Privacy Policy
Last updated: January 2026
1. Overview
Pacific Flow AI Limited ("we", "us", "our") is committed to protecting your privacy and handling your personal information responsibly. This Privacy Policy explains how we collect, use, disclose, and protect information in compliance with the New Zealand Privacy Act 2020.
This policy applies to information collected through our website (pacificflow.ai), AI chat interfaces, and in the course of providing our services.
2. Information We Collect
2.1 Information You Provide
- Contact Information: Name, email address, phone number, business name
- AI Audit Responses: Information you share during the AI Readiness Audit about your business processes and systems
- Project Information: Business data and documentation shared during service engagements
- Chat Conversations: Messages exchanged with our AI assistant
2.2 Information Collected Automatically
- Usage Data: Pages visited, time spent on site, click patterns
- Device Information: Browser type, operating system, device type
- Log Data: IP address, access times, referring URLs
3. How We Use Your Information
We use your information to:
- Provide and improve our AI consulting and automation services
- Generate AI Readiness Audit reports and recommendations
- Communicate with you about your projects and our services
- Send relevant updates and educational content (with your consent)
- Analyse and improve our website and services
- Comply with legal obligations
We do not sell your personal information to third parties.
4. AI and Data Processing
Our AI chat assistant processes your messages to provide helpful responses. Important information about our AI systems:
- Chat conversations may be used to improve our AI models, but only in de-identified, aggregated form
- We use third-party AI services (such as OpenAI) to power our assistant. Your data is processed in accordance with their privacy policies and our data processing agreements
- You should not share sensitive personal information (such as passwords, financial account numbers, or health information) in chat conversations
5. Privacy Act 2020 (NZ) Compliance
We collect, use, and disclose personal information in accordance with the 13 Information Privacy Principles set out in the Privacy Act 2020. Key commitments include:
- Collecting only information that is necessary for our lawful purposes
- Being transparent about why we collect information and how it will be used
- Taking reasonable steps to ensure information is accurate, complete, and up-to-date
- Protecting personal information from misuse, interference, loss, and unauthorized access
- Providing you access to your personal information on request
6. Data Sovereignty & Storage
We prioritize keeping your data close to home:
- Website and Services: Hosted on servers in Australia and/or New Zealand where possible
- AI Processing: May involve data transfer to servers in the United States (for AI model processing)
- Backups: Stored in secure cloud infrastructure with appropriate safeguards
Where data is transferred overseas, we ensure appropriate safeguards are in place as required by the Privacy Act 2020, including data processing agreements with our service providers.
7. Disclosure to Third Parties
We may share your information with:
- Service Providers: Companies that help us provide our services (hosting, AI processing, analytics)
- Professional Advisors: Lawyers, accountants, or other professionals as needed
- Legal Requirements: When required by law, court order, or to protect our legal rights
8. Your Rights
Under the Privacy Act 2020, you have the right to:
- Access: Request a copy of the personal information we hold about you
- Correction: Ask us to correct inaccurate information
- Deletion: Request deletion of your personal information (subject to legal retention requirements)
- Complaint: Lodge a complaint with the Office of the Privacy Commissioner if you believe we have breached your privacy
To exercise these rights, contact us using the details below. We will respond within 20 working days as required by law.
9. Data Security
We implement appropriate technical and organizational measures to protect your personal information, including:
- Encryption of data in transit and at rest
- Secure access controls and authentication
- Regular security assessments and updates
- Staff training on privacy and security practices
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by posting a notice on our website or contacting you directly if appropriate.
11. Contact Us
For privacy-related questions or to exercise your rights, contact our Privacy Officer:
Pacific Flow AI Limited
Privacy Officer
Email: privacy@pacificflow.ai
You may also contact the Office of the Privacy Commissioner:
privacy.org.nz