Effective date: September 2026
Kinex Health Pty Ltd (“Kinex Health”, “we”, “us” or “our”) is committed to protecting the privacy of the people whose personal information we hold. This policy explains how we collect, use, disclose, store and secure your personal information, and how you can access it, correct it or make a complaint.
We are bound by the Australian Privacy Principles (APPs) in the Privacy Act 1988 (Cth). More information about the APPs is available from the Office of the Australian Information Commissioner at www.oaic.gov.au.
1. What is personal information and why we collect it
Personal information is information or an opinion about an identified individual, or an individual who is reasonably identifiable. The personal information we collect may include names, addresses, email addresses, phone numbers, employer details, and health and wellbeing information.
We collect personal information so that we can deliver our services, communicate with you, respond to your enquiries, report to our client organisations (in aggregate or de-identified form), and carry out related administrative and marketing activities. Where we collect your information, we will, where practicable, explain why we are collecting it and how we intend to use it.
You may opt out of our marketing communications at any time using the unsubscribe link in our emails or by contacting us.
2. Sensitive and health information
Some of the information we collect is “sensitive information” under the Privacy Act, including health information gathered through wellbeing surveys, consultations and support sessions. We collect, use and disclose sensitive information only:
- for the primary purpose for which it was collected;
- for a directly related secondary purpose you would reasonably expect;
- with your consent; or
- where required or authorised by law.
Health and clinical records created through our psychology and wellbeing services are treated with a high level of confidentiality and are stored in Australia (see sections 5 and 6).
Where we collect wellbeing survey responses, they are recorded against a participant’s name and email so the correct survey reaches the correct person. Before any analysis is carried out, each response is assigned a unique identifier code and the name and email are separated from the dataset, so results can be matched to the same person over time without the analysis being performed against identifying details.
AI-assisted clinical documentation. Where our clinicians use AI assistance to help prepare clinical notes, we do so carefully and transparently. We use purpose-built clinical documentation tools, currently Heidi Scribe and Novonote (by NovoPsych), each of which assists the clinician by transcribing and drafting notes during a consultation. A clinician always reviews the notes and remains responsible for the clinical record; the AI does not make clinical decisions. We inform participants before these tools are used, and you may decline their use while still receiving your session as normal. Both platforms remove or mask personal identifiers before information is processed by AI, do not retain audio recordings after transcription, and do not use any patient information to train, develop or improve AI models. Australian health information is processed and stored onshore, and both platforms are ISO 27001 and SOC 2 Type II certified, with encryption in transit and at rest.
3. How we collect personal information
Where reasonable and practicable, we collect personal information directly from you, for example through surveys, bookings, consultations, correspondence, our website and email. In some cases, we may receive information from a third party, such as an employer arranging a wellbeing program on your behalf. Where this happens, we take reasonable steps to make you aware of the information we have received.
4. Service providers we use
We use a small number of established, security-certified platforms to deliver our services. Each processes personal information on our behalf under its own privacy and security obligations, and we take reasonable steps to ensure your information is handled appropriately. The platforms we use, the data they hold, where they host it, and the standards they operate to, are:
- Kinex Plus (powered by Wellifiy): our clinical and participant platform. It holds clinical records, consultation notes and bookings, together with participant account details, program content and self-reported wellbeing inputs (such as mood, sleep and check-in responses). Hosted in Australia; ISO 27001 certified and compliant with the Australian Privacy Principles; encrypted storage, multi-factor authentication, and access to health information restricted to exceptional circumstances under senior oversight.
- Heidi Health (Heidi Scribe): AI-assisted clinical documentation, as described in section 2. Australian health information stored onshore; ISO 27001, ISO 42001 and SOC 2 Type II certified; bank-industry encryption in transit and at rest; sensitive health information pseudonymised; audio not retained after transcription; no patient data used to train its AI models.
- Novonote (by NovoPsych): AI-assisted clinical documentation for our psychology services, as described in section 2. Australian data stored onshore on AWS; ISO 27001 and SOC 2 Type II certified; TLS 1.2 or higher in transit and AES-256 at rest; personal identifiers redacted before AI processing; audio deleted after transcription; no patient data used to train AI models; role-based access controls.
