care.
Our online properties may contain links to third party websites and features. We do not have direct control over and are not responsible for those third party assets.
Please read this policy carefully. If you have any questions or if you do not understand anything explained in it, please contact us.
We will handle your personal information and sensitive personal information as further described below.
"Sensitive personal information" is personal information about your race or ethnicity, political opinions, religious or philosophical beliefs, membership of a professional, trade or political association, sexual orientation or practices, criminal record, health information, genetic and biometric data.
In relation to our platform users, we typically handle the following types of information:
Please refer to section 11 which describes each type of information that we handle.
What may or may not be your personal information will depend on the circumstances of processing. We will not be processing your personal information if, in the circumstances, the information is anonymised or cannot be reasonably linked back to you.
You have the right to remain anonymous when interacting with us, unless this is impracticable. This means that you may send us an anonymous general enquiry. However, it will be impracticable not to know your identity if you wish to create a user account on our platform, make a complaint, exercise your data rights, apply to work for HAGA or use our services. Without your relevant personal information in those circumstances, we will be unable to engage with you, provide our services and fulfil our obligations.
We take reasonable steps to only handle personal information that is necessary for our lawful functions and activities. For example, HAGA does not collect or store copies of our candidate's resume, passport or visa document. Instead, we rely on your specific data input and we obtain limited information from your professional advisors who act in your interest. Employers can see a candidate's profile on our platform but contact details are only revealed if a match is made. If we receive your personal information which is not necessary, we will destroy or de-identify it as soon as practicable.
For some activities such as the technical operation of our website, display advertising, or information security processes, pseudonymised information will often suffice and we will not attempt to specifically identify you by name, unless necessary for our lawful functions and activities.
Please note that we will rely on the information provided by you as accurate, complete and up to date, and we will be grateful if you would inform us of any changes. If you provide incorrect information to us we may be unable to assess your eligibility for sponsorship, provide our services, publish or maintain your profile in our platform or other consequences.
If you provide to us another person's personal information, please only do so if they would reasonably expect it (and they did not object) or with their consent. Please note that we may share such information with relevant third parties as explained in this policy.
Information on social media, official public records and other public sources.
We collect, hold, use and disclose your personal information for the following purposes:
| Purpose | Personal information | How collected and held? | Consequences if not collected |
|---|---|---|---|
| To respond to your enquiry, service support request, data rights request, complaint or other communication. We may take steps to identify you by asking for your name and other details or checking your public profile, where this is necessary in the handling of your enquiry. We may record, transcribe and analyse your customer communications for service, compliance, training and development purposes. | Details of your enquiry Public data | From you, our records, our third party communication analysis tools, and from public sources. Information is held in our communication and case management systems. | Unable to efficiently and effectively assist with your enquiry without all necessary information and the use of communication analysis tools. Unable to ensure compliance and service improvement without appropriate records. |
| To provide our digital platform and related services to our users. You can take steps on our platform to create a user account, provide certain mandatory identity information and complete your user profile information. We do not collect any official identity information about our users but rely on alternative identity information (e.g. your education certificates, social media accounts, a confirmation of your identity by a trusted party, etc.). Our employer users can use our platform to display information such as company name, vacancy type, role requirements, compensation and benefits, and tell us about their company's hiring needs, budgets and sponsorship ability for better candidate matching. Our candidate users display candidate data in their profiles. They can input some qualifications and experience information, upload their education certificates and answer additional questions for pre-vetting and benefit from a mark signifying successful pre-vetting on their user profile. We will seek your prior consent to collect your health information which we use to assess your eligibility for sponsorship based on the Australian government's criteria. | Contact details Candidate data Candidate health data Device and browser data Identity information Immigration data User profile data Usage data | Input by the user when creating a user account. Uploaded by the user. Generated by us upon successful education and sponsorship pre-vetting. A visa and sponsorship status may be obtained from a third party immigration consultant acting for the candidate user. All such data is held on our systems. | Access to our platform and similar services is not possible without an active user account. When creating a user account, users must input certain mandatory information to verify that the user is genuine. Education certificates must be uploaded for pre-vetting and follow-up questions must be answered. Failing to provide such information may prevent us from creating a user account or failing to display certain marks indicating successful pre-vetting and a favourable visa prospect. |
