Penguin Pilot — Platform Terms of Service
The Network Software Limited trading as Penguin Pilot
Version 1.0 · Effective 04 September 2026
Read this first
These terms cover the whole Penguin Pilot platform — every module, every feature, now and in the future. You accept them once. You do not need to accept separate terms each time you turn on a new module.
Some modules have extra rules that only make sense for that module (for example, sending marketing email, e-signing a document, or listing a property on a portal). Those sit in Schedule 1 — Module Rules at the end. They apply automatically to the modules you actually use, and only to those modules.
Throughout, we’ve put a short plain-English summary at the start of each section. The summary is there to help you read quickly. If a summary and the clauses ever seem to disagree, the clauses are the ones that count.
1. Who we are and who you are
In short: we’re Penguin Pilot. You’re the business that signed up. Whoever clicks “I agree” must be allowed to agree on that business’s behalf.
1.1 Us. “We”, “us” and “our” mean The Network Software Limited (New Zealand company number 9429048076104), trading as Penguin Pilot.
1.2 You. “You” and “your” mean the organisation that has subscribed to the platform. If you signed up as an individual rather than on behalf of a business, “you” means you personally.
1.3 Authority. If you accept these terms on behalf of a business, you promise you’re authorised to bind that business. That business is then the customer, and it is responsible for everything done under its workspace.
1.4 Billing scope. Billing can be set at organisation, team or individual level. Whichever scope applies, the organisation that owns the workspace is the contracting party, owns the Customer Data in it, and is liable for all fees — including fees incurred under a team or individual scope. Data created under a team or individual scope stays with the organisation when that team or person leaves.
1.5 How you accept. You accept these terms by doing any of the following: clicking to accept them, signing an order or quote that refers to them, or using the platform. If you don’t accept them, stop using the platform. This doesn’t apply if you came through a Partner — see clause 1.6. In that case these terms don’t apply to you at all, however much you use the platform, unless you later take a subscription directly with us.
1.6 If you came through a Partner. Some businesses buy Penguin Pilot through a Partner who brands the platform as their own. If that’s you, your agreement is with your Partner, not with us — they set your price and packages, they invoice you, they support you, and their terms of service govern your use of the platform. These terms don’t apply to you unless and until you take a subscription directly with us. Clause 22 explains the position, and what your Partner has to give you.
1.7 What makes up our agreement. Our agreement with you is made up of: these terms; your order, package or plan (including the price and any limits shown at the time you subscribe); the Acceptable Use Policy; the Privacy Policy; and, if you’re a Partner, the White Label Partner Terms. If there’s a conflict, the order of priority is: your signed order form (if we’ve signed one with you); then the White Label Partner Terms, but only for matters about the partner relationship itself (branding, packaging, pricing to clients, payouts and partner termination); then these terms, which always prevail on how the software may be used; then the policies.
2. Words we use
In short: the definitions you’ll need. We’ve kept them short.
These words have the meaning given below wherever they appear, whether or not they’re capitalised — we’ve kept normal capitalisation so the terms stay readable.
AI Features — any part of the platform that uses artificial intelligence to generate, summarise, score, extract or transform content.
Included Allowance — the usage each meter includes in your package for a Usage Period. It resets each period and is not purchased.
Credits (or Purchased Credits) — units you buy to add usage to a meter once your Included Allowance is used up. See Schedule 2.
Customer Data — everything you or your users put into the platform, or that the platform collects for you: contacts, leads, properties, deals, documents, files, financial records, marketing lists, and anything else stored in your workspace.
Beta Program — a product or module offered for evaluation rather than as a finished service, however we label it. See section 4A.
Meters — the five things we measure: Automations, AI Credits, Marketing Emails, Storage and System Usage. See Schedule 2.
Module — a functional part of the platform (for example Pipelines, Digi-Sign, Marketing Emails, Training Academy, Properties).
Partner — a business that white-labels and resells the platform under our White Label Partner Terms. We also call this a reseller.
Partner Client — a business that subscribes to a Partner’s service and is provisioned a workspace on the platform. A Partner Client has no agreement with us.
Package — the plan you subscribe to. Your package sets which modules you can use, how many seats you have, and what usage allowances are included.
Platform — the Penguin Pilot software, websites, mobile apps, APIs and related services.
Seat — a licence for one named user to access the platform.
Usage Period — the recurring period over which usage allowances are measured and reset. Unless we say otherwise, this is monthly, running from your subscription’s billing date.
Workspace — your isolated tenant on the platform, containing your teams, users and Customer Data.
Your Users — the people you give access to your workspace: your staff, contractors and anyone else you invite.
3. Your account, workspace and users
In short: you’re responsible for who you let in and what they do. Keep credentials safe. Seats are per person, not shared.
3.1 To use the platform you must be at least 18, able to enter into a contract, and give us accurate registration details that you keep up to date.
3.2 We give you a workspace. You control who has access to it and what they can see, using the roles and permissions in the platform. You are responsible for configuring those settings correctly.
3.3 You are responsible for Your Users. Everything Your Users do in your workspace is treated as done by you. If one of them breaches these terms, you have breached these terms.
3.4 Seats are personal. Each seat is for one named individual. Seats must not be shared between people, and must not be used as a generic or shared login. You may reassign a seat when someone leaves your business, but you must not rotate seats between people to avoid paying for them.
3.5 Keep credentials secure. You and Your Users must keep passwords, API keys, tokens and multi-factor recovery codes confidential. Tell us immediately at support@penguinpilot.ai if you think an account has been compromised.
3.6 Our access to your workspace. We may access your workspace where we need to in order to provide support, investigate a problem, maintain security, or comply with the law. We limit that access to staff who need it, and we log it. If a workspace belongs to a Partner’s client, that Partner administers it — see clause 22.
3.7 We may suspend or remove any individual user who we reasonably believe is misusing the platform, without suspending your whole workspace.
3.8 Who owns the workspace. The business named as the customer owns the workspace. If you signed up as an individual and not on behalf of a business, you own it personally.
3.9 Ownership disputes. Businesses split up. If two or more people claim the same workspace, this is how we deal with it.
(a) We are not a court, an arbitrator or an investigator, and we won’t adjudicate the underlying dispute between you.
(b) We may ask anyone claiming the workspace for documentation, and we may decline to act until we get it.
(c) In deciding who to treat as the owner for the limited purpose of controlling the account, we may consider: who has consistently paid for it; who created it; company, partnership or trust records; a court order or settlement agreement; and anything else we reasonably consider relevant. We may disregard any document we reasonably believe is forged, altered or unreliable.
(d) Our decision is administrative only. It decides who controls the account, not who owns the business or the data, and it doesn’t bind anyone in any legal proceeding between you.
(e) If we can’t reasonably work out who the owner is, we may suspend the workspace until you reach a written agreement or a court decides. We’ll keep the data intact while it’s suspended.
(f) You indemnify us under clause 20.1 for any claim arising from how we handle an ownership dispute. This doesn’t apply to a decision we make dishonestly or in bad faith.
3.10 Competitors. You may not access or use the platform if you build, sell or work for a business that competes with Penguin Pilot, and you must not give anyone in that position access to your workspace, unless we agree in writing. Partners who white-label and resell the platform under our White Label Partner Terms are not competitors for this purpose.
3.11 Security testing. You must not conduct penetration testing, vulnerability scanning or any other security testing against the platform without our prior written consent. If you find a vulnerability, report it under clause 17.4.
4. What we provide
In short: we run the platform and keep improving it. We’ll aim for it to always be there, but we can’t promise perfection, features will change over time, and support is best-efforts with no service levels attached.
4.1 We grant you a non-exclusive, non-transferable, revocable right to use the platform for your own internal business purposes for as long as your subscription is current and paid for, in accordance with these terms.
4.2 We’ll provide the platform with reasonable care and skill and in accordance with applicable law.
4.3 Availability. We aim to make the platform available 24 hours a day, 7 days a week, other than during planned maintenance (which we’ll usually run between 9pm and 6am NZT) and unplanned maintenance or emergency work. We’ll give you advance notice of planned maintenance where we reasonably can. We do not promise uninterrupted or error-free access.
4.4 Support. Support is not a contracted part of what you’re paying for, and we make no commitment to provide it.
(a) We make self-help resources available — in-app help, a knowledge base and a ticketing system — and we generally do respond to tickets. But we give no service levels, no response times, no resolution times, no support hours and no availability commitment of any kind, and nothing on our website, in our marketing, in a ticket or in a conversation creates one.
(b) We may change, reduce, pause or withdraw support, in whole or for any individual customer, at any time and without notice.
(c) We may decline to assist with anything, and we don’t have to give a reason.
(d) Work that goes beyond answering a question about the platform — data migration, imports, bulk changes, configuration, training, integration work, or repairing something you or Your Users have done — is outside support entirely. We may decline it, or quote for it as a separate paid service.
(e) We may in future offer paid support plans with defined service levels. If we do, those service levels apply only to customers who have bought that plan, and only on its terms. Until then, no service level applies to anyone.
(f) If a workspace belongs to a Partner’s client, the Partner provides all support for it. We provide none to that client directly, except as clause 2.3 of the White Label Partner Terms allows.
4.5 Changes to the platform. We’re constantly developing Penguin Pilot. We may add, change, or remove features and modules at any time. If we permanently remove a material
feature that you’re actively using, and there’s no reasonable equivalent, we’ll give you at least 30 days’ notice by email or in the platform, and you may cancel the affected part of your subscription without penalty before the change takes effect.
4.6 Beta programs. We run beta, preview and early access programs. They work differently from the rest of the platform and carry real risk to your data. Section 4A sets out the rules, and you should read it before you join one.
4.7 Third-party dependencies. Parts of the platform rely on third parties (see Schedule 3). If a third party changes, restricts, prices or withdraws its service, the corresponding feature may change or stop working. That isn’t a breach of these terms by us.
4A. Beta programs
In short: betas are experiments. They break, they change, they can disappear, and if we fold one into the main platform your data may not come with it. Join one to help us build it — not to run your business on it.
What a Beta Program is
4A.1 From time to time we invite customers into a Beta Program — a product or module we’re still building, offered for evaluation and feedback rather than as a finished service. We may call it beta, preview, early access, pilot, trial release or something similar. It means the same thing.
4A.2 The Beta Programs running as at the effective date of these terms are: Web Builder, Video Studio and Social Media Automation. The current list, and what each one includes, is shown in the platform. We may add or remove Beta Programs at any time, and doing so is a minor change under clause 23.2.
4A.3 Joining is voluntary and you can leave at any time. If you’re in one and you’d rather not be, turn it off in the platform or tell us.
Betas are built differently — and that changes things
4A.4 A Beta Program is not part of the main platform. We build them separately so we can move quickly, which means a Beta Program may use:
(a) different authentication — a separate login, separate credentials, and possibly no single sign-on, multi-factor authentication or session controls;
(b) a different payment gateway — a separate checkout, a separate payment relationship, and separate card handling;
(c) different hosting, storage and infrastructure, in a different location from the one in clause 9.7; and
(d) different third parties from those listed in Schedule 3.
