Legal
Privacy Policy
Last updated: July 2026
In this policy
1. Overview
Klyvon is an AUSTRAC compliance platform for Australian businesses, operated from Melbourne, Victoria. We collect information to provide our services, deliver your documents, and keep your account running. We do not sell your data. We do not share it with advertisers.
This policy applies to klyvon.com.au and all Klyvon services. We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
2. Two Categories of Data We Hold
Klyvon holds two distinct categories of data, and we treat them differently. Australian privacy law applies to both: Klyvon handles all personal information it holds in accordance with the Australian Privacy Principles.
2.1 Your firm’s data
This includes your account information, subscription details, and intake form responses. Klyvon decides how this data is collected and used, as described in this policy.
2.2 Your clients’ data (held for your firm)
Client CDD records you enter into the platform — names, dates of birth, addresses, ID document details, risk ratings, PEP status — are records about your clients, not about you. Klyvon holds these records on your firm’s behalf as your firm’s record-keeping system, and uses them only to provide the platform’s features to your firm. Your firm remains responsible for the lawful collection of your clients’ personal information and for its own privacy obligations as an AUSTRAC reporting entity. Because Klyvon holds these records, the individuals they describe also have rights against Klyvon directly — see Section 10.
Before entering a client’s details into Klyvon, your firm should ensure the client is aware their identification records will be collected and held in a third-party compliance platform. This policy explains how Klyvon handles that information; those individuals’ access and correction rights are set out in Section 10.
Note: reporting entities under the AML/CTF Act have obligations under the Privacy Act regardless of size — the small business exemption does not apply to activities connected with AML/CTF obligations.
3. What We Collect and Why
3.1 Free checklist (no account required)
- Work email address, company name, industry — to generate and deliver your personalised compliance checklist
- Used for follow-up emails on Days 3 and 7 after checklist delivery
- One-click unsubscribe in every email — honoured immediately
- Retained until no longer needed for follow-up if no account is created — you can request deletion at any time via the unsubscribe link or privacy@klyvon.com.au
3.2 Newsletter
- Email address only — to send you compliance updates you subscribed to
- A confirmation email is sent when you subscribe; every email contains an unsubscribe link that works without logging in
- Unsubscribing takes effect immediately. We keep a minimal suppression record (your email and unsubscribe date) so we do not email you again
3.3 Account and subscription data
- Email address, firm name, compliance officer name (optional at signup), industry
- Payment processor customer ID and subscription ID — for billing management
- Subscription status, trial end date — to manage your access
- Dashboard access token (UUID) — our custom authentication credential
- Retained while your account is active. Deleted within 30 days of a verified account deletion request, except where we must retain records by law.
3.4 Intake form data (dashboard)
- Compliance officer name, effective date, cash acceptance policy, client types, services provided, trust account existence, annual transaction volume, operating state
- Used solely to generate your AML/CTF compliance documents
- Sent to our AI service provider for document generation (see Section 5)
- Retained while your account is active
3.5 Client CDD records (entered by your firm)
- Individual clients: full name, date of birth, residential address, ID document details
- Entity clients: entity name, ABN, ACN, registered address, directors, beneficial owners
- Risk rating, CDD tier, PEP status, TFS designated person status
- Verification status, next review date, source of funds, source of wealth (enhanced CDD)
- Audit log: every action on each record — timestamp, staff email, action type
- Retention: your firm is required by s.111 of the AML/CTF Act 2006 to keep these records for at least 7 years after the business relationship with the client ends (or after an occasional transaction is completed). Klyvon retains them on your firm's behalf so your firm can meet that obligation. You are notified of this retention requirement in the platform.