| To provide our online services to you, such as our website and online content. For example, when you visit our website, your browser will provide certain technical information to enable us to display our content in a compatible manner. Some of our features allow you to input your information, for example, our contact us form. | Device and browser data | From you, your device and browser, cookies and similar technologies, data generated by our systems and from third parties, such as our technology providers. Your information is held in our internal systems and relevant third party systems. | Our systems automatically collect and provide information necessary to deliver our online services to your device. If you block cookies and similar technologies in your browser, some of our online services may be reduced. |
| We identify suitable matches for our employers and candidates. We highlight within the platform and send you service messages about employers/candidates who match your requirements. | Candidate data Contact details Preferences and interests User profile information | From you and data generated by our matching algorithm. Information is held in our internal systems. | Unable to deliver relevant communications about matches without all necessary information accessed by our matching algorithms. |
| To send you relevant direct marketing communications and display ads about our services, services of our associated entities, third-party services, collaborations, by email, text, post, display ads or other channels if we have an existing relationship or with your consent, where required by law. We will use profiling for personalisation and targeting, where appropriate, based on information known, observed or inferred from your activity or information about you provided by our third-party marketing and advertising partners. We use retargeting services which recognise your device or browser and display our ads to you on different websites you visit. We use technologies to track campaign performance. | Contact details Preferences and interests | From you, your device and browser, cookies and similar technologies, data generated by our systems and from third parties, such as our technology providers, marketing and advertising partners. Your information is held in our internal systems and on relevant third party partner platforms. | Unable to deliver direct marketing, targeted advertising and personalised communications without all necessary information. If you block cookies and similar technologies in your browser, our direct marketing may be less targeted or personalised. |
| To carry on recruitment of staff and contractors to work for HAGA, for example, to assess your application, interview you, assess your qualifications, experience and fitness for a particular role, conduct background checks (as above), make hiring decisions, discuss your terms of engagement and similar activities. We may use automated decision-making tools to eliminate applicants who fail to meet the basic criteria for a role. We use your identifier information only where reasonably necessary to verify your identity as part of recruitment. We will ask for your tax file number (TFN) to set up your "pay as you go" income tax withholding, as appropriate. It is not an offence to choose not to provide your TFN, but this may prevent us from withholding the correct amounts of tax and you may be initially taxed more. We may only use your TFN as authorised under taxation law, personal assistance law or superannuation law. | Details of your enquiry Official identity information Recruitment details Public data Sensitive information (for example, where we wish to accommodate your needs on account of disability). | From you, your recruitment agent, data generated by our systems, public sources, and third parties, such as persons providing a reference or testimonial about you. Your information is held in our internal systems, systems of third parties such as our service provider or recruitment agents. | Unable to identify candidates, make hiring or engagement decisions, ensure correct tax deductions and manage our contactors without all necessary information. |
| To undertake research, analytics, and diversity monitoring, for example, service usage metrics, reviewing your Feedback, improving our services, quality assurance, market research, publishing statistical reports, business development, collaborating with third parties, sharing statistical research outputs, and other research. and personalise your experience on the platform. Analyse usage to improve our services and demonstrate platform value | Feedback Usage data All other de-identified information | From you, our records, data generated by our systems, and third parties, such as our analytics partners and providers. Your information is held in our internal systems and on relevant third party partner platforms. | Unable to conduct research and development without all necessary data, often based on de-identified personal information. |
| To administer our organisation, for example, working with our associated entities, contacting and working with our partners, managing our service providers and our professional advisers, maintaining our technology stack, keeping and updating our records, collecting debt, monitoring compliance with our terms, resolving complaints, and similar activities. We may use our record management systems and engagement tools, identifying opportunities and contacting you. | All necessary personal information Opportunity records | From you, our records, data generated by our systems, and from third parties, such as our service providers. Your information is held in our internal systems and on relevant third party systems. | Unable to perform certain tasks, provide services, administer our organisation, use our group's corporate resources, and comply with the law without all relevant information and without engaging relevant third parties to handle your personal information on our behalf. |
