Privacy policy

Last updated: 8 September 2026

Effective date: 8 September 2026

1. Introduction and scope

GWAITH DEVELOPMENT LIMITED (NZBN 9429053840806) of Mosgiel, New Zealand ("Gwaith", "we", "us", "our") develops and operates business management software, including point-of-sale, ERP, inventory management and CRM applications, and the API integrations that connect them.

Gwaith is the agency responsible for the personal information it holds in its own right, and is accountable for that information under the Privacy Act 2020. For some information Gwaith processes on a client's instructions, Gwaith acts on that client's behalf rather than as the responsible agency; the United States subsection of section 13 explains how that affects a request about information of that kind. This policy explains what personal information Gwaith collects, why it is collected, how it is used, who it is shared with, where it is stored, how long it is kept, and what rights you have in relation to it.

This policy applies to:

Gwaith's software reaches end users through reseller partners. If you are an end user, your commercial relationship and your support relationship are with the reseller that licenses the software from Gwaith. Depending on the arrangement between Gwaith and that reseller, the reseller will ordinarily be a separate agency responsible for the personal information it holds about you, and in that case its own privacy policy applies to that information. This policy governs the personal information held by Gwaith in the systems Gwaith operates.

This policy does not cover third-party systems that a client chooses to connect to Gwaith software. Information held in those systems is governed by the privacy policy of the organisation that operates them.

2. Information we collect

The information Gwaith holds depends on which applications a client uses and how those applications are configured. It may include:

Gwaith does not collect or process payment card numbers or bank account details. No Gwaith system stores card numbers, card verification values, or bank account numbers. Where a client's own processes involve payment, that payment is handled by the client, the reseller, or a third-party provider outside the Gwaith software.

3. How we collect information

Gwaith collects personal information in three ways:

4. How we use information

Gwaith uses personal information only for the following purposes:

Gwaith does not sell personal information. Gwaith does not trade, rent or license personal information to any third party for that party's own marketing purposes, does not disclose personal information in exchange for money or other valuable consideration, and does not use personal information for behavioural advertising.

5. The Gwaith API

The Gwaith API is internal. It is used by and between Gwaith applications and services to exchange data within the platform, and it is not exposed to third parties. Gwaith does not publish it, does not operate a public developer program for it, and does not issue credentials for it to organisations outside Gwaith.

This is separate from the third-party APIs that Gwaith software connects to, such as the RFMS, Xero and MYOB APIs. Those are operated by the third parties named in section 7, and Gwaith holds the developer agreement for each.

6. Artificial intelligence features

Some Gwaith applications include features that use artificial intelligence. The Boost AI assistant answers questions about a client's own data in the application, and the Auto-AP feature extracts structured information from uploaded invoices and price lists. The commitments below apply to every one of these features.

7. Third-party services and subprocessors

Gwaith uses the third parties listed below to host, operate and integrate its software. Each is engaged to provide a defined service, receives only the information required for that service, and is not permitted to use it for its own purposes.

Subprocessors engaged by Gwaith, their purpose, and the location in which processing occurs
Subprocessor Purpose Location
Microsoft Azure (Microsoft Corporation) Application hosting, databases, AI services, secrets management Australia East, US Central, West US 2
Twilio SendGrid (Twilio Inc.) Transactional email from Gwaith applications United States
Azure Communication Services (Microsoft Corporation) Website contact form email delivery United States, the data location set for the Communication Services resource serving this website and its API (see section 9)
Cyncly (RFMS Inc; Consilio Midco Limited) RFMS ERP integration via the RFMS API Operated by Cyncly
Xero Limited Accounting integration via the Xero API Operated by Xero Limited
MYOB NZ Limited; MYOB Australia Pty Ltd Accounting integration via the MYOB API Operated by MYOB NZ Limited; MYOB Australia Pty Ltd

Where information is transmitted to a third party listed above, that third party's own privacy policy governs its handling of the transmitted data. This applies in particular to the integration rows: information sent to the RFMS, Xero or MYOB APIs at a client's direction is thereafter held by Cyncly, Xero Limited or MYOB under their own terms and privacy policies, and Gwaith does not control its retention or use in those systems.

