Last Updated: 17-09-2026
This policy covers RTOPilot Jobs, the job board at jobs.rtopilot.com.au. It is written to be accurate about what this site actually does, including the parts that are unflattering.
1.1This Privacy Policy explains how XMB Technology Pty Ltd ABN 49 672 748 391 ("RTOPilot", "we", "us", or "our") collects, uses, discloses, and protects personal information through RTOPilot Jobs, the job board operated at jobs.rtopilot.com.au (the "Board").
1.2We are committed to protecting your privacy and ensuring compliance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
1.3This Privacy Policy applies to:
1.4The Board is a separate service from the RTOPilot training management platform. Where you also use that platform, the RTOPilot Privacy Policy at rtopilot.com.au applies to it.
2.1.1When you apply for a role through the Board, we collect and store:
2.1.2You may apply without creating an account. Where you do create one, we additionally store your first and last name, email address, telephone number, a cryptographic hash of your password, and the date on which your email address was verified. We do not store your password itself.
2.1.3Where a role requires evidence of a qualification, we store the document you upload together with its original filename, file type and size. We store these documents so the advertising employer can review them.
2.1.4Some evidence items ask for an identifying number rather than a document, including Working with Children Check and Blue Card numbers. Where you provide one, it is stored as you entered it, without masking. It is shown to the employer advertising the role, and is included if that employer downloads its applicant list. While you are still filling in the form, it is also held in your own browser so the form survives a refresh. These are sensitive identifiers and we ask you not to provide them anywhere on the Board other than in the field that requests them.
2.1.5The Board includes a directory of trainers and assessors. Your profile appears in it only if you choose to list it, and it is not listed by default. Where you do list it, the profile is public: it can be read by anyone, including people who are not signed in, and it is published at its own web address which search engines may index. A listed profile shows your headline, location and state, availability, pay range, years of experience, delivery modes and qualifications. Your name is shown only to signed-in employers on a paid plan and to our platform administrators. You can remove your profile from the directory at any time from your profile page.
2.1.6Where you save a role or create a job alert while signed in, we store that saved role, and for an alert the search terms you saved, the label you gave it, how often you asked to be notified, and when we last notified you.
2.1.7Where you sign up to the newsletter, we store your email address, a note of which page you signed up from, and the date you signed up. The newsletter is a weekly email listing the roles that went live that week, and it is sent only in weeks that have new roles. You do not need an account to sign up, and every newsletter carries a link that removes your address from the list.
2.2.1For employers who hold an account with us, we collect and store:
2.3.1The Board compiles some listings from roles that employers have advertised publicly on their own websites, and enters others for an employer ourselves, using details the employer gave us or that we hold for them. In both cases those employers have not registered with us and have not asked to be listed.
2.3.2For such a listing we collect and publish:
2.3.3Where a publicly listed contact address is available for that employer, we may use it once to invite them to take control of their listings. Section 6.4 describes that contact, and Section 7 describes how an employer stops it or has a listing removed.
2.4.1When a role is viewed, we record which role was viewed, the calendar day on which it was viewed, and a one-way hash of the network address and browser identification string that reached the part of our system which records the view. That hash exists only to avoid counting the same visitor twice on the same day. It does not achieve that today: the view reaches that part of our system through our own web server rather than from your device, so the address and browser string we hash are our own and the same hash is recorded for everyone. A view count is therefore a rough sign of activity rather than a count of people. We do not store your IP address or your browser identification string.
2.4.2The hash described in clause 2.4.1 is not reversible by ordinary means, but it is not anonymous in the strict sense: a party who already knows both an IP address and a browser identification string could test whether they produce a given hash. We do not do this and we do not provide the hashes to anyone.
2.4.3When a search is run on the Board, we record the words searched for and the number of results returned. We do not record who ran the search, and we do not record an IP address against it.
2.4.4Our servers keep operational logs in the ordinary course of running the service, which may include technical details of requests made to us.
2.4.5When something goes wrong on the Board, on our servers or in your browser, we record technical details of the fault so that we can find and fix it: the kind of error, the message it produced, where in our software it happened, the page or part of the service involved, when it first and last happened, and how many times. If a page fails in your browser, your browser sends those details to us automatically. Before anything is stored we remove email addresses, phone numbers, long numbers, sign-in and other access tokens, anything after a question mark in a web address, and the web address of any trainer profile. We do not record who was using the Board when the fault happened, or an IP address. An error message is written by our software, but it can occasionally quote other information that was being handled at the time. These records are seen only by our platform administrators, and when a new fault is recorded a summary of it is emailed to our own staff.
3.1We collect personal information:
3.2Where information about an organisation is compiled from a public source, we collect only what that source already published.
4.1We collect and use personal information to:
4.2We do not sell personal information. We do not use personal information for advertising, and we do not disclose it to advertising networks.
5.1Traffic between your browser and the Board is encrypted in transit using TLS, and the Board instructs browsers to use an encrypted connection for subsequent visits.
5.2Account passwords are stored only as bcrypt hashes. Sessions use a signed token, held in a cookie that scripts on the page cannot read, sent only to our own site, marked secure in production, and expiring after thirty (30) days.
5.3Uploaded evidence documents are stored on infrastructure operated for us, and are retrievable only through an authenticated request by the employer advertising the role or by our platform administrators.
5.4So that you can judge our safeguards accurately, we tell you plainly what we do not currently do:
5.5No method of transmission or storage is completely secure. While we take reasonable steps to protect personal information, we cannot guarantee absolute security.