| To maintain health, safety and security, for example, to manage incidents, investigations, to make reasonable health and safety adjustments to accommodate your health needs, to prevent imminent risk to health, make enquiries of our visitors where appropriate, deploy physical access control measures, and similar activities. | Details of your enquiry Identity details Public data Sensitive information (for example, injury details or where we act in a health emergency). | From you, our records, our security devices, and third parties, such as your health practitioner, ambulance service, our building's reception and security personnel. | Unable to make relevant risk assessment and take appropriate action without all necessary information. Unable to handle emergencies without using available and necessary information. |
| To maintain information security of our connected assets and online properties, for example, by monitoring use of our corporate resources, networks and website for suspicious activities, blocking access, isolating suspicious objects, preventing malicious software distribution and implementing other technical and organisational security measures to ensure the confidentiality, integrity and availability of information. | Usage data | From your device and browser, collected and generated by our systems, collected and generated by third party systems. | Unable to ensure information security without monitoring user and network activity and collecting relevant information including through server-side tracking and cookies and similar technologies. |
| To comply with the law, a binding decision or direction of a regulator, cooperate with a public authority, comply with mandatory disclosure, exercise legal rights and defend legal claims. | All necessary personal information | Collected from you, our records, third parties, and public sources. | Unable to comply with the law, exercise a right or defend a legal claim without the use and disclosure of your personal information. |
We will update this policy to include any new purposes from time to time and we will obtain your prior consent for such new purposes where we are required to do so at law. We may not require your prior consent if the secondary purpose is related to our primary purpose and reasonably anticipated by you or otherwise authorised or required by law.
For individuals in the European Union or the UK we rely on the following grounds of processing:
We may disclose your personal information on a need-to-know basis to the extent necessary for our lawful function or activity, or where otherwise authorised or required by law to:
We take reasonable steps to choose reliable service providers who hold your personal information on our behalf. Other than that, whilst we take reasonable steps to implement appropriate measures to safeguard your personal information in the hands of third parties, we are not responsible for third parties.
HAGA is based in Australia. However, your personal information may be transferred abroad, for example, if we use a service provider (e.g. AWS, Google cloud, Supabase, Stripe), collaborate with third parties, seek advice in relation to a matter, deal with a public authority located overseas, or in similar circumstances. This may include third parties in Australia, Europe, New Zealand, the United Kingdom or the United States.
When we disclose personal information to our recipients overseas, we take reasonable steps to satisfy ourselves of the recipient's information security and ensure that each recipient will protect your personal information and handle it in accordance with the law. This may include entering into contractual arrangements with the recipient to impose compliance with the Australian Privacy Principles or satisfying ourselves that they are already subject to laws that offer equivalent protection of your personal information that you can enforce.
You may request deletion of your personal information at any time by email and your data will be deleted or de-identified, save for any personal information which must be retained for our compliance with the law.
We will take such steps as are reasonable in the circumstances to destroy, anonymise or pseudonymise your personal information if no longer needed for our purposes, unless its continued retention is otherwise required by law.
By way of example, we may apply the following data retention periods, except where longer retention is necessary for a lawful purpose or required by law:
| Type of information | Retention period |
|---|---|
| Details of your enquiry | 6 months from resolution. |
| Device and browser data, usage data | 12 months from collection |
| Feedback | 12 months from collection or as long as it remains available on third party review platform |
| Official identity Information | We do not store copies of official identity documents. |
| Recruitment details | One year following unsuccessful application. |
| Transaction data | Seven years from collection or as otherwise required by law. |
| User information including candidate data, candidate health data, contact details, identifier information, immigration data, preferences and interests, transaction data and user account data | Retained for as long as your account remains active and 90 days following account closure. Your qualifications and supporting documents uploaded by you are retained until completion of our pre-vetting. Candidate health data is retained until completion of pre-vetting and no later than 14 days from collection. |
We take reasonable steps and implement appropriate technical and organisational measures to protect your personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure.
For example, your qualification certificates are uploaded to our third party encrypted data storage solution. They are accessed in that solution for pre-vetting purposes and not further shared within HAGA by email.
