Privacy notice
This explains what personal information we collect, why, and who else sees it, in line with the Privacy Act 2020.
Last updated: 4 October 2026.
Who we are
is provided by . Address: . Privacy contact: info@verfapp.co.nz.
What we collect, and why
| When | What we collect | Why |
|---|---|---|
| You take the free Health Check (Snapshot or full) | Your business name and email address, and your answers (for the full check, including how you hold your licence: on its own, with Authorised Bodies, as an Authorised Body, or not sure) | To show you your result, and to contact you about that result and how we can help. We use your details for this only, unless you tick the separate, optional box to receive emails about our services. If you ask us to email you the link to your full Health Check report, we send one email with that link to the address you gave. |
| You send an enquiry (the consultancy form or the platform interest form) | Your name, business name, email address, phone number (optional), number of employees (optional), what you would like help with or are interested in, your industry (platform interest form), and any note you add | To reply to your enquiry. |
| You email us at info@verfapp.co.nz | Your email address, your name if it shows, and whatever you write or attach | To reply to you and keep a record of the conversation. |
| You use the compliance obligations register | The business name we set the register up under, and everything you type into it | To provide the register to you. |
| You (or your firm) use Policies & procedures or the AI audit | See "Policies & procedures and the AI audit" below. | To keep the firm's policy documents, and to audit them when the firm asks. |
| You use the compliance calendar | The firm's dates, the name the firm gives as the owner of each obligation, and notes the firm types in | To track the firm's own dates and show what is due. |
| You open your dashboard | Counts and dates taken from what the firm has already entered, and a weekly setup-progress percentage we keep so the dashboard can show a trend | To show the firm its progress. |
| You (or your firm) use the CPD & PDP Register or the Skills & Expertise Matrix | See "CPD & PDP Register and Skills & Expertise Matrix" below. | To provide those tools to the firm and its advisers. |
| You (or your firm) use the Risk Register | See "Risk Register" below. | To provide the tool to the firm and to the people the firm names as owners of its risks. |
| You (or your firm) use the Incidents & Complaints registers | See "Incidents & Complaints" below. | To provide the tool to the firm, which records its complaints, incidents and breaches in it. |
| You (or your firm) use the Suppliers & Outsourcing register | See "Suppliers & Outsourcing" below. | To provide the tool to the firm, which records its suppliers and their contracts in it. |
| You (or your firm) use Advice Review with AI | See "Advice Review with AI" below. | To review the firm's client advice files when the firm asks. |
| You sign in | Your email address, and a one-time sign-in code we email you (we keep only a scrambled form of the code, briefly) | To check that you are the person your firm has given access to, and to open only what you are allowed to see. |
If you don't give us the details a form asks for, we can't show you your Health Check result or report, or reply to your enquiry. On the enquiry forms, the name, business name and email address are required, as is what you would like help with or are interested in, and (on the platform interest form) your industry. The phone number, number of employees and any note are optional and can be left blank.
Please don't put personal information about your own clients into the obligations register, an enquiry, an email to us, or anywhere else on this site. The exceptions are the Incidents & Complaints registers, which by their nature concern clients (use a client reference, not a name, in what you write; see below), and Advice Review with AI, which reviews a firm's client advice files at the firm's request (see below).
Policies & procedures and the AI audit
These tools are used by a firm to keep its own policy and procedure documents, and to have them audited. The firm decides what is uploaded.
What is held: for each document, its title, version, dates and notes, the name and email address of the person the firm says owns it (optional), the uploaded file (PDF or Word), text taken from the file so it can be checked, and the results of any audit: the findings, the firm's responses to them, who signed the audit off and when, and any redline drafted from it. The firm's answers to the required-policies checklist are kept too. Files are kept in Microsoft Azure Blob Storage (New Zealand North), in a private area that is never linked to directly: a file is handed back only through the firm's own private link. We do not scan uploaded files for malware.
Who can see it: anyone who has the firm's private link. A policy owner the firm invites sees only the audits they are invited to, through their own link. If the firm asks for an independent review of an audit, the reviewer we ask to carry it out can see that audit's results, the policy's title and the firm's name (not the document itself).
