Cata1yst AI Limited · NZBN 9429052486951 · New Zealand

Privacy
statement.

What we hold, where it sits, who else can see it, and what you can ask us to do about it. Written to be read, not to be survived.

Last updated 17 August 2026

01

The short version

We are an AI consultancy. To do our work we end up holding a lot of information about our clients, their staff, and the people they deal with. This statement explains what we hold, where it sits, who else can see it, and what you can ask us to do about it.

Three things worth knowing before the detail:

  1. Most of our systems run on a machine we own. Your documents, emails and notes are not sitting in someone else's cloud product by default. They are on our own server.
  2. We use AI services, and that means some of your information is sent to them. We say exactly which ones below. We do not think you should have to guess.
  3. You can ask us what we hold about you, ask us to correct it, and ask us to delete it. Details at the end.

This statement is written to be read, not to be survived. If anything in it is unclear, ask us and we will explain it.

02

Who this covers

If you are…This statement covers
A visitor to our websiteWhat the site collects while you browse it
Someone who contacts us or fills in a formWhat you send us and what we do with it
A subscriber to Field Notes, our newsletterHow you got on the list and how to get off it
A clientThe business information and personal information we hold to deliver your work
Someone who works at a clientInformation about you that reached us through your employer
Someone in a meeting we recordedRecordings and transcripts
03

What we collect, and why

From our website

Our website runs on Squarespace, and we use Google Analytics to see how many people visit and which pages they read. This uses cookies: small files a website stores in your browser so it can recognise the same visitor across pages.

What we get from this is counts and patterns: how many visitors, which pages, roughly where in the world. We do not use it to identify you personally, and we do not sell it. You can block cookies in your browser settings and the site will still work.

We also use Google Search Console, which tells us which search terms bring people to the site. That data reaches us already grouped. We never see who searched.

When you contact us or fill in a form

If you email us at talk@cata1ystai.com, use the Talk to a Human form on our site, or complete one of our surveys, we get whatever you put in it: typically your name, email address, business, and what you wrote.

We use it to reply to you, to do the work you asked for, and to keep a record of the conversation. Nothing more.

Our newsletter

Field Notes goes only to people who signed up for it themselves. Every issue has an unsubscribe link, and it works immediately. We do not buy lists and we do not add people who did not ask.

The list is held in Kit, an email platform based in the United States.

Staff surveys at client businesses

A lot of our work starts with a survey of a client's team. These are anonymous, and we mean it literally.

We do not collect names or email addresses in them. We have been asked directly by a client whether we could work out who gave a particular answer, and the answer was no, and stays no. If we ever need to run a survey that is not anonymous, we will say so on the survey itself, before you answer it.

Survey responses are collected through Tally, a form platform based in Belgium.

Meetings

We record and transcribe some meetings using Fireflies, so we have an accurate record of what was agreed rather than relying on memory and notes.

The recorder joins as a visible participant and is announced. If you would rather a meeting was not recorded, say so and we will turn it off, before the meeting or during it. No explanation needed.

Recordings and transcripts are used to write up what was discussed, produce actions, and inform the work. They are not shared outside Cata1yst AI without your agreement, and they are not used to train anyone's AI models.

You can have a recording deleted. Ask us and we will delete it. Deletion in Fireflies is immediate and cannot be undone, so once it is gone it is genuinely gone. You do not need to give a reason.

Client business information

This is the largest category by far, and the most important one to be clear about.

Delivering our work means we accumulate: your emails to us, documents you send us, transcripts of our meetings, notes we write about your business, and the records of what we built and why. Inside that sits information about real people: your staff, your customers, your suppliers.

We hold this to do the work you engaged us for, and for no other purpose.

Access into your own systems

For some engagements you give us an account inside your own systems: typically a named login that you create, protected by multi-factor authentication, which is an extra verification step beyond a password.

This arrangement is deliberate and it matters:

  • The account is yours, not ours. It is created under your organisation, sits under your administration, and you can see what it does.
  • You can switch it off at any time, without going through us. Removing our access is something you do, not something you have to ask for.

Information we get about you from someone else

Sometimes we learn about a person from their employer rather than from the person themselves. A client tells us who does what, or a name appears in a document sent to us.

Since 1 May 2026, New Zealand law (a rule called IPP 3A) requires us to take reasonable steps to make sure people know when we have collected their information this way. This statement is part of how we do that. If you work at one of our clients and want to know what we hold about you, you are entitled to ask us directly. See Your rights below.

04

Where your information is held

Most of it is on our own server, in New Zealand. We run a machine called ctrl1 that holds our operating systems, our knowledge index, our client records, and our database. It is not reachable from the open internet. It answers only to a private network our team connects through.

That is unusual for a business our size, and it is a deliberate choice. It means your information is not spread across a dozen vendor clouds by default.

