← Back to Kaha Tahi Accounts

Privacy Policy

Version 1.0 — effective 7 July 2026

This policy explains what personal information Kaha Tahi Ltd ("the Company", "we", "us") collects, why, how it is used and protected, and what rights individuals have, in connection with Kaha Tahi Accounts, our accounting and payroll web application at accounts.kahatahi.co.nz, used by Kaha Tahi Ltd itself and by other New Zealand small businesses as customers ("Customers"), and the employees of those Customers, whose payroll information is entered into the application by their employer ("Employees").

This policy is prepared to comply with the New Zealand Privacy Act 2020, including the Information Privacy Principles (IPPs).

1. What personal information we collect

About Customers (business owners/administrators using the software):

About Employees (where a Customer uses the payroll module):

Bank transaction data: with a Customer's explicit consent, we receive read-only bank transaction data through an accredited open banking intermediary (Akahu, and/or Fiskil for CDR-regulated connections) — never the Customer's online banking password or credentials directly.

We do not collect special categories of information beyond what is listed above, and we do not use cookies or third-party trackers for advertising or analytics purposes — the application uses only the technical session token (a signed JWT) needed to keep a user logged in.

2. Why we collect and how we use this information

Personal information is collected and used solely to provide the service: authenticating users, running the Customer's own accounting and payroll (including PAYE/KiwiSaver/student loan calculation and generating Employment Information for filing with Inland Revenue), reconciling bank transactions against the Customer's ledger, and generating the Customer's own reports and filings.

We do not use personal information for any secondary purpose (marketing, profiling, or automated decision-making about individuals), and we do not sell, rent, or share Customer or Employee data with any third party for marketing or data-brokerage purposes.

Artificial intelligence: the application itself does not use AI or machine learning to process personal information — the bank-transaction matching feature is a simple frequency-ranked lookup against the Customer's own prior manually-coded transactions, not a predictive model. The software is developed with the assistance of a generative-AI coding tool (Claude Code); that tool is used only in the development environment and has no access to production data or live personal information.

3. Who we share information with

Personal information is shared only with the service providers strictly necessary to run the application:

ProviderPurposeData accessedJurisdiction
Google Cloud PlatformApplication hosting, database hosting, backup storageAll platform dataUnited States (us-west1)
AkahuBank feed connectivityBank feed dataNew Zealand
FiskilAccredited open banking intermediary (CDR-regulated connections)Bank feed dataAustralia / New Zealand
GitHubSource code hostingSource code only — no customer dataUnited States
Google IdentitySign-in (OAuth)Identity assertions onlyUnited States
Inland RevenueEmployment Information (Payday) filingEmployment Information submitted by the Customer, once Gateway Services filing is enabledNew Zealand

No other party receives or can access Customer or Employee data. Where information is disclosed or stored overseas (Google Cloud Platform, GitHub, Google Identity — all in the United States), this is disclosed here in accordance with IPP 12; each of these providers is bound by data processing terms requiring privacy and security protections comparable to New Zealand law.

4. How long we keep information

Customer and Employee data is retained for the life of the Customer's account; database backups are retained for 35 days and then automatically deleted; bank feed access is revoked immediately if a Customer withdraws consent, and collected bank feed data is deleted at that point unless the Customer elects to retain it within their own accounting records or retention is required by law.

5. How we protect information

All traffic is encrypted in transit (TLS); all data at rest is encrypted (AES-256); access to any Customer's data is scoped to that Customer's own organisation; administrative access to production systems requires multi-factor authentication; and sensitive administrative actions are recorded in an audit trail.

6. Your rights

Under the Privacy Act 2020, Customers and Employees have the right to access the personal information we hold about them (IPP 6), and to correct that information if it is inaccurate (IPP 7).

For Employees, requests should generally be made to your employer (the Customer), who administers your payroll record in the application; the Company will assist the Customer in responding to such requests. Anyone may also contact the Company directly using the details below.

We do not charge a fee for a reasonable access or correction request and will respond within the timeframes required by the Privacy Act 2020.

7. Complaints

If you have a concern about how your personal information has been handled, please contact us first using the details below so we can address it directly. If you are not satisfied with our response, you may complain to the New Zealand Office of the Privacy Commissioner (privacy.org.nz).

8. Changes to this policy

This policy is reviewed at least annually, and additionally whenever the service, its vendors, or applicable law materially change. Material changes will be notified to Customers.

Contact

Privacy enquiries and requests can be directed to Kaha Tahi Ltd — email [email protected].