Paragon Talent SuiteAI-Native ATS
  • Features
  • AI Suite
  • Sovereignty
  • Pricing
  • Careers
Book a Demo Get Early Access

Privacy Policy

Version 1.0  |  Last updated: 31 May 2026  |  Governing law: Privacy Act 1988 (Cth) — Australian Privacy Principles
Contents
  1. Who we are
  2. The personal information we collect
  3. How we collect personal information
  4. Why we collect & use personal information
  5. How we store & protect personal information
  6. AI processing
  7. Call recordings, transcripts & voice data
  8. Disclosure & Sub-Processor Schedule
  9. Your privacy rights
  10. Cookies & tracking
  11. Data retention
  12. Children's privacy
  13. Changes to this policy
  14. Contact us

1. Who we are

Klaw Brands Pty Ltd (ACN 611 042 267, ABN 90 611 042 267) trading as Paragon Talent Suite ("we", "us", "our") operates the Paragon Talent Suite applicant tracking system (the "Platform") at paragonts.com.

We are committed to protecting the privacy of all individuals whose personal information we handle. This Privacy Policy explains how we collect, use, store, disclose and manage personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

Our Privacy Officer can be contacted at privacy@paragonts.com. Klaw Brands Pty Ltd is registered in New South Wales, Australia.

2. The personal information we collect

2.1 Agency administrators & recruiters

  • Name, email address, phone number and job title of team members
  • Business name, ABN, billing address and payment information (processed by our payment processor — we do not store full card details)
  • Login credentials, session data and activity logs
  • Platform usage data, feature interactions and preferences

2.2 Candidates

When a Candidate applies for a job, registers via a contact form, or accesses the Candidate Portal, we collect personal information on behalf of the relevant Agency, including:

  • Name, email address, phone number, residential suburb and LinkedIn URL
  • Work rights and visa status
  • Employment history, skills, education, qualifications and certifications
  • CV or resume files (PDF or Word format)
  • Expected salary or rates, availability and notice period
  • Screening notes, call recording transcriptions and AI-generated summaries
  • Referee details submitted by the Candidate or Agency
  • Reference responses provided by the Candidate's referees
  • Offer letter details and digital signature records
  • Candidate Portal profile information and application status interactions

Important: the Agency (not Paragon Talent Suite) is the data controller for Candidate Data. We process Candidate Data as a data processor on behalf of Agencies. Candidates should direct privacy-related requests to the Agency that collected their information.

2.3 Referees

When a referee submits a reference via the Platform, we collect their name, email address, phone number, job title and employer; their relationship to and employment-history details relating to the Candidate; and their responses to reference questionnaire questions.

2.4 Website visitors

When you visit our website we may collect your IP address, browser and device type, the pages you visit and referral source, and information via cookies and similar technologies (see section 10). We use Google Analytics (GA4) for website analytics.

3. How we collect personal information

We collect personal information directly from you when you register, complete forms, submit applications or contact us; from Agencies when they upload or enter Candidate Data; from Candidates when they update their Candidate Portal profile; from referees when they submit a reference via a unique token link; and automatically through your use of the Platform (session data, usage analytics, logs).

4. Why we collect & use personal information

We collect and use personal information to provide and operate the Platform; to process job applications on the Agency's instruction; to send transactional emails (confirmations, status updates, portal invites, reference requests); to provide AI Features the Agency chooses to use; for reference checking; for offer-letter signing; for billing and tax records; for security, fraud prevention and compliance; for product analytics and improvement using de-identified or aggregated data; and for business development, where permitted. Where we rely on consent, you may withdraw it at any time.

5. How we store & protect personal information

5.1 Data residency — a layered statement

Our core application database, file storage and sovereign AI inference environment are hosted in Australia. Some limited ancillary processing, including email delivery and payment processing, may involve overseas service providers, as disclosed in the Sub-Processor Schedule below. We distinguish the following layers rather than make a single absolute claim:

  • Core application data & file storage: Hosted in Sydney (ap-southeast-2). Candidate records, CVs and client logos are stored in Sydney.
  • Platform hosting / compute: Hosted in Sydney (syd1).
  • Sovereign AI inference (default): SCX.ai — Equinix SY5, Sydney. Under the platform default, personal information is not intentionally transmitted outside Australia for AI inference.
  • Email delivery: Transactional email is delivered via an Australian-resident provider (Sydney); candidate names, email addresses and authentication links remain in Australia. A US-based provider is retained as a fallback and is used only if the Australian provider is unavailable.
  • Ancillary: document signing: Offer-letter signing is provided by a third-party service whose current default host is not Australian-resident.
  • Customer-selected AI (BYOK): Where an Agency connects its own AI provider key, that provider processes the relevant data under its own terms and may be located outside Australia.

5.2 Security measures

We implement the following measures, which are operational in production:

  • Row-level security (RLS) enforced at the database level — each Agency can access only its own data
  • Encrypted data transmission using TLS/HTTPS across all connections
  • Encryption of sensitive credentials and API keys at rest
  • Time-limited signed URLs for CV and file access
  • Rate limiting on public API endpoints
  • Role-based access control — admin, recruiter and viewer separation
  • Automated dependency security scanning

Despite these measures, no system is completely secure, and we cannot guarantee the absolute security of information transmitted over the internet.

6. AI processing

The Platform includes AI Features such as job description generation, CV extraction, call transcription and email drafting. This section explains how personal information is handled by those features. The AI provisions of our Terms of Service apply in addition to this section.

6.1 Processing modes

  • Sovereign AI Mode (default). Australian-hosted inference via SCX.ai (Sydney). Personal information is not intentionally transmitted outside Australia for AI inference.
  • Standard AI Mode. Paragon-selected providers that may be overseas. Not used by default; if introduced, the provider is disclosed in the Sub-Processor Schedule.
  • BYOK Mode (all plans). The Agency connects its own AI provider. That provider operates under its own terms and may be overseas; the Agency is responsible for it.

