Privacy policy
Last updated: 8 September 2026
Effective date: 8 September 2026
1. Introduction and scope
GWAITH DEVELOPMENT LIMITED (NZBN 9429053840806) of Mosgiel, New Zealand ("Gwaith", "we", "us", "our") develops and operates business management software, including point-of-sale, ERP, inventory management and CRM applications, and the API integrations that connect them.
Gwaith is the agency responsible for the personal information it holds in its own right, and is accountable for that information under the Privacy Act 2020. For some information Gwaith processes on a client's instructions, Gwaith acts on that client's behalf rather than as the responsible agency; the United States subsection of section 13 explains how that affects a request about information of that kind. This policy explains what personal information Gwaith collects, why it is collected, how it is used, who it is shared with, where it is stored, how long it is kept, and what rights you have in relation to it.
This policy applies to:
- this website at gwaith.co.nz;
- the Gwaith API; and
- the client applications that Gwaith develops and operates, including the Boost AI assistant and the Auto-AP document processing feature.
Gwaith's software reaches end users through reseller partners. If you are an end user, your commercial relationship and your support relationship are with the reseller that licenses the software from Gwaith. Depending on the arrangement between Gwaith and that reseller, the reseller will ordinarily be a separate agency responsible for the personal information it holds about you, and in that case its own privacy policy applies to that information. This policy governs the personal information held by Gwaith in the systems Gwaith operates.
This policy does not cover third-party systems that a client chooses to connect to Gwaith software. Information held in those systems is governed by the privacy policy of the organisation that operates them.
2. Information we collect
The information Gwaith holds depends on which applications a client uses and how those applications are configured. It may include:
- Contact and identity information: names, postal addresses, physical addresses, phone numbers and email addresses of users, and of a client's own customers, suppliers and contacts where those records are entered into the applications.
- Authentication credentials: hashed passwords and hashed API tokens. Gwaith does not store passwords or API tokens in a form from which the original value can be recovered.
- Organisation and licensing data: the organisation a user belongs to, the licences held, licence entitlements, activation records and the reseller through which the licence was issued.
- User account data: usernames, roles, permissions, preferences, and records of activity within the applications such as sign-in times and changes made to records.
- Inventory and pricing data: product, stock, supplier and price list information held by a client in the applications.
- Financial performance data: sales, purchase, job costing and reporting data generated by a client's use of the applications.
- Uploaded documents: invoices, price lists and similar business documents that a user uploads for processing, together with the information extracted from them.
- Diagnostic logs: technical records generated automatically by the applications and the API, which may include user or account identifiers, IP addresses, timestamps, request details and error information.
- Correspondence: the content of enquiries sent to Gwaith, including submissions through the contact form on this website.
Gwaith does not collect or process payment card numbers or bank account details. No Gwaith system stores card numbers, card verification values, or bank account numbers. Where a client's own processes involve payment, that payment is handled by the client, the reseller, or a third-party provider outside the Gwaith software.
3. How we collect information
Gwaith collects personal information in three ways:
- Directly from users. Information that users enter into the applications, provide when an account is created, upload for processing, or send to Gwaith by email or through the contact form on this website.
- From resellers. Reseller partners provide the account, organisation and licensing information needed to provision and support a client's environment, including the contact details of the people who will administer it.
- Automatically through use of the applications and the API. Diagnostic logs, authentication records and operational telemetry are generated as a by-product of the software running. This information is produced by the systems themselves rather than supplied by a user.
4. How we use information
Gwaith uses personal information only for the following purposes:
- Service delivery. Operating, hosting and providing the applications and the API, and performing the functions a user asks the software to perform.
- Authentication and licence validation. Verifying who a user is, confirming that an organisation holds a valid licence, and enforcing the entitlements attached to that licence.
- Support and debugging. Investigating faults reported by a client or a reseller, reproducing and diagnosing errors, and restoring service.
- Product improvement. Understanding how the software behaves in production so that defects can be corrected and functionality improved. Where information is used for this purpose it is used in aggregate or in the narrowest form that answers the engineering question.
- Legal obligations. Meeting Gwaith's obligations under applicable law, responding to lawful requests, and establishing, exercising or defending legal claims.
Gwaith does not sell personal information. Gwaith does not trade, rent or license personal information to any third party for that party's own marketing purposes, does not disclose personal information in exchange for money or other valuable consideration, and does not use personal information for behavioural advertising.
5. The Gwaith API
The Gwaith API is internal. It is used by and between Gwaith applications and services to exchange data within the platform, and it is not exposed to third parties. Gwaith does not publish it, does not operate a public developer program for it, and does not issue credentials for it to organisations outside Gwaith.
