This policy explains what personal information Kaha Tahi Ltd ("the Company", "we", "us") collects, why, how it is used and protected, and what rights individuals have, in connection with Kaha Tahi Accounts, our accounting and payroll web application at accounts.kahatahi.co.nz, used by Kaha Tahi Ltd itself and by other New Zealand small businesses as customers ("Customers"), and the employees of those Customers, whose payroll information is entered into the application by their employer ("Employees").
This policy is prepared to comply with the New Zealand Privacy Act 2020, including the Information Privacy Principles (IPPs).
About Customers (business owners/administrators using the software):
About Employees (where a Customer uses the payroll module):
Bank transaction data: with a Customer's explicit consent, we receive read-only bank transaction data through an accredited open banking intermediary (Akahu, and/or Fiskil for CDR-regulated connections) — never the Customer's online banking password or credentials directly.
We do not collect special categories of information beyond what is listed above, and we do not use cookies or third-party trackers for advertising or analytics purposes — the application uses only the technical session token (a signed JWT) needed to keep a user logged in.
Personal information is collected and used solely to provide the service: authenticating users, running the Customer's own accounting and payroll (including PAYE/KiwiSaver/student loan calculation and generating Employment Information for filing with Inland Revenue), reconciling bank transactions against the Customer's ledger, and generating the Customer's own reports and filings.
We do not use personal information for any secondary purpose (marketing, profiling, or automated decision-making about individuals), and we do not sell, rent, or share Customer or Employee data with any third party for marketing or data-brokerage purposes.
Artificial intelligence: the application itself does not use AI or machine learning to process personal information — the bank-transaction matching feature is a simple frequency-ranked lookup against the Customer's own prior manually-coded transactions, not a predictive model. The software is developed with the assistance of a generative-AI coding tool (Claude Code); that tool is used only in the development environment and has no access to production data or live personal information.
Personal information is shared only with the service providers strictly necessary to run the application:
| Provider | Purpose | Data accessed | Jurisdiction |
|---|---|---|---|
| Google Cloud Platform | Application hosting, database hosting, backup storage | All platform data | United States (us-west1) |
| Akahu | Bank feed connectivity | Bank feed data | New Zealand |
| Fiskil | Accredited open banking intermediary (CDR-regulated connections) | Bank feed data | Australia / New Zealand |
| GitHub | Source code hosting | Source code only — no customer data | United States |
| Google Identity | Sign-in (OAuth) | Identity assertions only | United States |
| Inland Revenue | Employment Information (Payday) filing | Employment Information submitted by the Customer, once Gateway Services filing is enabled | New Zealand |
No other party receives or can access Customer or Employee data. Where information is disclosed or stored overseas (Google Cloud Platform, GitHub, Google Identity — all in the United States), this is disclosed here in accordance with IPP 12; each of these providers is bound by data processing terms requiring privacy and security protections comparable to New Zealand law.
Customer and Employee data is retained for the life of the Customer's account; database backups are retained for 35 days and then automatically deleted; bank feed access is revoked immediately if a Customer withdraws consent, and collected bank feed data is deleted at that point unless the Customer elects to retain it within their own accounting records or retention is required by law.
All traffic is encrypted in transit (TLS); all data at rest is encrypted (AES-256); access to any Customer's data is scoped to that Customer's own organisation; administrative access to production systems requires multi-factor authentication; and sensitive administrative actions are recorded in an audit trail.
Under the Privacy Act 2020, Customers and Employees have the right to access the personal information we hold about them (IPP 6), and to correct that information if it is inaccurate (IPP 7).
For Employees, requests should generally be made to your employer (the Customer), who administers your payroll record in the application; the Company will assist the Customer in responding to such requests. Anyone may also contact the Company directly using the details below.
We do not charge a fee for a reasonable access or correction request and will respond within the timeframes required by the Privacy Act 2020.
If you have a concern about how your personal information has been handled, please contact us first using the details below so we can address it directly. If you are not satisfied with our response, you may complain to the New Zealand Office of the Privacy Commissioner (privacy.org.nz).
This policy is reviewed at least annually, and additionally whenever the service, its vendors, or applicable law materially change. Material changes will be notified to Customers.
Privacy enquiries and requests can be directed to Kaha Tahi Ltd — email [email protected].