Kymora
Solutions How it Works Our Story
Contact us Get an opportunity report
Kymora
Solutions
How it Works
Our Story
Contact us
Get an opportunity report

Privacy Policy

ABN: 29 207 734 477

Contact: [email protected]

Last updated: 5 June 2026

1. About this policy

This Privacy Policy explains how Kymora AI ("we", "us", "our") collects, uses, stores, shares, and protects personal information when you use Kymora, our patient reactivation and appointment briefing platform for cosmetic clinics.

We are designed to operate consistently with the requirements of the:

  • Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs)
  • Notifiable Data Breaches (NDB) scheme
  • NSW Health Records and Information Privacy Act 2002 (HRIPA) where relevant
  • Spam Act 2003 (Cth) for our SMS and email communications

The platform also includes tooling designed to support AHPRA and TGA cosmetic advertising compliance. This tooling is supportive, not a guarantee that any individual message will be compliant in all circumstances; clinics remain responsible for the lawfulness of their communications.

If you're a patient of a clinic that uses Kymora, this policy applies. If you're a clinic considering using Kymora, this policy applies. If you're just visiting our website, this policy applies.

2. Health information and sensitive data

Cosmetic and aesthetic clinics are "health service providers" under the Privacy Act 1988, regardless of size or turnover. The patient information uploaded to Kymora (names, contact details, appointment history, treatment-related notes provided by the clinic, treatment interests, communication preferences) is health information under section 6FA of the Privacy Act, which is classified as sensitive information under section 6(1).

What this means in practice:

  • We apply heightened security and access controls appropriate for sensitive health-related information.
  • We require clinics using Kymora to obtain any consents required under applicable privacy, spam, and health-records laws before uploading patient information or sending communications.
  • Patients can manage communication preferences through the preferences page linked in every SMS we send.
  • We do not use patient information to train AI models operated by us. Our AI sub-processors (currently Anthropic) may retain limited logs for abuse-detection purposes as set out in their published terms. Based on Anthropic's published terms at the time of writing, API inputs and outputs are not used for model training, and standard API logs are retained for up to 7 days then deleted automatically (subject to change by the provider). We are not currently on Anthropic's Zero Data Retention agreement. We rely on sub-processor published terms and do not independently control their internal retention practices.
  • We do not sell, share for advertising, or disclose patient information to anyone outside the documented sub-processors required to deliver the service.
  • We follow the OAIC Guide to Health Privacy (collated May 2025) as our operational reference.

Kymora is not designed to function as a primary clinical records system or electronic medical record platform. The information clinics record in Kymora (appointment and treatment-related information, interests, milestones, notes recorded by the clinic) may nevertheless constitute health information under Australian law and is treated accordingly.

3. What personal information we collect

3.1 If you're a clinic operator (our customer)

  • Name, email, mobile number
  • Business name, ABN, trading address
  • Payment details (processed by Stripe; we never store card numbers)
  • Login credentials (we store only short-lived verification tokens, not passwords)
  • Communication records (support emails, in-app messages)

3.2 If you're a patient of a clinic using Kymora

The clinic uploads patient details to our system to deliver communications. The clinic determines how and why patient information is handled. Kymora processes the information on the clinic's behalf to provide the service.

Information processed via Kymora may include:

  • Name and contact details (mobile number, email)
  • Appointment history (dates, treatments, durations)
  • Appointment notes and treatment interests recorded by the clinic
  • Communication preferences and consent state
  • Message history sent through our system

3.3 If you're a website visitor

  • IP address, browser type, pages visited (standard server logs)
  • Cookies for session management (no third-party tracking without consent)

4. Why we collect it

4.1 For clinic operators

  • Provide the Kymora service (reactivation campaigns + appointment briefings)
  • Process payments
  • Respond to support requests
  • Comply with legal obligations (tax, financial records, regulatory)

4.2 For patients

  • Send appointment-related, reactivation, and clinic communications on behalf of the clinic, where the clinic has lawful basis to do so under the Spam Act and Privacy Act
  • Manage communication preferences (opt out, pause, channel choice)
  • Maintain a record of consent and message history for compliance with the Spam Act 2003 and APP 7

We do not use patient information for advertising, sell it to third parties, or use it to train AI models.

5. How we store and protect it

  • Information stored in Cloudflare D1, which encrypts data at rest by default using AES-256. We primarily store data in infrastructure regions that may include Australia where available. Data may be processed or transmitted through Cloudflare's global edge network as part of normal CDN and edge operations.
  • Transmission encrypted using TLS 1.2 or higher.
  • Authentication handled through secure magic-link verification. We do not store plaintext passwords.
  • Access controls restrict who can view information. Access is limited to authorised personnel and contractors who require it to operate or support the service.
  • Audit logs record send and access events.
  • Backups encrypted and retained on a rolling 30-day cycle then overwritten.

We do not claim ISO 27001 certification. Formal legal review and external security assessment are planned as the business grows.

6. Cross-border disclosure

Some of our sub-processors store and process information outside Australia. Under APP 8 we are accountable for how those overseas recipients handle that information.

Sub-processorPurposeLikely countries
CloudflareHosting, database, edge computeAustralia (primary); global edge routing may also touch the United States, United Kingdom, Singapore, and other Cloudflare edge locations depending on traffic
AnthropicAI message and brief generation (Claude API)United States
ClickSendSMS deliveryAustralia
ResendTransactional email deliveryUnited States
StripePayment processing (clinic operators only)Australia and United States

Where personal information is processed outside Australia (Anthropic, Resend, parts of Stripe and Cloudflare), we take reasonable steps to ensure those recipients comply with the APPs. This includes contractual data-protection commitments where available from the sub-processor. We remain accountable under APP 8.1 for how those overseas recipients handle the information.

