Trust Technical Services Limited (TTS NZ) · NZBN 9429053014481 · Effective 29 September 2026 · Contact: support@ttsnz.info
Pwoli Privacy Policy
Effective Date: 29 September 2026
1. Who we are
Trust Technical Services Limited trading as TTS NZ (“TTS”, “we”, “us”, “our”) is a New Zealand company (NZBN 9429053014481) that provides the Pwoli platform (pwoli.ai; dashboard also at ttsnzai.tech) and operates the website ttsnz.info. Our registered address is 20 Roslyn Farm Street, Ramarama, Drury 2579, New Zealand. Privacy contact: support@ttsnz.info. We have not appointed a data protection officer and have not appointed an EU or UK representative; contact us at the address above for any privacy matter.
2. Our role
2.1 Account data — TTS is the controller
When a business (“Customer”) creates a Pwoli account, TTS is the controller (the “agency” under the NZ Privacy Act 2020, and an “APP entity” under the Australian Privacy Act 1988) for personal information about the Customer’s account holders and users, billing contacts, support contacts and visitors to our websites. This policy mainly describes that processing.
2.2 Customers’ contacts — TTS is a processor / service provider
Personal information that a Customer uploads to, or collects through, Pwoli about its own callers, leads, contacts, clients, patients, recipients and staff (“Customer Data”) is processed by TTS as a processor (GDPR/UK GDPR), service provider (CCPA/CPRA) and on the Customer’s behalf under section 11 of the NZ Privacy Act 2020, under our Data Processing Agreement (“DPA”). The Customer decides why and how that information is used and is responsible for giving its contacts any required privacy notice (including the notice required by NZ IPP3A for information collected indirectly) and obtaining any required consent. If you are one of a Customer’s contacts, please direct privacy requests to that business; if you contact us, we will refer your request to the relevant Customer where we can identify it.
2.3 Notice for people who call or message a Pwoli Customer
If you call, message or book with a business that uses Pwoli, your call may be answered by an AI assistant. The assistant says at the start of the call that it is an AI assistant and that the call may be recorded. The business collects your name, phone number, the recording, a transcript, and the details you give (for example, the reason for your call or booking), and uses them to respond to you and manage its relationship with you. That business is responsible for your information; TTS processes your call as a processor for the business you called, not as the decision-maker. The AI assistant does not make decisions with legal or similarly significant effects about you. If you do not want to be recorded, you can end the call and contact the business another way. Please direct any privacy request about your call or your information to that business, not to TTS.
3. What personal information we collect
Collected from you directly (controller data):
- Account and billing — name, email, phone, business name and address, role, invoicing details, tax identifiers where required. Card details are collected and held by Stripe; we do not store full card numbers.
- Usage and security logs — login dates and times, IP address, device and browser type, and actions performed in the dashboard.
- Support communications — messages and attachments you send us.
- Website enquiries — details you submit through forms on ttsnz.info or pwoli.ai.
Collected indirectly (IPP3A notice): we may receive personal information about you from sources other than you — for example, from your employer or colleague who adds you as a user of their Pwoli account, from Stripe (payment status), from Google or Meta when you connect those accounts (profile name, email, page/calendar identifiers), and from public business registers when verifying a business. We use it for the purposes in section 4. You can access and correct it (section 11).
Processed for Customers (Customer Data, processor role): AI call recordings and transcripts; SMS, email, chat and social-media message content; CRM/contact records (names, phone numbers, emails, addresses, social handles, notes); calendar and booking data; bookkeeping records; and any other data the Customer chooses to store.
We do not use analytics, session-replay, tracking or advertising tools on the logged-in dashboard.
4. How we use personal information (and our GDPR legal bases)
| Purpose | GDPR / UK GDPR legal basis |
|---|---|
| Creating and running your account and delivering the Pwoli service | Contract |
| Billing and payments (via Stripe) | Contract; legal obligation (tax records) |
| Customer support | Contract; legitimate interests (resolving issues) |
| Service, security and legal notices | Contract; legal obligation |
| Marketing about our own services | Consent where required by law (e.g. NZ Unsolicited Electronic Messages Act 2007, Australian Spam Act 2003), otherwise legitimate interests; you can opt out at any time |
| Security, fraud and abuse prevention; keeping logs | Legitimate interests; legal obligation |
| Improving reliability and performance using aggregated or de-identified usage information | Legitimate interests |
| Complying with law and responding to lawful requests | Legal obligation |
We process Customer Data only to provide the service to the relevant Customer on its instructions. We do not use Customer Data to train generally available AI models of our own, and we do not sell or rent personal information. Our AI language-model and voice providers process call audio, transcripts and prompts only to provide the service to us. We aim to use settings or terms under which those providers may not use this data to train their own general-purpose models (details available on request).
5. AI processing and automated decisions
Pwoli uses AI services (including Retell AI and third-party large language model providers) to answer calls, transcribe and summarise conversations, draft messages and suggest content. AI output can be wrong; Customers are responsible for reviewing it. Pwoli does not make decisions that produce legal or similarly significant effects on individuals solely by automated means. If a Customer configures Pwoli in a way that does, the Customer is responsible for the notices, safeguards and human-review rights required by law (including GDPR Article 22 and, from 10 December 2026, APP 1 disclosures about automated decisions).