4A.5 What that means for the rest of these terms. While you’re using a Beta Program:
(a) the security measures in clause 17 apply only so far as they’ve been built — tenant isolation, permissions, encryption, audit logging and access controls may be incomplete, absent, or work differently;
(b) the workspace permissions and roles you’ve configured in the main platform may not carry across. Check who can see what inside the beta before you put anything in it;
(c) clause 7 (fees and payment) may not apply. Where a Beta Program is paid for through a different gateway, the payment terms are the ones shown to you at that checkout;
(d) your usage may not be metered, or may be metered differently, and Schedule 2 may not apply; and
(e) Schedule 3 may not list the third parties involved. We’ll tell you at signup where a Beta Program sends data somewhere the main platform doesn’t.
4A.6 Your credentials are still your responsibility. Clause 3.5 applies to a beta login the same as any other, and a beta login is not a reason to reuse a password.
4A.7 Everything else still applies. A Beta Program is still part of the platform for the purposes of these terms. The Acceptable Use Policy, clause 10 (privacy), clause 13A (you are the sender), clause 11 (AI), clause 15 (intellectual property) and clause 20 (indemnity) all apply in full. Your data in a beta is still your Customer Data, and it’s still personal information you’re responsible for under the Privacy Act 2020.
What we don’t promise — which is everything
4A.8 A Beta Program is provided “as is” and “as available”, with no warranty of any kind. To the maximum extent the law allows, we make no promise that it:
(a) works, works correctly, or works at all;
(b) is available, stable, or continues to be available;
(c) is finished, tested, secure, or fit for any purpose;
(d) produces accurate, complete or usable output; or
(e) will ever become a released product.
4A.9 Expect bugs. Beta Programs are not market ready. They contain defects, they behave unpredictably, they lose work, and features change or vanish between sessions without notice.
4A.10 No support and no service levels. Clause 4.4 already says we make no support commitment; for a Beta Program we make even less of one. We may not respond to a beta issue at all.
4A.11 Don’t run your business on it. Do not use a Beta Program for anything you can’t afford to lose, anything time-critical, anything a client is relying on, or anything you have a legal or professional obligation to get right. If you use beta output in front of a client, a vendor or a regulator, that is entirely your decision and your risk.
4A.12 Keep your own copies. Clause 9.5 applies with particular force here. Export anything you’d be upset to lose, and do it regularly.
We can change or stop a beta at any time
4A.13 We may change, restrict, suspend, withdraw or discontinue a Beta Program, in whole or in part, at any time, for any reason, with or without notice, and without liability to you. We don’t have to give a reason, and we don’t have to replace it.
4A.14 We’re not obliged to release a Beta Program as a product, to keep any feature it had, or to keep it at any price.
4A.15 If we discontinue a Beta Program, your data in it may be deleted. We’ll give you notice and a chance to export where we reasonably can, but the 30-day export window in clause 21.8 does not apply to a Beta Program, and we may not be able to provide an export at all. Clause 4A.12 is the answer to this.
If a beta becomes a real product
4A.16 We may fold a Beta Program into the main platform, in whole or in part, or release it as a separate paid module.
4A.17 Your data may not come with it. Beta Programs are built on different foundations, so when we merge one in we often have to rebuild the underlying structure. We do not promise to migrate your beta data, and in many cases we won’t be able to. That includes content, settings, templates, designs, sites, videos, schedules, connections and history.
4A.18 Where migration is possible we’ll offer it, and we’ll tell you before the merge what will and won’t come across so you can export the rest. Where it isn’t, we’ll tell you that too, with as much notice as we reasonably can.
4A.19 What it costs afterwards is a separate question. A Beta Program that becomes a released module may be included in your package, offered as a paid add-on, or priced separately. Using it free during beta gives you no entitlement to it afterwards, at any price, and there is no grandfathering unless we say so in writing.
4A.20 If it becomes a paid module and you don’t want it, you don’t have to take it — but you’ll lose access to it, and clause 4A.17 applies to whatever you had in it.
Fees, feedback and confidentiality
4A.21 Fees. A Beta Program may be free, discounted, or charged. Where it’s charged, the price and payment terms are the ones shown to you when you join, and clause 4A.5(c)
applies. Fees paid for a Beta Program are non-refundable, including where we discontinue it, except where the law requires otherwise.
4A.22 Feedback. The point of a beta is to tell us what’s wrong with it. Clause 15.4 applies: anything you tell us about a Beta Program we may use freely, without owing you anything.
4A.23 Confidentiality. A Beta Program may show you features we haven’t announced. Those are our confidential information under clause 16 until we release them publicly. Don’t demonstrate, screenshot, publish or describe an unreleased Beta Program outside your organisation without our written consent.
Liability
4A.24 We have no liability arising out of a Beta Program — including for defects, downtime, data loss, corruption, security failures, output errors, discontinuation, failure to migrate data, or any commercial consequence of any of those. Clause 19.5(f) applies, and clause 19 applies in full.
4A.25 Clause 19.4 still stands: nothing here limits liability for death or personal injury caused by negligence, for fraud or wilful misconduct, or for anything that can’t be limited by law. Clauses 18.4 and 18.5 apply to Beta Programs as they do to the rest of the platform.
5. Packages, modules and seats
In short: your package decides what you get. Turning on more costs more. Don’t work around the limits.
5.1 Your package defines your access. Which modules you can use, how many seats you have, and what usage allowances are included are all set by the package you subscribe to. This is shown to you when you subscribe and inside the platform.
5.2 New modules. If we release a new module, it becomes part of the platform and is covered by these terms. Whether it’s included in your package, available as an add-on, or priced separately is set out in the platform at the time. You never need to accept new terms to use a new module — but any module-specific rules in Schedule 1 apply automatically when you turn it on.
5.3 Adding modules or seats. You can add modules or seats at any time through the platform. Additional charges start from the date you add them, charged pro-rata for the balance of your current billing period, and then in full from your next billing date.
5.4 Removing modules or seats. You can reduce your modules or seats effective from your next billing date. We don’t refund or credit the balance of a period you’ve already paid for. Removing a module doesn’t delete the underlying data straight away, but you may lose the ability to access, search or export it, so export first.
5.5 No circumvention. You must not do anything designed to get around your package’s limits. That includes sharing seats, running multiple workspaces to split usage that should
sit in one, using automated tools or the API to avoid metering, or accessing modules you haven’t paid for. If you do, we may charge you for the usage you avoided, at our standard rates, and clause 7.9 applies.
5.6 Industry gating. Some modules are only available for particular industries (for example, the real estate modules). We may restrict access accordingly.
6. Usage: meters and credits
In short: five things are measured — Automations, AI Credits, Marketing Emails, Storage and System Usage. Your package includes an allowance of each. Run out, and that part of the platform pauses until your next period unless you buy more. Full detail is in Schedule 2.
6.1 The five meters. We measure your use of the platform against five meters: Automations, AI Credits, Marketing Emails, Storage and System Usage. Schedule 2 explains what each one counts.
6.2 System Usage. System Usage is a single, deliberately general meter that covers the everyday technical consumption of the platform that isn’t separately metered — things like API calls, webhooks, integration syncs, the number of records held in your workspace, background jobs, searches, reports, exports, and publishing or syncing to third-party services. We don’t itemise or separately price each of these. We measure them together as System Usage so that it’s simple to understand and simple to top up. We may change how System Usage is calculated to keep it fair and representative. If a change would materially increase what a typical workspace consumes, we’ll give you at least 30 days’ notice before it takes effect, and you may cancel your subscription before then if you don’t want to continue — in which case we’ll refund the unused prepaid portion of your current period.
6.3 Included allowances. Your package includes an allowance for each meter. Allowances are calculated per workspace, or per seat where your package says so. Allowances reset at the start of each Usage Period and do not roll over — unused allowance is lost.
6.4 Buying more. You can buy additional Credits for any meter at any time, at the prices shown in the platform. Credits are sold in fixed packages, and the size and price of each package is shown before you buy.
6.4A Auto top-up — you authorise us to charge you automatically. You can turn on auto top-up for any meter. It’s off unless you turn it on.
(a) What it does. When your balance for that meter falls below the threshold you set, we automatically buy the credit package you’ve chosen and charge your payment method on file, without asking you again. This can happen more than once in a period, and it can happen at any hour, including while nobody at your business is watching.
(b) You choose the settings. You set the meter, the trigger threshold, the package size, and a maximum spend per Usage Period. We show you the maximum you could
be charged before you turn it on. If you don’t set a maximum, the default for your package applies.
(c) You are responsible for what it buys. Auto top-up does what you configured it to do. A runaway automation, a misconfigured workflow, a bulk import, a looping integration or an unexpected spike in usage can consume credits quickly, and auto top-up will keep buying until it hits your cap. That’s your usage and your charge. Set a cap you’re comfortable with.
(d) When it stops. Auto top-up stops for the rest of the Usage Period once you hit your maximum spend, and the meter then pauses under clause 6.6. It also stops if your payment method fails or is declined — in which case the meter pauses and we’ll tell you.
(e) We’ll tell you each time. We email the billing contact on your account each time an auto top-up is purchased, and we show every purchase in the platform. Those notifications are a courtesy: a notification that doesn’t arrive, or arrives late, doesn’t affect the validity of the charge.
(f) Turning it off. You can turn auto top-up off at any time in the platform, and it takes effect immediately. Purchases already made before you turn it off still stand.
(g) We may pause it. We may suspend your auto top-up and contact you if the pattern of purchases looks anomalous — for example a sudden burst of top-ups that doesn’t match your normal usage. We don’t have to, and not doing so isn’t a failure on our part.
6.4B No refunds on auto top-ups. Credits bought by auto top-up are non-refundable, in exactly the same way as credits you buy by hand, and we don’t reverse an auto top-up charge because you didn’t intend the usage that triggered it. They expire on the same terms as any other Purchased Credits (clause 6.9). Clause 6.10 applies to them in full. If you’d rather approve every purchase, don’t turn auto top-up on.
6.5 The order things are used up. For each meter, we consume your included allowance first, then any purchased Credits, oldest purchase first.
6.6 Running out. If you use up your allowance and have no Credits left for a meter, the features that rely on that meter will pause until the start of your next Usage Period or until you buy more Credits — whichever comes first. This is a limit of your package, not a failure of the platform, and we’re not liable for what happens while a feature is paused. You should watch your usage. We show it in the platform and we’ll send warnings as you approach a limit, but those warnings are a courtesy — we don’t guarantee they’ll arrive or arrive in time.
6.7 Metering isn’t instant. Usage is measured and enforced on a short delay. You may be able to keep using a feature briefly after you cross a limit, and you remain liable for that usage. Equally, a pause may take a few minutes to lift after you top up.
6.8 Credits are not money. Credits are a prepayment for future use of the platform. They have no cash value, can’t be exchanged for money, can’t be transferred between workspaces or to another person, and are not a deposit held for you.
6.9 Credit expiry. Included allowances expire at the end of each Usage Period. Purchased Credits expire 12 months after the date you buy them, or when your subscription ends if that’s earlier.
