Penguin Pilot — Privacy Policy
The Network Software Limited trading as Penguin Pilot
Version 1.0 · Effective 04 September 2026
Read this first
Penguin Pilot is business software. Most of the personal information inside it doesn’t belong to us and wasn’t given to us — it was put there by our customers about their contacts, vendors, buyers, leads and staff.
So this policy has two halves, and it matters which one you’re reading:
Part A — information we’re responsible for. The information we collect directly: about our customers, the people who use the platform, our partners, and visitors to our website. We decide what happens to this.
Part B — information our customers are responsible for. The information our customers put into their workspaces. We only hold and process it on their instructions. If you want to know what a business is doing with your information, or you want it corrected or deleted, you need to contact that business, not us — although we’ll help you find them.
We’re a New Zealand company and we follow the Privacy Act 2020.
Who we are
The Network Software Limited, trading as Penguin Pilot New Zealand Business Number 9429048076104 Privacy contact: support@penguinpilot.ai
Part A — Information we’re responsible for
- Who this part covers
-
Customers — businesses that subscribe to Penguin Pilot.
-
Users — the individuals who log in and use it.
-
Partners — white label partners and their staff.
-
Website visitors — anyone browsing our public website.
-
Visitors to customer pages — but only the limited technical and audit information described in section 2.6.
2. What we collect
2.1 When you sign up and use the platform
-
Name, work email, phone number, job title and the business you work for.
-
Login credentials, multi-factor authentication settings and recovery codes.
-
Billing details — company name, address, GST number, and payment details (card details are handled by our payment processor; we don’t store full card numbers).
-
Your role, permissions, team and seat assignment.
2.2 How you use the platform
-
Login records, IP addresses, device and browser information.
-
Pages and features you use, actions you take, and timestamps.
-
Usage against the five meters (Automations, AI Credits, Marketing Emails, Storage, System Usage).
-
Error reports and diagnostic logs.
2.3 When you contact us
-
Support tickets, emails, chat messages and call notes.
-
Feedback, survey responses and bug reports.
2.4 From our website
- Cookies and similar technologies (section 9), analytics data, and information you submit through contact or demo forms.
2.5 From other sources
We may receive information about you from your employer (when they invite you to a workspace), from a white label partner (when they sign your business up), from our payment processor, and from publicly available business sources.
Notice about indirect collection (IPP 3A). Where we collect personal information about you from someone other than you — for example when your employer or a partner adds you to a workspace — we take reasonable steps to make sure you know we hold it, why, who we share it with, who we are, and that you can ask to see and correct it. This policy is one of those steps, and we also tell you in the invitation email you receive.
2.6 Visitors to customer pages
If you use a public page created by one of our customers — a booking page, a form, a vendor dashboard, an open home sign-in, a document to sign — we collect limited technical information to run the page securely: IP address, browser and device type, and access timestamps. For document signing and open home sign-ins we also create an audit record showing what happened, when, and from where, so the parties can prove what was signed or who attended. That audit record is held on behalf of the customer, under Part B.
Separately, we keep basic access logs — IP address, timestamp, request path — to run the platform securely and detect abuse; those logs are ours, under Part A. Everything else you enter on the page belongs to the customer.
3. Why we use it
We use the information in Part A to:
- create and administer accounts, workspaces and seats;
- provide, secure, support and improve the platform;
- authenticate you and protect against fraud, abuse and unauthorised access;
- measure usage against your package, bill you, and collect payment;
- send service messages — outages, security notices, billing, changes to terms;
- provide support and respond to your questions;
- understand how features are used so we can improve them;
- send you marketing about Penguin Pilot, where you’ve agreed or where we’re allowed to (you can opt out at any time — see section 11);
- meet legal, tax and regulatory obligations; and
- establish, exercise or defend legal claims.
4. Who we share it with
We share personal information with:
- Service providers who help us run the platform — hosting, email delivery, payments, analytics, error monitoring, support tooling. They’re listed in section 6 and may only use it to provide their service to us.
- Your business. If you use the platform through an employer, that business’s administrators can see your account details, permissions and activity in the workspace.
- A white label partner. If your business subscribed through a partner, that partner can see and administer your account and your workspace, and is your contracting party. Their privacy policy governs your relationship with them.
- Professional advisers — lawyers, accountants and auditors, under confidentiality.
- Authorities — police, regulators, courts and government agencies, where the law requires it or where it’s necessary to protect someone’s safety or our legal rights. We’ll tell you first unless we’re not allowed to.