- Records are soft-deleted only — flagged as archived, never permanently deleted within the statutory retention window. After the retention period for a record has ended, your firm may instruct permanent deletion by contacting privacy@klyvon.com.au
3.6 Staff records (entered by your firm)
- Staff name and email address — for staff training records and training reminder emails
- Training sessions, quiz results, and certificates — to maintain your firm's AML/CTF training register
- Staff names may appear in compliance digest and reminder emails sent to your firm
- Retained while your account is active
3.7 Children
Klyvon’s services are designed for businesses and are not intended for anyone under 18 years of age. We do not knowingly collect personal information directly from children. If we become aware that we have collected a child’s personal information without appropriate consent, we will delete it as soon as practicable.
4. How We Share Your Data
We share your information only where necessary to provide our services, with the following categories of providers:
- Payment processors — to manage billing and subscriptions. Klyvon does not directly store raw payment card numbers. All card data is handled by our payment processor via their hosted checkout.
- Email delivery providers — to send transactional emails, trial reminders, newsletter issues, and compliance checklist delivery.
- AI service providers — to generate your compliance documents and SMR drafts from the information you provide (see Section 5).
- Cloud hosting and database providers — to store your account data, client records, and generated documents. All structured data is stored on Australian-hosted infrastructure.
- Web hosting and analytics providers — standard server logs and the privacy-limited analytics described in Section 6.
We also use the information we hold for security monitoring, fraud and abuse prevention (for example, rate limiting), to comply with our legal obligations, and to improve our services.
We use reputable third-party providers with industry-standard security controls. We do not sell, rent, or trade your personal information to any third party for marketing purposes.
5. AI Processing
How we use AI to generate your documents
When you use Klyvon’s document generation or SMR drafting features, information you provide is sent to our AI service provider to generate your compliance documents.
What is sent
- ✓Your firm name and industry
- ✓Your compliance officer name
- ✓Your intake form responses
- ✓For SMR drafts: the client name and transaction details you enter in the draft form
What is not sent
- ✗Your clients' CDD register records (date of birth, residential address, ID document details)
- ✗Payment information
- ✗Your authentication credentials
Free-text fields are transmitted as you write them — anything you type into an SMR draft, guidance query, or chat message is sent to our AI service provider to generate the response. Do not include personal information that is not needed for the output you are requesting.
Your data is used solely to generate your documents in that session. Our AI service provider does not use your data to train their models under their standard API terms. If this changes, we will update this policy and notify you by email.
Klyvon’s AI features produce drafts and general guidance — draft compliance documents, SMR drafts, checklists, and guidance responses. These outputs may inform compliance decisions your firm makes (for example, whether to file a suspicious matter report) that can affect individuals. Klyvon’s systems do not make any such decision automatically: every output is reviewed by your firm, and each decision is made by a person at your firm. The kinds of information used by these systems are listed above.
For questions about AI processing, contact privacy@klyvon.com.au.
7. Overseas Disclosure
Some third-party providers we use store or process data outside Australia. The countries in which these recipients are likely to be located are: the United States (payment processing, email delivery, AI processing, web hosting and server logs, and session replay on marketing pages) and the European Union (product analytics). Where this occurs, we take reasonable steps as required by Australian Privacy Principle 8 to ensure overseas recipients handle personal information consistently with the APPs, including by using providers with established privacy and security programs and by relying on contractual protections. Klyvon remains accountable under the Privacy Act for the handling of personal information by these overseas recipients.
All structured data and client CDD records are stored on Australian-hosted infrastructure.
8. Security
All data is transmitted over TLS (HTTPS). Database access requires authenticated credentials — no public access. Client data is stored on Australian-hosted infrastructure with encryption at rest and in transit.
Dashboard authentication uses a cryptographically random token stored in a secure httpOnly cookie. Every action on client records is captured in an audit log.
Please note: no method of electronic storage or transmission is completely secure. While we implement industry-standard security measures, we cannot guarantee absolute security.
If you identify a security vulnerability, contact us immediately at support@klyvon.com.au.