Emails we send: a reminder to a policy owner when a review date is coming up (only if the firm has entered an owner email, and at most one email per policy every 14 days), and an invitation to a policy owner or reviewer when the firm or we ask for one.
AI: the audit, the policy review, the redline and the "Improve wording" button use AI, and only when a person clicks them. See "Where we use AI" below. If an audit's AI check sees what looks like personal information about people in a document, it stops and says so.
CPD & PDP Register and Skills & Expertise Matrix
These tools are used by a firm (the financial advice provider) for its advisers. The firm decides who is added and what is entered. We hold the information for the firm to provide the tools.
What is held about an adviser: name, email address, role and FSP number if entered, competence notes, advice scope, development plan goals, CPD entries (title, provider, hours, points, relevance and reflection notes), any certificate or qualification files uploaded, check-in notes, sign-offs and who made them, and a history of changes. The Skills & Expertise Matrix holds which skills each adviser has, at what level, and notes on gaps.
Who can see it: the adviser sees their own record. A manager or reviewer the firm has appointed sees the advisers they look after. The firm's administrator sees all of them. Nobody signs off their own record.
Emails we send: invitations, reminders about plans and CPD progress, notices that a record was updated or is ready for sign-off, and summaries to managers when something needs them. These are sent to the email addresses the firm has entered, and through Microsoft Azure Communication Services.
Signing in: a person enters the email address the firm has on file, and we email a six-digit code that works once and expires after 10 minutes. We store only a scrambled form of the code, briefly. Access can also be by a private link the firm sends. When a firm removes someone's email address or marks them as having left, their access stops.
AI features (optional, off until the firm turns them on): the firm can switch on AI suggestions for development plans and CPD entries. When used, the text of the plan or entry being worked on (advice scope, goals, activity titles, relevance and reflection notes, check-in notes) and, for goal ideas, the titles of the firm's audit findings are sent to Anthropic's AI service. Adviser and firm names are not sent. A separate switch lets the firm have AI read uploaded certificates; that sends the certificate file itself, which usually shows the adviser's name. Anthropic is an overseas provider, so this text leaves New Zealand to be processed, and the firm decides whether to switch it on. The AI only suggests; a person checks and saves. The Skills & Expertise Matrix does not use AI.
Risk Register
This tool is used by a firm (the financial advice provider) to record the risks to its own business. The firm decides what is entered and who is named as the owner of each risk. Please don't put personal information about the firm's own clients into it.
What is held about a person the firm names as a risk owner: name, role, email address, the private link we give them, when they were invited and when they last answered, anything they type (a note on their answer, or on an action), the actions assigned to them, and a record of what they changed. The firm enters the person's name and email address; the firm is responsible for having their agreement to be contacted. When the firm invites a person, our email tells them the firm has given us their name and email address and how to have them changed or removed.
Who can see it: an owner sees only their own risks and the actions assigned to them, through their private link. The firm's administrator sees everything in the register. Nobody else can.
Emails we send: an invitation with the person's private link and the titles and next dates of their risks; reminders about dates coming up or overdue (at most one email per person per week); and a single note to the firm's contact when something has been overdue for more than 30 days. These emails carry risk titles and dates only. They don't carry scores, and nothing the firm has written about a risk. The firm can switch reminders off.
Calendar files: an owner can add their dates to their own calendar. The address of that file is private to them, exactly like their link: anyone who has it can see those titles and dates, and the firm can replace it at any time, which stops the old one working.
No AI: the Risk Register does not send anything to an AI service.
Incidents & Complaints
These registers are used by a firm or business to record its complaints, incidents and privacy breaches (a financial advice provider also records breaches of its obligations), to run their reminders and deadlines, and to keep the evidence of what was done. They hold some of the most sensitive information on this site: what clients complained about, and what the firm has admitted went wrong.