- A buyer of our business, if we’re sold, merged or restructured — under confidentiality, and on the basis that this policy continues to apply.
We do not sell personal information.
5. Anonymous and aggregated information
We generate anonymised, aggregated statistics from platform activity — usage patterns, benchmarks and market statistics. The information is irreversibly anonymised and aggregated before it is used, so it can’t identify you or any individual and can’t be re-identified. At that point it is no longer personal information: we own it and may use, publish and disclose it for any purpose. We don’t otherwise use our customers’ workspace information for our own purposes — that’s what lets us hold it as their agent (section 15).
6. Our service providers
The main third parties we use, and what they do. Some run the platform for everyone; those marked on connection only receive data if a customer chooses to connect them.
Hosting and infrastructure
|
Provider |
What they do |
Where |
|---|---|---|
|
Amazon Web Services |
Hosts the whole platform — servers, database, cache, file and document storage, image delivery, background processing. Holds all CRM records. |
Australia (Sydney) |
|
Amazon Simple Email Service |
Delivers outbound email sent on a customer’s behalf, and records bounces and complaints. |
Australia (Sydney) |
|
Sentry |
Error and performance monitoring. Receives diagnostic data when something fails, which can include the signed‑in user’s identity and the page or request involved. |
United States |
|
Cloudflare |
Bot protection on public forms and enquiry pages; email authentication records in a customer’s own domain, on connection. |
Global edge network |
Payments and finance
|
Provider |
What they do |
Where |
|---|---|---|
|
Stripe |
Subscription and advertising payments. Card details go directly to Stripe and are not held by us. |
United States and global |
|
Xero |
On connection.Accounting and payroll sync — supplier invoices, commission statements, payslips. |
United States |
Email, calendar and messaging
|
Provider |
What they do |
Where |
|---|---|---|
|
Microsoft 365 |
On connection.Mailbox and calendar access, so email can be read into and sent from the CRM. Data stays in the customer’s own tenant. |
Customer’s own Microsoft 365 tenant |
|
TextBee |
On connection.SMS gateway, relayed through the user’s own mobile device. |
[CONFIRM WITH VENDOR] |
Artificial intelligence
| Provider | What they do | Where |
|---|---|---|
| Google (Gemini API) | Generates listing and marketing copy, drafts market updates, and reads supplier invoices to extract line items. | United States and global |
Property portals and listing distribution
| Provider | What they do | Where |
|---|---|---|
| Trade Me Property · realestate.co.nz · OneRoof | On connection.Publish and withdraw listings; return listing statistics and buyer enquiries. | New Zealand |
| Marq | On connection.Marketing design and print templates; reads a published listing feed. | United States |
| The customer’s own website | On connection.Receives listings for display and returns enquiry form submissions. | Wherever that customer hosts it |
Marketing, advertising and prospecting
| Provider | What they do | Where |
|---|---|---|
| Meta (Facebook and Instagram) | On connection.Property advertising campaigns and reporting. | United States and global |
| Mailchimp | On connection.Syncs selected contacts into the customer’s own Mailchimp audience. | United States |
| Apollo.io | On connection.Business contact lookup for prospecting. | United States |
| [SOCIAL PUBLISHING PROVIDER] | On connection.Publishes social media posts generated from CRM records. | [CONFIRM WITH VENDOR] |
Loaded in the visitor’s browser
These run on public pages and in the app. Each provider receives the visitor’s IP address — that’s inherent in the browser requesting a file from them, not something we send.
| Provider | What they do | Where |
|---|---|---|
| Google Maps and Places | Address lookup, geocoding and maps on property records. | United States and global |
| Google Fonts | Typefaces used in branded templates and designs. | Global edge network |
| Cloudflare Turnstile | Bot protection challenge on public forms and portals. Also receives browser signals. | Global edge network |
| YouTube and Vimeo | Play videos a customer has embedded in listings, forms or announcements. May set cookies. | United States and global |
The current list is maintained at https://penguinpilot.ai/subprocessors. We update it when it changes.
7. Sending information overseas
7.1 We store platform data on servers in Australia. Some of our service providers are also overseas, and we and they may access information from outside New Zealand.
7.2 Where a provider simply holds or processes information on our behalf and doesn’t use it for its own purposes, that isn’t treated as a disclosure under the Privacy Act — but we stay responsible for it.
7.3 Where we do disclose personal information to someone overseas, we only do it where we’re satisfied the information will be protected by safeguards comparable to the Privacy Act — usually through contractual protections based on the Privacy Commissioner’s model clauses — or where the law otherwise permits it.