This is separate from the third-party APIs that Gwaith software connects to, such as the RFMS, Xero and MYOB APIs. Those are operated by the third parties named in section 7, and Gwaith holds the developer agreement for each.
6. Artificial intelligence features
Some Gwaith applications include features that use artificial intelligence. The Boost AI assistant answers questions about a client's own data in the application, and the Auto-AP feature extracts structured information from uploaded invoices and price lists. The commitments below apply to every one of these features.
- Processing occurs entirely within Microsoft Azure, using Azure OpenAI Service and Azure AI Document Intelligence.
- The public ChatGPT product and the open OpenAI API are not used. No data is sent to either.
- Processing occurs within dedicated Gwaith resources. The Azure OpenAI Service and Azure AI Document Intelligence resources used are provisioned to and controlled by Gwaith.
- Customer data is never used to train models. No client information is used to train, fine-tune or otherwise adjust any model.
- Content is not shared with OpenAI, is not used to improve any model, and is not made available to other Microsoft customers.
- Data is used only to perform the requested task, and for no other purpose.
- All communication is encrypted using HTTPS/TLS, between the applications, the API and the Azure AI services.
- Access credentials are held in Azure Key Vault and are never embedded in the application.
- Boost AI assistant conversations are permanently deleted 24 hours after the last activity in the conversation. The deletion window is measured from the most recent message in a conversation, not from when the conversation began, and it restarts each time the conversation is continued. A conversation carried on over several days therefore remains available over those days and is permanently deleted 24 hours after its final message.
- Uploaded invoices and price lists are deleted within 90 days. The information extracted from them remains available in the Auto-AP records and in the client's accounting system.
- Data exported from the Boost AI assistant is deleted within 90 days.
7. Third-party services and subprocessors
Gwaith uses the third parties listed below to host, operate and integrate its software. Each is engaged to provide a defined service, receives only the information required for that service, and is not permitted to use it for its own purposes.
| Subprocessor | Purpose | Location |
|---|---|---|
| Microsoft Azure (Microsoft Corporation) | Application hosting, databases, AI services, secrets management | Australia East, US Central, West US 2 |
| Twilio SendGrid (Twilio Inc.) | Transactional email from Gwaith applications | United States |
| Azure Communication Services (Microsoft Corporation) | Website contact form email delivery | United States, the data location set for the Communication Services resource serving this website and its API (see section 9) |
| Cyncly (RFMS Inc; Consilio Midco Limited) | RFMS ERP integration via the RFMS API | Operated by Cyncly |
| Xero Limited | Accounting integration via the Xero API | Operated by Xero Limited |
| MYOB NZ Limited; MYOB Australia Pty Ltd | Accounting integration via the MYOB API | Operated by MYOB NZ Limited; MYOB Australia Pty Ltd |
Where information is transmitted to a third party listed above, that third party's own privacy policy governs its handling of the transmitted data. This applies in particular to the integration rows: information sent to the RFMS, Xero or MYOB APIs at a client's direction is thereafter held by Cyncly, Xero Limited or MYOB under their own terms and privacy policies, and Gwaith does not control its retention or use in those systems.
8. Non-affiliation
Gwaith Development Limited is an independent company. Gwaith is not affiliated with, endorsed by, or a subsidiary of Cyncly (Consilio Midco Limited), Xero Limited, MYOB NZ Limited, or any of their affiliated companies. Where Gwaith software integrates with a third-party system, it does so through that party's published API under the applicable developer agreement, and nothing in that arrangement should be read as a partnership, endorsement or joint venture.
RFMS Australasia Limited, a reseller partner of Gwaith Development Limited, is a separate company from RFMS Incorporated and the Cyncly group of companies. The statement of non-affiliation above concerns RFMS Incorporated and the Cyncly group of companies, not RFMS Australasia Limited.
All product names, brand names and trademarks referred to in this policy or in Gwaith software are the property of their respective owners, and are used only to identify the systems concerned.
9. Data storage and location
Client data is stored in Microsoft Azure, in either the Azure Australia East region or the Azure US Central region. The region for a given client is selected according to that client's location and data residency requirements.
This website and its API run in the Azure West US 2 region.
Gwaith also operates its own servers in New Zealand data centres. Those servers host internal engineering infrastructure only, such as source control, build and internal tooling. They do not hold end-user personal information.
The statements above describe deployments hosted by Gwaith. Where software developed by Gwaith is deployed on infrastructure that a client owns or controls, whether self-hosted by the client or run on-premises, the data held in that deployment resides on the client's own infrastructure and not on infrastructure operated by Gwaith. Gwaith does not hold or store that data, and the client is the agency responsible for it.
10. Data security
Gwaith applies the following measures to protect the personal information it holds in the systems it operates. Where software developed by Gwaith is deployed on infrastructure that a client owns or controls, the client is responsible for the security of that infrastructure and of the data held on it.
- Encryption in transit. All traffic between users, the applications, the Gwaith API and the underlying Azure services is encrypted using TLS.
- Encryption at rest. Databases, storage accounts and backups are encrypted at rest.
- Organisation-scoped access control. Data is partitioned by organisation, and application requests are authorised against the requesting user's organisation and role so that a user can reach only the data belonging to their own organisation.
- Secrets management. Connection strings, API keys and service credentials are held in Azure Key Vault. They are not embedded in application code, configuration files or source control.
- Restricted personnel access. Access to production systems and client data is limited to the Gwaith personnel who require it to operate and support the software, and is granted only for as long as that need exists.
- Password and token handling. Passwords and API tokens are stored only as hashes.
No system can be guaranteed to be completely secure. Gwaith maintains these controls and reviews them, but cannot warrant that a security incident will never occur. If a privacy breach occurs that is likely to cause serious harm, Gwaith will notify the Office of the Privacy Commissioner and the affected individuals as required by the Privacy Act 2020, and will also notify the affected client and its reseller without undue delay.
11. How long we keep information
This section describes how long Gwaith retains data in deployments it hosts; where software developed by Gwaith is deployed on infrastructure that a client owns or controls, retention of the data held on that infrastructure is the client's responsibility.
Retention depends on the category of information:
- Boost AI assistant conversations: permanently deleted 24 hours after the last activity in the conversation. The window is measured from the most recent message and restarts whenever the conversation is continued, so a conversation held over several days persists for those days and is deleted 24 hours after its final message.
- Uploaded invoices and price lists: deleted within 90 days. The information extracted from them remains available in the Auto-AP records and in the client's accounting system.
- Data exported from the Boost AI assistant: deleted within 90 days.
- Account, organisation and licensing data: retained for as long as the account and licence remain active, and afterwards only for as long as needed to meet legal, accounting and audit obligations.
- Client business records (inventory, pricing, financial performance and related data): retained for as long as the client's environment is active. On termination the data is dealt with in accordance with the agreement in place with the client or its reseller.
- Diagnostic logs: retained for a limited operational period sufficient for fault diagnosis, security monitoring and capacity planning, then deleted.
- Contact form submissions and correspondence: delivered by email and retained in the Gwaith inbox in accordance with normal correspondence retention.
- Rate-limiting records for this website: a salted hash of the submitting IP address, held only for the short period needed to enforce the rate limit.
Where Gwaith no longer needs personal information for any purpose for which it may lawfully be used, it is deleted or de-identified.
12. Disclosure of personal information
Gwaith discloses personal information only in the following circumstances:
- To subprocessors. To the third parties listed in section 7, for the purposes stated there.
- To resellers. To the reseller partner responsible for a client's account, to the extent needed to provision, license and support that account.
- At a client's direction. To third-party systems that a client connects to Gwaith software, such as an accounting or ERP platform, where the client has configured that integration.
- Where required by law. Where disclosure is required or authorised by law, by a court order, or by a lawful request from a regulator or law enforcement agency, or where disclosure is necessary to prevent or lessen a serious threat to life, health or safety.
- On a business transfer. If Gwaith is involved in a merger, acquisition, reorganisation or sale of assets, personal information may be transferred as part of that transaction. Any recipient would be required to handle it in a manner consistent with this policy, and Gwaith would update this policy to reflect any change in the responsible agency.
13. Your rights
The rights available to you depend on where you are located. In every case, you may exercise your rights by emailing development@gwaith.co.nz. Gwaith may need to verify your identity before acting on a request, and may ask for additional information for that purpose. Gwaith does not charge a fee for responding to a request except where the applicable law permits a charge, in which case you will be told the amount and the reason before any cost is incurred. If you are an end user of software supplied by a reseller, Gwaith may need to work with that reseller to locate and act on your information, and will tell you where your request has been directed.
New Zealand
Under the Privacy Act 2020 you have the right to ask whether Gwaith holds personal information about you, to request access to that information, and to request correction of it. If Gwaith declines a request, it will tell you the reasons to the extent the Privacy Act 2020 requires, and explain your right to complain. If correction is declined, you may ask that a statement of the correction sought be attached to the information.
If you are not satisfied with how Gwaith has handled your information or your request, you may complain to the Office of the Privacy Commissioner, which may investigate the matter.
