Legal

Privacy Policy

Effective date: 8 March 2026

Tenurify is committed to protecting your personal information. This policy explains what data we collect, why we collect it, and your rights under the Australian Privacy Act 1988 (including the Australian Privacy Principles) and the New Zealand Privacy Act 2020.

1. Who we are

Tenurify ("we", "our", "us") operates the academic job platform available at tenurify.com, connecting academic candidates with universities and research institutions across Australia and New Zealand.

We are the data controller for personal information processed through this platform. For privacy inquiries, contact us at privacy@tenurify.com.

2. Data we collect

We collect information you provide directly and data generated by your use of the platform.

Account & profile data

  • Full name and email address
  • Password (stored as a bcrypt hash — never in plain text)
  • Academic degrees: institution, field of study, year of completion
  • Research fields and areas of expertise
  • Profile preferences (e.g. recommendation settings)

Activity data

  • Jobs viewed, saved, and applied to
  • Search queries and filter selections
  • Pages visited and time spent on the platform
  • Timestamps for logins and profile updates

Technical data

  • IP address and approximate geographic location
  • Browser type, operating system, and device type
  • Referral source (e.g. search engine, direct link)
  • HTTP cookies and session tokens (see Section 5)

University account data

  • Institution name, campus details, and administrator email
  • Job postings created, including salary and deadline information
  • Aggregated analytics for posted positions (views, apply clicks)

We do not collect sensitive information such as racial or ethnic origin, health data, religious beliefs, or political opinions.

3. How we use your data

We use your personal information to:

  • Create and manage your account and authenticate your sessions
  • Display relevant job listings based on your profile and search history
  • Send job alert emails when new positions match your saved searches (only if you opt in)
  • Send transactional emails: account confirmation, password reset, application status updates
  • Allow universities to manage their job postings and review aggregate analytics
  • Improve platform performance, fix bugs, and develop new features
  • Comply with our legal obligations and enforce our Terms of Service

We rely on contract performance as the legal basis for processing data necessary to provide the service, and on legitimate interests for analytics and platform improvement. Where we send marketing emails, we rely on your explicit consent, which you can withdraw at any time.

4. Sharing your data

We do not sell your personal data. We share it only in the following circumstances:

  • Service providers: hosting (Google Cloud Platform), transactional email (Zoho Mail), analytics — all bound by data processing agreements
  • Universities: when you explicitly apply to a position, relevant profile information is shared with the hiring institution
  • Legal requirements: we may disclose data if required by Australian or New Zealand law, court order, or to protect the safety of users
  • Business transfer: in the event of a merger or acquisition, your data may be transferred to the new entity under equivalent protections

University administrators can see aggregate analytics (total views, apply click counts) for their own job postings. They cannot see the identities of individual candidates who viewed a listing unless those candidates submitted an application.

5. Cookies & tracking

We use the following types of cookies:

Essential cookies

An HttpOnly session cookie is used to authenticate you securely. This cookie cannot be accessed by JavaScript and is required for the platform to function. It expires when you log out or after 7 days of inactivity.

Analytics cookies

We use privacy-respecting analytics to understand aggregate usage patterns (most visited pages, popular job categories). No personally identifiable information is embedded in these cookies.

You can disable non-essential cookies in your browser settings. Disabling the session cookie will require you to log in each visit.

6. Data retention

We retain your data for as long as your account is active. Specifically:

  • Account data: retained while your account exists and for 30 days after deletion (to allow recovery in case of accidental deletion)
  • Activity logs: retained for up to 12 months for security and fraud prevention
  • Application records: retained for up to 2 years to maintain hiring audit trails for universities
  • Anonymised analytics: retained indefinitely in aggregate form (not linked to any individual)

When you delete your account, all personally identifiable information is removed within 30 days. Anonymised and aggregated data may be retained for platform analytics.

7. Your rights

Under the Australian Privacy Principles and the New Zealand Privacy Act 2020, you have the right to:

  • Access: request a copy of the personal data we hold about you
  • Correction: request correction of inaccurate or incomplete data
  • Deletion: delete your account and all associated data directly from your Profile page
  • Portability: request your data in a machine-readable format
  • Opt-out: unsubscribe from marketing and recommendation emails at any time via your profile settings or the unsubscribe link in any email
  • Complaint: lodge a complaint with the Australian Information Commissioner (OAIC) at oaic.gov.au or the New Zealand Privacy Commissioner at privacy.org.nz

To exercise any of these rights, email us at privacy@tenurify.com. We will respond within 30 days. You can also delete your account directly from your Profile page.

8. Security

We implement industry-standard safeguards to protect your data:

  • All data in transit is encrypted using TLS 1.2 or higher
  • Passwords are hashed using bcrypt with a high work factor — we never store plain-text passwords
  • Authentication uses HttpOnly, Secure, SameSite=Strict cookies to prevent XSS and CSRF attacks
  • Access to production databases is restricted to authorised personnel via VPN
  • Account deletion requires password confirmation as an additional safeguard

Despite these measures, no system is completely immune to breaches. If we become aware of a data breach that affects your rights, we will notify you and the relevant authority within 72 hours as required by law.

9. Children

Tenurify is intended for academic professionals and is not directed at children under 16 years of age. We do not knowingly collect data from anyone under 16. If you believe we have inadvertently collected such data, please contact us immediately at privacy@tenurify.com and we will delete it promptly.

10. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will update the effective date at the top of this page and, if the changes are material, notify you by email or via a prominent notice on the platform.

Your continued use of Tenurify after changes are posted constitutes your acceptance of the updated policy.

11. Contact us

For privacy-related questions, data access requests, or complaints, contact our privacy team:

Tenurify — Privacy Team

Email: privacy@tenurify.com

Response time: within 30 days

If you are not satisfied with our response, you may escalate to the Office of the Australian Information Commissioner (OAIC) or the New Zealand Privacy Commissioner.