6.10 No refunds on Credits. Purchased Credits are non-refundable, whether you bought them by hand or through auto top-up, and we don’t refund unused, partly used, expired or forfeited Credits — except where the law requires us to, or where clause 21.7(d) applies because we ended the arrangement.
6.11 Overage billing. Some packages let you keep going past an Included Allowance instead of pausing, by billing the extra usage at the published unit rate for that meter. Where your package does this, we’ll show you the unit rate, and you can set a hard cap on how much overage you’ll allow in a Usage Period and a threshold at which we warn you. When you hit your cap, clause 6.6 applies and the feature pauses. If you haven’t set a cap, the default cap for your package applies. Overage is billed in arrears with your next invoice.
6.12 Fair use. Even within your allowances, you must not use the platform in a way that materially degrades it for other customers. If your usage is an extreme outlier, we’ll contact you first and work with you before taking action, unless the issue is urgent.
7. Fees and payment
In short: pay on time, in NZ dollars, plus GST. Fees are non-refundable. If you don’t pay, we can suspend you.
7.1 What you pay. You pay the subscription fees for your package, plus any charges for extra seats, extra modules, Credits, per-transaction charges, ad spend, and anything else you buy through the platform.
7.2 Currency and GST. All amounts are in New Zealand dollars unless your order or the platform says otherwise. (Wholesale pricing to white label Partners is set in United States dollars — see clause 6.12 of the White Label Partner Terms. That doesn’t change what you pay here.) All amounts exclude GST and any other applicable taxes, which you pay on top. If we’re required to withhold tax, you’ll gross up so we receive the full amount.
7.3 When you pay. Subscription fees are payable in advance — monthly or annually, as your package says. Usage charges, Credits and per-transaction charges are payable when incurred or in arrears with your next invoice, as shown in the platform.
7.4 How you pay. You must keep a valid payment method on file and authorise us (and our payment processor) to charge it for all amounts due — including recurring subscription charges and automatic credit purchases under clause 6.4A, without further
authorisation from you each time. If we invoice you instead, payment is due within 14 days of the invoice date. Card payments may carry a surcharge, notified before you pay.
7.5 Automatic renewal. Your subscription renews automatically for successive periods of the same length until it’s cancelled under clause 21. We’ll email you a reminder before an annual subscription renews.
7.6 Non-refundable. Except where the law requires otherwise, all fees are non-refundable. That includes fees for a period you’ve paid for but then stop using, and fees for seats or modules you remove mid-period. We don’t give partial-period refunds.
7.7 Price changes. We may change our prices. We’ll give you at least 30 days’ notice by email or in the platform. The new price applies from your next billing date after the notice period ends. If you don’t want to pay the new price, you can cancel under clause 21 before it takes effect, and if you’ve prepaid for a period that extends past the change, we’ll refund the unused prepaid portion on a pro-rata basis. Prices agreed in a signed order form for a fixed term won’t change during that term.
7.8 Late payment. If you don’t pay on time we may charge interest on the overdue amount at 3% per annum above our bank’s corporate overdraft reference rate, calculated daily from the due date until payment. We may also charge you our reasonable costs of recovering the debt, including debt collection and legal costs.
7.9 Suspension for non-payment. If an amount is more than 7 days overdue, we’ll send you a reminder. If it’s still unpaid 7 days after that reminder, we may suspend your access to the platform until it’s paid in full. Suspension doesn’t stop fees accruing, and doesn’t extend your subscription period. We may charge a reactivation fee, which we’ll publish in our fee schedule at https://penguinpilot.ai/fees and tell you about before we charge it.
7.10 Disputed invoices. If you think an invoice is wrong, tell us within 14 days of the invoice date with reasons. You must still pay the undisputed part on time. We’ll work with you in good faith to resolve the disputed part quickly.
7.11 Set-off. You must pay all amounts in full without set-off, deduction or counterclaim. We may set off any amount you owe us against any amount we owe you.
- Ad spend, pass-through and transaction charges
In short: if you run ads or trigger a per-transaction charge through the platform, here’s how that’s billed.
8.1 Ad spend runs through your own accounts. Advertising you create in the platform is published to your own connected advertising accounts (for example your Meta ad account). You pay the advertising platform directly — we don’t hold, fund or pass through your ad spend, and we don’t have an ad balance.
8.2 Our advertising margin. We charge a usage margin on the advertising spend you run through the platform, calculated as a percentage of that spend at the rate shown in the
platform. It’s our fee for the campaign tools, publishing and reporting — not a share of your spend and not a payment to the advertising platform. We bill it in arrears with your next invoice, based on the spend the advertising platform reports for the period. It is non-refundable.
8.3 Ad platform rules. Your advertising must comply with the rules of the advertising platform. We’re not responsible if an ad is rejected, an account is restricted or suspended, spend is lost, or reporting is delayed or inaccurate because of a third party’s decision, outage or policy change. Where our figures and the advertising platform’s differ, theirs prevail, and we’ll adjust our margin accordingly.
8.4 Per-transaction charges. Some packages include charges triggered when a record reaches a particular point — for example when a property settles or an offer goes unconditional. Where these apply, the trigger and the amount are shown in the platform before you enable them. The charge becomes payable when the trigger occurs, whether or not the underlying transaction is later reversed, unless we agree otherwise in writing.
8.5 Third-party pass-through costs. Some features carry costs we pay to third parties on your behalf (SMS, portal listing fees, e-signature charges, AI provider costs). Advertising spend is not one of them — see clause 8.1. Where we pass those through, we show them in the platform. Third parties can change their pricing; if that happens we may change ours on 30 days’ notice under clause 7.7.
9. Your data
In short: your data is yours. We only use it to run the platform for you and to produce anonymous statistics. Keep your own backups.
9.1 Ownership. You own your Customer Data. Nothing in these terms transfers ownership of it to us.
9.2 Our licence. You grant us a worldwide, non-exclusive, royalty-free licence to host, store, copy, transmit, display, adapt and process your Customer Data, but only to the extent needed to: provide and support the platform for you; keep it secure; comply with the law; and produce Aggregated Data under clause 9.4. This licence ends when your data is deleted under clause 21.
9.3 Sub-processors. We may use the third parties listed in Schedule 3 and in our Privacy Policy to help provide the platform. We remain responsible to you for their handling of your Customer Data on our behalf.
9.4 Aggregated Data. We may generate anonymised, aggregated statistical data from platform activity — for example, benchmark figures, market statistics and product analytics. Aggregated Data is produced by irreversibly anonymising and aggregating information before it leaves your workspace boundary, so that it never identifies you, Your Users or any individual, contains no personal information, and cannot be re-identified. Once it is in that form it is no longer your Customer Data: we own it and may use and
disclose it for any purpose, including improving the platform and publishing market insights. We do not otherwise use your Customer Data for our own purposes — this is what allows us to hold it as your agent under clause 10.1(b).
9.5 We are not your archive. You are responsible for keeping your own copies of anything you can’t afford to lose. We take backups as part of running a reliable service, but we don’t offer backup as a service, we don’t guarantee that any particular data can be restored, and we don’t guarantee point-in-time recovery. Export tools are available in the platform throughout your subscription — use them.
9.6 Export. You can export your Customer Data in standard formats at any time during your subscription using the platform’s export tools. Clause 21 covers export after termination.
9.7 Data location. We store Customer Data on servers in Australia. We and our sub-processors may access and process it from New Zealand, Australia and other countries where they operate. Our Privacy Policy sets out how we protect personal information when it moves across borders.
10. Privacy and other people’s personal information
In short: most of the personal information in your workspace belongs to other people — your vendors, buyers, leads and contacts. Under NZ privacy law, that’s your responsibility, not ours. Read this one properly.
10.1 Who is responsible for what. Under the Privacy Act 2020:
(a) You are the agency responsible for the personal information you put into, or collect through, the platform — your contacts, leads, vendors, buyers, form respondents, open-home attendees, email recipients, document signers, employees and anyone else. You decide why it’s collected and what’s done with it.
(b) We hold and process that information on your behalf, as your agent under section 11 of the Privacy Act. We only use it to provide the platform to you and as set out in clause 9.2.
(c) We are the agency responsible for the account and usage information we collect about you and Your Users directly — billing details, login records, support conversations and usage analytics.
(d) Where a workspace belongs to a Partner’s client, the chain runs one step longer: that client is the agency responsible for the personal information in its workspace; the Partner holds it on that client’s behalf and is responsible to us for it; and we hold it on the Partner’s behalf. The Partner’s privacy statement, not ours, applies to that client and to the people whose information it holds. Clause 8 of the White Label Partner Terms sets out what the Partner must do.
10.2 Your obligations. You must:
(a) have a lawful basis and all necessary authority to collect, hold and use every piece of personal information you put into the platform;
(b) have your own privacy statement, and give the people whose information you hold the notices privacy law requires;
(c) comply with IPP 3A — since 1 May 2026, where you collect personal information about a person from a source other than that person (for example, buying a lead list, receiving a referral, capturing vendor or buyer details from a third party, or importing contacts you didn’t collect yourself), you must take reasonable steps to make that person aware that you hold their information, why, who will receive it, who you are, and their rights of access and correction. The platform gives you tools that can help — contact-update links, form notices, unsubscribe handling — but it’s your obligation, not ours, and configuring it is up to you;
(d) respond to access, correction, deletion and complaint requests from the people whose information you hold. We’ll give you reasonable help to locate, export or delete information in your workspace so you can respond; if a request takes significant work we’ll quote you before we start, and we won’t charge without your agreement; and
(e) comply with the Privacy Act 2020 and any other privacy or data protection law that applies to you, including offshore laws if you operate outside New Zealand.
10.3 Requests that come to us. If someone contacts us directly about personal information in your workspace, we’ll normally tell them to contact you, and let you know. We won’t respond on your behalf unless the law requires us to.
10.4 Sensitive categories. Some parts of the platform handle information that carries extra risk — voice samples used for voice cloning, signature images and signing audit trails, payroll and remuneration data, and financial account references. You must have express, documented consent from each individual before you put that kind of information into the platform, and you must not use it for any purpose that person hasn’t agreed to. Voice cloning in particular requires the documented consent of the person whose voice it is.
10.5 Privacy breaches. If we become aware of a security breach affecting your Customer Data, we’ll tell you without undue delay and give you the information you reasonably need to assess it. Where the workspace belongs to a Partner’s client, we notify the Partner, and clause 8.4 of the White Label Partner Terms then requires the Partner to tell its client — who decides on and makes any notification. You are responsible for deciding whether the breach is notifiable under the Privacy Act and for notifying the Privacy Commissioner and affected individuals. We’ll cooperate with you and won’t unreasonably delay or obstruct your notification.
10.6 Our Privacy Policy. Our Privacy Policy at https://penguinpilot.ai/privacy explains what we do with personal information we’re responsible for. It forms part of these terms.
11. AI features
In short: AI is a tool, not an expert. Check everything before you rely on it or send it to a client. We don’t train public AI models on your data.
11.1 What we provide. Parts of the platform use AI to draft copy, generate campaigns and workflows, score and suggest prospects, write market updates, parse invoices and documents, generate training content, create images, logos and designs, build websites and widgets, synthesise voice, and answer questions about your own content.
