Futurebound Privacy Policy

Elias Services Ltd trading as Futurebound (“we”, “us”, “our”) complies with the New Zealand Privacy Act 2020 (the “Act”) when dealing with personal information. Personal information is information about an identifiable individual (a natural person). This policy sets out how we will collect, use, disclose and protect your personal information.

This policy does not limit or exclude any of your rights under the Act. If you wish to seek further information on the Act, you can contact our Privacy Officer by email on [email protected] or visit www.privacy.org.nz for further information.

Changes to this policy

We may change this policy by uploading a revised policy onto the website. The change will apply from the date that we upload the revised policy.

What is personal information?

Personal information is information about an identifiable individual. It includes (but is not limited to) name, address, contact details, date of birth, occupations, payment details, employment history and/or details, education and qualifications, financial information, testimonials and feedback, evidence of source of funds or source of wealth (in some cases) and other information.

How we use your personal information

We will use your personal information:

  • to verify your identity
  • to provide services and products to you
  • to market our services and products to you, including contacting you electronically (e.g. by call, text or email for this purpose)
  • to improve the services and products that we provide to you
  • to respond to communications from you, including a complaint
  • to protect and/or enforce our legal rights and interests, including defending any claim
  • for any other purpose authorised by you or the Act.

 

SECTION 1: AI-Assisted Processing

1.1 Use of Artificial Intelligence

Futurebound uses third-party artificial intelligence (AI) services to process your data for business intelligence, reporting, and service improvement purposes.

AI Providers We Use:

  • OpenRouter – AI routing service
  • OpenAI – GPT AI models
  • Anthropic – Claude AI models

Purposes of AI Processing:

  • Generating automated business reports and insights
  • Analyzing financial patterns and trends
  • Providing operational intelligence to our team
  • Assisting with service improvement and development

1.2 Data Processed by AI
The following data may be processed by AI services:

  • Client identifiers and contact information (pseudonymized where possible)
  • Financial data including mortgage schedules, payment histories, and account information
  • Engagement and usage data from our platforms
  • Business metrics and performance data

1.3 Data Protection Measures

We implement these safeguards for AI processing:

  • Pseudonymization: Replacing names with unique identifiers
  • Aggregation: Using summarized data where individual identification isn’t needed
  • Limited Scope: Sharing only necessary data elements
  • Contractual Protections: Data Processing Agreements with AI providers
  • Training Exclusion: Configuring AI services to NOT use your data for model training

 

SECTION 2: Third-Party Processors Update

Service Provider Purpose Privacy Policy
OpenRouter
AI request routing and processing
https://openrouter.ai/privacy
OpenAI
AI model processing and analysis
https://openai.com/policies/privacy-policy
Anthropic
AI model processing and analysis
https://www.anthropic.com/privacy

These providers process your data on our behalf under Data Processing Agreements that require them to protect your data and only process it according to our instructions.

2.2 Other Third-Party

Processors and Disclosures
In addition to AI providers mentioned above, we may disclose your personal information to:

Service Providers and Data Processors (who act on our behalf):

  • Productivity & Collaboration Tools: Microsoft 365 (including Outlook, Word, Excel, Teams, OneDrive) for business operations, document storage, and communications
  • CRM and Data Storage Providers: Including Ontraport (our primary CRM platform with servers in the United States and other locations) – these providers process data on our instructions
  • Payment Processors: Companies that handle payment transactions on our behalf
  • Cloud Hosting Providers: Where our software and data are stored
  • Email and Communication Services: For customer communications and marketing
  • Analytics Providers: For website and service usage analysis
  • Other companies or individuals who assist us in providing services or who perform functions on our behalf (such as mailing houses, specialist consultants and legal advisers)

IMPORTANT: Referrals to Financial Services Providers

When you request a referral to a financial adviser, lender, or other financial service provider:

  • We will obtain your explicit consent before sharing any personal information
  • We will only share information necessary for the referral
  • We require these providers to protect your information
  • You can withdraw consent at any time

Compliance and Verification (as required or authorized by law):

  • Other companies or individuals who perform checks (such as but not limited to compliance reviews and audits) that are necessary or desirable under law on our behalf
  • Other companies, agencies or individuals that maintain databases against which your identity may be verified, which may include (but is not limited to) the New Zealand Department of Internal Affairs, and New Zealand Transport Agency

Legal and Regulatory (as required by law):

  • Courts, tribunals and regulatory authorities (such as the Financial Markets Authority, and Ministry of Justice in New Zealand)
  • Social media sites on which we may have a presence (for advertising and analytics – anonymized data only)
  • Office of the Ombudsman, where a complaint relates to official information
  • Office of the New Zealand Privacy Commissioner, where a complaint relates to breach of the Privacy Act 2020
  • Human Rights Commission, where a complaint relates to discrimination
  • CERT NZ, where appropriate to assist with the management of a voluntarily notified privacy breach
  • Overseas privacy regulator, where a complaint relates to the actions of an overseas agency

Data Security and Incident Response:

  • Any person or agency we believe could assist in responding to a serious privacy breach

With Your Consent:

  • Anyone else to whom you authorise us to disclose it through explicit consent

Except as described above, we will not disclose your personal information without your written consent, unless we are required to do so by applicable law.