6.1.1When you apply for a role, your application and the evidence attached to it are disclosed to the employer advertising that role. Once disclosed, the employer handles that information under its own privacy obligations.
6.1.2Some listings direct applications to the employer’s own website rather than collecting them here. Where that is the case, the listing says so, and anything you submit there is collected by that employer and not by us.
6.1.3Compiled listings, which are roles we have listed from an employer’s own advertisement before that employer has claimed the listing, do not take applications here at all. The listing sends you to the employer’s own advertisement, and anything you submit there is collected by that employer and not by us. We previously accepted those applications and forwarded them to a contact address we had found for the employer; we stopped doing that on 26 August 2026.
6.2.1We disclose personal information to the following service providers so that the Board can operate:
6.2.2We use an artificial intelligence provider to read publicly advertised roles and convert them into listings. Only the public text of an employer’s advertisement is sent for that purpose. Candidate personal information is never sent to that provider.
6.3.1Where an employer has not supplied a logo, the Board displays the icon published by that employer’s own website, retrieved through an icon service operated by Google or by DuckDuckGo. Your browser makes that request directly. As a result, your IP address, your browser identification string and the address of the page you are viewing are disclosed to Google or to DuckDuckGo each time such a page is displayed.
6.3.2That disclosure happens whether or not you hold an account with us, and we do not receive the resulting information. We are describing it here because it is a disclosure of your personal information that occurs as a consequence of using the Board.
6.4.1Where we have compiled a listing from an employer’s public advertisement, we may send that employer a single message at a publicly listed address inviting them to take control of the listings we have compiled for them. We record the address used, the subject of the message, and whether it was sent, together with the date and time.
6.4.2We maintain a list of addresses that have asked not to be contacted, and that list is checked before any such message is sent.
6.5.1Our platform administrators can access records across all employers on the Board, including applications and the evidence documents attached to them. This access exists so we can operate, support and moderate the Board. Administrator actions of this kind are recorded in an internal audit log.
6.6.1We may disclose personal information where required or authorised by law, to protect our legal rights, or in connection with a sale or transfer of our business, in which case the recipient would be bound by this Policy.
6.7.1Some of the providers described in this Section, and the icon services described in clause 6.3.1, are located outside Australia or may store or process information outside Australia, including in the United States. Where we disclose personal information to an overseas recipient we take reasonable steps to ensure it is handled consistently with the Australian Privacy Principles, but you should be aware that overseas recipients may be subject to different laws.
7.1You may request access to the personal information we hold about you, and ask us to correct it if it is inaccurate, out of date or incomplete. Contact us using the details in Section 12.
7.2The Board does not currently provide a self-service means of deleting an account or an application. Requests to delete personal information are handled manually by us on request, and we will tell you what we have deleted and what we are required to keep.
7.3An employer whose role has been listed under Section 2.3 may ask us to remove that listing, or to refrain from listing their roles in future, by contacting us using the details in Section 12. We will action a removal request without requiring a reason.
7.4We will respond to a request under this Section within thirty (30) days. Where we refuse a request we will tell you why in writing.
8.1The Board sets one cookie, which holds your sign-in session. It is not readable by scripts on the page, is sent only to our own site, and expires after thirty (30) days. Signing out clears it.
8.2The Board uses one analytics service, Simple Analytics, to count page views. It runs only on the live site. It does not set cookies, does not use a device identifier, and does not track visitors between websites. Your browser requests its script directly, which discloses your IP address to that provider.
8.3The Board does not use advertising cookies, advertising pixels, or any third-party cookie for measurement.
8.4Some conveniences, including recently viewed searches and an unsent application draft, are stored in your own browser and are never sent to us. Clearing your browser storage removes them.
8.5You may control cookies through your browser settings, though the Board will not keep you signed in without the cookie described in clause 8.1.
9.1Evidence documents uploaded with an application are deleted approximately six (6) months after the role they were submitted for closes, or approximately six (6) months after upload where the role has no closing date. This deletion runs automatically and removes both the stored document and our record of it.
9.2The application record itself is retained after the documents are deleted, and is not deleted automatically. That record comprises your name, email address, telephone number, any note you wrote, the status of the application, and any identifying number you entered under clause 2.1.4, including a Working with Children Check or Blue Card number. You may ask us to delete it under Section 7.
9.3A listing posted through the self-service flow expires thirty (30) days after publication and ceases to be shown publicly. A listing we compiled and published for an employer runs for thirty (30) days from publication, and for a further thirty (30) days from the day that employer claims it. Any other listing we publish ourselves through our management console has no fixed term and stays on the Board until it is closed. Account records are retained while the account is open.
9.4The technical records described in Section 2.4 are retained so that view counts and search coverage remain meaningful over time. They do not identify you by name. A record of a search is deleted twelve (12) months after the search was run. A record of a fault is kept while the fault remains unfixed, and is deleted ninety (90) days after we mark it as fixed.
10.1In the event of a data breach, we will:
11.1Privacy-related complaints may be submitted by email to support@xmb.com.au.
11.2We will:
11.3If you are not satisfied with our response, you may refer the matter to the Office of the Australian Information Commissioner at www.oaic.gov.au.
12.1For privacy-related enquiries, to request access, correction or deletion, or to ask that a listing be removed, please contact the Privacy Officer, XMB Technology Pty Ltd, by email at support@xmb.com.au.
13.1We may update this Privacy Policy from time to time. The date at the top of this page shows when it was last updated, and continued use of the Board after that date constitutes acceptance of the updated Policy.