Privacy Policy
Kriaka Limited ("Kriaka", "we", "us") operates kriaka.com and provides AI agent services to businesses in New Zealand. This policy explains how we collect, use, store, and protect personal information in compliance with the New Zealand Privacy Act 2020.
1. Information We Collect
Through Our Website
- Contact form submissions: name, email address, company name, and message content.
- Automatically collected data: IP address, browser type, pages visited, referring URL, and visit timestamp.
- Analytics: aggregated, non-identifying usage data via Cloudflare Web Analytics, with no cookies and no personal tracking.
Through Our Services
- Client contact details: names, email addresses, and phone numbers of client personnel.
- Business data: information provided by clients for agent configuration, such as email accounts, calendar data, CRM records, and customer lists.
- Connected Google Workspace data: if you connect Google Workspace, the Google account data and permissions you approve through Google's consent screen, such as Gmail sending, Drive file-scoped access, Calendar, Docs, Sheets, and Slides access.
- Service usage data: agent interaction logs, performance metrics, and error logs.
2. How We Use Your Information
| Purpose | Legal basis under the Privacy Act |
|---|---|
| Responding to contact form enquiries | IPP 1, lawful purpose, directly from you |
| Providing contracted AI agent services | IPP 10, purpose for which it was collected |
| Sending service updates or invoices | IPP 10, directly related purpose |
| Improving our website and services | IPP 10, legitimate interest, aggregated data |
| Complying with legal obligations | IPP 11, permitted disclosure |
We do not use personal information for unsolicited marketing, selling or renting to third parties, training AI models on your data, or profiling individuals for automated decisions.
3. Third-Party Disclosure
We may share personal information with:
- AI model providers, such as Anthropic, Google, and OpenAI, where client data is processed through LLM APIs to deliver our services. We minimise sensitive data in API calls.
- Google Workspace APIs, if you connect Google Workspace, so Kriaka can perform the Workspace actions you approve or request through the services.
- Cloud infrastructure providers, such as Cloudflare, for hosting, email delivery, and analytics.
- Professional advisors, including accountants, lawyers, and insurers, as needed for business operations.
- Law enforcement or regulators, if required by New Zealand law or court order.
We will not disclose your personal information to any other party without your prior consent.
Google Workspace API Data
If you connect Google Workspace, Kriaka will access only the Google account data and permissions you approve through Google's consent screen. We use that data only to provide or improve the Workspace features you ask your agent to perform, such as sending email, scheduling calendar events, or creating and updating Drive, Docs, Sheets, and Slides files.
We do not sell Google user data, use it for advertising, use it to determine creditworthiness, or use it to train generalized AI models. Kriaka's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
You can revoke Kriaka's Google access from your Google Account permissions. You can also contact us to disconnect a Google Workspace integration or request deletion of Kriaka-held data associated with that connection.
4. Data Storage and Security
- Personal information is stored on secure cloud infrastructure.
- We use HTTPS encryption for data in transit.
- Access to personal information is restricted to authorised Kriaka personnel.
- We implement reasonable technical and organisational safeguards against unauthorised access, loss, or misuse.
- Contact form data is retained for 12 months, then deleted unless a business relationship is established.
Data location: information may be stored and processed on servers located outside New Zealand, primarily in Australia and the United States. We use providers with data protection standards appropriate for our services.
5. Data Retention
| Data type | Retention period |
|---|---|
| Contact form enquiries with no engagement | 12 months |
| Client contract data | Duration of contract plus 7 years for tax and legal requirements |
| Agent interaction logs | Duration of contract plus 90 days |
| Website analytics | Aggregated, no personal data retained |
| Invoices and financial records | 7 years under the Tax Administration Act 1994 |
6. Your Rights
Under the New Zealand Privacy Act 2020, you have the right to access your personal information, request correction of inaccurate information, know what information we hold and why, withdraw consent for processing based on consent, and complain to the Office of the Privacy Commissioner if you believe we have breached the Privacy Act.
To exercise these rights, contact us at [email protected]. We will respond to access and correction requests within 20 Business Days, as required by the Privacy Act.
7. Cookies
kriaka.com does not use cookies for tracking or advertising. We use Cloudflare Web Analytics, which is privacy-first and does not use cookies or collect personal data. If we add cookies in the future, this policy will be updated.
8. AI-Specific Transparency
- No model training: your data is not used to train or fine-tune AI models. We use API-based access with data processing agreements from providers.
- Human oversight: client agents operate under configurable guardrails. External-facing actions can require human approval before sending.
- Data minimisation: we configure agents to process only the minimum data necessary for the task at hand.
- Logs and auditability: agent actions are logged. Clients can request audit logs of their agent's activity.
9. Children's Privacy
Our services are designed for businesses, not individuals under 16. We do not knowingly collect personal information from children.
10. Changes to This Policy
We may update this privacy policy from time to time. Material changes will be posted on kriaka.com with an updated effective date. If you are an existing client, we will notify you of material changes by email.
11. Contact Us
Kriaka Limited
Auckland, New Zealand
Email: [email protected]
Web: https://kriaka.com
Privacy complaints: if you are not satisfied with our response, you may contact the Office of the Privacy Commissioner at privacy.org.nz or 0800 803 909.