6. Who we share personal information with
We share personal information only with the service providers below, who process it for us or on the Customer’s behalf under written terms, and where required by law (for example, a court order).
| Provider | Purpose | Likely locations |
|---|---|---|
| Stripe | Payment processing | United States and other countries |
| Twilio | Phone and SMS | United States and other countries |
| Telnyx | Phone and SMS | United States and other countries |
| Retell AI | AI voice call handling | United States |
| Resend | Email delivery | United States |
| Amazon Web Services (SES) | Email delivery | United States and other countries |
| Google (Calendar, OAuth, Maps) | Calendar, sign-in and location services | United States and other countries |
| Meta (Facebook/Instagram) | Social-media publishing | United States and other countries |
| AI language-model providers | Natural-language processing | United States and other countries |
| Hostinger | Server (VPS) hosting | Malaysia (Kuala Lumpur) |
| Cloudflare | Network delivery and security | Global network |
| Bluehost | Hosting of our ttsnz.info website | United States |
We keep an up-to-date list and will notify Customers of changes as set out in the DPA. We do not sell personal information and do not “share” it for cross-context behavioural advertising (as those terms are used in the CCPA/CPRA).
7. Overseas disclosure and international transfers
We are based in New Zealand, and the providers in section 6 are located in, or may access information from, the countries listed there — most commonly the United States and Malaysia (our server host, Hostinger, is located in Kuala Lumpur, Malaysia). (This is our disclosure under APP 1.4(f)–(g) and APP 8.)
- New Zealand (IPP12): we disclose information overseas — including to the United States and to Malaysia, where our servers are hosted — only where the recipient is subject to comparable safeguards, usually through contractual terms, or as otherwise permitted by IPP12.
- Australia (APP 8): we take reasonable steps, including contractual terms, so that overseas recipients — including our server host in Malaysia — do not breach the APPs, and we remain accountable as required by the Privacy Act 1988.
- EU/EEA and UK: transfers rely on an adequacy decision (New Zealand has an EU adequacy decision) or on the European Commission’s Standard Contractual Clauses (Decision (EU) 2021/914), the UK International Data Transfer Agreement or UK Addendum, or another lawful mechanism. You may request a copy of the relevant safeguards by emailing us.
- Canada (PIPEDA): information transferred to a provider outside Canada may be accessible to courts and authorities in that country.
8. Cookies
The Pwoli dashboard uses only strictly necessary session cookies to keep you signed in and secure. No analytics, tracking or advertising cookies are set on the dashboard, and fonts are self-hosted.
9. Retention
- Account and billing data — while your account is active, then as long as needed for legal, tax and dispute purposes (NZ tax records are generally kept for 7 years).
- Usage and security logs; support communications — up to 24 months.
- Customer Data (including call recordings, transcripts, messages and CRM data) — call recordings and transcripts are retained for the period set by the business customer in its settings, or otherwise for as long as the customer’s account is active, then deleted within 30 days after termination. Other Customer Data is retained for as long as the Customer keeps it in Pwoli or the account is active. After the account ends, we delete or return it within 30 days as set out in the DPA; residual copies in backups are deleted in the ordinary backup cycle and are not used for any other purpose.
10. Security and breaches
We use reasonable technical and organisational measures to protect personal information against loss, unauthorised access, use, modification and disclosure (IPP5, APP 11, GDPR Art. 32), and require our providers to do the same. No system is completely secure.
If a privacy breach affects information we control, we will assess it promptly and, where required, notify:
- the NZ Privacy Commissioner and affected individuals as soon as practicable, where it is a notifiable privacy breach (serious harm is likely);
- the Office of the Australian Information Commissioner and affected individuals under the Notifiable Data Breaches scheme;
- the relevant EU/UK supervisory authority within 72 hours where required, and affected individuals where the risk is high;
- the Canadian Privacy Commissioner and affected individuals where there is a real risk of significant harm;
- affected individuals and regulators as required by applicable US state law.
If a breach affects Customer Data, we notify the affected Customer without undue delay under the DPA, and the Customer is responsible for notifying its regulators and contacts.
11. Your rights
Depending on where you live, you may have the right to: access your personal information; correct it; delete it; receive it in a portable format; restrict or object to processing (including direct marketing); withdraw consent; and not be subject to solely automated decisions with significant effects. California residents may also request to know the categories and specific pieces of personal information we collect, and to correct or delete it, and have the right not to be discriminated against for exercising these rights; we do not sell or share personal information, so no opt-out is needed. You may use an authorised agent; we will verify your identity (and the agent’s authority) before acting.
To make a request, email support@ttsnz.info. We will respond within 20 working days (NZ), within 30 days (Australia, Canada), within one month (EU/UK), or within 45 days (California), or any shorter period required by law, extended only where the law permits. We do not charge for requests unless the law allows it. If your request relates to Customer Data, we will refer it to the Customer and assist it as its processor.
12. Children
Pwoli is a business service and is not directed at anyone under 18. We do not knowingly collect personal information directly from children. Customers must not submit children’s data unless they have a lawful basis and have agreed this with us under the DPA.
13. Changes
We may update this policy. We will change the Effective Date above and post notice of material changes on this page and, for account holders, by email before the change takes effect.
14. Contact and complaints
Contact support@ttsnz.info first. If you are not satisfied, you may complain to:
- NZ Office of the Privacy Commissioner — https://privacy.org.nz
- Office of the Australian Information Commissioner — https://oaic.gov.au
- your local EU supervisory authority (list at https://edpb.europa.eu), or the UK Information Commissioner’s Office — https://ico.org.uk
- Office of the Privacy Commissioner of Canada — https://priv.gc.ca
- California Privacy Protection Agency — https://cppa.ca.gov
15. Governing law
This policy is governed by New Zealand law. This does not remove any right you have to complain to, or bring proceedings under, the data protection law and regulators of the place where you live.
See also our Terms of Service.