AI Policy
Overview
ScaleUp Recruitment uses artificial intelligence in parts of how we work. This policy sets out where we use it, what we will not use it for, and the commitments we make to the candidates and clients whose information passes through our hands.
We have written it in plain language on purpose. A policy about AI that needs a lawyer to interpret it is not doing its job.
This policy sits alongside our Privacy Policy, which governs how we collect, use, store and disclose personal information. Section 5 of this policy forms part of our Privacy Policy. Where the two overlap, read them together.
1. Scope of this policy
This policy applies to ScaleUp Recruitment, our directors, our staff, and anyone working on our behalf, across all of the work we do in software engineering, data and analytics, DevOps, UX and UI, and executive search.
It covers:
Candidates who apply to us, are approached by us, or are represented by us
Clients who engage us to fill a role
Anyone who contacts us or uses our website
It covers our own use of AI. It does not govern how our clients use AI inside their own hiring processes, which remains their responsibility. Where we are aware that a client uses AI in a way that materially affects a candidate we have introduced, we will tell that candidate.
Our approach is informed by Australia's AI Ethics Principles and the Guidance for AI Adoption published by the Department of Industry, Science and Resources.
2. Our principles
A person decides. AI helps us work faster and see more of the market. It does not decide who gets a call back, an interview, or a job.
We tell you where it is in use. Section 3 sets out where, and if you want to know how AI was used in your own application, ask us and we will tell you.
We put in only what the work requires. Personal information goes into an AI system when there is a reason for it to be there, and not otherwise.
We check the output. AI is confidently wrong often enough that we treat everything it produces as a draft, not a finding.
We stay accountable. If AI contributed to something that went wrong, the responsibility is ours. A tool is not a defence.
3. Where we use AI in our work
We use AI in five areas. In each one, a person is doing the deciding.
Sourcing and search. Building search strings, structuring searches, and identifying profiles that may be relevant to a brief. A consultant reviews every profile before anyone is approached.
Matching and ranking. Our applicant tracking system can score and order candidates against a role brief to help us prioritise. This changes the order in which we read a list. It does not shorten the list. See section 5.
Drafting. Job advertisements, role briefs, market reports, outreach messages, articles and LinkedIn content, and other written material. Every document is edited and approved by a person before it is sent or published.
Summarising and note-taking. Turning interview notes, call transcripts and CVs into structured screening notes. The judgement about a candidate is formed by the consultant who spoke to them, not by the summary.
Research. Company, market and salary research to prepare for a brief or a client conversation. Facts and figures are verified before they reach a client or a candidate.
We also use AI for internal scheduling and administration that does not affect an assessment.
4. Human oversight
These are the commitments that matter most, so we have set them out separately.
Every longlist is reviewed in full by a consultant. By longlist we mean every candidate who applies for a role or is identified for it, before anyone is narrowed out.
AI never removes a candidate from consideration. Ranking affects the order we read a list in. It does not decide who we read.
Every decision to progress, hold, or decline a candidate is made by a person who can explain the reason for it.
Every document that goes to a client or a candidate is read and approved by a person before it is sent.
Where a candidate is declined, that decision is made by a consultant. It is not generated by a system.
5. Automated decision-making and your rights
The short version is that no computer decides anything about you here. The rest of this section is the detail, including a law that takes effect in December 2026.
From 10 December 2026, Australian Privacy Principles 1.7 to 1.9, inserted by the Privacy and Other Legislation Amendment Act 2024 (Cth), require organisations to disclose the use of computer programs in decisions that could reasonably be expected to significantly affect an individual's rights or interests. That covers both decisions made by a computer program and decisions where a computer program does something substantially and directly related to making them. We are setting out our position ahead of that date.
No decision is made by a computer program alone. We make no decision by the operation of a computer program that significantly affects a candidate's rights or interests. There is no automated rejection, no automated shortlisting, and no automated offer or salary decision.
Where a computer program contributes to a decision. Our applicant tracking system and our sourcing tools can rank or score candidates against a role brief. That ranking contributes to one decision: the order in which a consultant reads a longlist they review in full. It sits alongside the CV, the conversation, the client brief, and the consultant's own judgement of the market. It does not determine who is read, who is contacted, who is submitted to a client, or who is declined.
The personal information used. Ranking and matching draw on the information you have given us or made publicly available in a professional context: your work history, skills and technologies, education, location, availability, salary or rate expectations, and the content of your CV or profile.
What you can ask us to do. At any point you may ask us:
Whether AI was used in the handling of your application, and how
For a consultant to review your application again, outside the ranked list
To correct information we hold about you that is wrong or out of date
To tell you what information a ranking was based on, where one was produced
There is no cost to any of these requests, and making one will not disadvantage your application. Contact details are at the end of this policy.
6. What we will not do
We do not use AI for any of the following. Where a tool we use offers one of these features, we keep it switched off, and we check that when we review the tool.
Facial analysis, emotion detection, or scoring of tone, body language or speech patterns
Inferring personality, psychometric traits or cultural fit from a CV, a video, or a social media profile
Automated scoring of recorded video interviews
Generating a rejection without a person having made that decision
Sourcing, filtering or ranking on a protected attribute. Where a search or a ranking turns out to have that effect through a proxy, we treat it as a fault and we fix it. See section 9
Presenting AI-generated words as someone else's own, including inventing or embellishing a reference, a testimonial, a quote, or anything in a candidate's CV or profile that the candidate did not provide
The last one deserves a plain explanation, because AI assistance in writing is now ordinary and we would rather say where we stand. We use AI to help draft our own material, and section 3 says where. What we do not do is put words into someone else's mouth. A candidate's CV stays theirs, a reference is what the referee actually said, and anything that goes out under a person's name has been written or approved by that person.
