Purpose and scope
Who this covers, what counts as AI here, and what it does not.
This policy establishes how Kwirl Australia Pty Ltd uses AI ethically, responsibly and effectively. It aims to protect the rights of candidates and employers, keep AI use transparent enough to maintain trust, and give a clear framework for identifying and managing AI risk.
It applies to everyone who builds, buys, configures or uses AI on Kwirl’s behalf — employees, contractors, and vendors — and to every AI system under our control, whether built in-house, bought from a vendor, or embedded in a larger platform.
We treat as an AI system any technology that uses data to make inferences and generate outputs such as predictions, recommendations or decisions with a degree of autonomy. That includes machine learning models, generative AI, ranking and matching systems, and conversational agents. It does not include ordinary spreadsheet formulas, simple if-then automations, or traditional business-intelligence dashboards.
If you are unsure whether something falls under this policy, ask legal@kwirl.com.au.
Systems in scope
Kira is our named AI system. New systems are screened before they ship.
The AI system in production scope today is Kira: matching and ranking, drafting, summarising, interview preparation, and employer shortlist suggestions. Those capabilities are recorded in our internal AI register with an accountable owner, risk rating and review date.
Any new AI use case is screened before adoption. Screening classifies the use as normal, elevated or prohibited, and sets the level of risk assessment, oversight and approval required. Prohibited and high-risk cases escalate before any deployment.
What Kira does
Matching, drafting, summarising and preparation. Always as a suggestion.
Kira ranks roles against your outcomes rather than your keywords, drafts follow-up messages you review before sending, summarises long listings, and prepares interview notes from a role and your showcase.
On the employer side Kira summarises applications, suggests a shortlist order, and drafts outreach. Every one of those outputs is presented as a recommendation with the reasoning shown, never as a decision.
Ethical and human-centred use
Aligned with Australia’s AI Ethics Principles. No deception.
AI on Kwirl must respect human dignity, support human judgment for final decisions, and contribute positively to fair hiring. We align our practice with Australia’s AI Ethics Principles and with our product rules on published salary bands, honest stages and no automated rejection.
AI must not be used to deceive or manipulate candidates or employers. Generated content is labelled. We do not use AI to fabricate roles, invent candidate credentials, or obscure who made a hiring decision.
Human oversight and control
No automated rejection. Humans can pause, override or stop AI.
Kwirl does not permit fully automated adverse decisions. An employer cannot configure Kwirl to auto-reject candidates on a Kira score, and no such feature exists in the product.
A named person must review and record a reason before any candidate is rejected. We log the reviewer and the timestamp, and a candidate can ask whether a human reviewed their application.
Oversight is proportionate to autonomy and impact. Users remain responsible for the quality of outputs they act on. We can pause, override or take an AI feature offline when needed, and hiring workflows continue without Kira if a feature is disabled.
This is stricter than most jurisdictions currently require, and it aligns with Australian automated-decision reform, the New Zealand Algorithm Charter, and transparency duties in United States state and city law.
Accountability and governance
Named owners, clear approval, and a place to escalate.
Every AI system in the register has an accountable AI system owner who understands the system and is responsible for its outcomes and compliance with this policy. Ownership is assigned before a system is adopted; vendor responsibilities are documented in the contract.
The AI policy owner is Kwirl’s legal function (legal@kwirl.com.au), which champions and maintains this policy, holds overall accountability for AI governance, and ensures people in AI roles get the training they need.
Material revisions to this policy are approved by Kwirl leadership. Day-to-day compliance — checking that risk assessments and documentation exist, monitoring AI-related incidents, and reporting gaps — sits with operations and trust and safety, escalating to the policy owner.
Elevated or disputed use cases escalate to leadership for review before deployment.
Risk and impact assessment
Assessed before use, with controls matched to the risk.
An AI system must complete a risk and impact assessment before we put it into use. Controls must match the risk we are taking on, including privacy, security, fairness and operational fallback.
Where a use case could affect candidates or employers in a material way — especially people from marginalised or vulnerable groups — we engage the relevant stakeholders or their advocates as part of the assessment.
Fairness and inclusion
Tested quarterly. No unfair discrimination.