11.2 Your inputs, your outputs. You keep ownership of everything you put into an AI Feature. As between you and us, you own the output that AI Feature generates for you, and we assign to you whatever rights we have in it. This is subject to the rest of these terms and to any rights in third-party content the output incorporates.
11.3 Outputs are not unique. AI can generate the same or similar output for different customers. We can’t and don’t promise your output is original, unique, or free of third-party rights. If the output matters commercially — a logo, a brand, a website — you should do your own clearance checks before you use it.
11.4 No warranty of accuracy. AI output may be wrong, incomplete, out of date, biased or fabricated. We give no warranty about the accuracy, completeness or reliability of any AI output.
11.5 You must review it. You are responsible for reviewing and evaluating every AI output — including by human review — before you use it, act on it, send it to anyone, or publish it. Do not use AI output as though it were checked work.
11.6 Not professional advice. Penguin Pilot is a software platform. We are not a law firm, an accounting firm, a valuer, a financial adviser or an employment adviser, and neither we nor our AI Features give you legal, financial, tax, valuation, employment or other professional advice. You must not present AI output as professional advice, and you must not rely on it as a substitute for advice from a qualified person. This applies especially to market updates, appraisals and property estimates, contract and clause drafting, invoice and payroll processing, and anything you send to a client.
11.7 Training. We do not use your Customer Data to train, fine-tune or improve any AI model — not a third party’s, and not our own. We contract with our AI providers so that data we send them on your behalf is not used to train their models. Where a feature learns from content (for example the training assistant answering questions about your own material), it does so within your workspace only, and never across workspaces. We may use anonymised, aggregated information about how AI Features are used to improve the platform, in line with clause 9.4.
11.8 AI providers are sub-processors. AI Features send data to third-party AI providers to generate output. Those providers are listed in Schedule 3 and in our Privacy Policy. By using an AI Feature you instruct us to send the relevant data to them.
11.9 Metering. AI Features consume AI Credits. Which actions consume Credits, and how many, is shown in the platform. Clause 6 and Schedule 2 apply.
11.10 Prohibited AI uses. You must not use AI Features to generate unlawful, deceptive, harassing or infringing content, to impersonate a real person, to clone a voice without that person’s documented consent, to create content that presents AI output as human-verified professional advice, or to attempt to extract, reverse engineer or replicate any underlying model. Our Acceptable Use Policy has the full list.
12. Integrations and third-party services
In short: connecting to Xero, Outlook, Meta, Trade Me and the rest is your call, and their terms apply to you.
12.1 The platform connects to third-party services. Schedule 3 lists the main ones. We may add or change them, and we’ll update Schedule 3 and our Privacy Policy when we do.
12.2 You need your own accounts and authority. Where an integration uses your account with a third party, you must hold that account lawfully and have authority to connect it. You are responsible for complying with that third party’s terms, and for any fees they charge you.
12.3 What connecting means. When you connect an integration, you instruct us to exchange data with that third party on your behalf, using the access you’ve granted. We store the necessary access tokens securely and use them only for that purpose.
12.4 We’re not responsible for third parties. We don’t control third-party services. We’re not liable for their availability, accuracy, security, pricing, policy changes, or for any loss you suffer from using them or from them ceasing to work with us.
12.4A Domains and sending domains. Where you connect or transfer a domain, or set up a sending domain, that domain is yours and stays yours. Where we register or hold a domain on your behalf, we do so as your agent, and we’ll transfer it to you on request when your account is in good standing. Where a domain was set up for a Partner’s client, it belongs to that client, not to the Partner — if the Partner’s arrangement with us ends, we may release the domain to the client on request, and clause 10.5 of the White Label Partner Terms requires the Partner to allow it. Domains registered through us may be subject to the registrar’s own terms and to nameserver requirements while they’re held with us.
12.5 Disconnection. You can disconnect an integration at any time. We’ll disconnect integrations and delete stored tokens when your subscription ends. Disconnecting doesn’t delete data the third party already holds — that’s between you and them.
13. Public pages and shared links
In short: the platform can publish pages and links that anyone with the address can open. What you publish is your call and your responsibility.
13.1 The platform lets you create pages and links that people can open without logging in — vendor dashboards, buyer file portals, booking pages, public forms, feedback links, open-home sign-in, brand boards, voice memo playback, photographer upload links and document signing sessions.
13.2 You decide what goes on them. You are responsible for the content of every public page and link you create, for who you send it to, and for making sure you’re allowed to publish what’s on it.
13.3 Links are not secret. A tokenised link is hard to guess, but it isn’t a password. Anyone who has the link can open the page. Don’t publish anything through a link that would cause harm if it were forwarded. You can revoke or expire links in the platform, and you should.
13.4 Public file storage. Some content — images, avatars, brand assets, marketing images, property photos — is served from public storage so it loads fast on public pages. Content in public storage can be accessed by anyone with the URL. Don’t put anything confidential there.
13.5 Visitor Terms. People who use these public pages are covered by our Visitor Terms at https://penguinpilot.ai/visitor-terms — except where a Partner has published its own equivalent under clause 7.2(n) of the White Label Partner Terms, in which case those apply on that Partner’s pages. Visitor terms don’t create any relationship between us and your clients beyond what’s needed to run the page.
13A. Communications — you are the sender
In short: we supply the pipe. Every message that leaves it is yours, in law and in fact.
13A.1 Our role. We are a technology provider. We supply the software that lets you send email, SMS, voice and other messages. We do not create, initiate, time, target or control any message you send. Every message sent from your workspace is created and initiated by you or Your Users.
13A.2 You are the sender. Wherever a law puts obligations on whoever sends, advertises or markets something, those obligations are yours, not ours. You are the sender of every commercial message that leaves your workspace — including messages the platform sends automatically on your instructions, and messages an automation or AI feature drafted for you. We are never the sender.
13A.3 Your compliance obligations. You are solely responsible for complying with every law that applies to the messages you send, including:
(a) the Unsolicited Electronic Messages Act 2007 (NZ) — consent, sender identification and functional unsubscribe;
(b) the Privacy Act 2020, including IPP 3A where you contact someone whose details you got from a third party;
(c) the Fair Trading Act 1986, for the accuracy of what you claim in a message;
(d) the rules of the carriers and messaging networks you send through; and
(e) if you send outside New Zealand, the equivalent laws where your recipients are — including Australia’s Spam Act 2003, Canada’s CASL, the US CAN-SPAM Act and the GDPR.
13A.4 Consent evidence. You must hold, and be able to produce, evidence of consent for every recipient. Keep it. This obligation survives termination.
13A.5 Compliance features are a convenience. The platform includes tools that help with compliance — unsubscribe handling, suppression lists, consent fields, sending-domain setup. They exist to make your life easier, nothing more. They aren’t legal advice, using them doesn’t make you compliant with anything, and setting them up correctly is your job. The fact that the platform has a feature is not us telling you that using it satisfies the law.
13A.6 Complaints and regulatory contact. If a regulator, carrier or recipient contacts us about a message sent from your workspace, we may give them your identity and the records we hold, and we may suspend your sending immediately while we look into it. Clause 20.1(c) means the cost of any resulting claim is yours.
14. Acceptable use
In short: don’t do the obvious bad things. Full list in the AUP.
14.1 You must comply with our Acceptable Use Policy at https://penguinpilot.ai/acceptable-use, which forms part of these terms. In summary, you must not use the platform to send spam, hold data you have no right to hold, clone a voice without consent, present AI output as professional advice, get around your package’s limits, resell the platform without a partner agreement, access another workspace, or break the law.
14.2 We may investigate suspected breaches and may remove content, disable features, suspend users, or suspend your workspace where we reasonably believe there’s a breach — immediately, and without notice, if the breach is serious, unlawful, or creates a risk to us, the platform or another customer. Otherwise we’ll give you notice and a reasonable chance to fix it.
14.3 We’ll restore access once the issue is resolved to our reasonable satisfaction. We may charge our reasonable costs of dealing with a breach, itemised and notified to you before we invoice them.
15. Intellectual property
In short: the platform is ours, your content is yours.
15.1 We and our licensors own all intellectual property rights in the platform — the software, interfaces, designs, documentation, templates we supply, and every improvement or modification to them. You get the right to use it, not to own it.
15.2 You must not copy, modify, adapt, translate, create derivative works from, reverse engineer, decompile or disassemble the platform, or try to derive its source code, except to the extent the law says you may despite this clause.
15.3 You must not remove or obscure our (or anyone else’s) trademarks, copyright notices or proprietary notices, except where you’re operating under a white label arrangement that expressly permits it.
15.4 Feedback. If you give us ideas, suggestions or feedback about the platform, we may use them freely, without owing you anything.
15.5 Your brand. You grant us a limited licence to use your name and logo inside the platform to provide branded features to you (branded emails, forms, portals, documents). We won’t use your name or logo in our own marketing without your prior written consent.
15.6 Take-down. If you believe content on the platform infringes your rights, email support@penguinpilot.ai with your contact details and enough information for us to assess it. We’ll review it and decide what action to take, and we’ll respond promptly.
16. Confidentiality
In short: keep each other’s confidential information confidential.
16.1 Each of us may receive information from the other that is confidential or would obviously be treated as confidential. Each of us must keep the other’s confidential information secret, use it only for the purposes of our agreement, and only share it with people who need it and are under similar obligations.
16.2 This doesn’t apply to information that is public through no fault of the receiver, was already known to the receiver, is independently developed, or must be disclosed by law or a regulator (in which case the receiver will tell the other party first, if it’s allowed to).
16.3 Your Customer Data is your confidential information. The platform, its features, pricing not publicly published, and our roadmap are our confidential information.
17. Security
In short: we take security seriously and we’ll tell you if something goes wrong. You have to do your part too.
17.1 We maintain technical and organisational security measures appropriate to the nature of the platform and the data it holds, including tenant isolation, access controls, encryption in transit, audit logging and vulnerability management. We may change these measures, provided we don’t materially reduce the overall level of protection.
17.2 You must do your part: use strong, unique credentials; enable multi-factor authentication where offered; manage roles and permissions properly; remove users who leave; and keep your own devices and networks secure.
17.3 If we become aware of a security incident affecting your Customer Data, we’ll notify you without undue delay, tell you what we know, and keep you updated. Clause 10.5 covers who notifies whom.
17.4 Reporting a vulnerability. If you find a security vulnerability, tell us at support@penguinpilot.ai. We’ll work with you in good faith and we won’t pursue anyone who reports responsibly, stops as soon as they’ve confirmed the issue, and doesn’t access, copy or disclose anyone else’s data. We don’t run a bug bounty and we don’t pay for reports.
18. Warranties and disclaimers
In short: we do our best, but we can’t promise the platform is perfect or that everything in it is accurate. If you’re in business, consumer protection laws don’t apply to you.
18.1 We warrant that we will provide the platform with reasonable care and skill, and that we have the right to grant you the rights in these terms.
