Privacy policy.
How Coupland Consulting handles your information.
What's in this policy
1. What we collect
Coupland Consulting is an AI strategy practice working with NZ businesses. To do the work you have engaged us for, we need to collect a limited amount of personal and business information about you, your firm, and the people in it. We collect only what we need, and only for as long as we need it.
The categories of information we typically collect during an engagement include:
- Contact information for the people we are working with: name, role, work email, work phone number, and the business they represent.
- Business details discussed during scoping calls, readiness audits, and workflow design sessions. This may include team size, current tool stack, internal workflows, supplier relationships, financial context (e.g. revenue band, fee structure), and any AI use already in place.
- Screen-shared materials reviewed during audits or workshops. This can include software dashboards, anonymised client files, internal documents, prompts and outputs from existing AI tools, and process maps. We do not retain copies of these unless they are explicitly handed to us as deliverable inputs.
- Written deliverables and working drafts we produce for you (audit reports, tool comparison matrices, workflow specifications, training materials, runbooks). These are stored in our engagement record.
- Payment information needed to invoice and receive payment. For most clients this is limited to a billing email and a business address. Bank reference details flow through your accounts payable process, not through us.
We do not collect health information, identity documents, or other sensitive categories of data unless an engagement specifically requires it (rare for our work, and always discussed in writing first).
2. How we use it
We use the information you give us to:
- Deliver the engagement you have signed a Statement of Work for. That means running the audit, evaluating tools, designing workflows, drafting policies, training your team, and producing the documented deliverables we agreed.
- Communicate with you about the engagement in progress: status updates, meeting scheduling, draft reviews, follow-up questions, and handover.
- Invoice and collect payment for the work, and keep the records our accountant and IRD need us to keep.
- Meet our legal and professional obligations, including responding to a regulator, a court order, or a legitimate request under the Privacy Act 2020.
- Improve our own practice, in anonymised form only. For example, an engagement may inform a generic case pattern we publish later, but never with any client-identifying detail without your written consent.
We do not use your information for sales prospecting, marketing list-building, or any purpose outside the engagement you have engaged us for. We do not sell client data to anyone, for any reason, ever.
3. Who we share it with
Most engagements run entirely between Craig Coupland and the named client. Where the work requires another party to be involved, we share only the minimum necessary, only with parties who are bound by confidentiality, and (where practical) only with your knowledge.
Parties we may share information with during an engagement:
- Sub-contractors under written NDA. Occasionally an engagement needs a specialist (a developer, a data analyst, a sector lawyer). When we bring one in, they sign a project-specific NDA before they see anything sensitive, and they only get the part of the engagement they need.
- Accountants and tax advisers (ours, not yours), for invoicing and tax compliance only. They see payment-related information, not the substance of your engagement.
- Lawyers, where Coupland Consulting needs legal advice on a specific matter (rare). Privileged and confidential.
- IT providers who host our document storage, email and practice management systems. These are commercial cloud providers (described in section 4) with their own privacy obligations.
- Regulators or courts, where we are legally required to. We will tell you about any such request unless legally prevented from doing so.
We never share your information with third parties for marketing, sales, list rental, advertising, or AI vendor referrals. We take no commissions, kickbacks, or referral fees from any AI vendor (see also our terms of service).
4. Storage and security
We keep client data on a small number of well-known business systems, preferring NZ-resident hosting where the option exists, Australian or other reputable jurisdictions where it does not. At the time of writing, the main systems we use are:
- Document storage and email on Microsoft 365 (AU/NZ data centres) with multi-factor authentication required on every account.
- Engagement records and notes in a NZ-hosted practice management system.
- Backups are encrypted, versioned, and kept in geographically separate cloud regions.
Operational controls include:
- Encryption in transit (TLS) on every system, and at rest on every backing store.
- Multi-factor authentication on every Coupland Consulting account, with hardware-key options where supported.
- Role-based access. Only Craig and a named sub-contractor (where one is engaged) can see your file.
- A minimum-retention principle. We keep engagement records for a default of seven years after delivery, to satisfy IRD record-keeping. After that, files are securely deleted unless you have asked us to keep them longer, or unless we are legally required to.
