Data processing agreement
This data processing agreement (DPA) explains how Kinfold handles the personal information providers put into Kinfold. It forms part of our terms of service.
1. Who this applies to
This DPA applies to every customer that uses Kinfold to handle referrals and enquiries. It covers the personal information Kinfold handles for the customer about participants, clients, patients, nominees, families, referrers and the customer's own staff.
2. Roles
You, the customer, decide what personal information is collected and why. You're responsible for meeting your obligations under the Privacy Act 1988 (Cth), the Australian Privacy Principles and any other rules that apply to you.
Kinfold handles that information on your behalf, only to provide the service and only on your documented instructions. These terms, your settings and your rules in Kinfold are your instructions.
3. The information involved
- Contact details of the people referred to you, and of their nominees, families and referrers
- Referral details, funding information and documents
- Sensitive information, including health and disability information
- Call recordings, transcripts and messages
- Consent records and audit logs
- Your staff's account details
4. Processing on your instructions
We won't use your information for any other purpose, including training AI models, ours or anyone else's. If we think an instruction breaks the law, we'll tell you.
5. Our people
Everyone at Kinfold who could access customer information is bound by confidentiality. Nobody at Kinfold can see your referrals by default. Support access happens only when you invite us in, and every access is logged where you can see it.
6. Security
- Encryption in transit and at rest
- Data, backups, logs and AI processing in Australian cloud regions
- Two-factor sign-in for every staff member, ours and yours
- Access limited to the people who need it, with audit logs
- An independent security review and penetration test before any real participant information is handled
7. Where data is kept
Customer data is stored and processed in Australia, including AI processing. We won't move it outside Australia without your written agreement.
8. Sub-processors
We use a small number of trusted service providers (sub-processors), such as Australian cloud hosting, AI model providers running in Australian regions, telephony, email and SMS delivery, and e-signature. Each is bound by written terms at least as protective as this DPA.
We'll keep a current list available to customers and give you notice before adding or replacing one, so you can raise any objection.
9. Data breaches
If we become aware of a data breach involving your information, we'll tell you promptly, without undue delay, with the details we have. We'll help you assess it and, where it's an eligible data breach, notify the people affected and the OAIC under the Notifiable Data Breaches scheme.
10. Requests from individuals
If someone asks us to access, correct or delete information we hold for you, we'll pass the request to you and help you respond.
11. Audits and information
We'll give you the information you reasonably need to show you're meeting your privacy obligations, including our security pack. Email security@kinfold.ai.
12. Deletion and return
You can export your data at any time. When you delete information, or when the agreement ends, we erase it from live systems straight away and from backups within our fixed backup cycle, which we'll state here before launch.
13. Contact
Privacy: privacy@kinfold.ai. Security: security@kinfold.ai.
Questions about this page? Email privacy@kinfold.ai for privacy, or hello@kinfold.ai for anything else.