18.2 What we don’t warrant. To the maximum extent the law allows, we do not warrant or guarantee that:
(a) the platform will be uninterrupted, timely, secure or error-free;
(b) it will meet your particular requirements or expectations;
(c) any content, data or output in the platform is accurate, complete or current — including AI output, property data, portal data, market statistics, third-party data and data entered by you or anyone else;
(d) any document signed through the platform is valid, binding or enforceable in your circumstances (see Schedule 1, Part F);
(e) any marketing campaign, listing, advertisement or automation will achieve any particular result; or
- (f) any loss of data will not occur; or
- (g) support will be provided at all, within any timeframe, or to any standard — we give no service levels and no service level agreement, and clause 4.4 governs; or
- (h) any Beta Program will work, remain available, or ever be released — section 4A governs, and it disclaims more than this clause does.
18.3 Everything else is excluded. Other than the warranties expressly given in these terms, and to the maximum extent the law allows, all warranties, guarantees, terms and conditions implied by law are excluded.
18.4 Business use — Consumer Guarantees Act. Penguin Pilot is business software, and we supply it in trade. Where you acquire the platform in trade for the purposes of a business, you and we agree in writing that the Consumer Guarantees Act 1993 does not apply, and that it is fair and reasonable for us both to be bound by that agreement — having regard to the nature of the platform, its value, your ability to assess it and to obtain advice, and the fact that our pricing reflects this allocation of risk. If you acquire the platform as a consumer under that Act, this clause does not apply to you at all, and your rights under that Act are unaffected. We ask for your business details at signup so that we both know which applies.
18.5 Fair Trading Act. Where you acquire the platform in trade, and we supply it in trade, you and we agree in writing that sections 9, 12A, 13 and 14(1) of the Fair Trading Act 1986 do not apply, and that it is fair and reasonable to be bound by this provision. This clause does not apply where you are not in trade.
18.6 Nothing in these terms excludes or limits any liability that cannot be excluded or limited by law.
19. Liability
In short: neither of us is liable for indirect losses, and our total liability is capped at 3 months’ fees.
19.1 Indirect loss. Neither party is liable to the other for any loss of profit, revenue, savings, business, goodwill, opportunity, anticipated savings, or for any indirect or consequential loss, however caused, whether in contract, tort (including negligence), under statute or otherwise.
19.2 Loss of data. To the maximum extent the law allows, we are not liable for any loss, corruption or unavailability of Customer Data. Clause 9.5 explains why you must keep your own copies.
19.3 Cap. Our total aggregate liability for all claims arising out of or in connection with these terms, whether in contract, tort (including negligence), under statute or otherwise, is
limited to the greater of NZ$500 and the total fees you paid us in the 3 months immediately before the event giving rise to the claim.
19.4 What the cap doesn’t cover. Clauses 19.1 to 19.3 do not limit liability for death or personal injury caused by negligence, for fraud or wilful misconduct, or for any liability that cannot be limited by law.
19.5 Things we’re not liable for at all. To the maximum extent the law allows, we have no liability for:
(a) anything caused by your breach of these terms or by Your Users;
(b) content, data or instructions you or anyone else put into the platform;
(c) third-party services, including their availability, accuracy, decisions or policy changes;
(d) features pausing because you’ve used up an allowance or run out of Credits;
(e) suspension or termination that we’re entitled to make under these terms; or
(f) Beta Programs, which section 4A governs; or
(g) support we don’t provide, delay in providing, decline to provide, or withdraw.
19.6 Contributory conduct. Our liability is reduced to the extent that you, Your Users or anyone associated with you contributed to the loss.
19.7 Time limit. You must bring any claim under these terms within 12 months of the date you first became aware, or ought reasonably to have become aware, of the circumstances giving rise to it.
19.8 Force majeure. Neither party is liable for a failure to perform caused by something outside its reasonable control — including natural disaster, epidemic, war, terrorism, civil unrest, industrial action, government action, failure of power or telecommunications, internet or hosting provider failure, or cyber attack. This doesn’t excuse an obligation to pay money that’s already due.
20. Indemnity
In short: if you get us into trouble with your data or your marketing, you cover us.
20.1 Where you acquire the platform in trade, you indemnify us against all losses, damages, costs and expenses (including reasonable legal costs) we suffer arising from any claim relating to:
(a) your Customer Data, including a claim that it infringes someone’s rights or was collected or used unlawfully;
(b) your failure to obtain the consents, authorisations and notices required by clause 10;
(c) messages you send through the platform, including any claim or regulatory action under the Unsolicited Electronic Messages Act 2007 or equivalent spam law;
(d) content you publish through public pages, websites, forms, listings or advertising;
(e) your use of AI output, including any claim that it is inaccurate, infringing or was presented as professional advice; or
(f) your breach of these terms or the Acceptable Use Policy.
20.2 We’ll tell you promptly about any claim we want to be indemnified for, let you take conduct of the defence if you want it (using lawyers we reasonably approve), and give you reasonable assistance at your cost. You must not settle any claim in a way that admits fault on our part or imposes an obligation on us without our written consent.
21. Term, cancellation and what happens afterwards
In short: cancel before your renewal date. Fees already paid aren’t refunded. You get 30 days after termination to export your data before we delete it.
21.1 Term. Your subscription starts when you first subscribe and continues for the period in your package, renewing automatically under clause 7.5 until cancelled.
21.2 Trials. If we offer you a trial, you can use the platform on these terms for the trial period. If you don’t cancel before the trial ends, your subscription starts and you’ll be charged from that date. Trials are not meant to be run back to back. If we find you’re taking consecutive trials, or creating new workspaces, businesses or email addresses to keep trialling rather than subscribing, we may end the trial immediately, charge you for the period you’ve used at our standard rates, and refuse you further trials.
21.3 Cancelling. You may cancel your subscription:
(a) for a monthly subscription, by giving notice at least 7 days before your next billing date; or
(b) for an annual subscription, by giving notice at least 30 days before the renewal date.
Cancel through the platform or by emailing support@penguinpilot.ai. Cancellation takes effect at the end of your current paid period. You keep access until then. Prepaid fees are not refunded.
21.4 Suspension by us. We may suspend your access immediately if: you don’t pay (clause 7.9); we reasonably believe you’ve breached the Acceptable Use Policy or clause 5.5; there’s a security or legal risk; or a third party requires it. We’ll tell you and, where the circumstances allow, give you a chance to fix the problem.
21.5 Termination by us. We may terminate your subscription on 30 days’ notice, or immediately if:
(a) you materially breach these terms and don’t fix it within 14 days of us asking you to;
(b) you breach clause 5.5, clause 14 or clause 15 in a way we consider serious;
(c) any amount is more than 30 days overdue;
(d) you become insolvent, go into liquidation, receivership or administration, or make an arrangement with creditors; or
(e) we reasonably believe your use of the platform exposes us to legal or regulatory risk.
If we terminate under clause 21.5(a)–(e), no refunds are payable. If we terminate for convenience on 30 days’ notice, we’ll refund the unused prepaid portion of your subscription on a pro-rata basis.
21.5A Inactive accounts. If a workspace has no paid subscription and no user has logged in for 12 months, we may close it and delete its data. We’ll give at least 30 days’ notice first, so there’s a chance to log in or export. For a workspace in a Partner’s Studio we give that notice to the Partner, who must pass it on to its client.
21.6 Withdrawing the platform. We may decide to stop offering the platform, or a package, entirely. If we do, we’ll give you at least 90 days’ notice and refund the unused prepaid portion of your subscription.
21.7 What happens on termination. When your subscription ends:
(a) your right to use the platform stops immediately;
(b) all amounts you owe us become immediately payable;
(c) we disconnect your integrations and delete stored access tokens;
(d) your Purchased Credits — however they were bought, including by auto top-up — are forfeited where we have terminated for cause under clause 21.5(a)–(e), or where you have cancelled under clause 21.3. Where we terminate for convenience under clause 21.5, withdraw the platform under clause 21.6, or you leave because of a material change under clause 23.3, we will instead refund the amount you paid for unused Purchased Credits. Our advertising margin under clause 8.2 is earned when the spend occurs and is not refunded in any case; and
(e) public pages, links, published websites and pending signing sessions stop working.
21.8 Data export window. For 30 days after termination we will provide read-only access to your workspace so you can export your Customer Data yourself, at no charge, using the platform’s standard export tools. If you’d rather we produced the export for you, ask us and we’ll provide it in a standard machine-readable format; we may charge a fee for a bespoke
or assisted extract, quoted and agreed before we start. Export before you cancel — it’s simpler.
21.9 Deletion. After the 30-day window, we’ll delete your Customer Data from our production systems within a further 30 days, and it will age out of our backups in line with our normal backup cycle (currently 35 days). We may keep data we’re required to keep by law, and Aggregated Data.
21.10 What survives. Clauses 7 (for amounts owed), 9.1, 9.4, 11.2, 15, 16, 18, 19, 20, 21.7–21.10 and 24 survive termination, along with anything else that by its nature should. Clauses 10 (privacy) and 17 (security) continue to apply to your Customer Data until it has been deleted under clause 21.9 — including our obligation to tell you about a security incident affecting it.
22. Partners and white label
In short: if you buy through a Partner, your contract is with them, not with us. If you are a Partner, there’s a separate set of terms for you.
22.1 If you’re a Partner Client, your contract is with your Partner. Your Partner is the merchant of record: it sets your price and packages, it invoices and collects from you, it supports you, and its own terms of service and privacy policy govern your use of the platform. We have no direct agreement with you and no direct obligation to you. If you have a billing question, a service complaint or a request about your data, it goes to your Partner.
22.1A What your Partner must give you. We require every Partner to put its own written terms and privacy policy in place with you before you get a workspace, and those documents must be at least as protective of us as these terms, the Acceptable Use Policy and our Privacy Policy. Your Partner cannot grant you rights we haven’t granted it, cannot make promises about the platform on our behalf, and cannot make us liable to you. If your Partner has told you something about the platform that these terms don’t support, that’s your Partner’s statement, not ours.
22.2 Partner access. Your Partner can access and administer your workspace, including your Customer Data, so that it can set you up, support you and manage your subscription. Your Partner’s terms should tell you this. We’re not responsible for what your Partner does with that access — that’s between you and them.
22.2A Enforcement runs through your Partner. Because our agreement is with your Partner and not with you, we act through them. If we believe a workspace is being used in breach of the Acceptable Use Policy or the law, we may require the Partner to suspend or terminate it, and the Partner must comply promptly. Where the issue is serious, unlawful, or creates a risk to us, the platform, another customer or a member of the public, we may suspend the workspace ourselves without going through the Partner first.
22.3 Partner failure, and going direct. If your Partner’s agreement with us ends, or your Partner stops responding to you, we may contact you and offer to move your workspace to a direct subscription with us at our then-current standard pricing, or place you with another Partner. We’re not obliged to do either. If you accept a direct subscription, these terms then apply to you in full from that date. We’re not responsible for anything you paid your Partner — including prepaid subscription fees, setup, migration, training or consulting.
22.4 If you are a Partner. Reselling, white-labelling, sub-licensing, rebranding or otherwise providing the platform to anyone else requires our White Label Partner Terms at https://penguinpilot.ai/partner-terms, which you must accept in addition to these terms. Without them, you must not do any of those things.
