Skip to main content

Luminous

Privacy Policy

Privacy & Data Protection Policy

Luminous Talent Limited

Last updated: May 2026

Part A: Privacy Policy

1. Who we are

Luminous Talent Limited (“Luminous”, “we”, “our”, “us”) is a New Zealand-owned specialist recruitment firm focused on financial services, based in Auckland. We recruit across banking and insurance, finance and investments, and corporate functions.

We are committed to handling personal information responsibly and in accordance with the Privacy Act 2020 and its Information Privacy Principles. This policy explains what personal information we collect, how we collect and use it, who we share it with and the rights you have.

2. Who this policy applies to

This policy applies to personal information we hold about candidates, prospective candidates, referees, client contacts, and anyone else who interacts with us in connection with our recruitment services or our website.

3. What we collect

The personal information we collect depends on our relationship with you, but may include:

       Contact details: your name, email address, phone number and location.

       Career information: your CV, employment history, qualifications, professional memberships, remuneration and career preferences.

       Information from the recruitment process, such as interview notes, assessment results and reference feedback.

       Verification information, where relevant to a role and with your authorisation. This can include criminal record, credit, qualification and right-to-work checks.

       Client contact information: business contact details, role requirements and information relevant to our engagement.

       Technical information collected through our website, such as analytics data.

Some roles call for information of a more sensitive nature, such as health information relevant to the position. We collect this directly from you with your authorisation and only use it for the purpose it was provided.

4. How we collect it

We collect most personal information directly from you, through conversations, meetings, applications and the documents you give us. In line with normal recruitment practice we also collect information about you from other sources, including:

       Referees you nominate, where authorised by you.

       Publicly available professional sources such as LinkedIn, Seek, company websites, professional registers and media.

       Verification and background checking providers, where checks are undertaken with your authorisation. These include the Ministry of Justice for criminal record checks, Immigration New Zealand for right-to-work verification, and universities and other qualification bodies.

       Our clients, where they refer or introduce you to us in connection with a role.

       Our professional networks and market research.

Where we collect personal information about you indirectly, we take reasonable steps to ensure you are aware that we have collected it, where it came from, why we collected it, and your right to access and correct it. In many cases this notification is provided through this policy; where required, we will also tell you directly.

5. Why we collect and use it

We collect and use personal information to:

       Assess your suitability for current and future opportunities and represent you to prospective employers.

       Match candidates to our clients’ roles and manage recruitment processes end to end.

       Conduct reference and background checks where relevant and authorised.

       Maintain our candidate and client relationships over time, including keeping in touch about opportunities and market developments.

       Operate, improve, and secure our business and systems.

       Meet our legal and regulatory obligations.

6. AI-assisted tools

We use AI-assisted tools as part of our recruitment processes to help us work more efficiently and deliver a better experience for candidates and clients. These tools may assist with tasks such as recording and transcribing meetings, summarising candidate information, preparing notes and documents, and supporting research.

Where your personal information is processed using these tools, we take reasonable steps to ensure this is done consistently with the Privacy Act 2020. This includes:

       Using established AI platforms on commercial terms with appropriate security and privacy controls.

       Ensuring your data is not used to train AI models.

       Restricting access to authorised Luminous personnel only.

       Where generative AI is used for research, restricting prompts to publicly available sources and verifying information against its source before we rely on it.

       Ensuring all recruitment decisions are made by our consultants. AI tools support our processes; they do not make decisions about candidates.

We regularly review our use of AI-assisted tools to ensure they remain appropriate, secure, and consistent with this policy.

7. Who we share it with

We share personal information only where necessary for our recruitment services and in ways you would reasonably expect. This may include:

       Clients: we present candidate information to clients in connection with specific opportunities, and only with your knowledge.

       Referees and background checking providers, where checks are undertaken.

       Service providers who support our business, such as our recruitment database, cloud storage and communications providers, under appropriate confidentiality and security arrangements.

       Regulators, law enforcement, or other parties where required or permitted by law.

We do not sell personal information.

8. Where information is stored

We use reputable cloud-based systems to store and manage personal information. Some of our providers store information on servers located outside New Zealand, primarily in Australia and the United States. Where personal information is held overseas, we take reasonable steps to ensure it is subject to safeguards comparable to those required by the Privacy Act 2020, including through our contractual arrangements with providers.

9. How long we keep it

We retain personal information for as long as needed for the purposes described in this policy. Recruitment relationships are often long term. An opportunity may come up months or years after we first meet, so we keep candidate information on our database while our relationship remains active. If we have had no meaningful contact with you for seven years we securely delete or de-identify your information, except where we are required by law to retain it, such as financial records.

You can request deletion of your information at any time, and we will action this unless we are required to retain it by law.

10. How we protect it

We take reasonable security safeguards to protect personal information against loss, unauthorised access, use, modification, or disclosure. These include access controls and authentication across our systems, encryption of data in transit and at rest through our providers, and confidentiality obligations for everyone who works with us. Further detail is set out in Part B of this document.

11. Scams and impersonation

Recruitment firms are sometimes impersonated in phishing and job scams. We will never ask you for payment, bank login details or remote access to your devices. If you are contacted by someone claiming to be from Luminous and something feels off, contact us directly using the details below before responding.

12. Your rights

Under the Privacy Act 2020, you have the right to request access to the personal information we hold about you and to request correction of that information. You may also withdraw an authorisation you have given us, or ask us to delete your information, at any time.

To exercise any of these rights, contact us using the details below. We will respond within 20 working days, as required by the Privacy Act. If your request is refused for a reason permitted by law, we will tell you why in writing and explain your options.

If you have a concern or complaint about how we have handled your personal information, contact our Privacy Officer using the details below. We will investigate and respond within 20 working days. If you are not satisfied with our response, you can complain to the Office of the Privacy Commissioner (privacy.org.nz).

13. Contact us

Luminous Talent Limited

Ground Floor, Princes Court, 2 Princes Street, Auckland CBD 1010

hello@luminoustalent.co.nz

luminoustalent.co.nz

Part B: Information Security Overview

This overview summarises the practical measures we apply to protect the personal and confidential information entrusted to us by clients and candidates.

1. Systems and infrastructure

Our candidate and client information is managed through established, cloud-based recruitment and business systems provided by reputable vendors that maintain independent security certifications and controls. We do not store candidate or client records on local servers.

2. Access control

Access to our systems is limited to Luminous personnel and protected by individual user accounts and multi-factor authentication. Access to candidate and client information is on a need-to-know basis, and access is removed promptly when personnel leave the business.

3. Data in transit and at rest

Information held in our core systems is encrypted in transit and at rest by our providers. Candidate documents are shared with clients through secure channels rather than uncontrolled distribution.

4. Confidentiality

All Luminous personnel are bound by confidentiality obligations covering client and candidate information. Client-specific information, including search strategy, remuneration details, and organisational context, is treated as confidential and is not shared outside the engagement.

5. AI and technology governance

Where AI-assisted tools are used in our work, we select providers on commercial terms under which our data is not used to train their models, and the same confidentiality and security standards apply as to any other information we hold. A consultant reviews all output; no decisions about candidates are made by automated means.

6. Incident response

In the event of a privacy breach likely to cause serious harm, we will notify the Office of the Privacy Commissioner and affected individuals as required by the Privacy Act 2020, and take prompt steps to contain and remediate the breach.

7. Review

We review our privacy and security practices periodically and update this policy as our business and legal obligations evolve.