Founding provider places are open in Queensland. See the offer

Privacy policy

Draft for legal review. Last updated 2 October 2026.

This policy explains how Kinfold handles personal information: what we collect, why we collect it, where it's kept and the choices you have.

1. Who we are

Kinfold is an Australian company based in Brisbane, Queensland. We make an AI intake coordinator for NDIS, aged care and allied health providers. In this policy, “Kinfold”, “we” and “us” mean the company that operates Kinfold. Our full legal name and ABN will appear here and in our website footer.

We're bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). We designed Kinfold around them: collect only what intake needs, tell people why, keep it secure, and let people see and correct what's held about them.

2. Our two roles

We handle personal information in two different ways, and this policy covers both.

  • For our own business. When you visit our website, contact us, apply for early access or become a customer, we decide what we collect and why.
  • For providers who use Kinfold. When a provider uses Kinfold to handle its referrals, the provider decides what is collected and why, and its own privacy policy applies. We handle that information only on the provider's instructions, under our terms of service and data processing agreement.

If you were referred to a provider that uses Kinfold, the best first contact for questions about your information is that provider. We'll help them respond.

3. What we collect

From people who use our website or contact us:

  • your name, work email, mobile, organisation, website and role, when you fill in a form or book a demo
  • what you tell us in a message or on a call
  • basic technical information, like your browser type and the pages you visit, if you accept analytics cookies. Analytics run on our public website only, never inside the Kinfold app.

From customers and their staff:

  • account details, like the names, work emails and roles of the people who use Kinfold
  • sign-in and security records, like two-factor settings and access logs
  • billing details. Card payments are handled by our payment provider, and we don't store full card numbers.

For providers, as part of the service:

  • referral details, like a person's name and contact details, the supports they're looking for, their funding type and the documents a referrer sends
  • sensitive information, including health and disability information, where it's part of a referral
  • call recordings and transcripts, and messages sent by email, SMS, web form or chat. Every call says it's recorded.
  • consent records, and the collection notice each person was given

Please don't include participant or patient details in our website forms. They aren't built for that information.

4. How we use it

We use personal information to:

  • provide, secure and support Kinfold
  • answer enquiries, run demos and manage early access
  • bill customers and keep business records
  • tell you about Kinfold, if you've agreed to hear from us
  • meet our legal obligations

We never sell personal information.

We never use customer data to train AI models, ours or anyone else's. Nell learns how a provider likes to work from that provider's templates, rules and approved drafts, kept inside the provider's own account.

Marketing emails follow the Spam Act 2003 (Cth). Every one has an unsubscribe link.

5. Automated decision-making

Nell, the AI assistant in Kinfold, reads referrals, checks them against each provider's own rules and recommends a next step. She can book an intake call, but she can't turn someone away. Declining a referral always needs a person from the provider's team, and so do waitlist and capacity messages.

Nell doesn't give clinical advice, diagnose or triage. She says she's an AI assistant at the start of every conversation, and anyone can ask for a person.

From 10 December 2026, the Privacy Act requires privacy policies to explain the kinds of decisions made using automated decision-making that could significantly affect people. Kinfold is designed so those decisions stay with people. We give providers template wording to adapt with their lawyer for their own privacy policies.

6. Where it's stored

Care data stays in Australia. Kinfold's database, files, backups, logs and AI processing all run in Australian cloud regions. The AI models we use run through Australian cloud regions under contract, so care data isn't processed overseas.

Some tools we use to run our own business, such as email delivery and billing, may store business contact details (like your name and work email) outside Australia. Where that happens, we take reasonable steps under APP 8 to make sure the information is protected to Australian standards. We'll list these providers here before launch.

7. Who we share it with

We share personal information only when we need to:

  • with service providers who help us run Kinfold, such as Australian cloud hosting, AI model providers, telephony, email and SMS delivery, and e-signature. They act on our instructions and must protect the information.
  • with the provider a referral was sent to. No provider can ever see another provider's referrals, clients or numbers.
  • with our professional advisers, like lawyers and accountants, under confidentiality
  • where the law requires or allows it, for example to lessen a serious threat to someone's life, health or safety

Nobody at Kinfold can see a provider's referrals by default. Our team gets support access only when a provider invites us in, and every access is logged where the provider can see it.

8. Keeping it secure

  • Encryption in transit and at rest, with backups in Australia.
  • Two-factor sign-in for every staff member, and no shared accounts.
  • Access limited to the people who need it, with audit logs.

No real participant information goes into Kinfold until our independent security review and penetration test are complete.

9. How long we keep it

Providers choose how long Kinfold keeps their referral information once it's written back to their care system, and how long call recordings are kept.

When information is deleted, it's erased from live systems straight away and from backups within our fixed backup cycle, which we'll state here before launch.

We keep business records, like invoices, for as long as Australian law requires.

10. Accessing and correcting your information

You can ask for a copy of the personal information we hold about you, or ask us to correct it. Email privacy@kinfold.ai. There's no charge to ask, and we'll respond within 30 days.

If your information was collected by a provider using Kinfold, contact that provider first. We'll help them respond.

11. If something goes wrong

If a data breach is likely to cause serious harm, we follow the Notifiable Data Breaches scheme. That means telling the people affected and the Office of the Australian Information Commissioner (OAIC). Where a breach involves a provider's information, we tell the provider promptly, as set out in our data processing agreement, and work with them under the scheme.

12. Complaints

If you're worried about how we've handled your information, email privacy@kinfold.ai. We'll acknowledge your complaint and aim to resolve it within 30 days.

If you're not satisfied with our response, you can contact the OAIC at www.oaic.gov.au (opens in a new tab) or on 1300 363 992.

13. Changes to this policy

We'll update this policy as Kinfold grows. The date at the top shows when it last changed, and we'll tell customers about important changes before they take effect.

14. Contact us

Privacy questions: privacy@kinfold.ai. Everything else: hello@kinfold.ai. Kinfold, Brisbane, Queensland.

Questions about this page? Email privacy@kinfold.ai for privacy, or hello@kinfold.ai for anything else.