# HKM Systems — Privacy Policy > **DRAFT for review by an Australian lawyer before publishing.** Items > in [square brackets] must be filled in. Structured around what APP 1.4 > requires a privacy policy to cover. HKM commits to the Australian > Privacy Principles whether or not the small business exemption applies > to it. Not legal advice. Version 2026-09-6 ## About us HKM Systems ([legal entity name], ABN [number]) provides messaging software to trade and service businesses in Australia ("our clients"). Most of the personal information we handle is about our clients' customers, and we handle it **on our clients' behalf**, to send the messages they approve. ## The personal information we hold **About our clients' customers:** name, email address, phone number, state; the jobs and quotes our client sent us about them; the messages sent to them and any replies; whether they opted out; and the basis on which they may be contacted (express or inferred consent, and how it was given). **About people who call a client:** their phone number, and when they called. **About people we contact about HKM:** the business name, a work email address, the person's name and role where published, and the web page where we found them. We only collect addresses that the business has published for anyone to see (on its own website or a public directory), and only contact them about HKM's services for their business. **About our clients' staff:** name, email address, a scrambled ("hashed") version of their password (never the password itself), and records of sign-ins and actions in our console. We do not collect sensitive information (such as health information) and ask our clients not to send it to us. ## How we collect it - From our clients, through their own job, quote or accounting systems, file uploads, or our console. - From the people themselves, when they reply to a message, text back, or call a client's number. - From service providers that deliver messages and report whether they arrived (for example, "this address does not exist"). ## How we hold it On servers run for us by [hosting provider] in [country / region], in a database protected by access controls, with encrypted backups kept by [backup provider] in [country / region]. Passwords are stored only as hashes. Credentials for our clients' email and text accounts are kept separately from the database. ## Why we collect, hold, use and disclose it - To send the review requests, quote follow-ups and missed-call replies our client approves, in our client's name. - To stop sending to people who opt out, and to keep them opted out. - To keep a record of what was sent, when, and why, including the basis on which each person may be contacted. - To run, secure and support the service. We do **not** sell personal information, use our clients' customers' information for our own marketing, or use one client's information for another client. The only people we contact about HKM itself are those described above, whose business addresses are published, and each email says where we found the address and how to stop hearing from us. We may use statistics that identify no client and no individual (for example, how many messages were sent in a month) to run and improve the service. ## Who we disclose it to - **Our client** whose customer the person is, through a login limited to that client. - **Our service providers**, only as needed to run the service: - Google (Gmail), when a client sends email through it; - Twilio, for text messages; - Cloudflare, which routes replies to us; - Anthropic (Claude), for HKM's own emails to other businesses only: to draft them from what a business publishes on its website, and to sort replies. It receives the business's name, the published address, a short excerpt of its website and any reply. It does not receive our clients' customers' information; - [hosting provider] and [backup provider]. We tell our clients at least 14 days before adding a provider that will hold their data. - Anyone we are required to disclose to by law. ## Overseas disclosure Some of these providers store or process information outside Australia. Google, Twilio, Cloudflare and Anthropic may process it in the **United States** and other countries where they operate. [Hosting provider] and [backup provider]: [countries]. We choose providers with appropriate security commitments and take reasonable steps to ensure they handle personal information consistently with the Australian Privacy Principles. ## How long we keep it Message and reply text is removed after 24 months, unless our client has agreed a different period with us. The record that a message was sent, and opt-outs, are kept so that people who opted out are never contacted again. When a client leaves, we delete their data within 60 days, except opt-outs, the record of who accepted our terms, and anything we must keep by law. Copies in our encrypted backups are deleted in the normal backup cycle within a further 30 days. ## Opting out Reply STOP to any text, or reply "stop" or "unsubscribe" to any email. It takes effect straight away for that business. If we emailed you about HKM, replying "stop" or using your email program's unsubscribe button stops every email from us, from any of our addresses. ## Access and correction You can ask for a copy of the personal information held about you, or ask for it to be corrected. The quickest way is to ask the business you dealt with; you can also contact us at [privacy email]. We will respond within 30 days. We may need to confirm your identity first. There is no charge. You can also ask for your information to be **erased**. We will remove your name, contact details and message text, and keep only the opt-out, so that you are not contacted again. ## Complaints If you think we have mishandled your personal information, contact us at [privacy email] with the details. We will acknowledge your complaint within 7 days and aim to resolve it within 30 days. If you are not satisfied with our response, you can complain to the **Office of the Australian Information Commissioner (OAIC)**: www.oaic.gov.au, phone 1300 363 992. ## Security and data breaches We protect personal information with HTTPS, access limited to each client's own staff, hashed passwords and sessions, and encrypted off-site backups. If a data breach is likely to cause serious harm to anyone, we will notify the people affected and the OAIC, following the Notifiable Data Breaches scheme. We tell the clients affected within 72 hours of becoming aware of any unauthorised access to or disclosure of their data. ## Changes We will post any change to this policy here with a new version number. If a change reduces the protection of personal information, we will give our clients at least 30 days' notice first, as our client terms require. ## Contact [Privacy contact name] [privacy email] [postal address]