7. Who we share it with

We share personal information only with:

  • Sub-processors listed in Section 6 (necessary to deliver the service)
  • Required by law — Australian courts, regulators, or law enforcement under valid legal compulsion
  • With your direct consent — if you ask us to integrate with another tool

We do not sell personal information or share it with unrelated third parties for advertising purposes.

8. Your rights

You can:

  • Access the personal information we hold about you
  • Correct information that's inaccurate or incomplete
  • Request deletion of your information, subject to applicable legal retention requirements
  • Withdraw consent for marketing communications at any time (via the preferences link in every SMS, or by contacting us)
  • Lodge a complaint with us or the OAIC

8.1 For patients of a Kymora-using clinic

Contact your clinic first; the clinic determines how and why your information is handled and is generally responsible for patient-facing rights requests. We will assist the clinic in responding within 30 days as required by APP 12 / APP 13.

8.2 For clinic operators or general inquiries

Email [email protected]. We respond within 30 days as required by the APPs.

8.3 To opt out of marketing

Tap the preferences link in any SMS you receive, or email [email protected]. The Spam Act allows up to 5 business days for an unsubscribe to take effect; we aim to apply it promptly.

9. Data retention

  • Clinic operator data: retained while the account is active, then deleted from production systems within 30 days of cancellation. Some records retained longer where required by tax law or other legal obligations.
  • Patient data: retained while the clinic remains an active Kymora customer, then deleted from production systems within 30 days of clinic cancellation.
  • Backups: roll on a 30-day cycle and are overwritten. This means information may persist in backups for up to a further 30 days after production deletion.
  • Audit logs (minimum information required for compliance): retained for 7 years.

10. Data breaches

We maintain an internal Data Breach Response Plan.

Where we suspect a personal data breach, we carry out an assessment without undue delay, and in any event within the timeframe required under the NDB scheme (the scheme contemplates assessment up to 30 days, but we aim to complete it sooner where practicable). Once we and the affected clinic form a reasonable belief that an eligible data breach has occurred, the clinic (as the entity that holds the patient relationship and the underlying records) is generally responsible for notifying the OAIC and affected individuals as soon as practicable, with our assistance and support. Where Kymora itself is the entity required to notify, we will do so as soon as practicable in accordance with the NDB scheme.

Nothing in this policy alters which party is legally required to comply with the Privacy Act or the Notifiable Data Breaches scheme. Operational allocation between Kymora and the clinic is set out here for clarity; statutory obligations apply regardless.

Breaches involving health information are treated at the highest severity level in our internal response plan.

11. Complaints

If you believe we have mishandled your personal information:

1. First step: email [email protected] with the details. We investigate and respond within 30 days.

2. If unresolved: you can lodge a complaint with the OAIC at www.oaic.gov.au or call 1300 363 992.

3. In NSW, the NSW Information and Privacy Commission also accepts complaints about handling of health records by private-sector providers under HRIPA: www.ipc.nsw.gov.au.

12. Roles and responsibilities

To make the boundaries clear:

The Clinic is responsible for:

  • Obtaining valid patient consent under the Privacy Act, the Spam Act, and any applicable state health-records law
  • Complying with applicable AHPRA, TGA, and state-level requirements relating to communications (including any restrictions on cosmetic procedure communications to patients under 18)
  • The accuracy of patient information uploaded to Kymora
  • The lawfulness of any communication sent using the service
  • Providing patients with an APP 5 collection notice at the point of intake (not via Kymora)

Kymora is responsible for:

  • Delivering the Kymora service in line with this policy, the Terms of Service, and the DPA
  • Operating heightened security and access controls appropriate for sensitive information
  • Maintaining preference-management infrastructure that respects opt-outs
  • Maintaining audit logs and a breach response plan
  • Taking reasonable steps to ensure sub-processors handle personal information consistently with the APPs

Both parties remain APP entities with direct obligations under the Privacy Act. Contractual roles do not displace those direct statutory obligations.

13. Children and minors

Kymora is intended for use by cosmetic and aesthetic clinics and is not directed toward minors. Clinics using Kymora are required to comply with all applicable laws, AHPRA guidelines, and advertising restrictions relating to communications involving patients under 18 years of age.

14. Changes to this policy

We may update this policy from time to time. Material changes will be communicated to existing customers via email and through the app. The latest version is always available at kymora.ai/privacy.

15. Contact

Privacy queries, requests, complaints, and legal notices:

[email protected]

General service support and inquiries:

[email protected]

Postal:

Kymora AI

PO BOX 77

Tahmoor NSW 2573

Australia

*This Privacy Policy reflects Kymora AI's current privacy practices and operational approach as of the effective date. Independent legal review will be obtained as the business grows.*

Kymora

Contact Us

[email protected]
LinkedIn

About us

The Kymora Story

Who it is for

Cosmetic Clinics

Skin Clinics

Med Spas

Injectable Clinics

Cosmetic Nurse Clinics

Laser Clinics

Dermal Clinics

Aesthetic Clinics

Customers

Case studies, coming soon

Copyright © 2026 Kymora
Terms & Conditions Privacy Policy