Privacy Policy
Last updated: 15 September 2026
1. Who we are
Weft Technologies Ltd provides building communication and onboarding software for management companies in New Zealand through the WEFT platform.
For privacy enquiries contact us at privacy@weftbuildings.com.
2. Scope — platform vs management company
This Privacy Policy describes how WEFT processes personal information when you use WEFT's web applications (the people app and admin portal).
Your building’s management company is your primary contact for day-to-day building matters. They decide who to onboard, approve self-registrations, and send building notifications. Each management company may also have its own privacy statement for building-specific processing.
3. What personal information we collect
| Category | Examples | When collected |
|---|---|---|
| Identity & contact | First name, surname, email, phone | Registration, account settings |
| Occupancy | Building, floor, unit, occupancy type, lease dates | Registration, admin assignment |
| Account / auth | OTP codes, session tokens, last login | Sign-in, magic links |
| Optional profile | Vehicle registration plates | Account settings |
| Communications | Notification title/body, delivery receipts | Admin broadcasts, system emails/SMS |
| Requests | Title, description, category, location, messages | Resident requests |
| Approval workflow | Approver decisions, rejection reasons | Self-registration approval |
| Contractor visits | Name, email, mobile, company, visit location and activity | Contractor QR sign-in |
| Device (if enabled) | Push notification tokens | Optional push channel |
| Building information Q&A | Questions you type about building rules; AI-generated answers; citation links | Information tab — “Ask about your building” (when enabled for your building) |
We do not collect government ID documents, proof of income, bank statements, credit or background checks, or tenancy-application bundles.
Building information (AI-assisted Q&A): When your building has published knowledge, you may ask questions in the people app. Your current question (and, for follow-ups in the same browser session, prior questions and answers in that session) are sent to our AI provider to generate a reply grounded in documents your building manager has published. We do not store a chat thread in the database — follow-up context is held in your browser until you refresh the page or start a new conversation. Each question and answer is logged separately for quality and support for 30 days, then deleted. Do not include sensitive personal information in your questions (for example names of neighbours, medical details, or financial account numbers). Official rules remain in the cited documents; AI answers are summaries only.
We do not use non-essential analytics cookies or ad tracking.
4. Why we collect it
We use personal information to:
- Onboard residents, owners, and property managers
- Authenticate users (magic links and OTP)
- Deliver building notifications by email and SMS
- Route and record self-registration approvals
- Handle resident requests and complaints
- Record contractor sign-in and sign-out at buildings
- Answer building rule questions using AI-assisted search over documents published by your management company (where enabled)
- Maintain security and service reliability
5. Legal basis
We collect personal information directly from you when you register or use the service. By registering you acknowledge this Privacy Policy and our Terms of Service.
6. Who we share information with
Within a management company, access is limited by role (company admin, property manager, owner, resident). Residents cannot see other households’ personal information.
We use subprocessors to operate the service:
- Resend — transactional email
- Twilio — SMS where enabled
- Render / PostgreSQL — hosting and data storage (including building knowledge text and embeddings used for search)
- OpenAI — AI embeddings and chat completions for building information Q&A (questions, session follow-up context when you ask a follow-up, and relevant excerpts from published building documents). Under OpenAI’s standard API terms, API data is not used to train OpenAI’s models by default. OpenAI may retain API inputs and outputs for a limited period (typically up to 30 days) for abuse monitoring and safety, as described in OpenAI’s data controls documentation.
We do not sell personal information.
7. International transfers
Some subprocessors may store or process data outside New Zealand (including OpenAI and Render in the United States). We require appropriate safeguards consistent with the Privacy Act 2020.
8. Retention
We retain personal information while your account is active and as needed to provide the service, meet legal obligations, and resolve disputes. OTP and session logs are kept for a limited period for security.
Building information Q&A logs (your question text and the answer returned) are kept for 30 days, then automatically deleted. In-browser conversation context for follow-ups is not retained on our servers after the request completes.
9. Security
We use encryption in transit, access controls, and tenant isolation so each management company’s data is separated.
10. Your rights
Under the Privacy Act 2020 you may request access to or correction of your personal information. You may also complain to the Office of the Privacy Commissioner.
11. Contact
Privacy requests: privacy@weftbuildings.com Building-specific matters: contact your building manager.
12. Changes
We may update this policy. The “Last updated” date at the top will change when we do. Material changes may be communicated through the service or by email where appropriate.