Backups. We take nightly backups and copy them off the machine, because a backup sitting on the same disk as the thing it protects is not a backup. Those copies are encrypted before they leave, using a method where the key needed to unlock them is deliberately not kept on the server. Even someone with full access to our machine cannot read our backups from it. The encrypted copies are stored in a private repository on GitHub.

05

Who else can see your information

We use outside services to run the business. Each one below can see some category of your information. We have listed what each actually touches rather than giving a generic list.

ServiceWhat it handlesBased in
Google WorkspaceOur email, calendar, and file storageUnited States
Anthropic (Claude)AI assistance across our work, including drafting and analysisUnited States
OpenAIPowers the search inside our knowledge index (see below)United States
FirefliesMeeting recording and transcriptionUnited States
SlackOur internal team messagingUnited States
Make.comRuns automations, including ones built for clientsEuropean Union
XeroInvoicing and accountsNew Zealand company; data hosted offshore
PandaDocAgreements and electronic signaturesUnited States
TallySurveys and formsBelgium
KitOur newsletterUnited States
SquarespaceOur website and domainUnited States
GitHubStores our encrypted backupsUnited States
LovableHosts applications we build for clientsSweden
SupabaseDatabases behind those applicationsUnited States
VercelHosts some client applicationsUnited States

Being offshore is not a loophole. Under New Zealand law we remain responsible for your information wherever it is processed. Sending it to an overseas provider does not transfer that responsibility away from us.

We do not sell your information, and we do not share it for anyone else's marketing.

One thing we do reuse, and it is in your agreement. We learn things doing this work: what approaches succeed, where projects stall, what a good process looks like. We use those general lessons to get better at our job. What we never reuse is anything that identifies you: no client names, no staff names, no figures, no documents. If a lesson cannot be told without naming you, we do not tell it without asking you first.

06

AI, specifically

This is the part most people actually want to know, so it gets its own section.

What goes to an AI service. Our knowledge index lets us search across our own email, documents and meeting transcripts. When we run a search, the system sends parts of the documents it finds to OpenAI in order to work out what is relevant. So a search across our records may send extracts of your correspondence to OpenAI. We also use Claude, from Anthropic, throughout our work, which means the same class of material passes through it.

What does not. The step that converts documents into a searchable form runs on our own machine, using a model installed locally. That processing does not leave our server.

Processed is not the same as stored, and we think you should have both numbers. When information is sent to an AI service, most of the time it is used to produce an answer and then discarded, but "discarded" usually means "kept briefly, then deleted", not "gone the instant it arrives". Here is what each provider actually does:

ProviderHow long they hold itUsed to train their models?
OpenAIUp to 30 days, for detecting misuse of their service, then deletedNo, not for information sent through their business interface
Anthropic (Claude)30 days, then deletedNo, we keep model training switched off
FirefliesMeeting content is not retained by the outside services that process itNo

So the honest summary is: extracts of your information can sit in a provider's misuse-detection logs for up to a month before being deleted. That window is real, it is short, and it is not the same as them keeping your data.

We keep model training switched off. Our Claude subscriptions carry a setting controlling whether conversations may be used to help improve Anthropic's models. We keep that setting off, on every account. With it off, conversations are held for 30 days and then deleted, and are not used to train anything.

We check this rather than assume it, because it is a per-account setting that can be on by default, and the same setting applies to every session our team runs, including the ones that read client correspondence.

Judgement stays human. AI drafts and analyses. It does not decide anything about you. Nothing AI-generated goes to a client or a third party without a person at Cata1yst reading it first.

07

When our work involves decisions about people

Some of our clients are HR and recruitment businesses, and some of what we build for them touches processes about individuals: summarising a phone screening with a candidate, or preparing the paperwork for an employment meeting.

We treat this as the most sensitive work we do, and we hold three rules on it.

A named person decides. Always. Our tools summarise, draft and organise. They do not decide whether someone gets a job, keeps a job, or faces a process. A human at the client makes every decision about a person, and nothing we build changes that.

Nothing AI-drafted reaches anyone without a person reading it first. No automated output goes to a candidate, an employee or a third party unreviewed.

If a process involved you, you can ask us about it. If you were a candidate or an employee in a process one of our tools touched, you are entitled to ask us what we hold about you and to have it corrected. You do not have to go through your employer or the recruiter to ask us. See Your rights below.

08

Sensitive information

Some information deserves more care than the rest: health and medical details, disciplinary matters, criminal history, financial hardship.

We try not to hold any of it. Where our work involves documents that contain this kind of information, our practice is to strip the personal details out before the document goes into any of our systems, so what we keep is the shape and structure of the document, not the person it was about.

This is a working rule with a real edge to it, and it is worth being plain about why it exists: a document supplied as an example of good practice is still a real document about a real person until somebody deliberately makes it not one. Treating the two as the same thing is exactly how sensitive information ends up somewhere it should never be. So the stripping is a deliberate step someone performs, not an assumption.

If you believe we hold sensitive information about you, tell us and we will find it and remove it.

