CheckedWell CheckedWell

Privacy policy

Last updated 27 August 2026

CheckedWell collects reference checks, which means we hold personal information about three kinds of people and only one of them is our customer. Most of this page is about the other two.

The short version

  • Recruiters — the people with accounts, who work for the agency that pays us.
  • Candidates — the people being referenced. They are not our customers and usually never see the product.
  • Referees — the people asked to give the reference. They did not choose us either, and they are giving us their opinion about somebody else.

We do not sell personal information, we do not use it to train anybody's model, and nobody gets marketing because they appeared in a reference.

Who we are

CheckedWell is an Australian reference-checking service, built and hosted in Sydney. In this policy, “we” and “our” mean that operator.

Contact us at support@checkedwell.com.

The law this is written to

The Privacy Act 1988 (Cth) and the Australian Privacy Principles, and the Privacy Act 2020 (NZ) and the Information Privacy Principles, which apply to any New Zealand agency using CheckedWell and any New Zealand individual whose information we hold.

What we hold

Recruiters and agency staff

Name, work email, phone if given, job title. A password stored only as an Argon2id hash, which we cannot read. Two-factor enrolment data. Sign-in times, IP addresses, and a record of what you did: who raised a reference, who sent it, who read a report, who exported data. Billing contacts.

Candidates

Name, email, phone. The role being checked and the employment history relevant to it. The referees nominated. And everything the referees say about them — which is the part candidates are least likely to expect, so we say it plainly.

Referees

Name, email, phone, employer, job title, and their relationship to the candidate. Their answers, including free text. The date, time and IP address of the submission, recorded so a reference can be shown to be genuine if it is ever disputed. Whether they declined, and any reason given.

What we do not ask for

Our question sets avoid sensitive information as the Privacy Act defines it — health, disability, race, ethnicity, religion, political opinion, sexual orientation, criminal record, union membership. We do not ask about any of it, and agencies writing their own questions should not either.

If a referee volunteers something sensitive anyway, and people sometimes do, it is stored as part of their answer, encrypted like every other answer, and visible only to the agency. Tell us and we will remove it.

Most of this was not collected from you

If you are a candidate: we got your contact details from the agency placing you, and opinions about you from the referees you or the agency nominated. Your agency is required to have your consent before seeking a reference. This page is also how we tell you, which is what APP 5 and — from 1 May 2026 — New Zealand's IPP 3A require.

If you are a referee: we got your name and contact details from the candidate or the agency. Before you answer a single question the form tells you what is collected, who will see it, and that your submission time and IP address are recorded. That notice is on the screen, above the button — not buried in this policy.

Why we hold it

To provide the reference-checking service to the agency that raised the reference: sending the invitation, chasing a referee who has not replied, producing the report, keeping the audit trail, keeping the service secure. That is the whole list.

Who else sees it

The agency that raised the reference. Where they are recruiting for a client, a client report may go to that client — answers marked internal are excluded from it and never reach them. The agency decides who inside their organisation can see a reference. We do not.

Beyond that, only where the law requires it, where it is necessary to establish or defend a legal claim, or with the consent of the person concerned.

Information that leaves Australia

Our application, database, files and backups are in Sydney and stay there. Two things cross a border, and you should know about both.

Email

We send through Postmark, operated in the United States. Anything in an email — a candidate's name, a referee's name, the invitation link — passes through and is retained there for a limited period. There is no way to send email at a professional standard of deliverability without a specialist provider, and no Australian-hosted one we consider good enough.

Call-note drafting, only if your agency turns it on

A consultant taking a reference by telephone can have their notes placed into the answer boxes as a draft they then read, correct and submit under their own name. Those notes go to Anthropic in the United States. They are not used for training, they are not kept by us unless the consultant keeps them with the submission, and the feature does not exist unless the agency has enabled it.

Under APP 8 and IPP 12 we take reasonable steps to ensure these recipients handle personal information consistently with the Australian and New Zealand principles, and we remain accountable to you for what they do with it.

Automated decisions, and the fact that we do not make any

We say this ahead of the transparency obligation that commences on 11 December 2026, because it is a fair thing to know now.

Nothing in CheckedWell makes a decision about anybody. No scoring, no ranking, no recommendation to hire or reject, no number a recruiter could mistake for a verdict. The hiring decision is made by a person, on the basis of a reference a human being gave and a human being read.

The one place a computer touches what somebody said is the call-note drafting above, and three things constrain it: it only produces a draft a consultant must submit under their own attestation; an answer is discarded, not corrected, if the supporting words do not appear verbatim in the notes or the value is outside the allowed scale; and it is off unless the agency switched it on.

If that ever changes, this section will say so before we ship it.

How we protect it

Names, email addresses, phone numbers and free-text answers are encrypted at the column, not just the disk. Two independent mechanisms keep one agency out of another's data. Referee links are stored only as a one-way hash and expire after fourteen days. Passwords are Argon2id. Two-factor is mandatory for owners. The audit log is append-only and cannot be quietly tidied, including by us.

The detail, including what we have not done, is on the security page.

How long we keep it

7 years from the completion of a reference by default, because that is the outer edge of most Australian employers' record-keeping obligations. Each agency can set a shorter period. When an agency deletes its organisation everything goes — references, answers, files and audit records — subject only to backups, which age out on their own cycle.

Your rights

If you are a candidate or a referee, the agency that raised the reference holds it and is the fastest route. But you can come to us at support@checkedwell.com and we will either deal with it or tell you honestly that we have to refer you to the agency, and why.

  • A copy of what we hold about you — APP 12, IPP 6.
  • Correction of anything wrong — APP 13, IPP 7. We will not delete a referee's opinion because a candidate disagrees with it, since that would defeat the point of a reference, but we will record that it is disputed and correct anything factual that is wrong.
  • To be left alone. A referee can decline, and once they have, we do not chase them again.

No charge. We answer within 30 days in Australia, 20 working days in New Zealand.

Complaints

Us first — support@checkedwell.com, marked “Privacy complaint”. Acknowledged within 5 business days, answered within 30. If you are not satisfied: the Office of the Australian Information Commissioner (oaic.gov.au, 1300 363 992), or in New Zealand the Office of the Privacy Commissioner (privacy.org.nz, 0800 803 909).

If we suffer a data breach

Where serious harm is likely we notify the affected individuals and the relevant Commissioner, as the Notifiable Data Breaches scheme and the New Zealand notifiable privacy breach provisions require. We tell the agency whose data is involved promptly either way, whether or not the threshold for notifying a regulator is met.

Cookies

A session cookie to keep you signed in, and a Cloudflare Turnstile cookie on public forms to tell a person from a bot. That is all. No advertising cookies, no analytics, no third-party trackers, and the fonts on this page come from our own servers rather than a font network.

Changes

If we change this policy in a way that materially affects how we handle personal information, account holders get an email before it takes effect. The date at the top is always the current version.