6.2 No training without opt-in

We do not use Agency Data, Candidate Data, CVs, job data, screening notes, call recordings, transcripts, reference responses or AI outputs to train, fine-tune or improve general-purpose AI models, and we do not instruct or authorise our AI providers to do so, unless the Agency has expressly opted in under a separate written agreement. Our current sovereign provider, SCX.ai, does not train on customer inference data under its terms as at the date of this policy. BYOK providers operate under their own terms.

6.3 Human review

AI outputs are assistive only and must not be used as the sole basis for shortlisting, rejection, hiring or other material recruitment decisions. Agencies are responsible for human review and for lawful, non-discriminatory recruitment.

6.4 Provider substitution and sovereign continuity

To maintain availability we may, at our sole discretion and at any time without prior notice, substitute or supplement our sovereign AI provider with any other Australian-hosted provider; data in Sovereign AI Mode remains in Australia. We will not silently route Sovereign AI Mode data to an overseas provider. If a sovereign provider is unavailable and no Australian-hosted alternative can maintain an affected AI feature, that feature is suspended by default, and we will not process the data through a non-Australian provider unless the Agency gives explicit, revocable opt-in to temporary non-sovereign processing.

7. Call recordings, transcripts & voice data

Where an Agency uses call transcription, audio recordings are processed into text and summaries. The Agency is responsible for providing all required notices and obtaining all required consents before recording, uploading or transcribing any call, and recording laws differ between Australian states and territories. Audio and transcripts are processed to provide the feature, are retained for the duration of the Agency's subscription unless deleted earlier, and raw audio is not retained beyond what is needed to produce and store the transcript except where the Agency chooses to store the recording.

Text-to-speech and synthetic voice features are not currently enabled. If introduced, they will be disclosed here, and the Platform does not create voice clones, biometric voiceprints or speaker-identification profiles unless expressly agreed in writing.

8. Disclosure & Sub-Processor Schedule

We share personal information with third-party sub-processors only to the extent necessary to operate the Platform. This schedule is kept operationally current.

Function (provider)Data sharedRegionTraining use
Database, auth & file storageAll Platform dataSydney, AUn/a
Platform hosting / computeServer requests, logsSydney, AUn/a
Sovereign AI inference (default) — SCX.aiCV text, job data, notesSydney, AUNo training
Transactional emailName, email, auth linksSydney, AU (US fallback)n/a
Offer-letter signingOffer details, signer name & email, signature recordsCloud (non-AU) defaultn/a
Payment processingBilling name, email, card detailsUS-basedn/a
Website analyticsIP address, usage dataUS-basedn/a

This schedule reflects our sub-processors as at the last-updated date of this policy. Sub-processors may change, and we will update this schedule accordingly. We can provide the current named provider for any layer on request.

8.1 Overseas transfers

Some sub-processors (the document-signing provider's default host, our payment processor and, if enabled, our analytics provider) are based outside Australia. Our transactional email provider is Australian-resident; a US-based email provider is retained only as a failover and is not used in normal operation. Where we transfer personal information overseas, we take reasonable steps under APP 8 to ensure the recipient handles it consistently with the Australian Privacy Principles.

8.2 Other disclosures

We may also disclose personal information where required by law or regulatory authority; to protect rights, property or safety; or in connection with a merger or sale of assets, subject to equivalent privacy protections. We do not sell personal information.

9. Your privacy rights

You may request access to, and correction of, the personal information we hold about you by contacting our Privacy Officer at privacy@paragonts.com. We respond within 30 days. Candidates may update their information via the Candidate Portal at any time, and requests to delete Candidate Data should be directed to the relevant Agency as data controller. If you are not satisfied with our response to a complaint, you may contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

10. Cookies & tracking

Our website and Platform use strictly necessary cookies (session authentication, CSRF protection), functional cookies (preferences) and Google Analytics (GA4) with anonymised IP addresses. Analytics cookies are off until you accept them via our cookie banner. You can control cookies through your browser settings; disabling strictly necessary cookies affects Platform functionality. For Google Analytics opt-out, see tools.google.com/dlpage/gaoptout.

11. Data retention

Data typeRetention periodBasis
Agency account & team dataSubscription + 30 daysContract; export window
Candidate applications & profilesDuration of subscriptionAgency instruction
CV filesDuration of subscriptionAgency instruction
Call recordings & transcriptsDuration of subscription (audio only as long as needed for transcript unless stored)Agency instruction
Reference submissionsDuration of subscriptionAgency instruction
Offer letter recordsSubscription + 7 yearsLegal obligation (contract records)
Billing records7 yearsLegal obligation (ATO)
System & security logs90 daysSecurity monitoring

12. Children's privacy

The Platform is not directed at individuals under 18, and we do not knowingly collect their personal information. If you believe a minor has provided information without parental consent, contact our Privacy Officer.

13. Changes to this policy

We may update this policy to reflect changes in our practices or legal requirements. We will notify users of material changes by email and by posting the updated policy at paragonts.com/privacy with a new "last updated" date.

14. Contact us

  • Privacy Officer: The Privacy Officer
  • Email: privacy@paragonts.com
  • Postal address: Klaw Brands Pty Ltd, registered in New South Wales, Australia
  • Response time: within 30 days of receipt
© 2026 Klaw Brands Pty Ltd trading as Paragon Talent Suite · Sydney, Australia
Platform Pricing Privacy Terms Cookie preferences
Cookies on this site
We use necessary cookies to make the site work, and Google Analytics to understand how it is used. You choose what to allow. See our Privacy Policy.