Privacy Policy

Last updated 24 June 2026

AdviserDesk Technologies Ltd (“AdviserDesk”, “we”, “us”) builds CRM software for New Zealand insurance advisers. This policy explains what personal information we collect, how we use it, and the choices you have. We handle personal information in accordance with the Privacy Act 2020.

Information we collect

Account information — the email you sign in with, plus your name and firm details. You can create an account yourself on our website to start a free trial; the mobile app has no sign-up of its own — you sign in there with the account you created.

Client and practice records you enter — names, emails, phone numbers, addresses, policy details (insurer, premiums, sums insured), notes, tasks and pipeline. You are the controller of this data; we process it on your behalf.

Meeting audio and transcripts — when you use the optional 'Voice scribe' in the app, it records a meeting (only after you confirm the client has been informed) and uploads the audio to our service for transcription and summarisation. The transcript and summary are stored with the meeting.

Limited technical data — on our website we collect device, browser, IP and usage events to keep it secure. The mobile app uses no analytics, advertising or tracking SDKs and does not track you across other apps or websites.

App permissions

The mobile app requests the microphone only for 'Voice scribe', and only after you tap Start recording. It does not access your camera, location, contacts or photo library.

How we use information

To provide and maintain the CRM, with your data scoped to your practice only.

To transcribe and summarise the meetings you choose to record, and to answer questions about your own records ('Ask AdviserDesk').

To communicate with you about your account and support, and to meet legal and regulatory obligations that support your own FMA compliance.

AI and your client data

We do not sell your data, and we do not use your client data to train third-party AI models. Meeting audio and transcripts are processed by OpenAI solely to produce transcriptions and summaries for your practice; they are not used to train models. AI outputs are drafts you review before use.

Connecting your Google Calendar

AdviserDesk lets you optionally connect your Google Calendar so your meetings stay in sync both ways. You start this from Settings → Calendar sync and grant access through Google's standard consent screen, and we only request the access this feature needs.

With your permission we request the Google OAuth scope https://www.googleapis.com/auth/calendar.events, which lets AdviserDesk read, create and update calendar events in the Google account you connect, plus your basic profile email (openid, email) to identify and label that account. We do not request access to your contacts, files or Gmail through this integration.

We use this access only to provide the two-way sync you turn on: meetings you create in AdviserDesk are written to your Google Calendar, events on your Google Calendar are shown alongside your AdviserDesk schedule, and a background sweep keeps the two aligned. We use Google Calendar data for no other purpose.

AdviserDesk's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google Calendar data obtained through this integration is never sold; never used for advertising; never used to develop, improve or train generalised or non-personalised AI or machine-learning models; not read by humans except with your consent, for security, or where required by law; and not transferred to others except as needed to provide the feature or as required by law.

Your Google access and refresh tokens are encrypted at rest under the same per-practice, row-level isolation as the rest of your data (Supabase, Sydney, Australia region). We keep them only while the integration is connected and your account is active; when you disconnect (Settings → Calendar sync → Disconnect) or delete your account, we delete the stored tokens and stop syncing. You can also revoke AdviserDesk's access at any time from your Google Account at myaccount.google.com/permissions.

Where your data lives and how it's protected

Customer data is hosted on Supabase (Australia region), encrypted in transit (HTTPS/TLS) and at rest. Each practice's data is isolated at the database level with row-level security, and the app ships no privileged database keys.

Retention and deletion

We retain your data while your account is active. To support adviser record-keeping obligations, compliance records can be retained for up to seven years.

You can permanently delete your account and practice data from within the mobile app: More → Settings → Account → Delete account. This removes your login and your practice records and cannot be undone. You can also request export or deletion by contacting us, subject to those obligations.

Your rights

Under the Privacy Act 2020 you may request access to, or correction of, the personal information we hold about you. Contact us and we will respond within the statutory timeframe.

Contact us

Questions about this policy or your information can be sent to privacy@adviserdesk.co.nz. If you are not satisfied with our response, you may contact the Office of the Privacy Commissioner.