What is held: for each record, a reference number, the dates, what the firm wrote in its summary and notes, categories and choices (for an advice firm, for example the product and insurer), who at the firm handled it and what they did and when, the decisions the firm made about whether to notify a regulator (who decided, when and why, including a decision not to notify), the dates it told the regulators, corrective actions, and a history of every change with the email address of the person who made it. The firm is asked to use a client reference, not a client's name, and to keep names and contact details out of summaries. Names are not stored: a name typed into a letter on the screen stays on the screen. The oversight pack shows references only.
Who can see it: only the firm's own administrator, signed in with an email code. There is no private link for these registers, because a link can be forwarded. Nobody at another firm can see them. Access to a firm's records inside Verfapp is limited to authorised people, and only as needed to run and secure the service, to fix a fault the firm asks us to look at, or to meet a legal obligation.
Deadlines: the registers count New Zealand working days using a public-holiday list that has not yet been verified. They show a reminder; a person decides what to do and whether to notify anyone. Nothing is sent to a client, the FMA or the Privacy Commissioner from here: the firm sends its own letters, and enters its own notifications in the regulators' forms.
AI helper (off until we switch it on, then optional to use): when on, a person can ask the AI to reword their own rough notes into a paragraph for a letter, or to suggest a complaint category from a short summary. Only the text typed into the helper's box (or the summary) is sent to Anthropic's AI service, after emails, web addresses and phone numbers are removed. The record itself, names, client references and dates on the record are not sent. Anthropic is an overseas provider, so this text leaves New Zealand to be processed. The AI only drafts or suggests: it never decides whether something is a complaint, whether an event is material, whether serious harm is likely, or what the outcome is, and nothing goes into a letter until the person clicks to use it.
Emails: these registers send no emails of their own.
Not in your browser: these pages don't keep a copy of the records in your browser.
Suppliers & Outsourcing
This register is used by a firm (the financial advice provider) to list its suppliers, put each in a risk tier, and record the contracts it holds and the person in the firm who owns each one.
What is held: each supplier's business details (legal and trading name, company number, country, website, what it does for the firm), the names and email addresses of the people involved (the firm's own business owner and contract owner, and the supplier's contact people, all typed in by the firm), the firm's yes-or-no answers to the triage questions with who gave them and when, each contract's dates, owner, category and whether it is signed, the insurance the contract requires, and the firm's record of each supplier's insurance policies (the type of cover, insurer, policy number, the name insured, the limits, the dates, and who at the firm confirmed the details and when). The firm's due diligence on each supplier is kept too: its yes, no or not-applicable answers to the assessment questions with notes, who gave each answer and when, where the supplier says it stores and processes the firm's information, the ratings the register works out, and the decision (the outcome, the reasons, the name of the person who decided and of anyone who signed it off, and any conditions with their owners and due dates). Once a decision is recorded it is kept as a fixed record. The firm can also record what each signed contract says, clause by clause, and the controls it relies on where a supplier offers only standard terms; the reputation checks it ran on public registers (which check, the date, whether the result was clear or something was found, a short note, and who at the firm ran it, but not copies of the records themselves); and the issues that arose with the supplier (the type, the date, a factual summary, who at the firm owns putting it right, what is being done, and where relevant a reference to a record in the firm's own Incidents, Breaches & Complaints register). Every change is kept in a history with the signed-in email. It is not meant to hold information about the firm's own clients: keep client names out.
Only the firm's own administrator, signed in by email code, can open it. There is no private link. It is switched on for a firm only when we grant it. The firm can attach a copy of each insurance certificate (a PDF, JPG or PNG file). Those files are kept in Microsoft Azure Blob Storage (New Zealand North), in a private area that is never linked to directly: a file is handed back only to the firm's signed-in administrator. Each file is kept with a fingerprint of its contents and is never overwritten by a later upload. We check that a file is the kind it says it is, but we do not scan uploaded files for malware. A certificate can name people (a broker, a signatory). This stage sends no emails to suppliers and uses no AI: the register can draft a reminder for the firm to send from its own email, and sends nothing itself. The register can also produce reports for the firm (a vendor register, a working sheet for the FMA's annual return, insurance, overdue items, a section for the firm's oversight body, a business continuity extract, a list of where supplier information is held, and a concentration view). A report is worked out from the records above each time it is opened, is downloaded by the firm's signed-in administrator only, and is not stored or sent anywhere by us. Copies of contracts, and of the evidence the firm relied on for a due diligence answer (a certification report, a policy), can be attached in the same way, kept in the same private area, and are never overwritten. Such files are commercially confidential and may name people.