While we take reasonable steps to ensure information security, the transmission of information over the Internet is never completely secure, malicious actors constantly improve their attack vectors and human error cannot be completely ruled out. The transmission and exchange of information is carried out at your own risk.
Subject to certain conditions, exemptions and verification of your identity, as appropriate, you may have the following data privacy rights in respect of your personal information:
If you are an individual in the European Union or the UK (also referred to as a 'data subject'), you may also have the following additional rights in relation to your personal information:
Please contact us if you wish to exercise your rights. In most cases, we will be able to respond free of charge. We will take reasonable steps to process your request and respond without delay and no later than within one month.
To protect all personal information held by us, we may require you to confirm your identity before resolving your request. If necessary, reasonable costs may be charged to you, where doing so is appropriate and lawful.
We may refuse requests on certain grounds, for example, if they are unreasonably repetitive, disproportionately demanding or otherwise exempt or if refusing your request is appropriate and lawful in the circumstances. If we refuse your request, we will explain our lawful reason for doing so.
You can disable cookies and similar technologies through your internet browser. Alternatively, you could prevent some tracking by:
Please be aware that if you opt-out of certain trackers, some or all of the functionality of our online services may be reduced. If you clear cookies in the browser on your device, the next time you visit our online services, cookies and similar technologies will be deployed again. However, you can prevent this by permanently blocking them in your browser.
If you consider that we have interfered with your privacy, or you are not happy about how we have handled your personal information, please contact us.
We will respond to you within a reasonable period of time to acknowledge your complaint and inform you of the next steps we will take in dealing with your complaint. We will endeavour to do so within 7 days of receipt and work with you to resolve your complaint without delay and generally within one month of receipt.
If you are not satisfied with our response, you may complain to the OAIC. If there are other government agencies we consider you can complain to base on the nature of your complaint, we will inform you of this at the time we respond to your complaint.
We will handle the following information which may constitute your personal information.
| Type of information | Description |
|---|---|
| Candidate data | Information input by you in our platform including information about your work history, skills, education, language proficiency, location, and job preferences. |
| Candidate health data | Information about a candidate's health as required to assess eligibility for a sponsorship application based on the Australian government's criteria. |
| Contact details | Name, email, linked social media profile and other contact details. |
| Details of your enquiry | Information in your query, request for services, complaint, job application or other communication. |
| Device and browser details | Information automatically provided by your device and browser including mobile device ID, internet protocol (IP) address, cookie ID, online identifiers, operating system, browser type, language, time zone setting, location and date and time of access and other information. |
| Feedback | Information communicated by you to us in online reviews, surveys or otherwise. |
| Immigration data | Information about your immigration status and visa sponsorship eligibility. |
| Job application data | Information about your application to work for us including your |
| Identity information | Information about you that can serve as proof of identity, your social media accounts, your education records, a confirmation of your identity by a trusted third party, official identity information such as your national identification number, passport number, driving license, healthcare insurance number or other identifier issued by a public authority. |
| Opportunity records | Information about your personal and professional activities as a prospective business partner, service provider and other opportunity records. |
| Preferences and interests | Information about your preferences and interests known, observed or inferred from other data, your marketing preferences and consents, information about you from our third-party advertising partners and similar information. |
| Public data | Information about you from social media, official records (e.g. electoral, postal, court, bankruptcy records, etc.) and similar information. |
| Transaction data | Expression of interest in an employer's vacancy or in a candidate, enquiry, positive hiring decision, placement outcome, invoice, payment receipt, subscription status, and other transaction information. We do not collect or store credit card numbers as all payments are processed via Stripe. |
| User account data | Username, password, profile information input by you, your linked social media accounts, user account choices and preferences, marketing opt-out and similar information provided by you. |
| Usage data | Information about how you navigate and engage with our online services, features, websites, your sign-ups, logins, searches, matches, messages, your online activity data, clickstream data, page interaction, search text, results, security log data and similar information. |
We may update this policy from time to time to reflect changes in our practices, legal requirements, or platform features.
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your personal information.
Questions or concerns? Contact us at: