Taylor Consulting

Privacy Policy

Version
1.0
Status
In force
In force
28 August 2026

This Privacy Policy sets out how Taylor Consulting, a sole trader business operated by Zavier Taylor of Christchurch, New Zealand ("Taylor Consulting", "we", "us") collects, uses, discloses, stores and protects personal information.

It is written to comply with the Privacy Act 2020 (NZ) and the Information Privacy Principles. Where this policy and the Privacy Act differ, the Act prevails.

1.Interpretation

  1. 1.1

    In this policy, unless the context requires otherwise:

    1. (a)“Client” means a business or organisation that engages Taylor Consulting to provide services.
    2. (b)“Client Data” means any material a Client provides to us, or to a system we build or maintain, including documents, correspondence, records and files, and any personal information contained in them.
    3. (c)“Personal information” has the meaning given in the Privacy Act 2020.
    4. (d)“the System” means any software, model or machine supplied, configured or maintained by Taylor Consulting for a Client.
  2. 1.2

    This policy distinguishes throughout between personal information we collect about you directly (as a website visitor or an enquirer) and Client Data we handle on a Client's behalf. Different obligations attach to each, and sections 6 to 8 deal with Client Data specifically.

2.Information we collect

  1. 2.1

    From website visitors and enquirers, we may collect: your name; your email address; your telephone number; the name of your organisation; and the content of any message or booking request you send us.

  2. 2.2

    We do not operate advertising, tracking or behavioural analytics on this website, and we do not use third-party analytics services. No cookie is set for the purpose of tracking you.

  3. 2.3

    Where you book a call through a third-party scheduling service, that service collects the information you enter into it, under its own privacy terms. We receive only the resulting booking details.

  4. 2.4

    In the course of an engagement, we may collect Client Data and the contact details of a Client's staff for the purpose of operating and supporting the System.

3.How we collect information

  1. 3.1

    We collect information directly from you, from a Client, or from a Client's staff, in each case where it is provided to us for a purpose connected with our services.

  2. 3.2

    We do not purchase personal information, and we do not collect it from data brokers or by scraping.

4.Purposes for which we use information

  1. 4.1

    We use personal information only for purposes connected with providing our services, namely: responding to enquiries; preparing proposals; delivering, configuring, supporting and maintaining the System; invoicing; and meeting our legal obligations.

  2. 4.2

    We do not use personal information for marketing to you unless you have asked to receive it, and any such communication will carry a means of unsubscribing.

  3. 4.3

    We do not sell personal information or Client Data to anyone, in any circumstances.

5.Client Data and confidentiality

  1. 5.1

    Client Data belongs to the Client. We claim no ownership of it and acquire no right to use it for any purpose other than performing the engagement.

  2. 5.2

    We treat Client Data as confidential. We do not disclose it to any third party except as required by law, or with the Client's prior written instruction.

  3. 5.3

    Where an engagement involves documents subject to legal professional privilege or an equivalent professional obligation, we will say so in writing in the proposal and handle those documents on the terms recorded there.

  4. 5.4

    We access Client Data only to the extent necessary to deliver, support or repair the System, and each such access is logged.

6.Training models on Client Data

  1. 6.1

    This section exists because training a model on a Client's documents is a different act from processing them, and is treated separately.

  2. 6.2

    We will not use Client Data to train, fine-tune or otherwise adapt any model without the Client's specific, informed and written consent.

  3. 6.3

    Consent is sought for an identified purpose and an identified set of documents. It is not general, it is not implied by the engagement, and it is not obtained by a clause in a services agreement.

  4. 6.4

    Where consent is given, we will record in writing: the documents used; the purpose; where training took place; and what becomes of the training dataset afterwards.

  5. 6.5

    An adapter trained on a Client's documents is used only for that Client. It is never applied to another Client's System, offered to anyone else, or incorporated into a general-purpose product.

  6. 6.6

    Any adapter trained on a Client's Client Data is the Client's property. See clause 9 of our Terms of Service.

  7. 6.7

    A Client may withdraw consent for future training at any time. Withdrawal does not reverse training already completed, because a trained adapter cannot be selectively unlearned, but the adapter will be deleted on request, and we will say so plainly rather than implying otherwise.

7.Where processing occurs

  1. 7.1

    Where we supply an on-premise System, Client Data is processed on the Client's own machine, on the Client's own premises. It is not transmitted to us and it is not transmitted to any artificial intelligence provider.

  2. 7.2

    A System configured in this way has no outbound network path to any artificial intelligence provider. This is a configuration of the System, not merely a policy commitment, and the System provides a facility by which the Client can verify it.

  3. 7.3

    Software updates are retrieved from a container registry over the internet. This is outbound traffic, and it is disclosed here so that the statement in clause 7.2 is not misunderstood as meaning the machine has no internet connection at all. A container registry is not an artificial intelligence provider and no Client Data is sent to it.

  4. 7.4

    Where a Client elects a configuration in which some requests are referred to an external model provider, that is a material change to clause 7.1 and 7.2. It will be documented in the proposal, the Client's consent recorded in writing, and the categories of data that leave the premises identified before the configuration is enabled.

  5. 7.5

    Personal information we hold about enquirers and Clients' staff (names, email addresses, correspondence) is held by us in New Zealand and, where a service provider is used, as set out in clause 10.

8.Tools you already subscribe to

  1. 8.1

    Some engagements involve configuring an artificial intelligence tool the Client already subscribes to in its own name, rather than supplying a System. The whole of clause 7 concerns on-premise Systems and does not apply to such a tool.

  2. 8.2

    To build a configuration we may be given templates, standards, worked examples and sample documents. That material is Client Data and every protection in this policy applies to it.

  3. 8.3

    Once the configuration is in place, what the Client's staff enter in the ordinary use of the tool is transmitted to its operator under the Client's own agreement with that operator. It does not pass through us and we do not receive, hold or retain it.

  4. 8.4

    What that operator does with such material, including whether it retains it or uses it to train its models, is governed by its terms and not by this policy. We will identify the operator and point the Client to its current terms before configuration begins, and we will say plainly where in our assessment those terms are unsuitable for a category of the Client's work.

  5. 8.5

    We will advise in writing on the categories of information that in our assessment should not be entered into such a tool. That advice is a recommendation, and responsibility for what is entered remains with the Client.

9.Disclosure to third parties

  1. 9.1

    We use a small number of service providers in operating our own business: an email provider; a website host; a scheduling provider; and an invoicing and tax provider. Each has access only to the information necessary for its function.

  2. 9.2

    We will provide a current list of these providers to any Client on request.

  3. 9.3

    We do not engage sub-contractors on a Client engagement without the Client's prior written agreement.

  4. 9.4

    We may disclose information where required by law, by a court, or by a regulator with jurisdiction. Where we are permitted to tell the affected party that we have done so, we will.

10.Overseas transfer

  1. 10.1

    Some of the service providers in clause 9.1 store information outside New Zealand. Before disclosing personal information to such a provider we take reasonable steps to satisfy ourselves that it is subject to comparable safeguards to those in the Privacy Act 2020, as Information Privacy Principle 12 requires.

  2. 10.2

    Client Data held on an on-premise System does not leave New Zealand, because it does not leave the Client's premises.

11.Security

  1. 11.1

    We take reasonable technical and organisational measures to protect information against loss, misuse and unauthorised access, having regard to its sensitivity.

  2. 11.2

    We do not claim certification against any information security standard, and nothing in this policy should be read as such a claim.

  3. 11.3

    Where we hold credentials for a Client's System, they are held in a password manager and are not shared by email or message.

12.Retention and destruction

  1. 12.1

    We keep personal information only as long as it is needed for the purpose it was collected for, or as long as we are required by law to keep it.

  2. 12.2

    Enquiries that do not proceed to an engagement are deleted within twelve months.

  3. 12.3

    Copies of Client Data taken for the purpose of building or repairing a System are deleted when that work is complete, and in any event within thirty days of the engagement ending, unless the Client asks in writing that we retain them.

  4. 12.4

    Records we are required to keep for tax purposes are retained for seven years, as the Inland Revenue Department requires.

13.Remote access

  1. 13.1

    Where remote access to a Client's System is available, it is disabled by default.

  2. 13.2

    It is enabled by the Client, for a period the Client determines, and it may be disabled by the Client at any time without reference to us.

  3. 13.3

    Every remote session is logged, and the log is visible to the Client.

14.Privacy breaches

  1. 14.1

    If a privacy breach occurs that it is reasonable to believe has caused, or is likely to cause, serious harm, we will notify the Office of the Privacy Commissioner and the affected individuals as soon as practicable, as Part 6 of the Privacy Act 2020 requires.

  2. 14.2

    Where the breach concerns Client Data, we will notify the Client immediately on becoming aware of it, before and independently of any other notification, and we will not delay that notification in order to complete our own investigation.

15.Access and correction

  1. 15.1

    You have the right to ask what personal information we hold about you, to be given access to it, and to ask us to correct it. These rights are given by Information Privacy Principles 6 and 7.

  2. 15.2

    Requests should be made to the address in clause 18. We will respond within twenty working days.

  3. 15.3

    We do not charge for access or correction requests.

16.Complaints

  1. 16.1

    If you believe we have not met our obligations under the Privacy Act 2020, please raise it with us first, using the contact details in clause 18.

  2. 16.2

    If you are not satisfied with our response, you may complain to the Office of the Privacy Commissioner at privacy.org.nz.

17.Amendments

  1. 17.1

    We may amend this policy. The version number and date at the head of this document identify the current version.

  2. 17.2

    Where an amendment materially reduces the protections given to a Client, we will notify that Client in writing rather than relying on publication of the amended policy.

18.Contact

  1. 18.1

    Privacy enquiries, access requests and complaints may be sent to zavier@thelongwhitecloud.com, or by post to Taylor Consulting, Christchurch, New Zealand.