09

Automations we run for clients

Where we build automations (processes that move information between systems without someone doing it by hand), these currently run in our own Make.com account, not yours.

That means your information passes through a platform we control rather than one you control, and you should know two things about it:

  • The platform keeps a record of each run, including the information that passed through it, for up to 30 days by default. This is normal for automation platforms and it exists so failures can be diagnosed.
  • We can shorten or switch that off, and where an automation handles sensitive information we will.

If you would rather automations ran in your own account so the data never rests with us, say so. That is a reasonable thing to want, and it is arrangeable.

10

Applications and databases we build

Some of our work is building actual software: a web application, the database that sits behind it, or both. We build these on Lovable, Supabase, Vercel and occasionally Airtable.

These are not demonstrations. They hold real information about real people: job applicants and their CVs, customers, service records, product data. One of them has taken well over a thousand visitors and several hundred job applications.

Whose account they sit in varies, and it matters. An application built quickly to prove an idea usually starts in ours. One you run your business on should sit in yours. We will tell you which yours is in, and moving it to your own account is something you can ask for at any time.

Our commitment on these, plainly stated. Before an application we built holds real information about real people at any scale, we check its access controls: who can read what, and whether uploaded files such as CVs and recordings are protected rather than simply sitting at a web address. Where we find a gap, we fix it, and we tell you it existed.

We make that commitment specifically because an application that began as a quick prototype and quietly became the thing a business runs on is the case that goes wrong. Prototypes are built for speed. Speed and access control pull against each other. The moment real people's information goes in, the prototype has to be held to a different standard, and that transition is easy to miss from the inside.

Young people. Some recruitment work we support involves school leavers, which means we sometimes handle information about people under 18, including video they record of themselves. We treat that as deserving more care, not less: tighter access, shorter retention, and a higher bar before anything is shared.

11

How long we keep it

We keep your information for as long as we are working with you.

If you ask us to delete it, we will. Write to us and we will remove what we hold from our live systems within 30 days, and confirm when it is done.

Two honest limits on that:

  • Some records we must keep. Financial records (invoices, payments, agreements) have to be retained for seven years under New Zealand tax law. We cannot delete those on request, and neither can anyone else.
  • Backups are not deleted individually. Our backups are encrypted snapshots that roll forward over time. Deleting one person's information from inside a historic encrypted snapshot is not something the format allows. Those snapshots age out on their own cycle, and nothing is restored from them except in an actual disaster.

We would rather tell you this than promise a clean deletion we cannot deliver.

When an engagement ends. For the working material that sits on our side (the automations, the notes, the examples we used to build with), you can ask us to hand it over, delete it, or both, and we will do it within 30 days of the request.

We will be straight with you about the status of that commitment: we are a young company and no engagement where we built something has ended yet. So this is what we will do, described in advance, rather than a process we have run many times. We would rather write it down now, while nobody is upset, than improvise it later.

12

Keeping it secure

What we do:

  • The server holding your information is not exposed to the public internet.
  • Backups are encrypted with a key that is not stored on the machine being backed up.
  • Access to client systems is through accounts you create and can revoke.
  • Our team is small, which means the list of people who can reach your information is short and known.

What we do not claim. We are a two-person company, not a bank. We hold no security certification, we have not been independently audited, and we do not claim our systems are impenetrable. Anyone who tells you their systems cannot be breached is selling something.

What we can tell you is that we treat this seriously, we know where our weak points are, and we work on them.

If something goes wrong. If we have a privacy breach that is likely to cause serious harm, New Zealand law requires us to notify both the Office of the Privacy Commissioner and the people affected, as soon as we can. We will do that. We will also tell you what happened and what we did about it, rather than the minimum the law requires.

13

Your rights

Under the Privacy Act 2020 you can:

RightWhat it means
AccessAsk us what personal information we hold about you, and get a copy
CorrectionTell us something we hold is wrong, and have it fixed
DeletionAsk us to delete what we hold, subject to the limits above
ComplaintRaise a concern about how we have handled your information

These rights are yours personally. You do not need to be our client to use them. If you work at a client business, or you were in a meeting we recorded, you can ask us directly.

To make a request, email us at the address below. We will respond as soon as we can, and within 20 working days at the latest. There is no charge.

14

Contact, and complaints

Our privacy officer is Jack Hellier.

Emailjack@cata1ystai.com

Post239 Irwin Road, Kings Seat, Auckland

If you are not happy with how we have handled a privacy issue, please raise it with us first. We would rather fix it than have you go elsewhere unhappy. If we cannot resolve it, you can complain to:

Office of the Privacy CommissionerWebsite: privacy.org.nz
Phone: 0800 803 909

Complaining to them is free, and you do not need a lawyer.

15

Changes to this statement

If we change how we handle information, we will update this statement and change the date at the top. Where a change is significant (a new AI provider, a new category of information), we will tell clients directly rather than relying on you noticing.

Cata1yst AI Limited · NZBN 9429052486951 Last updated 17 August 2026