AI systems must be inclusive and accessible. They must not involve or result in unfair discrimination against individuals, communities or groups, and they must reinforce — not undermine — our commitments to diversity, inclusion and accessibility.
We test matching and ranking outputs quarterly for disparate impact across gender, age band, name origin, and disclosed disability, using held-out evaluation sets rather than live user data.
Where a test shows material drift we hold the model version and correct it before release. Summary results are published in our transparency report.
Employers using Kwirl for candidate screening in New York City are responsible for their own annual bias audit and candidate notice under Local Law 144. We provide the model documentation and audit artefacts they need, but the audit obligation is theirs.
Quality, reliability and security
Tested before release, monitored in production, checked before you send.
AI features go through testing against documented acceptance criteria matched to identified risks before release. Once live, we monitor for performance issues, quality drift and emerging risks.
Language models produce fluent text that can be factually wrong. Kira can misread a listing, invent a detail about a company, or overstate a match. Read what it drafts before you send it.
Kira does not give legal, migration, tax or financial advice. Where it summarises visa or right-to-work information it is repeating what the employer published, not advising you.
Privacy and security safeguards in our Security Overview and Privacy Policy apply equally to AI systems that handle personal information.
Transparency and contestability
Labelled output, visible reasoning, and a way to challenge outcomes.
Anything Kira generated is labelled in the interface. Drafts are marked as drafts and are never sent without your action.
You can read every fact Kira has remembered about you, delete any of them, and turn memory off entirely. Turning it off degrades match quality rather than breaking the product.
You can ask what data informed a particular match. The reasoning panel lists the signals used. Where an AI-assisted outcome affects you — for example a ranking or a shortlist suggestion an employer acted on — you can contest it by writing to contact@kwirl.com.au or privacy@kwirl.com.au; we will investigate and respond.
From 10 December 2026, Australian Privacy Principle disclosures about automated decisions that significantly affect individuals will also appear in our Privacy Policy. This AI Policy remains the place for how Kira is governed day to day.
Training and your content
Off by default. Your conversations are not training data.
We do not train foundation models on your Kira conversations, your showcase, or your applications unless you switch model improvement on in settings. It is off by default and switching it off later stops future use immediately.
We use aggregated, de-identified interaction signals — such as which of two ranking orders users preferred — to tune retrieval and ranking. That data carries no identifiers and is not reversible.
We never train on sensitive information, on messages between a candidate and an employer, or on material an employer has marked confidential.
Kira session and library data you keep is retained while your account is open; sessions and items you delete are removed about 30 days later. Opted-in activity signals used for personalisation are kept for up to 90 days. See the Data Retention and Deletion Policy for the full schedule.
Vendors and where inference happens
Named providers, contractual limits, no training on our traffic.
We use third-party model providers for inference under contracts that prohibit training on our traffic and require deletion of prompt and completion data within 30 days. Responsibilities across Kwirl and each vendor are documented before that vendor is used for an AI system.
Inference may occur outside Australia. Prompts carry the minimum context needed and strip direct identifiers where the task allows.
Incidents and reporting
Report it. We can take AI offline and keep hiring working.
Report an AI-related incident, unexpected harmful behaviour, or suspected misuse to security@kwirl.com.au for security issues, or to contact@kwirl.com.au / legal@kwirl.com.au for product and governance issues. We handle reports under our incident response process.
We maintain the ability to take an AI feature offline when necessary, and documented manual alternatives so core hiring workflows continue while the issue is fixed.
How we review this policy
At least annually, and sooner when something material changes.
This policy is reviewed at least annually by the AI policy owner, with formal approval for substantive changes. An earlier review can be triggered by a significant AI-related incident, a new class of AI capability we adopt, or a change in relevant law, regulation or industry guidance — including Australia’s Guidance for AI Adoption.
Previous versions are kept in the Archived section of the Policy Center.
Questions about this policy
Write to legal@kwirl.com.au for anything on this page, privacy@kwirl.com.au for a privacy request, or security@kwirl.com.au to report a vulnerability. Postal mail reaches us at Kwirl Australia Pty Ltd, Australia.