We do not supply candidate or client data to a third party for the purpose of training their models, and where a provider offers a training opt-out, we take it.
7. Personal information and AI
Our Privacy Policy sets out how we handle personal information generally. The following applies specifically to AI systems.
We use business-grade tools with contractual protections in place, rather than free consumer products, wherever personal information is involved.
Some of the tools we use process information outside Australia. Where that happens, we take reasonable steps to ensure the information is protected to the standard the Australian Privacy Principles require, and we will tell you which countries if you ask.
Where a provider offers the option, we disable the use of our data for training their models.
We give an AI system the minimum personal information the task requires.
We do not deliberately enter sensitive information into an AI tool. Where sensitive information reaches a tool incidentally, for example because a candidate mentions a health matter in a call we are transcribing, it is handled under the same protections as the rest of that record and is not used for any purpose beyond the note it was captured for.
Where we use a third-party AI provider, we rely on that provider's business terms and, where one is available, its data processing agreement. We assess those terms before we adopt a tool and we keep a current record of what each provider commits to.
AI providers that handle personal information on our behalf are Contracted Service Suppliers as described in our Privacy Policy, and we take reasonable steps to ensure they are bound to protect it. Whatever a provider's terms say, we remain accountable to you for how your information is handled.
Sensitive information has the meaning given in the Privacy Act 1988 (Cth), and includes information about health, criminal record, racial or ethnic origin, religious beliefs, political opinions, sexual orientation, and biometric information.
8. Recording and transcription of conversations
We do not record or transcribe every conversation.
Where we do use a transcription tool in a call or interview, we will tell you at the start of that conversation and explain that it is for note-taking. If you would prefer we did not, say so and we will take notes by hand. That decision will not affect how your application is treated.
A transcript is a working note used to produce an accurate summary.
9. Fairness and non-discrimination
Australian anti-discrimination law applies to a decision assisted by AI in exactly the same way it applies to any other decision. We treat it that way.
We do not use AI to screen on age, sex, gender identity, sexual orientation, race, national or ethnic origin, religion, disability, marital or relationship status, pregnancy, family responsibilities, or any other protected attribute.
We are alert to proxies. A search built on a graduation year, a suburb, a spoken language, or a career gap can carry the same effect as screening on the attribute itself, and we treat those as design faults to be fixed.
Human review of every longlist is our primary control against biased output, because it is the point at which a person can see who is missing.
Before adopting a new tool that touches candidate assessment, we consider its potential for discriminatory effect. We do not adopt it unless we are satisfied that risk can be identified and managed, and we record how.
10. Accuracy and verification
AI systems generate probable answers, not verified facts. They can produce material that is fluent and wrong.
Facts, figures, company details, names, dates and market claims are verified before they appear in anything we send to a client or a candidate.
An AI-generated summary of a candidate never substitutes for having spoken to them. We do not represent a candidate we have not interviewed.
11. Client and commercial confidentiality
Client briefs, commercial terms, rates, fee arrangements and any information provided to us in confidence are not entered into general purpose consumer AI tools.
Confidentiality obligations we owe a client under an agreement or an NDA extend to our use of AI, without exception.
Where a client's requirements on AI use are stricter than this policy, we apply theirs, and we confirm them in writing at the start of the engagement. Where a client asks for something this policy does not permit, we decline that part of the work.
12. Candidates using AI
We are not going to hold it against you. Using AI to tighten a CV, prepare for an interview, or research a company is sensible, and we would rather you were well prepared.
Two things we would ask.
The experience should be yours. A CV that describes work you did not do creates a problem later, for you more than for us, and it is the sort of thing that surfaces in a technical interview.
In a live conversation, we want to hear from you. Interviews are how a client forms a view of the person they would be working with, and a real answer beats a polished one.
Where a client tells us it has rules on AI use during its process, we pass those on before you go in. We ask the question at briefing, but we cannot see inside a client's process, so if you are unsure, ask us and we will ask them.
13. When something goes wrong
If an AI tool we use suffers a data breach, we treat it as we would any other breach of personal information we hold, under our Privacy Policy and the Notifiable Data Breaches scheme. Where a breach is likely to result in serious harm, we notify affected individuals and the Office of the Australian Information Commissioner as soon as practicable.
If AI-generated material that was materially wrong has reached a client or a candidate, we correct it, we tell the people affected, and we tell them what we have changed so it does not happen again.
If you think something we have sent you is wrong, tell us. We will look at it and come back to you.
14. Governance and review
This policy is owned by the Director of ScaleUp Recruitment, who is accountable for its application.
We assess every AI tool before adopting it, covering what it does with personal information, where that information is stored, who can access it, what happens to it on termination, and its potential for discriminatory effect. We withdraw a tool if it stops meeting the standards in this policy.
We maintain an internal register of the AI tools we use, what each is used for, and what data it touches. Clients may request a current copy as part of supplier due diligence, along with our data residency and retention positions.
Our staff are briefed on this policy and on the limitations of the tools they use.
We will review this policy again before 10 December 2026, and at least annually after that. We will also review it whenever we adopt a tool that materially changes how personal information is handled, or when the law changes.
15. Questions, requests and complaints
If you have a question about how AI has been used in your application or engagement, or you want to make one of the requests in section 5, contact us using the details below.
If you wish to make a complaint, please put it in writing. We will consider it, determine what action is appropriate, and respond within 30 days of receiving it.
If you are not satisfied with our response, you may refer the matter to the Office of the Australian Information Commissioner at oaic.gov.au.
Contacting us
ScaleUp Recruitment
Email: info@scaleuprecruitment.com.au
Telephone: +61 2 8358 2491
This policy takes effect on 10 September 2026.