9. How Long We Keep Your Data
- Checklist leads (no account): until no longer needed for follow-up; deleted on request at any time
- Newsletter subscribers: until you unsubscribe; a minimal suppression record is kept afterwards
- Account and subscription data: while your account is active; deleted within 30 days of a verified deletion request, except where retention is required by law
- Intake form data: while your account is active; deleted with your account
- Client CDD records: at least 7 years after the business relationship ends or the occasional transaction completes (s.111, AML/CTF Act 2006) — these records cannot be permanently deleted within that window, even on request, because the law requires your firm to retain them. After that window ends, your firm may instruct permanent deletion
- Audit logs of actions on client records: retained for as long as the related client record
- Analytics identifier: a random identifier stored in your own browser (localStorage) — it persists until you clear your browser storage
- Server logs: 30 days
10. Your Rights Under the Australian Privacy Act
Under the Privacy Act 1988 (Cth) and the Australian Privacy Principles, you have the right to:
- Access the personal information Klyvon holds about you (APP 12)
- Request correction of inaccurate or incomplete information (APP 13)
- Request deletion of your account and associated data (subject to our retention obligations under the AML/CTF Act for client CDD records)
- Opt out of marketing emails at any time via the unsubscribe link in any email (APP 7) — honoured immediately
These rights are not limited to account holders. If your personal information is held in Klyvon because a firm you deal with uses our platform, you can contact us to request access to or correction of that information. We will verify your identity, and may coordinate with the relevant firm to do so and to process the request. Corrections to compliance records are appended to the record rather than overwriting it, so the record’s history and audit trail are preserved as the law requires.
You may make privacy enquiries or complaints anonymously or under a pseudonym where practicable. Anonymity is not practicable for account holders — we cannot operate your account, process payments, or maintain AML/CTF compliance records without identifying information — and we may require certain information to confirm your identity before actioning a request about your personal information.
To exercise any of these rights, contact us at privacy@klyvon.com.au. We aim to respond within 30 days. We may decline a request only where the Privacy Act permits, and we will give you written reasons if we do.
If you make a privacy complaint, we will acknowledge it promptly, investigate it internally — including reviewing the relevant records and audit logs — and respond with our findings and any corrective action within 30 days. If a complaint requires longer, we will tell you and keep you updated.
If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC):
- Website: oaic.gov.au/privacy/privacy-complaints
- Phone: 1300 363 992
11. Notifiable Data Breaches
Klyvon is subject to the Notifiable Data Breaches (NDB) scheme under the Privacy Act 1988 (Cth). If we become aware of reasonable grounds to suspect an eligible data breach, we will carry out a reasonable and expeditious assessment and take all reasonable steps to complete that assessment within 30 days, as required by s.26WH of the Privacy Act.
If we determine that an eligible data breach has occurred and it is likely to result in serious harm to any individual, we will:
- Notify affected individuals as soon as practicable
- Notify the Office of the Australian Information Commissioner (OAIC) as soon as practicable
- Take immediate steps to contain the breach and prevent further harm
- Include in each notification the information the Privacy Act requires — a description of the breach, the kinds of information involved, and the steps we recommend you take
Where a suspected breach involves client CDD records, that information is held for your firm as well as by Klyvon. We will notify the affected firm promptly and coordinate the assessment with it, including which entity notifies the OAIC and affected individuals (as the Privacy Act permits, s.26WM), so that individuals receive one clear notification rather than conflicting ones.
12. Changes to This Policy
We may update this policy from time to time. We will notify you of material changes by email to your registered address at least 30 days before they take effect. The date at the top of this page reflects the most recent update.
13. Contact
For privacy questions, access requests, or complaints:
Email: privacy@klyvon.com.au
For general support:
Email: support@klyvon.com.au
For legal matters:
Email: legal@klyvon.com.au
Mail: Klyvon, Melbourne VIC, Australia
We aim to respond to all privacy requests within 30 days. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC):
- Website: oaic.gov.au/privacy/privacy-complaints
- Phone: 1300 363 992
Privacy questions? Email us at privacy@klyvon.com.au