Trust and data.

No blanket access and no unchecked authority. Every engagement begins with a defined purpose, an evidence boundary, an access boundary and a human owner.

What information does Kriaka need?

During strategy work, Kriaka uses the representative evidence needed to understand the decision. This may include existing documents, targeted conversations, examples of real work and read-only walkthroughs inside the agreed boundary. The aim is decision-sufficient evidence, not exhaustive collection.

Implementation requires a separate scope and access boundary. Kriaka connects to or imports only the information required for the authorised work.

What can Kriaka access or change?

You approve each connection, permission and allowed use. The boundary distinguishes between reading information, preparing work, recommending an action and carrying it out.

A connection being technically available does not give Kriaka authority to use it. Write-capable actions remain draft-first or approval-gated unless the signed scope explicitly allows a narrower action after testing.

Who remains in control?

Your business systems remain the authoritative record. People retain judgement over consequential external, financial, legal, employment, safety and binding actions unless narrower authority is separately agreed, tested and documented.

Every operating scope names the human reviewer, the escalation path and the actions the system must refuse or return for a decision.

Where can information be processed?

Approved AI, hosting, authentication, integration, search and business-system providers may process information needed to deliver the agreed work. Processing may occur outside New Zealand.

Kriaka does not promise a fixed provider, New Zealand-only processing, zero retention or a certification unless the specific deployment supports that claim. The relevant provider information and data-handling terms are confirmed before production work.

How are access and your information protected?

Within each agreed scope, Kriaka uses accounts, credentials and operating areas specific to your business. Access is limited to the people, systems and permissions required for that scope.

Before real data from your business is used, we name the source, the purpose, the reviewer, how long it is kept, the backup path, the incident response and the offboarding path. A connection is not considered ready merely because authentication succeeds.

What happens when something fails?

Production readiness includes testing normal work, missing information, unsafe actions and edge cases. It also requires monitoring, a named escalation path, recovery procedures and the ability to stop or disconnect affected work.

Kriaka does not promise that failures cannot happen. The responsibility is to make the agreed boundary, evidence and response visible enough to contain and recover from them.

What happens when the work ends?

Access can be revoked and connected tools can be disconnected. Your information is returned, exported or deleted according to the signed scope, the Privacy Policy and applicable legal or accounting retention obligations.

Continued Kriaka management is not required. Transfer, internal ownership, another provider or stopping are valid outcomes when the evidence supports them.

Where are the exact terms?

The engagement agreement, data-handling schedule, approved access record and provider information govern the exact scope of your engagement. The Privacy Policy explains Kriaka's general handling of personal information.

If your business has a specific residency, provider, accreditation, self-hosting or external-processing requirement, raise it early. Kriaka will confirm whether the requirement can be met rather than inventing a deployment path to preserve the opportunity.

Privacy Policy

Bring the objective first.

Start a conversation