23. Changes to these terms
In short: we can update these terms with notice. Significant changes give you a chance to leave.
23.1 We may change these terms. We’ll publish the updated version and tell you by email or in the platform.
23.2 Minor changes take effect when published. These are: typographical corrections; clarifications that don’t change meaning; adding a new Part to Schedule 1 for a module you haven’t turned on; and removing a third party from Schedule 3.
23.3 Material changes that reduce your rights or increase your obligations take effect 30 days after we notify you. These include adding a new third party to Schedule 3, and any change to a Part of Schedule 1 for a module you’re using. If you don’t accept a material change, you may cancel before it takes effect and we’ll refund the unused prepaid portion of your subscription on a pro-rata basis. Continuing to use the platform after the 30 days means you accept the change.
23.4 We may make a change immediately where it’s needed to comply with the law, to address a security risk, or because a third party requires it.
24. General
24.1 Governing law. These terms are governed by the law of New Zealand.
24.2 Courts. You and we submit to the exclusive jurisdiction of the New Zealand courts.
24.3 Complaints and disputes. If you have a complaint, email support@penguinpilot.ai. We’ll consider it and respond in a reasonable time; we don’t commit to a fixed timeframe. If we can’t resolve it, either of us may refer it to mediation with a mediator agreed between us (or, failing agreement, appointed by the Chair of the Arbitrators’ and Mediators’ Institute of New Zealand) before starting court proceedings. Nothing stops either of us seeking
urgent injunctive relief. Privacy complaints are dealt with under section 14 of our Privacy Policy, which sets out the timeframes the Privacy Act requires.
24.4 Notices. Notices to us go to support@penguinpilot.ai. Notices to you go to the email address on your account, or through the platform. A notice by email is treated as received when sent, unless the sender knows it wasn’t delivered. A notice that starts a period for you to fix something, object to something, or lose a right — clauses 7.7, 21.5(a) and 23.3 — is only effective if we also post it in the platform, so you’ll see it when you next log in. It’s your job to keep your contact details current.
24.5 Assignment. You may not assign or transfer these terms without our written consent, which we won’t unreasonably withhold. We may assign or transfer them, including on a sale of our business, on notice to you.
24.6 Subcontracting. We may subcontract any of our obligations. We stay responsible to you for performance.
24.7 No partnership. Nothing here creates a partnership, joint venture, employment or agency relationship between us, except as expressly stated in clause 10.1(b).
24.8 Entire agreement. These terms, together with the documents listed in clause 1.7, are the entire agreement between us about the platform, and replace anything said or agreed before.
24.9 Waiver. Failing to enforce a right isn’t a waiver of it.
24.10 Severability. If any part of these terms is unenforceable, it’s severed and the rest stays in force.
24.11 Third parties. Except where these terms say otherwise, no one other than you and us has any right to enforce them under subpart 1 of Part 2 of the Contract and Commercial Law Act 2017.
24.12 Counterparts and electronic acceptance. These terms may be accepted electronically, and that acceptance is binding.
Schedule 1 — Module Rules
These rules apply only to the modules you actually use. If you don’t use a module, its rules don’t apply to you. If we release a new module, we may add a new Part to this Schedule.
Part A — CRM, Pipelines, Prospecting and Tasks
A.1 You are responsible for the accuracy of the records you create and for having the right to hold them.
A.2 Prospecting and “who to call” suggestions are generated from your own data and from AI scoring. They are suggestions, not recommendations, and they are not a compliance check. You must still comply with any do-not-call, do-not-contact or marketing-preference obligations that apply to you.
A.3 Pipelines can be configured to trigger charges when a record reaches a stage. Clause 8.4 applies. You are responsible for configuring those triggers correctly, and charges triggered by your configuration are payable.
A.4 Records count towards your System Usage meter.
Part B — Email (connected mailboxes)
B.1 Connecting a mailbox lets us read, sync, send and store messages from that mailbox on your behalf. You must have the right to connect that mailbox and, where it isn’t your own, the account holder’s permission.
B.2 Email contents synced into the platform become Customer Data. Be aware that mail from third parties, including personal correspondence, may be synced. You are responsible for the privacy consequences of connecting a mailbox.
B.3 We’re not responsible for messages that fail to sync or send because of the mail provider, spam filtering, deliverability decisions, or your own mailbox configuration.
Part C — Marketing Emails, SMS and Voice Memos
C.1 Consent. You warrant that you have valid consent — express, inferred or deemed under the Unsolicited Electronic Messages Act 2007 — for every recipient of every commercial message you send through the platform, and that you can evidence it. This applies to lists you upload, lists you import, and audiences you build.
C.2 Identification and unsubscribe. Every marketing message must clearly identify you as the sender with accurate contact details, and must include a functional unsubscribe that stays working for at least 30 days, is free, and can be used by the same method as the message. You must not remove, disable, alter or bypass the platform’s unsubscribe or suppression handling. Unsubscribe requests must be actioned within 5 working days — the platform does this automatically, and you must not undo it.
C.3 Suppression lists. The platform maintains suppression lists from unsubscribes, bounces and complaints. You must not send to a suppressed address, re-import a suppressed address, or move an address between audiences to get around suppression.
C.4 Deliverability. Sending reputation is shared infrastructure. If your sending generates excessive bounces, spam complaints or blocklisting, we may throttle, pause or terminate your sending immediately to protect other customers. We don’t guarantee delivery, inbox placement, or any open, click or conversion rate.
C.5 Sending domains. If you use your own sending domain, you’re responsible for the DNS records we specify and for the reputation of that domain.
C.6 SMS. SMS is subject to the same consent, identification and unsubscribe rules, plus the rules of the carriers and the destination country. SMS charges are passed through under clause 8.5.
C.7 Voice memos and voice cloning. You must have documented consent from the person whose voice is cloned, and that person must be a real person who has agreed to that specific use. You must not clone the voice of a public figure, a deceased person, or anyone who hasn’t consented. You must not use a cloned voice to deceive anyone about who is speaking. We may remove voice models and recordings that we reasonably believe breach this.
C.8 Marketing Emails consume the Marketing Emails meter. Voice generation consumes AI Credits.
Part D — Forms, Bookings, Websites and Widgets
D.1 You are the publisher of every form, booking page, website and widget you create. You are responsible for its content, for its privacy notice, and for the lawfulness of what you collect through it.
D.2 Where a form or booking page collects personal information, you must display a privacy notice that meets your obligations under the Privacy Act 2020, including IPP 3 and (where relevant) IPP 3A.
D.3 Published websites and widgets are served from our infrastructure. We may take down content that breaches the Acceptable Use Policy, is unlawful, or creates a security risk.
D.4 We don’t guarantee any uptime, search ranking, or performance for published sites.
D.5 Booking pages sync with your connected calendar. Double bookings, timezone errors and sync delays can happen. Confirm important appointments independently.
Part E — Social Advertising
E.1 You must hold your own advertising accounts and comply with the advertising platform’s policies. You pay the advertising platform directly for your spend. Clause 8 governs our advertising margin.
E.2 We’re not responsible for ad rejections, account restrictions, disapprovals, spend discrepancies between our reporting and the ad platform’s, or lost spend. The ad platform’s figures prevail over ours.
E.3 Leads captured through lead forms are Customer Data. You are responsible for contacting those leads lawfully.
Part F — Documents and Digi-Sign
F.1 What we provide. We provide software for preparing, sending, signing and storing documents electronically, including audit trails and cryptographic hash chains that record what happened and when.
F.2 What we don’t provide. We are not a law firm and we don’t give legal advice. We don’t draft, review or approve your documents.
F.3 Enforceability is your call. Where you use Digi-Sign properly and in accordance with our documentation, the signature is designed to meet the requirements for an electronic signature under Part 4 of the Contract and Commercial Law Act 2017 — that is, to adequately identify the signatory, adequately indicate their approval, and be as reliable as is appropriate in the circumstances. We do not warrant that any particular document signed through the platform is valid, binding or enforceable. Some documents cannot be signed electronically at all (for example wills, affidavits, statutory declarations, powers of attorney and certain land transfer documents), and some require specific consents or formalities. It is your responsibility to determine whether electronic signing is appropriate for each document, and to take legal advice if you’re unsure.
F.4 Consent to electronic form. You are responsible for obtaining each signer’s consent to sign and receive documents electronically, and for identifying signers correctly.
F.5 Retention. Signed documents and audit records are stored in private storage. You are responsible for keeping your own copies of anything you must retain, including after your subscription ends.
Part G — Design, Brand Studio and Generated Imagery
G.1 Designs, logos, brand boards and images you generate are yours, subject to clause 11.2 and 11.3.
G.2 Templates, fonts, stock imagery and brand elements we supply may be licensed from third parties. You may use them within the platform and in your own outputs, but you may not extract, redistribute or resell them separately.
G.3 AI-generated logos and brand marks are not cleared for trademark use. Before you use a generated mark as a trademark, do your own searches and take advice.
G.4 You must not use the design tools to reproduce someone else’s trademark, copyrighted work or brand without permission.
Part H — Calendar and Microsoft/Google Sync
H.1 Two-way sync is provided on a best-efforts basis. Sync can fail, lag or duplicate. Treat the third-party calendar as the source of truth for anything critical.
H.2 Connecting a calendar grants us access to events, attendees and availability in that account. Clause 12.2 applies.
Part I — Accounting, Payroll and Xero
I.1 The platform records and organises financial information. It is not an accounting system of record, a tax agent, or a payroll bureau, and it does not give accounting, tax or employment advice.
I.2 You must check everything. AI invoice parsing, matching, commission calculations, expense splits, payslips and pay runs must all be reviewed by a competent person before you rely on them, pay anyone, or file anything. We are not liable for underpayment, overpayment, incorrect deductions, tax penalties, or errors in any figure produced by the platform.
I.3 Payroll and remuneration data is sensitive. Clause 10.4 applies. You must restrict access to it using the platform’s permissions.
I.4 Xero and other accounting integrations sync data as you configure them. You are responsible for the mapping, and for reconciling in your accounting system.
Part J — Training Academy
J.1 AI-generated course content, quizzes and answers must be reviewed before you publish them to learners. Clause 11.5 applies.
J.2 Certificates issued through the platform record completion of your course. They are not an accreditation by us and carry no professional recognition unless you’ve arranged that separately.
J.3 The training assistant answers questions using your own workspace content. It can be wrong, and it can surface content the asker was not intended to see if you have configured permissions incorrectly. Check your permissions.
Part K — Real Estate Modules
Available only where your workspace is configured for a real estate or property development industry.
K.1 Property data. Listing data, market statistics, comparable sales, suburb data and estimates come from you and from third parties. We don’t verify them. They are not an appraisal, a valuation, or a registered valuer’s opinion.
K.2 Market updates and vendor reports. Reports generated by the platform — including AI-generated market updates — are marketing and information tools. They must be reviewed by a licensed person before they are sent to a vendor. You are responsible for their accuracy and for compliance with the Real Estate Agents Act 2008, the associated rules, and any REA guidance on advertising and appraisals.
