Privacy Policy

Effective 25 May 2026

This Policy explains how EZ-AI.NZ Limited (NZBN/NZ-registered), trading as Brieva collects, uses, and shares personal information in connection with the Brieva service. It is written to comply with the New Zealand Privacy Act 2020. Our role differs depending on whose data is involved (see section 3).

1. Who we are

The data controller is EZ-AI.NZ Limited (NZBN/NZ-registered), trading as Brieva, contactable at skene@ez-ai.nz. The IPP12 Privacy Officer is the company director.

2. Information we collect

From customers (account holders):

  • Account: email, name, password hash, organisation name.
  • Configuration: newsletter settings, branding, feed URLs, sending domain.
  • Billing: payment-method tokens (held by our payment processor, not us).
  • Usage and diagnostics: IP, user-agent, log timestamps, API calls.

From subscribers (your audience):

  • Email address, double-opt-in confirmation timestamp and source IP.
  • Delivery events from Amazon SES: sent, delivered, bounced, complained.
  • If enabled by the customer: open and click events.

3. Controller vs processor

For customer account data we are the controller: we decide what we collect and why.

For subscriber data we are a processor, acting on the customer's instructions. The customer is the controller of their own subscriber list and is responsible for lawful collection, consent and responding to access or deletion requests from their subscribers.

4. How we use information

  • To operate the service: research, draft, deliver and archive newsletters.
  • To send transactional email about your account.
  • To compute reputation metrics and protect the shared sending infrastructure.
  • To prevent fraud and abuse; to comply with legal obligations.
  • To improve the service via aggregated and de-identified analytics.

5. AI processing

Drafting and fact-checking are performed by large language models (Anthropic Claude via Amazon Bedrock). Content sent to those models is not used to train them. We do not feed subscriber email addresses or personal data through the AI pipeline.

6. Sharing

We do not sell personal information. We share it only with vendors needed to operate the service (see Subprocessors below), our professional advisors under duties of confidentiality, and where required by law or to enforce our rights. All vendors process personal information on our instructions.

7. Subprocessors

Brieva relies on the following subprocessors to operate the service. Each processes only the personal information necessary for its role and under contractual obligations consistent with this Policy.

SubprocessorPurposeRegion
Amazon Web Services, Inc.Application hosting, database (DynamoDB), object storage (S3), identity (Cognito), API gateway.us-east-1 (US)
Amazon Simple Email Service (SES)Outbound email delivery, bounce / complaint feedback.us-east-1 (US)
Amazon BedrockHosted access to Anthropic Claude foundation models. Inputs are not used to train the models.us-east-1 (US, cross-region inference)
Anthropic, PBCProvider of the Claude model family invoked via Bedrock.US (delivered through Bedrock)
Payment processor (added with paid plans)Card tokenisation, subscription billing, invoicing.Provider region (US/EU)

We will notify customers by email or in-product notice at least 14 days before adding a new subprocessor that processes subscriber data, so a customer with a material objection can address it before it takes effect.

8. Location and transfers

Data is stored in Amazon Web Services region us-east-1 (United States). By using the service you acknowledge that personal information is processed in the United States. We require comparable protections under contract, consistent with IPP12.

9. Retention

  • Customer account: while active, plus 12 months after closure.
  • Subscriber records (active): for the life of the customer's newsletter.
  • Unsubscribed records: kept as a suppression list to honour the opt-out.
  • Billing and tax records: 7 years, as required by NZ tax law.
  • Logs and event data: 90 days.

10. Your rights

You may request access to or correction of your personal information by emailing skene@ez-ai.nz. Subscribers should direct access and correction requests to the customer whose newsletter they subscribed to; we will forward requests we receive.

11. Security and breach notification

We use TLS in transit, AWS-managed encryption at rest, scoped IAM roles, tenant-isolated database queries, per-tenant rate limiting on public endpoints, multi-factor authentication on administrator access, and an audit log of mutating operations. No system is perfectly secure.

If we become aware of a personal-information breach that meets the notifiable threshold under the New Zealand Privacy Act 2020 or any other applicable law, we will notify affected customers without undue delay, and in any event within 72 hours of becoming aware, with the information we have at that time. We will follow up with further detail as the investigation progresses, and will support our customers’ own notification obligations to their subscribers and regulators. Notify us at skene@ez-ai.nz if you suspect a breach affecting your account.

12. Cookies

The Brieva app uses a session cookie (authentication) and local storage (UI preferences). The public marketing site uses no third-party tracking.

13. Children

Brieva is not directed to children under 13 (or under 16 in jurisdictions where that threshold applies). We do not knowingly collect their information.

14. Complaints

If we cannot resolve a privacy concern, you may contact the New Zealand Office of the Privacy Commissioner: privacy.org.nz.

Questions: skene@ez-ai.nz.