- SurveyMonkey: wellbeing and program survey responses. Hosted in the United States on AWS; SOC 2, ISO 27001 and PCI DSS certified; encryption in transit and at rest.
- Acuity Scheduling (Squarespace): appointment bookings (name, email and times), which we are moving to Kinex Plus. Hosted in the United States; PCI DSS certified and HIPAA-capable.
- Campaign Monitor: general program emails, holding participant name and email only, with no survey or health information. Hosted in the United States.
- Google Workspace: direct email correspondence. ISO 27001, SOC 2 and SOC 3 certified, with encryption.
If we change providers, hosting locations, or introduce a new platform in a way that affects your personal information, we will give affected client organisations at least 21 days’ advance written notice, or notify them as soon as reasonably practicable where a change is unexpected. Any such change is made on the basis that protections are maintained at an equivalent or higher standard.
5. Overseas storage and disclosure
We host as much data in Australia as we can. The current position for each type of information is:
- Clinical records, consultation notes, bookings and the participant app are hosted in Australia on Kinex Plus (powered by Wellifiy).
- AI-assisted clinical documentation processes and stores Australian health information onshore (Heidi Scribe and Novonote).
- Wellbeing and program survey responses are stored on servers in the United States (SurveyMonkey).
- Appointment bookings are currently managed through a provider based in the United States (Acuity Scheduling), and we are moving this function to Australian-hosted Kinex Plus.
- General program emails are managed through an email platform based in the United States and contain contact details only, not survey, consultation or health information (Campaign Monitor).
Where personal information is stored or disclosed overseas, we take reasonable steps to ensure it is handled consistently with the Australian Privacy Principles.
6. Security and storage of personal information
We store personal information in systems that protect it from misuse, interference, loss and unauthorised access, modification or disclosure. Our clinical and consultation records are held in encrypted, Australian-hosted practice management software, with access limited to authorised practitioners.
In addition to the protections provided by the platforms we use, we operate a number of controls directly. We enforce multi-factor authentication on the accounts and platforms where personal or sensitive information is stored or accessed. We apply a least-privilege approach to access, so that team members and practitioners can only access the information relevant to their role, and access is fully revoked when a person offboards. Access to raw identifiable survey data is restricted to a single authorised person. All clinical and non-clinical personnel are bound by signed confidentiality obligations, and our clinicians are additionally bound by the professional confidentiality requirements of their registration. We are also undertaking an independent security review as part of our current platform build.
When personal information is no longer required, we take reasonable steps to destroy or de-identify it. Health and clinical records are retained for a minimum of seven years, or longer where required by law or professional obligations.
7. Data breaches
We take reasonable steps to prevent data breaches. If a data breach occurs that is likely to result in serious harm, we will respond in line with the Notifiable Data Breaches scheme under the Privacy Act, including notifying affected individuals and the Office of the Australian Information Commissioner where required.
Where a breach, or suspected breach, affects a client organisation’s data, we will notify that organisation’s nominated contact within 48 hours of becoming aware of it. This applies whether the incident originates with Kinex Health or with one of the providers we use to deliver the service. We maintain a documented breach response process to guide how we contain, assess and communicate about an incident.
8. Disclosure of personal information
We may disclose your personal information:
- to the service providers described above, so they can help us deliver our services;
- to your employer or program sponsor, always in aggregate form and never for a group of fewer than nine people, to protect against re-identification;
- where you have consented to the disclosure; or
- where required or authorised by law.
We do not sell your personal information.
9. Access and correction
You may request access to the personal information we hold about you, and ask us to update or correct it, subject to certain exceptions under the Privacy Act. Please contact us in writing. To protect your information, we may ask you to verify your identity before we release it.
10. Keeping your information accurate
We take reasonable steps to ensure the personal information we hold is accurate, complete and up to date. If your details change or you believe our records are inaccurate, please let us know so we can update them.
11. Complaints and enquiries
If you have a question or complaint about how we have handled your personal information, please contact us at [email protected]. We will respond within a reasonable time. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner at www.oaic.gov.au or on 1300 363 992.
12. Changes to this policy
We may update this policy from time to time. The current version will always be available on our website.