8. How long we keep it
-
Account and contact details (name, work email, role, business) — while your account is active, then 12 months.
-
Billing and transaction records — 7 years after your account closes, to meet tax and accounting obligations.
-
Login records, IP addresses and security logs — up to 12 months.
-
Product usage analytics — up to 24 months in identifiable form, then anonymised.
-
Support conversations — up to 3 years.
-
Marketing contact details — until you opt out, and then a minimal record so we honour your opt-out.
-
Customer workspace data — see section 15.
-
Backups — data persists in backups for up to 35 days after deletion from live systems.
We delete or anonymise information when we no longer need it, unless the law requires us to keep it.
9. Cookies
9.1 Our website and the platform use cookies and similar technologies to keep you logged in, remember your settings, keep the service secure, and understand how it’s used.
9.2 We use:
-
Strictly necessary cookies — authentication, security, load balancing. The platform can’t work without these.
-
Preference cookies — remembering your settings.
-
Analytics cookies — understanding usage so we can improve.
9.3 You can block or delete cookies in your browser. If you block strictly necessary cookies, you won’t be able to log in.
10. Security
We protect personal information with measures appropriate to its sensitivity, including:
- tenant isolation and row-level security, so one customer’s workspace can’t reach another’s;
- role-based access control and permission checks;
- encryption in transit;
- private file storage that’s access-controlled per workspace and record;
- audit logging of access and significant actions;
- multi-factor authentication;
- restricted internal access, granted only where it’s needed and logged; and
- vulnerability management and monitoring.
A note on public file storage. Some content — profile photos, brand assets, feed images, marketing images and property photos — is stored in public buckets so it loads quickly on public pages. Anything in public storage can be accessed by anyone who has the URL. Don’t put confidential material there.
No system is completely secure. We can’t guarantee absolute security, and we ask you to do your part: strong unique passwords, multi-factor authentication, and removing users who leave.
11. Marketing and opting out
11.1 We may send you marketing about Penguin Pilot where you’ve agreed or where we’re permitted to.
11.2 You can opt out at any time using the unsubscribe link in any marketing message, or by emailing support@penguinpilot.ai. We’ll action it within 5 working days.
11.3 You can’t opt out of service messages — outages, security notices, billing and changes to terms — while you have an account.
12. Your rights
12.1 Access. You can ask for a copy of the personal information we hold about you under Part A.
12.2 Correction. You can ask us to correct information that’s wrong. If we don’t agree, you can ask us to attach a statement of the correction you sought.
12.3 How to ask. Email support@penguinpilot.ai. We’ll respond as soon as we can, and within 20 working days as the Privacy Act requires. We may need to verify who you are. Access is free, unless the request takes significant work — in which case we’ll tell you the cost before we start.
12.4 Limits. Some information is exempt from access — for example where it would reveal someone else’s personal information, breach legal privilege, or prejudice legal proceedings. If we refuse, we’ll tell you why.
12.5 If your information is in a customer’s workspace, see Part B — you need to contact that business.
13. Privacy breaches
Which of us notifies depends on whose information it is.
Information we’re responsible for (Part A). If we have a privacy breach affecting information we’re responsible for, and it has caused or is likely to cause serious harm, we notify the Office of the Privacy Commissioner and the people affected, as soon as we practicably can after we’ve confirmed it’s notifiable.
Information in a customer’s workspace (Part B). The customer is the agency responsible for that information, so the customer decides whether the breach is notifiable and makes the notifications. Our job is to tell that customer without undue delay, give them everything they need to assess it, and support them. We won’t delay or obstruct their notification, and we won’t notify on their behalf unless the law requires us to. Where a business uses Penguin Pilot through a white label partner (section 15.2A), we tell the partner, and the partner must tell the business — which still decides on and makes any notification.
14. Complaints
14.1 If you’re unhappy with how we’ve handled your personal information, email support@penguinpilot.ai. We’ll acknowledge it promptly and aim to resolve it within 20 working days.
14.2 If you’re not satisfied, you can complain to the Office of the Privacy Commissioner: www.privacy.org.nz · 0800 803 909 · enquiries@privacy.org.nz.
Part B — Information our customers are responsible for
15. How this works
15.1 Our customers use Penguin Pilot to run their businesses. In doing so they store personal information about people who are not our customers — vendors, buyers, tenants, leads, contacts, form respondents, open home attendees, booking guests, email recipients, document signers, staff and contractors.
