Privacy Policy
Last updated: May 10, 2026
DiveGigs ("DiveGigs", "we", "us", or "our") respects your privacy and is committed to handling personal information responsibly.
This Privacy Policy explains how we collect, use, store, disclose, and otherwise handle personal information when you use divegigs.com and any related services, features, communications, and applications we provide (collectively, the "Services").
If an employer receives your application or profile information through DiveGigs, that employer may handle your information under its own privacy practices as well. We are not responsible for the privacy practices of third-party employers, websites, or services.
1. Who this policy applies to
This policy applies to people who use DiveGigs, including:
- job seekers, candidates, and divers
- employers, recruiters, and hiring businesses
- people who visit or browse our website
- people who contact us or sign up for updates
2. The information we collect
We may collect the following categories of personal information.
A. Information you provide directly
When you create an account, complete a profile, post a job, apply for a role, contact us, or otherwise use the Services, we may collect information such as:
- your name
- email address
- password credentials (stored in secured or hashed form, not in plain text)
- profile details such as headline, bio, certifications, experience, location, preferences, availability, languages, and other career-related information
- CVs, resumes, cover letters, application responses, and supporting documents you upload
- employer or company details, including organisation name, contact details, job listings, and hiring information
- communications you send to us or through the platform
- any other information you choose to submit
B. Information collected automatically
When you use DiveGigs, we may automatically collect certain technical and usage information, such as:
- IP address
- browser type
- device information
- pages viewed
- referring URLs
- timestamps
- login activity
- approximate location from IP address
- cookie or session identifiers
- security, diagnostic, and abuse-prevention logs
C. Payment and billing information
Payments made through DiveGigs are processed by third-party payment providers such as Stripe. We do not store full payment card numbers or card security codes on our own systems. We may receive limited transaction-related information such as payment status, customer identifier, subscription status, billing country, and the last four digits of a card where made available by the payment provider.
D. Information from third parties
We may receive information from third parties, such as:
- payment providers
- email delivery or communication providers
- analytics, fraud-prevention, and security providers
- employers or candidates involved in applications or disputes
- social sign-in providers, if enabled
3. How we collect personal information
We collect personal information:
- directly from you when you create an account, complete your profile, post a job, apply for a job, contact us, or subscribe to alerts
- automatically through your use of the Services
- from service providers and integration partners that help us operate the platform
- from other users where relevant to an application, listing, report, or support request
4. Why we use personal information
We use personal information for the following purposes:
- to provide and operate DiveGigs
- to create and manage user accounts
- to display candidate profiles and employer listings in line with your settings
- to enable candidates to apply for roles and employers to receive applications
- to send transactional emails and service messages
- to send job alerts, saved search alerts, newsletters, or marketing communications where enabled or permitted
- to process subscriptions, purchases, and payments
- to provide customer support
- to maintain platform security and prevent fraud, spam, abuse, or misuse
- to improve the Services, including troubleshooting, analytics, product development, and performance monitoring
- to comply with legal, regulatory, and contractual obligations
- to establish, exercise, or defend legal claims
5. Candidate privacy and profile visibility
Candidate privacy is important to us.
By default, candidate profiles may be set to private unless and until the candidate chooses to make them discoverable or visible in accordance with the platform settings. Where profiles are private:
- employers generally cannot browse full candidate details publicly through the platform
- employers can view a candidate's application materials when the candidate applies for that employer's listing
- a candidate may choose to opt in to public or employer discoverability, in which case selected profile details may become visible to employers or, if enabled, on public pages
Candidates are responsible for deciding what information they include in profiles, CVs, cover letters, and applications. Please avoid including unnecessary sensitive personal information unless it is genuinely relevant and requested.
6. When we disclose personal information
We may disclose personal information:
- to employers, recruiters, or hiring organisations when you apply for a job or choose to make your profile discoverable
- to candidates when an employer communicates through the platform
- to service providers who help us operate DiveGigs, such as hosting, email, analytics, support, security, and payment providers
- where required by law, regulation, court order, or lawful request from authorities
- where necessary to investigate fraud, abuse, security incidents, or violations of our terms
- in connection with a sale, merger, acquisition, restructure, or transfer of all or part of our business or assets
- with your consent or at your direction
We do not sell personal information in the ordinary sense of selling user databases to data brokers.
7. Overseas disclosure and international use
DiveGigs may use service providers, infrastructure, or partners located in countries outside Australia. In addition, employers and candidates using the platform may be located in different countries. As a result, your personal information may be accessed, processed, or stored outside your country of residence, including in Australia, the United States, the European Union, the United Kingdom, and other countries where our service providers or users operate.
By using DiveGigs, you acknowledge that international transfers may occur where reasonably necessary to provide the Services.
8. Cookies and similar technologies
We may use cookies, local storage, pixels, and similar technologies to:
- keep you signed in
- remember preferences and settings
- maintain security and session integrity
- understand usage and improve the Services
- measure the effectiveness of communications or site features
You can manage cookies through your browser settings. However, some parts of DiveGigs may not function properly without essential cookies.