Australia
Under the Privacy Act 1988 and the Australian Privacy Principles you have the right to request access to the personal information Gwaith holds about you, to request correction of information that is inaccurate, out of date, incomplete, irrelevant or misleading, and to be told how Gwaith handles your information. You may also deal with Gwaith anonymously or under a pseudonym where it is lawful and practicable to do so.
If you are not satisfied with Gwaith's response to a request or a complaint, you may complain to the Office of the Australian Information Commissioner.
United States
If you are a resident of a state with a comprehensive privacy statute, including California under the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), Virginia under the Virginia Consumer Data Protection Act (VCDPA), and Colorado under the Colorado Privacy Act (CPA), you have the following rights:
- The right to know what categories of personal information Gwaith has collected about you, the purposes for which it is used, and the categories of third parties it is disclosed to.
- The right to access the specific pieces of personal information Gwaith holds about you, and to receive them in a portable form where required.
- The right to delete personal information Gwaith holds about you, subject to the exceptions the applicable statute allows, such as information Gwaith must retain to comply with a legal obligation or to complete a transaction requested by a client.
- The right to correct inaccurate personal information Gwaith holds about you.
- The right to opt out of the sale or sharing of personal information. Gwaith does not sell personal information and does not share it for cross-context behavioural advertising, so there is nothing to opt out of. This policy will be updated if that position ever changes.
- The right to non-discrimination. Gwaith will not deny service, charge a different price, or provide a different level of service because you have exercised a privacy right.
Where Gwaith processes personal information on behalf of a client, Gwaith acts as a service provider or processor. In that case Gwaith will refer your request to the client responsible for the information, or act on that client's instructions, and will tell you where your request has been directed.
14. Cross-border transfer of information
Gwaith operates internationally. Personal information may be transferred to, stored in, and accessed from Australia, the United States, and other Microsoft Azure regions used to operate the services described in this policy. The countries in which those regions are located may have data protection rules that differ from those of the country in which you are located, and in some cases those rules may offer a lower standard of protection.
Where information is transferred, Gwaith takes reasonable steps to ensure that it remains subject to protections comparable to those required by the Privacy Act 2020, including through the contractual terms Gwaith holds with the subprocessors listed in section 7. By using the applications or the API, you acknowledge that your information may be transferred and stored as described in this section and in section 9.
15. Sensitive information
The Gwaith applications are business management tools and are not designed to hold sensitive information. You must not submit sensitive information to Gwaith or enter it into the applications. Sensitive information means information of a kind treated as sensitive under the applicable statutes, including health and medical information, biometric and genetic information, racial or ethnic origin, political opinions or affiliations, religious or philosophical beliefs, trade union membership, sexual orientation, criminal records, precise geolocation, and government identifiers such as passport, driver licence, tax or social security numbers.
If sensitive information is submitted despite this, Gwaith will delete it once it becomes aware of it, unless it is required by law to retain it. Gwaith does not seek, request or knowingly process sensitive information.
16. Use by minors
The Gwaith applications, the Gwaith API and this website are business tools directed at organisations and their staff. They are not directed at minors, and Gwaith does not knowingly collect personal information from them. Accounts are created for and by the staff of client organisations.
If you believe that a minor has provided personal information to Gwaith, contact development@gwaith.co.nz and it will be deleted.
17. This website
This website collects personal information in one way only: through the contact form. The information collected is the name, email address, optional company name and message that you enter.
This website sets no cookies. It runs no analytics, no tracking, no advertising, no session recording and no third-party scripts, and it does not build a profile of visitors. Nothing on this website is loaded from an external origin.
Contact form submissions are delivered by email to Gwaith and are retained in the Gwaith inbox in accordance with normal correspondence retention. The IP address from which a submission was made is recorded in the body of that message so that abuse can be traced, and a salted hash of the same address is held briefly for the sole purpose of enforcing a submission rate limit. The hash is not reversible and is not used to identify or track visitors.
18. Changes to this policy
Gwaith may update this policy from time to time to reflect changes to the software, to the subprocessors it uses, or to the law. When it does, the revised policy is published at this address and the "Last updated" date at the top of the page is changed. Where a change materially affects how personal information is handled, Gwaith will take reasonable steps to notify affected clients and resellers.
This policy is effective from 8 September 2026. Your continued use of the applications, the Gwaith API or this website after a change is published constitutes acceptance of the updated policy. If you do not accept a change, stop using the services and contact Gwaith or your reseller.
19. Contact
For any privacy enquiry, access or correction request, or complaint about how Gwaith has handled personal information, contact:
GWAITH DEVELOPMENT LIMITED
NZBN 9429053840806
Mosgiel, New Zealand
development@gwaith.co.nz
Gwaith will acknowledge your enquiry and respond within the time frame required by the law that applies to you.