15.2 Under section 11 of the Privacy Act 2020, the customer is the agency responsible for that information. We hold and process it as their agent, on their instructions. We don’t decide why it’s collected, what it’s used for, or how long it’s kept.
15.2A If the business bought through a white label partner, the chain runs one step longer. Many businesses use Penguin Pilot under a partner’s brand, and may not know we exist. In that case: the business is still the agency responsible for the information in its workspace; the partner holds it on that business’s behalf; and we hold it on the partner’s behalf. The partner’s privacy policy, not this one, applies — to that business and to the people whose information it holds. Requests and complaints go to the business, or if you can’t identify it, to the partner.
15.3 This means:
-
The customer must have a lawful basis to hold your information, and must give you the notices the Privacy Act requires — including under IPP 3A, where they got your information from someone other than you.
-
The customer’s own privacy statement governs what they do with it, not this policy.
-
Requests to access, correct or delete your information go to that customer, not to us.
15.4 If you don’t know who holds your information, or you can’t reach them, email us at support@penguinpilot.ai. We’ll help identify the business — or the partner that supplies it — and pass your request on. We won’t respond on their behalf.
16. What we do with workspace information
16.1 We only use it to:
-
provide, secure and support the platform for that customer;
-
keep the service running — backups, monitoring, troubleshooting;
-
send messages the customer instructs us to send, on their behalf;
-
send data to the third parties the customer has connected;
-
generate anonymised, aggregated statistics that don’t identify anyone (section 5); and
-
comply with the law.
16.2 We do not use workspace information for our own marketing, sell it, or share it with other customers.
17. AI processing
17.1 Where a customer uses an AI feature, the relevant content is sent to a third-party AI provider to generate a result. That may include personal information the customer has put into the platform.
17.2 We do not use customer workspace data to train, fine-tune or improve any AI model — not a third party’s, and not our own. We contract with our AI providers so that data we send on a customer’s behalf is not used to train their models, and is retained only in accordance with the zero-retention or limited-retention terms we’ve agreed with them, which we publish at https://penguinpilot.ai/subprocessors. Where a feature learns from content — for example a training assistant answering questions about a business’s own material — it does so within that business’s workspace only, never across workspaces.
17.3 AI output can be wrong. Our terms require customers to have a human review AI output before relying on it or sending it to anyone. Decisions about you should not be made by AI alone — and if you believe a business has made a decision about you using AI output without proper review, raise it with that business.
17.4 Our AI providers are listed in section 6.
18. Information that needs extra care
Some information the platform can hold carries extra risk. Our terms require customers to have express, documented consent before they put it in:
- Voice recordings used for voice cloning. A cloned voice is derived from a real person’s voice. Customers must have that person’s documented consent for that specific use.
- Signature images and signing audit trails. These are kept in private storage as evidence of what was signed and when. Please download and keep your own copy of anything you sign. The record is held for the business that sent it to you, and it is removed when that business stops using the platform — which may happen without notice to you.
- Payroll and remuneration data, and financial account references.
If you believe a business has put this kind of information about you into the platform without your consent, contact them, and tell us at support@penguinpilot.ai — we’ll investigate under our Acceptable Use Policy.
19. Public pages
19.1 Customers can create pages anyone with the link can open. What’s on them, and who they’re sent to, is the customer’s decision.
19.2 A tokenised link is hard to guess but isn’t a password. Anyone with the link can open the page.
19.3 If you think a page is exposing your information inappropriately, contact the business that published it, and tell us at support@penguinpilot.ai.
20. Retention and deletion of workspace information
20.1 Customers control retention within their workspace, and can delete records at any time.
20.2 When a customer’s subscription ends, their data stays available for export for 30 days, and is then deleted from our production systems within a further 30 days. It ages out of backups within 35 days after that. Where a business bought through a
white label partner, that partner’s own terms set the export and deletion window — we require it to be at least as protective as ours, but the partner is the one who provides it. 20.3 We may keep information we’re legally required to keep, and anonymised aggregated data.
21. Children
The platform isn’t intended for children, and we don’t knowingly collect information from anyone under 16 through our own website or signup. Customers must not use the platform to hold information about children without a lawful basis and appropriate consent.
22. Changes to this policy
We may update this policy. We’ll publish the updated version with a new effective date, and where the change is significant we’ll tell customers by email or in the platform. Please check back from time to time.
The Network Software Limited trading as Penguin Pilot · support@penguinpilot.ai
