Hound privacy policy

Last updated 3 September 2026

Who this covers

Hound is recruitment CRM software. Recruitment businesses subscribe to it and use it to keep records about the candidates and clients they work with.

That makes two different relationships, and this policy is about the first one. Hound holds information on behalf of the businesses that subscribe — it does not decide what those businesses collect, why they collect it, or how long they keep it. Each business decides that for itself and answers for it.

So if you are a candidate and want to know what is held about you, or want it corrected or deleted, the people to ask are the recruitment business you have been dealing with. They can see, change and delete your record; they are the ones with the relationship to you. The notice you were shown when you filled in one of their forms names them and tells you how to reach them.

This is a draft policy provided with the software. Each business using Hound should have its own privacy policy reviewed by its own lawyer, and should not rely on this one as a substitute.

What is held

For a subscribing business: the business name and trading address, the name, email address and username of each of its users, their password stored only as a one-way hash, and a record of when and from where each of them signed in.

For the people that business recruits: whatever the business chooses to record. Typically that is a name, contact details, work history, the roles they are interested in, notes from conversations, and documents such as CVs and references that the business or the candidate has uploaded.

Emails and text messages sent through the CRM are stored against the record they relate to, so the business has a history of its own correspondence.

Where it is stored, and who can reach it

Data is stored in Australia, in a Postgres database hosted in Sydney, with uploaded documents in file storage attached to the same account.

Each business's records are separated at the database layer rather than by convention: every query is filtered to the business that asked it, and a query that cannot establish which business it belongs to is refused rather than answered. One business cannot read another's records.

Hound's own operators can see the list of subscribing businesses, their plan and their user counts. Reaching a business's actual records requires impersonating one of its users, which is recorded in an audit log the operator cannot edit.

What leaves the system

Email sent from the CRM goes out either through the sending user's own Microsoft Outlook mailbox, or through Resend, an email delivery service, where Outlook is not connected.

Text messages, where a business has switched them on, are sent through Twilio using that business's own account.

Where a business has connected Outlook, calendar events and emails are read from and written to Microsoft 365 on that user's behalf.

Nothing is sold, and nothing is shared with anyone else for advertising or profiling. There is no advertising or analytics tracking in the CRM.

Artificial intelligence

The CRM includes an optional assistant. It only works if a user supplies their own Anthropic API key, which is stored encrypted and is readable only inside that business.

If a business chooses to use it, the record content that user asks about is sent to Anthropic to answer the question. A business that does not add a key sends nothing anywhere.

How long it is kept

A subscribing business's records are kept for as long as it holds an account. Deleting a record in the CRM moves it to Recently Deleted, where it can be restored, and it is purged after that window.

Each business decides how long to keep candidate information, and should have a retention rule of its own. Hound provides the deletion and purge tools; it does not decide the schedule.

Security

Passwords are stored as one-way bcrypt hashes and are never recoverable. Repeated failed sign-ins lock an account. One account can hold one live session, so signing in on a new device ends the previous one.

Traffic is encrypted in transit. Uploaded documents are stored privately and are served only to signed-in users of the business that owns them, never from a public link.

No system is perfect. If you believe something has gone wrong with data held in Hound, tell the business whose CRM it is, and tell us.

Complaints

If you are a candidate or client, raise it first with the recruitment business holding your record — they are the ones who collected it and who can change it.

If your concern is about the software itself, contact Ezra Recruitment, which operates Hound.

If you are not satisfied with the response, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.

← Back to sign-up