K.3 Portal syndication. Publishing to Trade Me, realestate.co.nz, OneRoof or any other portal is subject to that portal’s terms, data standards and fees, which you must comply with directly. We’re not liable for listings that fail to publish, publish incorrectly, are withdrawn or are delayed, or for fees the portal charges you. Withdrawals and updates may not be instant.
K.4 Vendor and buyer portals. Seller dashboards, buyer file portals and feedback links are public pages under clause 13. You decide what to share with a vendor or buyer, and you’re responsible for it.
K.5 Open homes and viewings. Sign-in data collected at an open home is personal information you collect. You must display an appropriate privacy notice at the point of collection, and comply with IPP 3A where you use it to contact someone about anything other than the property they attended.
K.6 Offers and clauses. Clause templates in the platform are starting points, not legal advice. Every offer, clause and contract must be reviewed by a licensed person and, where appropriate, a lawyer.
K.7 Trust money.
The platform does not hold, receive or handle trust money or deposits. Nothing in the platform is a substitute for your trust accounting obligations.
Part L — Chat, Feed and Notifications
L.1 Chat messages, feed posts, comments, reactions and attachments are created by Your Users. You are responsible for their content and for the conduct of Your Users, and you should have your own internal policy on acceptable use.
L.2 We may remove content, and suspend a user, where we reasonably believe it breaches the Acceptable Use Policy or the law. We don’t monitor internal content routinely.
L.3 Feed images are stored in public storage. Like avatars, brand assets and property photos, images posted to the internal feed are served from public storage so they load quickly. That means anyone with the file’s URL can open it, even if they can’t see the post. Don’t post confidential material as a feed image.
L.4 Chat attachments are stored in private, access-controlled storage.
L.5 Content posted by a user stays in your workspace when that user leaves. It is your Customer Data.
Part M — Automations and API
M.1 Automations run on your instructions. You are responsible for what they do, including messages they send, records they change and charges they trigger.
M.2 Automation runs consume the Automations meter. A run that fails still consumes usage where processing has occurred.
M.3 API access is subject to rate limits, which we may set and change. API calls consume System Usage. You must not use the API to circumvent metering, to scrape the platform, or to build a competing product.
Part N — Social Media Connector
These rules apply if you connect a social media account and publish, schedule or report on posts through the platform. They are written to stand on their own, so they read the same way wherever this connector is offered.
What this module is
N.1 The Social Media Connector lets you connect accounts you already hold on third-party social media platforms — for example Facebook, Instagram, LinkedIn, X, TikTok, YouTube, Pinterest and Google Business Profile — and then compose, schedule, publish and report on posts to those accounts from inside the platform.
N.2 We are a tool, not a broadcaster. We don’t create your posts, choose your audience, or decide when something goes out. Every post published through the connector is composed and scheduled by you, published to your own account, in your own name. You are the publisher of everything that leaves it.
Your accounts and permissions
N.3 You must hold each connected account lawfully and have authority to connect it. If the account belongs to a client, an employer or someone else, you must have their permission, and you are responsible for having it.
N.4 Connecting an account authorises us to act on that account through the platform’s published interfaces, using the permissions you grant — reading profile and page details, posting and scheduling content, and retrieving statistics. We use those permissions only to provide the connector to you.
N.5 We store the access tokens the platform issues, securely, on your behalf. You can disconnect an account at any time, and you can revoke our access from within the social platform itself. Disconnecting stops future scheduled posts for that account; it does not remove anything already published.
N.6 Tokens expire, get revoked, and break when a password changes or an account’s permissions are altered. When that happens, scheduled posts to that account will fail. We’ll show the connection as broken, but keeping your connections alive is your responsibility.
The social platforms’ own rules apply to you
N.7 Each social platform has its own terms, policies and community standards, and they apply to you directly. Connecting an account through us does not put us between you and them. You must comply with:
(a) the terms of service and community guidelines of every platform you connect;
(b) their advertising, commerce, political content and disclosure policies;
(c) their rules on automation, scheduling, duplicate content, and posting frequency; and
(d) their rules about who may post on behalf of whom.
N.8 YouTube. If you connect a YouTube account, you agree to be bound by the YouTube Terms of Service (https://www.youtube.com/t/terms), and you acknowledge that content you upload must comply with them. Google’s Privacy Policy
(https://policies.google.com/privacy) governs Google’s handling of the data involved. You can revoke our access to your Google account at any time via your Google security settings (https://myaccount.google.com/permissions).
N.9 Meta, and every other platform. Where a platform requires you to accept its terms, make a disclosure, or hold a particular account type or permission before an app may post on your behalf, that requirement is yours to meet. We may require you to accept a platform’s terms before we enable a connection.
N.10 We can be required to act by a platform. If a social platform tells us to stop a connection, remove content, or restrict a feature, we’ll comply, and we may disconnect your account without notice. That isn’t a breach of these terms by us.
What you publish
N.11 You warrant that, for everything you publish through the connector:
(a) you own it or have the rights to publish it — including images, video, music, fonts and any third-party material in it;
(b) it doesn’t infringe anyone’s intellectual property, privacy or publicity rights;
(c) it isn’t unlawful, misleading, deceptive, defamatory, harassing or discriminatory;
(d) where it’s an advertisement, an endorsement, a sponsored post or a paid partnership, it is disclosed as one, in the way the law and the platform require; and
(e) where it features a real person, a property, a client or a testimonial, you have the consents you need.
N.12 You own your content. We don’t claim ownership of anything you publish. You grant us only the licence in clause 9.2 — enough to store it, schedule it, format it for each platform, and send it where you’ve told us to send it.
N.13 We don’t review, approve or moderate what you publish. We may remove content or suspend the connector where we reasonably believe it breaches the Acceptable Use Policy, a platform’s rules, or the law.
Publishing is best efforts — read this one
N.14 We do not guarantee that any post will publish. Scheduling a post is an instruction to attempt publication at a time, not a promise that it will appear. Posts fail, and they fail for reasons that are ordinary rather than exceptional:
• the platform’s API is down, slow, rate-limiting us, or has changed;
• your token has expired or been revoked;
• your account has been restricted, suspended, throttled or shadow-limited;
• the platform rejects the content, the format, the media dimensions, the length, or the link;
-
the platform changes what a connected app is allowed to post, or withdraws the capability entirely; or
-
the platform’s own rules on frequency or duplication block it.
N.15 We are not liable for a post that fails to publish, publishes late, publishes twice, or publishes in a form you didn’t intend — including any commercial consequence of that: a missed campaign, a launch, an auction date, an open home, an event, or a time-limited offer. Clause 19 applies in full.
N.16 If it matters, check it. For anything time-critical or high-value, confirm the post actually appeared on the platform. We show delivery status where the platform gives it to us, and we’ll retry a failure where retrying is sensible, but neither is a guarantee.
N.17 Platforms change. Social platforms alter, restrict, price and withdraw their APIs regularly and without meaningful notice. A platform we support today may become unavailable, partially available, or available only on paid terms. We may add or remove supported platforms and features at any time, and clause 4.7 applies — that isn’t a breach of these terms by us.
Statistics and reporting
N.18 Reach, impressions, engagement and follower figures come from the platforms. We pass them through. We don’t verify them, and we don’t warrant they’re accurate, complete or current. Platforms restate figures, backfill, deduplicate and change their definitions, and historic numbers can move.
N.19 Where our figures and a platform’s own reporting differ, the platform’s prevail.
N.20 Some statistics are only available for a limited window, or only for certain account types. When a connection ends or a platform withdraws access, historic statistics may become unavailable, and we may not be able to recover them.
AI-assisted content
N.21 Where you use AI to draft, caption, hashtag or schedule a post, clause 11 applies in full — including that output can be wrong, that you must review it before it goes out, and that you are responsible for it once it does.
N.22 Several platforms now require AI-generated or materially AI-altered content to be labelled. Meeting that requirement is yours, on every platform you post to.
Your account, and enforcement against it
N.23 We are not responsible for what a social platform does to your account. If your account is restricted, suspended, banned, demonetised, deranked or deleted — whether because of what you posted, how often you posted, the platform’s automated enforcement, or for no stated reason at all — that is between you and that platform. We can’t restore it, appeal it, or compel them to explain it.
N.24 Nothing about using the connector reduces the risk of platform enforcement, and using it doesn’t make your posting compliant with anything.
Data and retention
N.25 Posts, drafts, schedules, media and statistics held in the platform are your Customer Data. Clauses 9 and 21 apply, including the export window on termination.
N.26 Content you have already published lives on the social platform, not with us. Deleting a post in the platform does not delete it from the social network unless the network supports deletion through its API and it succeeds. To be certain something is gone, remove it on the platform itself.
N.27 When you disconnect an account, we delete the stored tokens for it. We retain the posts, schedules and statistics already in your workspace unless you delete them.
Usage
N.28 Publishing, scheduling and statistics retrieval consume System Usage. AI drafting consumes AI Credits. Schedule 2 applies, including that a meter running out will pause scheduled publishing until the next Usage Period or a top-up.
Schedule 2 — Usage Meters and Credits
This Schedule sets out what we measure and what happens when you reach a limit. Current allowances, unit rates and Credit prices are shown in the platform and in your package — they aren’t repeated here so that they can be kept current.
1. The meters
| Meter | What it counts | What pauses if you run out |
|---|---|---|
| Automations | Each run of an automation, workflow step, scheduled job or triggered action that performs work in your workspace. | Automations and workflows stop running. Manual work continues. |
| AI Credits | Each use of an AI Feature — generation, summarisation, scoring, parsing, image generation, voice synthesis and similar. Different AI actions consume different numbers of Credits, shown in the platform. | AI Features stop generating. |
| Meter | What it counts | What pauses if you run out |
|---|---|---|
| Marketing Emails | Each marketing or campaign email sent to a recipient, counted per recipient per send. Transactional emails and internal notifications are not counted. | Campaign sending pauses. Queued campaigns hold rather than fail. |
| Storage | The total volume of files and attachments held in your workspace, measured as the amount stored, not the amount uploaded. | New uploads are blocked. Existing files stay accessible. |
| System Usage | The general technical consumption of the platform — see paragraph 2. | Non‑essential background processing, syncs, exports, reports, publishing and API access may pause. Core read access to your data continues. |
2. System Usage — what it covers
2.1 System Usage is deliberately general. It covers the ordinary technical work of running your workspace, including:
- API calls and webhook deliveries
- integration syncs (calendar, mailbox, accounting, advertising, portals)
- the number of records held in your workspace
- background and scheduled jobs
- searches, reports, dashboards and analytics generation
- exports, bulk operations and imports
- publishing, syndication and deployment operations
- rendering and serving of public pages, widgets and websites
2.2 We do not itemise or separately price these operations. They are measured together in a single System Usage meter, and topped up with a single kind of Credit. This is intended to keep pricing simple and predictable rather than to charge for each technical event.
2.3 We may change how System Usage is calculated — including the weighting of different operations — to keep the meter fair and representative of actual consumption. If a change would materially increase what a typical workspace consumes, we’ll give you at least 30 days’ notice, and you may cancel before it takes effect (clause 6.2).