Suppliers & Outsourcing records (the suppliers, their contracts and policies, the stored certificate files, their history and the numbering) are kept while the firm's access is active, and are deleted with the rest of the firm's data if the firm's account is deleted. A firm that is leaving should download the register as a file (there is a download button) first.
Business Continuity Plan
This module is used by a firm (the financial advice provider) to write, approve, test and evidence its business continuity plan.
What is held: the firm's answers about its size and licence class, the text of each part of the plan, the impact analysis (what must come back and how fast), the contacts the firm lists (staff, a locum, suppliers, insurers, the regulator, and others: names, roles, phone numbers, email addresses and account references, typed in by the firm, some of them personal phone numbers of staff or a locum), the list of key documents and where their off-site copies are kept, the firm's messages to clients, its reviews, changes, approvals and tests, and who made each change and when. The plan is not meant to hold client information or passwords, and a firm should not enter either.
Only the firm's own administrator, signed in by email code, can open it. There is no private link. It is switched on for a firm only when we grant it. Everyone who can open it sees all of it. When the firm approves the plan, we keep a frozen copy of exactly what was approved, and a history of every change that cannot be edited or deleted. Nothing is filed with the FMA or sent to anyone from this module, and it uses no AI and sends no emails. The firm can print the plan and a one-page grab sheet; phone numbers marked personal are left off the printed copy unless the firm chooses to include them, and the firm is responsible for storing printed copies securely.
These records are kept in the same database as the firm's other records (Azure Cosmos DB, New Zealand North) and are kept while the firm's access is active. They are deleted with the rest of the firm's data if the firm's account is deleted. A firm that is leaving should print its plan first.
Advice Review with AI
This tool is for a financial advice firm to review its own client advice files (life, fire and general insurance) with the help of AI. It is available on request. It is switched on for a firm only when we agree it with that firm in writing, and we will update this notice, and tell the firm, before the first file is reviewed.
What is held: the advice files the firm chooses to submit for review (for example a fact-find, needs analysis, quotes, a statement of advice, disclosures, notes and emails), text taken from them so they can be reviewed, the standard each review is run against (the FMA's expectations, an insurer's requirements, or the firm's own service standards, which the firm may supply as documents), the findings, the firm's responses, and who confirmed them and when. Client advice files hold personal information about the firm's own clients, and can include health and financial information. We hold it for the firm, to provide the tool.
Who can see it: only the firm's own administrator, and only as needed to run and secure the service, to fix a fault the firm asks us to look at, or to meet a legal obligation. How the firm signs in and where the files are stored will be confirmed when the tool is switched on for the firm.
AI: a review sends text from the file to an AI service, and only when a person asks for it. We plan to use the same AI provider as the rest of the platform, Anthropic, which is overseas, so that text would leave New Zealand to be processed (see "Where we use AI" below). The firm decides which files are submitted and should remove names and identifiers the review does not need. Results are labelled as AI and are drafts: a person at the firm confirms each finding before relying on it, and the AI never decides whether the firm or an adviser has met an obligation.
The firm's clients: a firm should make sure its terms of engagement with its clients allow it to use their information this way. If you are a client of a firm and want to see or correct information about you, ask the firm first, or contact us at the privacy contact above and we will help.
Not yet decided, and to be confirmed before we switch it on: where the files and results are stored, how long they are kept, and where Anthropic processes the text and how it handles it.
People whose details a firm enters
Firms enter details of other people: advisers and managers, risk owners, policy owners, supplier contacts, business continuity contacts (including staff and locums), and references to clients. The firm decides who is added.