9. How we protect personal information
We take reasonable technical and organisational steps to protect personal information from misuse, interference, loss, and unauthorised access, modification, or disclosure. These measures may include access controls, encryption in transit, password protection, secure third-party infrastructure, monitoring, and limited internal access on a need-to-know basis.
No method of transmission over the internet or electronic storage is completely secure. While we take reasonable steps to protect your information, we cannot guarantee absolute security.
10. Data retention
We retain personal information only for as long as reasonably necessary for the purposes described in this policy, including to:
- provide the Services
- maintain account records
- support hiring workflows and application history
- comply with legal, tax, accounting, and regulatory obligations
- resolve disputes
- enforce our terms
- detect and prevent fraud or security issues
Retention periods may vary depending on the type of information and the reason we hold it. When personal information is no longer reasonably required, we will take reasonable steps to delete it or de-identify it, subject to legal and operational requirements.
11. Access, correction, and account choices
You may request access to personal information we hold about you and request correction of inaccurate, incomplete, or out-of-date information.
In many cases, you can also review or update information directly through your account settings.
You may also:
- update your profile and account information
- change job alert or marketing preferences
- close your account
- request deletion of certain personal information, subject to legal or operational retention needs
To make a privacy request, please contact us.
12. Complaints
If you have a complaint about how we handle your personal information, please contact us first and provide enough detail for us to investigate.
We will review your complaint and respond within a reasonable time.
If you are not satisfied with our response, you may have the right to escalate your complaint to the relevant privacy or data protection regulator in your jurisdiction.
13. Additional information for EEA and UK users
If you are located in the European Economic Area or the United Kingdom, you may have additional rights under applicable data protection law, which may include the right to request access, rectification, erasure, restriction, objection, portability, and the right to withdraw consent where processing is based on consent.
Where applicable, we process personal data on grounds such as:
- performance of a contract
- compliance with legal obligations
- our legitimate interests in operating, securing, and improving DiveGigs
- your consent
You may also have the right to lodge a complaint with your local supervisory authority.
14. Third-party services and links
DiveGigs may contain links to third-party websites, employer career pages, payment providers, or other external services. We are not responsible for the privacy practices or content of those third parties. You should review their privacy policies separately.
15. AI agents and Model Context Protocol (MCP)
DiveGigs offers an optional Model Context Protocol (MCP) integration that lets you connect a third-party AI client, such as Claude, ChatGPT, Cursor, or other compatible assistants, to your DiveGigs account so that the AI can search jobs, manage applications, draft listings, or perform other actions on your behalf. Use of this integration is entirely opt-in.
A. How the connection works
To connect an AI client you complete an OAuth authorisation step in your browser. You see and approve the specific scopes the AI is requesting (for example, read access to your account, the ability to apply for jobs, the ability to draft job listings, the ability to review applicants, or the ability to generate checkout links for paid actions). The connection only grants the scopes you approve, and you can revoke it at any time from your account settings at /profile/mcp-tokens.
B. What data flows through the AI provider
When you use an AI client to interact with DiveGigs:
- the prompts and instructions you give the AI are processed by that AI provider's servers
- the data DiveGigs returns to the AI client (such as job listings, applicant details, your profile, or course enquiries) is sent back through that AI provider in order to answer you
- the AI provider's own privacy policy and data-handling terms apply separately to anything you send through their service
DiveGigs is not responsible for how a third-party AI provider stores, processes, or trains on the conversations you have with their assistant. You should review the privacy terms of any AI client you choose to connect.
C. What MCP can and cannot access
An AI client connected to your account can only access the same data you can already see and act on through the DiveGigs dashboard, scoped further by the OAuth abilities you approve. Tenant isolation is enforced server-side: an employer's AI client cannot see other employers' jobs or applicants, and a candidate's AI client cannot see other candidates' profiles or applications.
Resume files uploaded to DiveGigs are never returned through MCP. The AI receives only metadata and, where appropriate, a download link that a human can click to retrieve the file directly from DiveGigs.
Actions that involve payment, such as publishing a paid job listing or topping up a course-leads wallet, are never executed autonomously. The AI generates a checkout link, and you must review and complete the payment yourself with the payment provider.
D. What we log
For security, abuse-prevention, and support purposes, we keep an audit log of MCP tool calls made against your account. This log records the calling user, the OAuth token used, the name of the tool that was invoked, whether it succeeded, the duration of the call, and a one-way hash of the arguments. We do not store the raw argument values themselves in the audit log. Standard application logs may also retain limited diagnostic information in line with section 9 of this policy.
E. Your control
You can disconnect an AI client at any time by revoking its token in your account settings, which immediately ends its access. You can also choose not to connect an AI client at all; the rest of DiveGigs works the same way regardless.
16. Children
DiveGigs is not directed to children, and we do not knowingly collect personal information from children under 16. If you believe a child has provided personal information to us, please contact us so we can take appropriate steps.
17. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. Where appropriate, we may also provide notice through the website or by email.
18. Contact us
For privacy questions, requests, or complaints, please contact us.