1.Who We Are & What This Policy Covers
1.1 This Privacy Policy explains how the entity operating ChangeOS.co ("ChangeOS", "we", "us", or "our") collects, uses, discloses, and protects personal information when you use the website and SaaS application at changeos.co and associated services (the "Service").
1.2 We are an agency for the purposes of the Privacy Act 2020 (New Zealand) and handle personal information in accordance with its thirteen Information Privacy Principles. Where a Client uploads personal information about its own staff and stakeholders, the Client is the agency responsible for that information and we process it on the Client's instructions under our Terms and Conditions. Read the Terms and Conditions.
1.3 This Policy forms part of the Terms and Conditions. Capitalised terms not defined here have the meaning given in the Terms.
2.Information We Collect
2.1 Account Information: your name, email address, password (stored only as a salted hash), organisation name, role, the organisations you belong to, and your sign-in history.
2.2 Client Data: change requests, stakeholder records (names, roles, teams, agreement and trust ratings, engagement notes), readiness assessments, communication and training plans, adoption metrics, case-for-change text, Partner Notes, uploaded Excel workbooks, and any other content you or your organisation enter into the Service.
2.3 AI Interactions: the prompts you send to AI Features (including the "Gayle" adviser), the Client Data included with them, the outputs returned, and usage counts against your quota.
2.4 Billing Information: your plan, subscription status, invoices, and the identifiers our payment processor assigns to you. Card numbers are entered directly with Stripe and never touch our servers.
2.5 Technical & Usage Information: IP address, browser and device type, pages visited, actions taken (recorded in your organisation's audit trail), error reports, and the timestamps of each.
2.6 Correspondence: messages you send us through the contact form, by email, or in reply to an email we send you.
3.How We Use Information
3.1 We use personal information to:
- Provide, operate, secure, and support the Service, including authenticating you and enforcing roles and permissions;
- Generate AI outputs you request and account for your usage;
- Process subscriptions, payments, trials, discounts, and billing transfers between Partners and clients;
- Send transactional emails — invitations, payment and trial notices, handover and vault notices — from gayle@changeos.co;
- Maintain an audit trail so your organisation can see who did what and when;
- Detect, investigate, and prevent fraud, abuse, and security incidents, including rate limiting and sign-in lockouts;
- Improve the Service using aggregated, de-identified usage patterns; and
- Comply with Applicable Law and enforce our Terms.
3.2 We do not sell personal information, we do not use Client Data for advertising, and we do not use Client Data to train machine-learning models.
4.AI Providers
4.1 AI Features send your prompt and the relevant Client Data to a third-party large language model provider (currently Anthropic and/or OpenAI, either directly or through our platform's credit provider) for processing. The provider processes the request under its own terms and returns an output to us.
4.2 Where your organisation connects its own provider API key, requests are sent directly to that provider under your organisation's agreement with it. We store the key encrypted and use it only for your organisation's own requests.
4.3 We instruct providers not to train on the data we send where the provider offers that control. We recommend that you avoid entering more personal information into prompts than the task requires.
6.Cross-Border Disclosure
6.1 Our infrastructure, payment, email, and AI providers may store or process information outside New Zealand, including in the United States and Australia. Under Information Privacy Principle 12 we only disclose personal information to an overseas recipient where we reasonably believe it is subject to comparable privacy safeguards, whether by law, by contract, or by the recipient's own binding commitments.
7.Retention & Deletion
7.1 Account and Client Data are retained for as long as your Account is active. Following termination we may permanently delete Client Data within thirty (30) days, as set out in the Terms. You may export your data at any time using the Excel export.
7.2 Partner Notes archived in a Partner's vault are retained for the period the Partner configures (default 24 months) and then purged automatically. A client owner may request earlier deletion through the Service.
7.3 Audit trails, email logs, and payment records are retained for as long as necessary to meet our legal, tax, and security obligations.
7.4 Rate-limiting and lockout records expire automatically within hours.
8.Security
8.1 We protect personal information with measures that include encryption in transit, hashed passwords, encrypted storage of connected API keys, role-based access control, sign-in lockouts, rate limiting, and an audit trail of every change. No method of transmission or storage is completely secure, and you remain responsible for the confidentiality of your credentials and invite links.
8.2 If a privacy breach occurs that is likely to cause serious harm, we will notify the Office of the Privacy Commissioner and affected individuals as required by the Privacy Act 2020.
10.Your Rights
10.1 Under Information Privacy Principles 6 and 7 you may request access to, and correction of, the personal information we hold about you. Most Account information can be viewed and edited directly in Settings. For anything else, contact us using the details below; we will respond within twenty (20) working days.
10.2 Where the information was entered by your organisation or a Partner as Client Data, we will refer your request to that organisation, which controls it.
10.3 If you believe we have breached the Privacy Act 2020 you may complain to us first, and then to the Office of the Privacy Commissioner (privacy.org.nz).
11.Children
11.1 The Service is intended for business use by adults. We do not knowingly collect personal information from anyone under sixteen (16). If you believe we hold such information, contact us and we will delete it.
12.Changes to This Policy
12.1 We may update this Policy from time to time by posting a revised version on changeos.co and updating the date above. Material changes will also be announced in the Service or by email. Continued use of the Service after a change constitutes acceptance of the revised Policy.
Contact Information
For privacy questions, access or correction requests, or complaints, please contact us at:
- Entity
- ChangeOS.co
- Jurisdiction
- New Zealand
- legal@changeos.co
Prefer a form? Send us a message.