3. How the meters work
3.1 Allowances. Each package includes an allowance for each meter. Allowances may be per workspace or per seat, as your package says. Where an allowance is per seat, adding or removing a seat changes the allowance from the date of the change.
3.2 Reset. Allowances reset at the start of each Usage Period. Unused allowance does not roll over.
3.3 Order of consumption. For each meter we consume: (a) your Included Allowance; then (b) your Purchased Credits, oldest first; then (c) overage, if your package offers it and you’ve enabled it.
3.4 Top-ups. You may buy additional Purchased Credits at any time at the prices shown in the platform. They’re added to the relevant meter immediately.
3.4A Overage instead of pausing. Where your package offers overage billing, you may choose to keep going past your Included Allowance and be billed at the published unit rate rather than pausing. Clause 6.11 of the terms sets out how caps and warnings work.
3.5 Auto top-up. Auto top-up is off unless you turn it on. When it’s on, we automatically buy the credit package you’ve chosen and charge your payment method whenever your balance for that meter falls below your trigger threshold — repeatedly if your usage requires it, up to the maximum spend you’ve set for the Usage Period. Once you hit that maximum, auto top-up stops and the meter pauses under paragraph 3.6. Credits bought this way are non-refundable and are not reversed because the usage that triggered them was unintended. Clause 6.4A of the terms sets out the full rules, including what happens when a payment fails and how to turn it off.
3.6 Running out. When a meter is exhausted, the features that depend on it pause until the earlier of the start of your next Usage Period and your purchase of more Credits. Pausing is a limit of your package, not a service failure. Clause 6.6 and clause 19.5(d) of the terms apply.
3.7 Enforcement delay. Metering is near real time but not instantaneous. Usage that occurs in the short window after a limit is reached is still your usage and is still payable.
3.8 Warnings. We show your usage in the platform and send warnings as you approach a limit. Warnings are a courtesy and are not guaranteed.
3.9 Expiry. Included Allowances expire at the end of each Usage Period. Purchased Credits expire 12 months after purchase, or on termination — but clause 21.7(d) of the terms refunds them where we ended the arrangement rather than you.
3.10 No cash value. Credits are not money, not a deposit, not transferable and not refundable, except where the law requires.
3.11 Storage over limit. If your stored data exceeds your Storage allowance, we’ll ask you to reduce it or buy more. If it stays over the limit for 30 days after we ask, we may block uploads and, after a further 30 days’ notice, archive or delete files above the limit, oldest first. We’ll always tell you before we delete anything.
Schedule 3 — Third-Party Services and Sub-processors
Current as at the effective date. The live list is maintained at https://penguinpilot.ai/subprocessors and in our Privacy Policy. We’ll update it when it changes, and clause 23.3 applies to additions.
Some of these we use to run the platform for every customer. Others only receive data if you choose to connect them — those are marked “on connection”, and connecting one is your instruction to us to exchange data with it (clause 12.3).
Hosting and infrastructure
| Provider | Purpose | Where |
|---|---|---|
| Amazon Web Services | Hosts the entire platform — application servers, database, cache, file and document storage, image delivery and background processing. Holds all customer records entered into the CRM. | Australia (Sydney) |
| Amazon Simple Email Service | Delivers all outbound email we send on your behalf — notifications, portal links and marketing campaigns — and records bounces and complaints. | Australia (Sydney) |
| Sentry | Error and performance monitoring. Receives diagnostic information when something fails, which can include the signed-in user’s identity and the page or request involved. | United States |
| Cloudflare | Bot protection on public forms and enquiry pages. Also used, where you choose to connect it, to create email authentication records in your own domain. | Global edge network |
Payments and finance
| Provide r | Purpose | Where |
|---|---|---|
| Stripe | Processes subscription payments and advertising payments. Card details are entered directly into Stripe and are not held by us. | United States and global |
| Xero | On connection. Accounting and payroll synchronisation — supplier invoices, commission statements and payslips. | United States |
Email, calendar and messaging
| Provider | Purpose | Where |
|---|---|---|
| Microsoft 365 | On connection. Mailbox and calendar access for users who connect their own Microsoft account, so email can be read into and sent from the CRM. Data remains in your own Microsoft tenant. | Your own Microsoft 365 tenant |
| TextBee | On connection. SMS gateway. Messages are relayed through the user’s own mobile device. | [CONFIRM WITH |
| Meter | What it counts | What pauses if you run out |
|---|---|---|
| System Usage | The general technical consumption of the platform — see paragraph 2. | Non‑essential background processing, syncs, exports, reports, publishing and API access may pause. Core read access to your data continues. |
Artificial intelligence
| Meter | What it counts | What pauses if you run out |
|---|---|---|
| System Usage | The general technical consumption of the platform — see paragraph 2. | Non‑essential background processing, syncs, exports, reports, publishing and API access may pause. Core read access to your data continues. |
Property portals and listing distribution
| Provider | Purpose | Where |
|---|---|---|
| Trade Me Property | **On connection.** Publishes and withdraws listings, and returns listing statistics and buyer enquiries. | New Zealand |
| realestate.co.nz | **On connection.** Publishes and withdraws listings, and returns listing statistics and buyer enquiries. | New Zealand |
| OneRoof | **On connection.** Receives listing feeds and returns listing statistics. | New Zealand |
| Marq | **On connection.** Marketing design and print templates. Reads a listing feed we publish. | United States |
| Your own website | **On connection.** Receives listings for display and returns enquiry form submissions. | Wherever you host your website |
Marketing, advertising and prospecting
| Provider | Purpose | Where |
|---|---|---|
| Amazon Web Services | Hosts the entire platform — application servers, database, cache, file and document storage, image delivery and background processing. Holds all customer records entered into the CRM. | Australia (Sydney) |
| Amazon Simple Email Service | Delivers all outbound email we send on your behalf — notifications, portal links and marketing campaigns — and records bounces and complaints. | Australia (Sydney) |
| Sentry | Error and performance monitoring. Receives diagnostic information when something fails, which can include the signed‑in user’s identity and the page or request involved. | United States |
| Cloudflare | Bot protection on public forms and enquiry pages. Also used, where you choose to connect it, to create email authentication records in your own domain. | Global edge network |
Loaded in the visitor’s browser
These run on public pages and in the app. The provider receives the visitor’s IP address, which is how the internet works — it is not something we send them.
| Provider | Purpose | Where |
|---|---|---|
| Google Maps and Places | Address lookup, geocoding and maps on property records. | United States and global |
| Google Fonts | Supplies typefaces used in branded templates and designs. | Global edge network |
| Cloudflare Turnstile | Bot protection challenge on public forms and portals. Receives the visitor’s IP address and browser signals. | Global edge network |
| YouTube and Vimeo | Plays videos you have embedded in listings, forms or announcements. Receives the visitor’s IP address and may set cookies. | United States and global |
Note on AI. We contract with our AI providers so that data we send on your behalf is not used to train their models, and is retained only in accordance with the zero-retention or limited-retention terms we’ve agreed with them. Clause 11.7 applies.
line: horizontal separator
These terms are provided by The Network Software Limited trading as Penguin Pilot. Questions: support@penguinpilot.ai.
Extracted images (43):
parsed-documents://20260908-023503-003032/terms_with_Beta.docx/images/page_1.jpgparsed-documents://20260908-023503-003032/terms_with_Beta.docx/images/page_10.jpgparsed-documents://20260908-023503-003032/terms_with_Beta.docx/images/page_11.jpgparsed-documents://20260908-023503-003032/terms_with_Beta.docx/images/page_12.jpgparsed-documents://20260908-023503-003032/terms_with_Beta.docx/images/page_13.jpgparsed-documents://20260908-023503-003032/terms_with_Beta.docx/images/page_14.jpgparsed-documents://20260908-023503-003032/terms_with_Beta.docx/images/page_15.jpgparsed-documents://20260908-023503-003032/terms_with_Beta.docx/images/page_16.jpgparsed-documents://20260908-023503-003032/terms_with_Beta.docx/images/page_17.jpgparsed-documents://20260908-023503-003032/terms_with_Beta.docx/images/page_18.jpgparsed-documents://20260908-023503-003032/terms_with_Beta.docx/images/page_19.jpgparsed-documents://20260908-023503-003032/terms_with_Beta.docx/images/page_2.jpgparsed-documents://20260908-023503-003032/terms_with_Beta.docx/images/page_20.jpgparsed-documents://20260908-023503-003032/terms_with_Beta.docx/images/page_21.jpgparsed-documents://20260908-023503-003032/terms_with_Beta.docx/images/page_22.jpgparsed-documents://20260908-023503-003032/terms_with_Beta.docx/images/page_23.jpgparsed-documents://20260908-023503-003032/terms_with_Beta.docx/images/page_24.jpgparsed-documents://20260908-023503-003032/terms_with_Beta.docx/images/page_25.jpgparsed-documents://20260908-023503-003032/terms_with_Beta.docx/images/page_26.jpgparsed-documents://20260908-023503-003032/terms_with_Beta.docx/images/page_27.jpgparsed-documents://20260908-023503-003032/terms_with_Beta.docx/images/page_28.jpgparsed-documents://20260908-023503-003032/terms_with_Beta.docx/images/page_29.jpgparsed-documents://20260908-023503-003032/terms_with_Beta.docx/images/page_3.jpgparsed-documents://20260908-023503-003032/terms_with_Beta.docx/images/page_30.jpgparsed-documents://20260908-023503-003032/terms_with_Beta.docx/images/page_31.jpgparsed-documents://20260908-023503-003032/terms_with_Beta.docx/images/page_32.jpgparsed-documents://20260908-023503-003032/terms_with_Beta.docx/images/page_33.jpgparsed-documents://20260908-023503-003032/terms_with_Beta.docx/images/page_34.jpgparsed-documents://20260908-023503-003032/terms_with_Beta.docx/images/page_35.jpgparsed-documents://20260908-023503-003032/terms_with_Beta.docx/images/page_36.jpgparsed-documents://20260908-023503-003032/terms_with_Beta.docx/images/page_37.jpgparsed-documents://20260908-023503-003032/terms_with_Beta.docx/images/page_38.jpgparsed-documents://20260908-023503-003032/terms_with_Beta.docx/images/page_39.jpgparsed-documents://20260908-023503-003032/terms_with_Beta.docx/images/page_4.jpgparsed-documents://20260908-023503-003032/terms_with_Beta.docx/images/page_40.jpgparsed-documents://20260908-023503-003032/terms_with_Beta.docx/images/page_41.jpgparsed-documents://20260908-023503-003032/terms_with_Beta.docx/images/page_42.jpgparsed-documents://20260908-023503-003032/terms_with_Beta.docx/images/page_43.jpgparsed-documents://20260908-023503-003032/terms_with_Beta.docx/images/page_5.jpgparsed-documents://20260908-023503-003032/terms_with_Beta.docx/images/page_6.jpgparsed-documents://20260908-023503-003032/terms_with_Beta.docx/images/page_7.jpgparsed-documents://20260908-023503-003032/terms_with_Beta.docx/images/page_8.jpgparsed-documents://20260908-023503-003032/terms_with_Beta.docx/images/page_9.jpg
