Privacy Policy
Kriaka Limited ("Kriaka", "we", "us") operates kriaka.com and provides AI strategy and implementation services to businesses in New Zealand. This policy describes the collection, use, storage and protection of personal information for those activities.
1. Information We Collect
Through Our Website
- Contact form submissions: name, email address, company name, and message content.
- Automatically collected for hosting and security: IP address, browser type, referring URL, and visit timestamp.
- Website analytics: aggregate visits, pageviews, pages visited, country, referring hostname, and browser performance metrics through Cloudflare Web Analytics.
Through Our Services
The standard AI Operating Strategy Assessment uses information supplied or made available inside the Assessment Charter and Data-Handling Schedule. It does not include Kriaka-held production credentials, independent access to live systems or write access. Connected-system information below applies only to a separately authorised scope and access method.
- Client contact details: names, email addresses, and phone numbers of client personnel.
- Business and Assessment data: information provided by clients for an AI Operating Strategy Assessment or later services, including operational documents, representative work examples, meeting transcripts, screenshots, reports, process notes, email, calendar, CRM records, customer lists, and other evidence inside the agreed boundary.
- Connected business-system data: if you connect Google Workspace, Microsoft, Xero, Fergus, email, calendar, document storage, or another approved system, the account data, permissions, and records approved through consent, onboarding authority, API token, or another agreed access method.
- Connected-account metadata: OAuth metadata, connected account IDs, scopes, connection status, provider errors, and audit records needed to operate and support approved integrations.
- Staff, customer, supplier, and contractor information: personal information contained in client systems where it is necessary for the agreed scope and purpose.
- Service usage data: agent interaction logs, performance metrics, and error logs.
2. How We Use Your Information
We use personal information to:
- respond to enquiries;
- deliver the agreed Assessment or separately authorised implementation and support;
- communicate about the engagement and issue invoices;
- operate, secure and troubleshoot the service;
- understand aggregate website performance; and
- meet applicable legal and accounting obligations.
We collect only information necessary for a lawful purpose connected with our activities. Use for another purpose and disclosure to another party are subject to their separate Privacy Act limits; a provider list or commercial agreement does not remove those obligations.
We do not use personal information for unsolicited marketing, selling or renting to third parties, training AI models on your data, or profiling individuals for automated decisions.
3. Third-Party Disclosure
We may share personal information with:
- AI model providers, such as OpenAI, Anthropic, Google, or other approved model providers, where client data is processed through LLM APIs to deliver our services. We minimise sensitive data in API calls.
- AI routing providers, such as OpenRouter, where needed to route requests to selected or fallback model providers.
- Managed integration brokers, such as Composio, where approved for hosted OAuth, token management, tool execution, or proxied business-system API calls. These providers may process connected-account metadata and selected business-system data returned by or sent through approved tools.
- Connected business-system providers and APIs, such as Google Workspace, Microsoft, Xero, Fergus, email, calendar, document storage, and job management systems, where you approve a connection or ask us to use that system for the services.
- Search, enrichment, or research providers, where a workflow expressly includes web search, company research, contact lookup, or similar research support.
- Cloud infrastructure, monitoring, and email delivery providers, such as Cloudflare, for hosting, email delivery, security, and reliability.
- Professional advisors, including accountants, lawyers, and insurers, as needed for business operations.
- Law enforcement or regulators, if required by New Zealand law or court order.
We will not disclose your personal information to any other party unless it is needed for the services, listed in the applicable provider register or client agreement, authorised by you, or allowed or required by law.
Google Workspace API Data
Data we access: Kriaka's direct Google Workspace connection uses your stable Google account identifier and verified email address to identify the connection. It can access Google Drive files that Kriaka creates or that you explicitly make available to Kriaka, including supported Google Docs and Sheets files; your primary calendar identity, calendar list, free/busy information, and events; and your Google Tasks lists and tasks. It does not request access to Gmail, Google Contacts, your Google profile, all files in Drive, Google Slides, or restricted Google scopes.
How we use it: we use Google Workspace data only to provide the user-visible features you request or approve, such as finding or creating an available Drive file, reading or updating supported Docs and Sheets files, checking availability, managing calendar events, and managing tasks. The source record remains in Google. Kriaka does not build a permanent copy of your Google Workspace content.
Transfers and AI processing: we transfer Google Workspace data only to approved service providers where necessary to carry out the feature you request. This may include AI model, routing, hosting, monitoring, and integration providers. We require those providers to process the data only for the requested service and not to use it to train general-purpose or shared AI models. We do not sell Google user data, use it for advertising, transfer it to data brokers, use it to determine creditworthiness or for lending, or allow it to be used for unrelated purposes.
Human access: Kriaka personnel do not read Google Workspace content unless you have given explicit consent for support, it is necessary to investigate security or abuse, we are required to do so by law, or the data has first been aggregated or anonymised for internal operations. Access is limited to authorised personnel.
