Privacy Policy
Last updated: 18 July 2026
1. Overview
This policy explains how AIQCtrl (“we”, “us”) collects, uses, shares, and protects personal information when you use the AIQCtrl platform, websites, and related services (the “Service”). We handle personal information in accordance with the New Zealand Privacy Act 2020 and, where it applies, other privacy law relevant to you.
2. Our two roles
For information about MSP accounts, waitlist and lead submissions, and visitors to our websites, we decide how and why information is processed — we act as the responsible agency (controller).
For information that MSPs and their clients submit into engagements — interview transcripts, questionnaire answers, uploaded documents, and Ctrl Assist conversations — we process it on the MSP’s instructions to deliver the Service. The MSP is responsible for having a lawful basis and any necessary consents to collect that information from its clients and their staff.
3. What we collect
- Account information — name, email address, company, role, and password (stored as a secure hash).
- Waitlist and lead information — contact details, company, location or area of interest, and anything you include in a message, including Quick-Scan answers and scores.
- Engagement content — discovery interview transcripts, staff questionnaire responses, email replies and attachments, technical fact sheets, and generated reports and blueprints.
- Avatar session data — when you or your client speak with an AI interviewer or reception avatar, the audio and video of the session are processed in real time by our avatar provider to provide speech recognition, speech synthesis, and the on-screen avatar; the text transcript is stored by us.
- Ctrl Assist and chat messages — messages sent to AI assistants through the platform, retained with the relevant company attribution.
- Usage and technical data — log data such as feature usage, API usage volumes, timestamps, IP addresses, and diagnostic events.
4. How we use information
- To operate the Service: run interviews, score readiness, generate deliverables, provide AI assistants, and deliver training content.
- To administer accounts, billing, allowances, and usage caps.
- To communicate with you: service emails, interview invitations and follow-ups sent on an MSP’s behalf, and responses to enquiries.
- To secure the Service: authentication, abuse detection, and audit records.
- To improve the Service, using aggregate usage patterns rather than the content of engagements.
We do not sell personal information, and content submitted to the Service is not used to train AI models.
5. AI processing and service providers
Parts of the Service send content to third-party providers to function:
- AI model providers — interview answers, engagement evidence, and assistant messages are sent to large-language-model providers (via an API gateway) to generate analysis, scores, narratives, and responses.
- Avatar provider — live audio/video for AI interviewer and reception sessions is processed to provide the interactive avatar.
- Email delivery provider — to send invitations, follow-ups, notifications, and to receive email replies (including attachments) into engagements.
- Payment processor — when paid subscriptions launch, payment card details will be collected and processed by our payment provider; we do not store card numbers.
These providers process information to supply their service to us and are not permitted to use it for their own purposes, including model training. Some providers process data outside New Zealand; where they do, we take reasonable steps to ensure comparable safeguards apply.
6. White-label engagements
The Service is designed so an MSP’s clients see the MSP’s brand. If you are a client (or a client’s staff member) interacting with an interview, questionnaire, report, or assistant branded to your IT provider, that provider is running the engagement on the AIQCtrl platform. Questions about why your information was collected should go first to your provider; privacy questions about the platform itself can come to us at the address below.
7. Cookies
We use essential cookies to keep you signed in and to secure sessions. We do not currently use third-party advertising or tracking cookies. If we add product analytics, we will update this policy first.
8. Retention
- Account information: kept while your account is active, then deleted or anonymised within a reasonable period after closure.
- Engagement content and deliverables: kept while the owning MSP’s subscription is active; on termination, the MSP may request an export within 30 days, after which content may be deleted.
- Waitlist and lead records: kept while relevant to launch and sales activity, and deleted on request.
- Logs and usage records: kept for a limited period for security, billing, and diagnostics.
9. Security
Information is stored in access-controlled databases with row-level tenant isolation, encrypted in transit, and accessible only to roles that need it. API keys and credentials are stored securely, and administrative access is limited and audited. No system is perfectly secure; if we become aware of a breach that causes, or is likely to cause, serious harm, we will notify affected parties and the regulator as the Privacy Act requires.
10. Your rights
You may request access to, or correction of, personal information we hold about you. Where we process engagement content on an MSP’s behalf, we may refer your request to that MSP, since they control the engagement. To make a request, contact us at the address below; we will respond within the timeframes the Privacy Act 2020 sets. If you are not satisfied, you can complain to the Office of the Privacy Commissioner (privacy.org.nz).
11. Changes to this policy
We may update this policy as the Service evolves. Material changes will be notified by email or in-product notice before they take effect, and the “last updated” date above always reflects the current version.
12. Contact
Privacy questions and requests: support@aiqctrl.com. See also our Terms of Service.