Privacy Policy
Last updated: 6 October 2026 ยท Effective for all WireWrite NZ accounts
This privacy policy explains how Phase Logic Ltd ("we", "us", "our") collects, uses, stores, and protects your personal information when you use WireWrite ("the Service"). We are committed to protecting your privacy in accordance with the New Zealand Privacy Act 2020 and the Information Privacy Principles.
1. Data Controller
The data controller for information collected through the Service is:
Phase Logic Ltd
Contact: Support form
2. Information We Collect
2.1 Information you provide
- Account information — your name, email address, and password (or Google profile if using OAuth).
- Professional information — your EWRB practising licence details, licence class, and registration number.
- Certificate data — client names, addresses, phone numbers, job details, test results, and signatures you enter when creating certificates.
- Company information — company name, address, phone number, and logo (for company accounts).
- Payment information — billing details are collected and processed by Stripe (see section 5).
- Financials data (New Zealand) — the invoices you issue, including your clients' names, contact details and addresses, the work and amounts invoiced, your GST number and the bank account clients pay into; a record of each invoice email (the recipient's address, when it was sent, and a fingerprint and size of any attached PDF); and how many times each invoice share link has been viewed. Payment claims are generated from your invoices and are not stored.
Your clients' information. When you enter your clients' details on certificates or invoices, you collect that information and are responsible for doing so lawfully under the Privacy Act 2020, including telling your clients how you will use it. We hold it on your behalf to provide the Service and do not use it for any other purpose.
2.2 Information collected automatically
- Usage data — pages visited, features used, and session duration (via Google Analytics).
- Device information — browser type, operating system, screen resolution, and IP address.
- Cookies — authentication tokens and session cookies necessary for the Service to function.
2.3 Google OAuth data
If you sign in with Google, we access your email address and basic profile information (name and profile photo) via Google OAuth. We do not access your Google contacts, calendars, files, emails, or any other Google services data.
3. How We Use Your Information
We use your personal information for the following purposes:
- Providing the Service — creating your account, generating certificates, and processing payments.
- Authentication — verifying your identity and maintaining your session.
- Communication — sending certificate and invoice emails to your clients on your behalf, account notifications, trial reminders, and support correspondence.
- Preventing misuse — applying sending limits and keeping email records so that invoice emails can't be used to send spam or fraudulent attachments.
- Legal compliance — keeping records we are required by law to keep, such as tax and billing records.
- Service improvement — analysing anonymised usage patterns to improve features and performance.
We do not use your data to serve advertisements, build advertising profiles, or train machine learning models.
4. Legal Basis for Processing
We process your personal data on the following legal bases:
- Contract — processing necessary to provide the Service you have signed up for.
- Legitimate interest — improving the Service, preventing fraud, and ensuring security.
- Legal obligation — complying with laws that apply to us (see Legal compliance above).
- Consent — where you have opted in to receive marketing communications (you may withdraw consent at any time).
5. Data Sharing
We share your data only with the following service providers, each of whom processes data on our behalf:
- Cloud infrastructure providers (database, authentication & hosting) — store your account and certificate data securely and serve the application; they receive standard web request data (IP address, user agent).
- Stripe (payment processing) — receives your email and billing details to process subscription payments.
- Google Analytics — receives anonymised usage data to help us understand how the Service is used.
- Email delivery provider (Resend, United States) — delivers certificate and invoice emails, so it receives the recipient's address, the email content and any attached PDF.
- Document rendering (Google Cloud) — turns certificates, invoices and payment claims into PDF files; documents are processed to create the file and not kept.
- Certificate and invoice recipients — when you email or share a certificate or invoice, the recipient (and anyone you or they pass a share link to) can see that document, including your bank details on an invoice.
We do not sell, rent, or trade your personal information to any third parties.
6. International Data Transfers
Phase Logic Ltd is based in New Zealand. Your data may be transferred to and processed in countries outside New Zealand, where our cloud infrastructure providers operate. Emails we send for you are processed by our email delivery provider in the United States.
We take reasonable steps to ensure that overseas recipients of your personal information handle it in accordance with the New Zealand Privacy Act 2020.
7. Data Retention
- Issued certificates — kept while your account has an active paid subscription or free trial. If your account moves to the Free plan, you have 90 days to download your certificates, after which they may be permanently deleted. Certificates issued on the Free plan are kept for 90 days from the date of issue, then may be permanently deleted. Phase Logic does not keep certificates for the regulatory retention period: the person who issued a certificate is responsible for keeping their own copy (at least 7 years under NZ electrical regulations).
- Draft certificates — retained for 90 days from last modification, then permanently deleted.
- Invoices (including your clients' details on them), their email records and share-link records — kept while your account or company is active. After it closes, they are kept for up to 7 years from the invoice date so the business that issued them can obtain copies for its tax records, then deleted. The account holder (for a company, its Manager) can ask us to delete them sooner. Share links stop working after 90 days or when revoked.
- Account data — retained while your account is active. Upon account deletion, all other personal data is permanently removed within 30 days.
- Usage analytics — anonymised data is retained for up to 26 months.
8. Data Security
We implement appropriate technical and organisational measures to protect your data:
- All data is encrypted in transit (TLS/HTTPS) and at rest.
- Account data and certificates are stored in managed cloud databases with row-level security.
- Access to production systems is restricted to authorised personnel only.
- Two-factor authentication (2FA) is available and recommended for all user accounts.
- Payment data is handled entirely by Stripe (PCI DSS compliant) and is never stored on our servers.
- Digital signatures are stored as encrypted data associated with your account.
9. Your Rights
You have the following rights regarding your personal data:
- Access — you can request a copy of the personal data we hold about you.
- Rectification — you can update your personal information at any time through your account settings.
- Deletion — you can request deletion of your account and all associated personal data.
- Data portability — you can download your certificates as PDF files at any time from your dashboard, and export your invoices to Xero or as PDF files.
- Objection — you can object to processing based on legitimate interest.
- Withdraw consent — where processing is based on consent, you may withdraw it at any time.
To exercise any of these rights, contact us via our support form. We will respond within 20 working days as required by the NZ Privacy Act 2020.
10. Cookies
WireWrite uses essential cookies required for the Service to function, plus Google Analytics cookies (see below):
- Authentication cookies — to keep you signed in during your session.
- Preference cookies — to remember your settings.
We also use Google Analytics, which sets its own cookies to collect anonymised usage data. You can opt out of Google Analytics by installing the Google Analytics Opt-out Browser Add-on.
11. Children's Privacy
The Service is not intended for use by anyone under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child, we will delete it promptly.
12. Google API Services
WireWrite's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We only use Google user data for authentication and do not use it for advertising, profiling, or any purpose unrelated to the Service.
13. Supervisory Authority
If you are not satisfied with how we handle your personal data, you have the right to lodge a complaint with the Office of the Privacy Commissioner at privacy.org.nz.
14. Changes to This Policy
We may update this privacy policy from time to time. Material changes will be communicated by email or through a notice on the Service. Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.
15. Governing Law
This privacy policy is governed by the laws of New Zealand. See also our Terms of Service for the full terms covering use of WireWrite.