 

SECTION 3: International Transfers Update

3.1 International Data Transfers


Your personal information may be transferred to, stored, and processed in countries outside New Zealand, including but not limited to:

United States: Where many of our service providers operate, including:

  • Productivity Tools: Microsoft 365 services
  • AI Providers: OpenRouter, OpenAI, Anthropic
  • CRM Platform: Ontraport
  • Cloud Hosting Providers: Various infrastructure providers
  • Analytics and Marketing Services: Various providers

Other Countries: Depending on the service provider and their infrastructure locations

3.2 Safeguards for International Transfers
We ensure international data transfers are protected by:

For AI Providers:

  • Data Processing Agreements with standard contractual clauses
  • Training exclusion configurations
  • Data minimization and pseudonymization practices
  • Regular security assessments

For Other Service Providers (like Microsoft 365 and Ontraport):

  • Data Processing Agreements or equivalent contractual protections
  • Standard contractual clauses or other approved transfer mechanisms
  • Due diligence on provider security practices
  • Regular review of provider compliance

General Protections:

  • We only work with providers who demonstrate adequate data protection standards
  • We conduct regular assessments of international provider security
  • We ensure contracts require compliance with Privacy Act principles
  • We maintain records of international data transfers and safeguards

Where personal information is transferred outside New Zealand, we will comply with the requirements of the Privacy Act 2020 that relate to the transfer of personal information overseas.

 

SECTION 4: Your Rights Update

4.1 Rights Regarding AI Processing


In addition to your general privacy rights, you have specific rights regarding AI processing:

Right to Information: You can request details about how your data is used in AI processing.

Right to Opt-Out: You may opt-out of AI processing of your data by contacting us at [email protected].

Right to Correction: If AI processing uses inaccurate data, you can request correction.

Exercise These Rights: Contact us at [email protected] to exercise any of these rights.

4.2 General Privacy Rights


Subject to certain grounds for refusal set out in the Act, you have the right to access your readily retrievable personal information that we hold and to request a correction to your personal information. Before you exercise this right, we will need evidence to confirm that you are the individual to whom the personal information relates.

In respect of a request for correction, if we think the correction is reasonable and we are reasonably able to change the personal information, we will make the correction. If we do not make the correction, we will take reasonable steps to note on the personal information that you requested the correction.

If you want to exercise either of the above rights, email us at [email protected].

Your email should provide evidence of who you are and set out the details of your request (e.g. the personal information, or the correction, that you are requesting).

 

SECTION 5: Data Retention Update

5.1 AI Processing Retention


Data shared with AI providers is:

  • Temporarily processed for generating responses
    – Retained by providers according to their policies (typically 30 days for abuse monitoring)
  • Not used for AI model training purposes
  • Deleted according to provider retention schedules

We do not retain AI-generated insights containing personal data beyond our standard retention periods.

5.2 General Retention Policy


We will only retain personal information as long as it is required for the purposes for which the information may lawfully be used. Specific retention periods vary by:

Type of Data:

  • Financial data: Retained as required for service delivery and legal obligations
  • Contact information: Retained while you are an active client and for reasonable period after
  • Usage data: Retained for service improvement and analytics
  • Legal/compliance records: Retained as required by law

Storage Locations:

  • Primary storage: Cloud-based systems (like Ontraport) with servers in various international locations
  • On-premise storage: Data may sometimes be held at 173 E Main Road, Tawa, Wellington or 1/1 Walton Leigh Ave Porirua if provided outside our primary software
  • Third-party storage: Various service providers as listed in this policy

Deletion Procedures:
All data stored online is backed up and can be retrieved in the event of data loss or corruption. When data is no longer needed, we:

  1. Delete from primary systems according to retention schedules
  2. Ensure deletion from backups within reasonable timeframes
  3. Request deletion from third-party processors where applicable
  4. Maintain deletion records for audit purposes

 

SECTION 6: Data Security Update

6.1 AI-Specific Security


We implement additional safeguards for AI data processing:

  • Regular audits of data shared with AI providers
  • Monitoring for anomalous data exposure
  • Immediate response procedures for AI-related data incidents
  • Contractual requirements for AI provider breach notification

6.2 General Data Security


We will take reasonable steps to keep your personal information safe from loss, unauthorised activity, or other misuse. Our security measures include:

Technical Safeguards:

  • Encryption of data in transit (using TLS/SSL protocols)
  • Encryption of sensitive data at rest
  • Secure network connections and firewalls
  • Regular security updates and patches
  • Access controls and authentication mechanisms

Organizational Safeguards:

  • Staff training on data protection and privacy
  • Confidentiality agreements with employees and contractors
  • Regular security audits and assessments
  • Incident response planning and testing

Third-Party Provider Security:

  • Due diligence on provider security practices
  • Contractual security requirements for all processors
  • Regular review of provider security certifications
  • Monitoring for provider security incidents

Audits and Compliance:

Our software and practices are subject to regular audits to ensure continuing compliance with security requirements and Privacy Act obligations.

Data Breaches
Our Privacy Officer has processes and systems in place in the unfortunate event of a data breach. If such an event occurs, we will promptly identify, report and examine a personal data breach.

Internet use
While we take reasonable steps to maintain secure internet connections, if you provide us with personal information over the internet, the provision of that information is at your own risk.

If you follow a link on our website to another site, the owner of that site will have its own privacy policy relating to your personal information. We suggest you review that site’s privacy policy before you provide personal information.

We use cookies (an alphanumeric identifier that we transfer to your computer’s hard drive so that we can recognise your browser) to monitor your use of the website. You may disable cookies by changing the settings on your browser, although this may mean that you cannot use all of the features of the website.

We may use information about your use of our websites and other IT systems to prevent unauthorised access or attacks on our software. We may utilise services from one or more third party suppliers to monitor use of our systems. These third-party suppliers will have access to monitoring and logging information as well as information processed on our websites and other IT systems.

Contact Information:
Elias Services Ltd trading as Futurebound
Privacy Officer: [email protected]