- An annual review of our security posture, vendor list, and incident response plan.
If we become aware of a privacy breach that is likely to cause you serious harm, we will notify both you and the Office of the Privacy Commissioner without unreasonable delay, as required under section 114 of the Privacy Act 2020.
5. Your rights under the NZ Privacy Act 2020
Under the Privacy Act 2020 you have the right to:
- Access any personal information we hold about you. We will respond within twenty working days, the maximum allowed by the Act.
- Correct information that is wrong, incomplete, or out of date.
- Have deleted information we are no longer required to keep for legal, tax, or regulatory reasons.
- Withdraw consent for any future processing of your data. Note that withdrawing consent partway through an engagement may make it impossible for us to continue the work.
- Complain to us first, and then if you remain unsatisfied, directly to the Office of the Privacy Commissioner (0800 803 909, privacy.org.nz).
To exercise any of these rights, contact our Privacy Officer (details in section 8). We will not charge you a fee for access or correction requests except in unusual cases where the request is unreasonably large, in which case we will tell you in advance.
6. Cookies and analytics
The Coupland Consulting website uses a deliberately small set of cookies and similar technologies. We do not run third-party advertising trackers, retargeting pixels, or social media tracking on this site.
- Functional cookies remember your preferences (such as whether you have dismissed a banner). These do not identify you personally.
- Privacy-first analytics via Cloudflare Web Analytics. This tells us anonymously how many people visit each page, where they came from, and which device class they used. It does not set a tracking cookie, does not fingerprint visitors, and we cannot link a page view back to an individual.
- Booking and form tools may set short-lived session cookies when you are actively using them (e.g. submitting a contact form). These are not used for tracking outside that single session.
You can disable cookies in your browser settings. The site will still function but a small number of features (such as remembering you have closed the demo banner) may not.
7. AI tools we use in our work
Coupland Consulting uses AI tools in our day-to-day work, openly. It would be inconsistent to advise on AI adoption without using these tools ourselves. The tools we currently use include Claude (Anthropic), ChatGPT (OpenAI), Microsoft Copilot, Google Gemini, and a small number of specialist tools (e.g. Perplexity for research, Cursor for code review). The vendor list evolves as the market evolves.
Because clients reasonably ask how this affects their data, we apply the following rules across every engagement:
- We never paste client-identifying detail into a public AI model. Names, contact details, financial figures, internal staff names, supplier names, and any other directly identifying field are stripped or anonymised before any prompt that goes to a third-party AI tool.
- We prefer paid tiers with privacy commitments. Where we use a third-party AI tool in an engagement, we use the business or enterprise tier of that tool, with training opt-out enabled, retention set to the minimum the vendor allows, and (where offered) zero data retention.
- Sensitive material stays out of public models entirely. For example, raw client lists, unredacted financial statements, employment records, and unfiled regulatory submissions are never put into a third-party model. Where AI assistance is needed on that kind of material, we either work on-premise, use a private deployment, or do the work manually.
- We disclose which tools we used in the delivered work, so you can see where AI was in the loop and where it was not.
- Outputs are reviewed before delivery. Nothing produced by an AI tool reaches you as a deliverable without human review and (where needed) correction.
If you have a specific concern about a particular AI tool we may use during your engagement (for example, your firm has a policy against a named vendor), tell us at the scoping stage and we will work around it.
8. Privacy Officer contact
Coupland Consulting's Privacy Officer is Craig Coupland, the firm's founder.
| Privacy Officer | Craig Coupland |
|---|---|
| To be confirmed before launch. In the interim, use the contact form and mark your message "Privacy enquiry". | |
| Phone | To be confirmed before launch. |
| Postal | Tauranga, New Zealand. Full address provided on request. |
| Response time | Within five working days for acknowledgement, twenty working days for a substantive reply. |
If you are unhappy with how we have handled a privacy enquiry or complaint, you can escalate directly to the Office of the Privacy Commissioner:
| Phone | 0800 803 909 |
|---|---|
| Online | privacy.org.nz |
We may update this privacy policy from time to time. The "last updated" date at the top of this page reflects the most recent revision. Material changes will be communicated to current engagement clients by email.