Security, retention, and deletion: OAuth refresh tokens are encrypted at rest and data is encrypted in transit using HTTPS. Google remains the authoritative source. Kriaka retains metadata-only Workspace connection and action audit records for 30 days. Those audit records do not contain raw message, document, spreadsheet, calendar-event, or task content. Any temporary or derived Workspace data is minimised and deleted when it is no longer needed for the requested feature, when the connection is disconnected, or following a valid deletion request, subject to legal, contractual, security, and bounded backup requirements.
Kriaka's use and transfer of information received from Google Workspace APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
You can revoke Kriaka's access at any time from your Google Account permissions. You can also contact us at contact@kriaka.com to disconnect a Google Workspace integration or request deletion of Kriaka-held data associated with that connection.
4. Indirect Collection
We may receive information about staff, customers, suppliers or other people from customer-provided evidence or a separately authorised system connection.
For each information flow, we identify which agency collects and holds the information, why it is needed and which notice duties or exceptions apply. Where Kriaka collects personal information indirectly, Kriaka remains responsible for its applicable notification duties. A client may deliver an agreed notice on Kriaka's behalf, or an applicable exception may remove the need for another notice; neither is assumed merely because the client has the original relationship.
We record the notice or exception and the responsible owner for the actual engagement. A contract cannot simply transfer every Kriaka obligation to the customer.
5. Data Storage and Security
- Personal information is stored on secure cloud infrastructure and approved service providers.
- We use HTTPS encryption for data in transit.
- Access to personal information is restricted to authorised Kriaka personnel.
- We implement reasonable technical and organisational safeguards against unauthorised access, loss, or misuse.
- Contact form data is retained for 12 months, then deleted unless a business relationship is established.
Data location: information may be stored and processed outside New Zealand by Kriaka or approved providers. We take reasonable steps to use providers, contractual safeguards, or authorisations appropriate for New Zealand Privacy Act overseas disclosure requirements.
6. Data Retention
| Data type | Retention period |
|---|---|
| Contact form enquiries with no engagement | 12 months |
| Website analytics aggregates | Cloudflare provider retention; Kriaka weekly aggregate reports are retained for 90 days after the analytics trial decision |
| Client contract data | Duration of contract plus 7 years for tax and legal requirements |
| AI Operating Strategy Assessment working material | Deleted within 30 days after the Assessment closes unless earlier deletion is practical or specific material is recorded for transfer into a separately authorised Stage 2 data schedule. The final Decision Pack and minimal engagement record follow the client-contract retention period. |
| Agent interaction logs | Duration of contract plus 90 days |
| Google Workspace connection and action audit records | 30 days; metadata only, without raw Google Workspace content |
| Invoices and financial records | 7 years under the Tax Administration Act 1994 |
7. Your Rights
Under the New Zealand Privacy Act 2020, you have the right to access your personal information, request correction of inaccurate information, know what information we hold and why, withdraw consent for processing based on consent, and complain to the Office of the Privacy Commissioner if you believe we have breached the Privacy Act.
To exercise these rights, contact us at contact@kriaka.com. We will respond to access and correction requests within 20 Business Days, as required by the Privacy Act.
8. Cookies and Website Analytics
kriaka.com does not use cookies or advertising pixels. We use Cloudflare Web Analytics to understand aggregate website traffic, referring sources, countries, pages visited, and browser performance. Cloudflare Web Analytics does not use cookies, local storage, or fingerprinting to identify or track individual visitors.
Kriaka uses these aggregate results to assess whether the website is reaching relevant visitors and whether site performance needs attention. Cloudflare also processes ordinary network and security metadata when serving the site.
If we add cookies, advertising pixels, or individual visitor tracking in the future, this policy will be updated before that processing begins.
9. AI-Specific Transparency
An Assessment or separately authorised implementation may use approved AI providers to process the information needed for the agreed work. The signed data schedule names the actual provider route. Important things to know:
- No model training or improvement: Kriaka configures approved provider accounts and routes so Client Data is not used to train, fine-tune, or improve general-purpose or shared AI models. The providers, routes and safeguards used for a client scope are recorded in the applicable agreement or provider schedule. This does not mean zero retention. Provider security, moderation, debugging, and backup retention may still apply under current provider terms.
- Human oversight: people retain consequential judgement. The Assessment recommends a decision and does not authorise live actions. Any later external, financial, legal, employment, safety or binding action follows the exact human-review or narrower pre-approved authority in its separate scope.
- Data minimisation: we configure agents to process only the minimum data necessary for the task at hand.
- Logs and auditability: consequential connector actions create metadata-only audit records. Connector audit records do not contain raw message, document, spreadsheet, calendar-event, or task content. Clients can request available audit information about their agent's activity.
10. Children's Privacy
Our services are designed for businesses, not individuals under 16. We do not knowingly collect personal information from children.
11. Changes to This Policy
We may update this privacy policy from time to time. Material changes will be posted on kriaka.com with an updated effective date. If you are an existing client, we will notify you of material changes by email.
12. Contact Us
Kriaka Limited
Company number: 9431431
NZBN: 9429053691804
Auckland, New Zealand
Email: contact@kriaka.com
Web: https://kriaka.com
Privacy complaints: if you are not satisfied with our response, you may contact the Office of the Privacy Commissioner at privacy.org.nz or 0800 803 909.