8. Non-affiliation

Gwaith Development Limited is an independent company. Gwaith is not affiliated with, endorsed by, or a subsidiary of Cyncly (Consilio Midco Limited), Xero Limited, MYOB NZ Limited, or any of their affiliated companies. Where Gwaith software integrates with a third-party system, it does so through that party's published API under the applicable developer agreement, and nothing in that arrangement should be read as a partnership, endorsement or joint venture.

RFMS Australasia Limited, a reseller partner of Gwaith Development Limited, is a separate company from RFMS Incorporated and the Cyncly group of companies. The statement of non-affiliation above concerns RFMS Incorporated and the Cyncly group of companies, not RFMS Australasia Limited.

All product names, brand names and trademarks referred to in this policy or in Gwaith software are the property of their respective owners, and are used only to identify the systems concerned.

9. Data storage and location

Client data is stored in Microsoft Azure, in either the Azure Australia East region or the Azure US Central region. The region for a given client is selected according to that client's location and data residency requirements.

This website and its API run in the Azure West US 2 region.

Gwaith also operates its own servers in New Zealand data centres. Those servers host internal engineering infrastructure only, such as source control, build and internal tooling. They do not hold end-user personal information.

The statements above describe deployments hosted by Gwaith. Where software developed by Gwaith is deployed on infrastructure that a client owns or controls, whether self-hosted by the client or run on-premises, the data held in that deployment resides on the client's own infrastructure and not on infrastructure operated by Gwaith. Gwaith does not hold or store that data, and the client is the agency responsible for it.

10. Data security

Gwaith applies the following measures to protect the personal information it holds in the systems it operates. Where software developed by Gwaith is deployed on infrastructure that a client owns or controls, the client is responsible for the security of that infrastructure and of the data held on it.

No system can be guaranteed to be completely secure. Gwaith maintains these controls and reviews them, but cannot warrant that a security incident will never occur. If a privacy breach occurs that is likely to cause serious harm, Gwaith will notify the Office of the Privacy Commissioner and the affected individuals as required by the Privacy Act 2020, and will also notify the affected client and its reseller without undue delay.

11. How long we keep information

This section describes how long Gwaith retains data in deployments it hosts; where software developed by Gwaith is deployed on infrastructure that a client owns or controls, retention of the data held on that infrastructure is the client's responsibility.

Retention depends on the category of information:

Where Gwaith no longer needs personal information for any purpose for which it may lawfully be used, it is deleted or de-identified.

12. Disclosure of personal information

Gwaith discloses personal information only in the following circumstances:

13. Your rights

The rights available to you depend on where you are located. In every case, you may exercise your rights by emailing development@gwaith.co.nz. Gwaith may need to verify your identity before acting on a request, and may ask for additional information for that purpose. Gwaith does not charge a fee for responding to a request except where the applicable law permits a charge, in which case you will be told the amount and the reason before any cost is incurred. If you are an end user of software supplied by a reseller, Gwaith may need to work with that reseller to locate and act on your information, and will tell you where your request has been directed.

New Zealand

Under the Privacy Act 2020 you have the right to ask whether Gwaith holds personal information about you, to request access to that information, and to request correction of it. If Gwaith declines a request, it will tell you the reasons to the extent the Privacy Act 2020 requires, and explain your right to complain. If correction is declined, you may ask that a statement of the correction sought be attached to the information.

If you are not satisfied with how Gwaith has handled your information or your request, you may complain to the Office of the Privacy Commissioner, which may investigate the matter.