When a firm adds someone as a risk owner and asks us to invite them, our email tells them the firm has given us their name and email address and that they can ask the firm to change or remove them. For other people, we only contact them if the firm asks us to send an invitation or a reminder. If you think a firm has entered your details and you want to see or correct them, contact us at the privacy contact above and we will help.
Authorised Bodies
If your firm is an Authorised Body, or holds a licence with Authorised Bodies, we record that (and the licence class) against your firm. We set it up; you can't change it yourself. If an Authorised Body's licence holder is also our client, the Authorised Body's own pages show the licence holder's business name and nothing else about it. We don't show one firm's records to the other. A report an Authorised Body builds for its licence holder leaves the platform only when the firm itself sends it: we don't send it.
Where we use AI
These are all the places the platform uses AI. Anything AI produces is labelled as AI, and a person decides what to do with it.
| Feature | When it runs | What is sent |
|---|---|---|
| Full Health Check report | When you submit the full check | Your answers, the question wording, your licence role and the results. Not your business name, email address or phone number. |
| AI check in the obligations register | Automatically, when you edit "current control" or "evidence" | The obligation and the text you typed. |
| "Improve wording" | Only when you click it | The text in the box you are improving. |
| AI audit of policies & procedures | Only when you click to run it | The document's title, version and effective date, the required policy it is meant to cover, and up to the first 6,000 characters of its text. If the text looks like it holds personal information about people, the audit stops. |
| AI review of an uploaded policy | Only when you click "Get AI review" | The policy's title and type, and an excerpt of its text. |
| AI redline of a policy | Only when you click to draft it, for findings you agreed with | The document's text (up to about 40,000 characters) and your comments on the agreed findings. |
| CPD & PDP suggestions and certificate reading | Off until the firm turns them on; certificate reading has its own switch | As described under CPD & PDP Register above. |
| Advice Review with AI | Not in use yet. When it is, only when a person asks for a review | Text from the client advice file being reviewed, and the standard it is reviewed against. What exactly is sent, and what is removed first, will be confirmed and set out here before the tool is switched on for a firm. |
| Incidents, breaches & complaints helper | Off until we switch it on, then only when a person asks | The text typed into the helper's box, with emails, web addresses and phone numbers removed. |
Advice Review with AI is the one place we expect to send client advice files, which hold personal information about the firm's clients, to the AI service. That is why it is switched on only by agreement with the firm. AI is not used in the Risk Register, Suppliers & Outsourcing, the Business Continuity Plan or the Skills & Expertise Matrix. The free Snapshot's score, and every score in the full report, are worked out by fixed rules.
We use Anthropic's AI service for all of this. Anthropic is based overseas, so the text above leaves New Zealand to be processed. We are confirming where Anthropic processes it and its data-handling terms, and will update this notice when we have.
Who else sees it, and where it goes
- Microsoft Azure. Our hosting, database and file storage. The database and uploaded files (such as certificates) are stored in New Zealand North. The website's code that handles each request runs in the Central United States, so information passes through and is processed there as you use the site; it is not stored there.
- Microsoft Azure Communication Services (email). Sends our emails, including sign-in codes and reminders. The email service's data location is Australia. Email is also carried over the internet to your own mailbox provider.
- Anthropic (AI features). The AI features listed under "Where we use AI" send the text described there to Anthropic's AI service. Anthropic is an overseas provider.
- Kiwidata (our domain name and email forwarding). A New Zealand company that runs our domain name and forwards email sent to info@verfapp.co.nz to our mailbox. Forwarded email passes through its systems and its email delivery partners.
- Google (our mailbox). Email sent to info@verfapp.co.nz ends up in a Gmail mailbox that Google runs. Google is an overseas provider, so those emails are stored and processed outside New Zealand.
We don't sell your information.
How long we keep it
Free Health Check answers and details are kept for 12 months from when you take the check. Full Health Check reports are kept for 24 months, since the report page lets you bookmark and come back to it. Enquiries (consultancy and platform interest) are kept for 12 months. After that they are automatically deleted.
Emails you send to info@verfapp.co.nz are kept in our mailbox for 12 months after the last message in the conversation, and are then deleted.
If you have a compliance obligations register, your register data is kept for as long as your subscription is active, and is deleted on request once your access is paused.
Risk Register records (the risks, the owners' names and emails, and the history of changes) are kept while the firm's access is active, and are deleted with the rest of the firm's data if the firm's account is deleted. Deactivating an owner stops their emails and their link straight away; we will remove their name and email on request.
Incidents & Complaints records (the records, their history, the numbering and any oversight sign-offs) are kept while the firm's access is active, and are deleted with the rest of the firm's data if the firm's account is deleted. A firm's licence conditions ask it to keep records of its advice service for at least seven years, so a firm that is leaving should download each register as a file (each register has a download button) before its account is deleted. A person can ask for the record of their own complaint; we will help the firm to provide it, with other people's details removed.
CPD & PDP Register records are kept for a period the firm chooses, between 7 and 15 years from the end of each CPD year, and are then removed automatically. The firm also chooses whether uploaded certificates are kept, or deleted once they have been verified (the record of the verification is kept). Records of an adviser who has left are kept for the same period from the date they left. Pending sign-in codes expire within an hour. To limit misuse we keep a scrambled (hashed) form of the network address that made a request, and a count of requests, for up to 30 days.
Advice Review with AI records: how long they are kept will be agreed with the firm and set out here before the tool is switched on for it.
When a firm leaves
When a firm's account is deleted, we delete its records, the files it uploaded (policy documents, certificates and AI redlines) and their histories. Some records a firm must keep for a set period under its own obligations, for example records of an advice service for at least seven years. A firm that is leaving should export what it needs first. Most tools have a download or print option, and we can export anything else on request.
How we protect your information
- Information is encrypted in transit (HTTPS), and Microsoft Azure encrypts stored data by default.
- Access is controlled: private links, one-time sign-in codes for the more sensitive tools, and an authenticator app for our own admin access. Only authorised people have admin access, and only as needed.
- Uploaded files are kept in a private area and are never linked to directly.
- We keep logs and are alerted if something goes wrong. Data is backed up automatically, and we have tested restoring it.
We don't claim any security certification.
Your rights
You can ask to see the personal information we hold about you and to correct it. Contact us at the privacy contact above. If you're unhappy with how we've handled your information, you can complain to the Office of the Privacy Commissioner (privacy.org.nz).
Cookies and tracking
This site doesn't use advertising cookies or tracking, sets no cookie to count visits, and doesn't load anything from other companies' sites. This is what it keeps in your own browser:
- Sign-in cookie. When you sign in with a code, we set one cookie that keeps you signed in for up to 8 hours. It holds your email address and an expiry time, is signed so it can't be altered, and can't be read by scripts on the page. It is removed when you sign out. Signing in is optional for most tools; the private links work without it.
- Health Check answers. The Health Check remembers your answers (and, for the full check, how you hold your licence) in your browser so you don't lose them if you leave the page. They are cleared when you submit.
- CPD page. The CPD page remembers which tab you last opened, and the name you type to sign something off, in your browser, until you clear your browser's data.
- Last view. To load faster, the CPD, Skills and Dashboard pages keep a copy of the last thing they showed in your browser tab. It is cleared when you close the tab, when you sign out, or if the page is told you no longer have access.
- The Risk Register doesn't keep a copy of your risks in your browser. Nor do the Incidents & Complaints registers.
Counting visits. When you open one of our public pages (not the signed-in tools), the page sends a small message to our own server saying which page was opened and which website you came from (the site's name only, not the full address). We also work out a code from your network address and browser type that changes every day, so we can count how many different people visited on a given day. We can't turn that code back into your address or follow it from one day to the next, and nothing is stored in your browser. The Azure service that holds these counts also records the approximate place a visit came from (country, region and city), worked out from your network address. It doesn't keep the address itself with these counts. These counts and locations are kept in Microsoft Azure for 90 days. We don't send your visit to any other company. If your browser sends a Do Not Track or Global Privacy Control signal, we don't count your visit.