Australia

Under the Privacy Act 1988 and the Australian Privacy Principles you have the right to request access to the personal information Gwaith holds about you, to request correction of information that is inaccurate, out of date, incomplete, irrelevant or misleading, and to be told how Gwaith handles your information. You may also deal with Gwaith anonymously or under a pseudonym where it is lawful and practicable to do so.

If you are not satisfied with Gwaith's response to a request or a complaint, you may complain to the Office of the Australian Information Commissioner.

United States

If you are a resident of a state with a comprehensive privacy statute, including California under the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), Virginia under the Virginia Consumer Data Protection Act (VCDPA), and Colorado under the Colorado Privacy Act (CPA), you have the following rights:

Where Gwaith processes personal information on behalf of a client, Gwaith acts as a service provider or processor. In that case Gwaith will refer your request to the client responsible for the information, or act on that client's instructions, and will tell you where your request has been directed.

14. Cross-border transfer of information

Gwaith operates internationally. Personal information may be transferred to, stored in, and accessed from Australia, the United States, and other Microsoft Azure regions used to operate the services described in this policy. The countries in which those regions are located may have data protection rules that differ from those of the country in which you are located, and in some cases those rules may offer a lower standard of protection.

Where information is transferred, Gwaith takes reasonable steps to ensure that it remains subject to protections comparable to those required by the Privacy Act 2020, including through the contractual terms Gwaith holds with the subprocessors listed in section 7. By using the applications or the API, you acknowledge that your information may be transferred and stored as described in this section and in section 9.

15. Sensitive information

The Gwaith applications are business management tools and are not designed to hold sensitive information. You must not submit sensitive information to Gwaith or enter it into the applications. Sensitive information means information of a kind treated as sensitive under the applicable statutes, including health and medical information, biometric and genetic information, racial or ethnic origin, political opinions or affiliations, religious or philosophical beliefs, trade union membership, sexual orientation, criminal records, precise geolocation, and government identifiers such as passport, driver licence, tax or social security numbers.

If sensitive information is submitted despite this, Gwaith will delete it once it becomes aware of it, unless it is required by law to retain it. Gwaith does not seek, request or knowingly process sensitive information.

16. Use by minors

The Gwaith applications, the Gwaith API and this website are business tools directed at organisations and their staff. They are not directed at minors, and Gwaith does not knowingly collect personal information from them. Accounts are created for and by the staff of client organisations.

If you believe that a minor has provided personal information to Gwaith, contact development@gwaith.co.nz and it will be deleted.

17. This website

This website collects personal information in one way only: through the contact form. The information collected is the name, email address, optional company name and message that you enter.

This website sets no cookies. It runs no analytics, no tracking, no advertising, no session recording and no third-party scripts, and it does not build a profile of visitors. Nothing on this website is loaded from an external origin.

Contact form submissions are delivered by email to Gwaith and are retained in the Gwaith inbox in accordance with normal correspondence retention. The IP address from which a submission was made is recorded in the body of that message so that abuse can be traced, and a salted hash of the same address is held briefly for the sole purpose of enforcing a submission rate limit. The hash is not reversible and is not used to identify or track visitors.

18. Changes to this policy

Gwaith may update this policy from time to time to reflect changes to the software, to the subprocessors it uses, or to the law. When it does, the revised policy is published at this address and the "Last updated" date at the top of the page is changed. Where a change materially affects how personal information is handled, Gwaith will take reasonable steps to notify affected clients and resellers.

This policy is effective from 8 September 2026. Your continued use of the applications, the Gwaith API or this website after a change is published constitutes acceptance of the updated policy. If you do not accept a change, stop using the services and contact Gwaith or your reseller.

19. Contact

For any privacy enquiry, access or correction request, or complaint about how Gwaith has handled personal information, contact:

GWAITH DEVELOPMENT LIMITED
NZBN 9429053840806
Mosgiel, New Zealand
development@gwaith.co.nz

Gwaith will acknowledge your enquiry and respond within the time frame required by the law that applies to you.