Supporting · Privacy

Privacy policy, in plain terms.

How Yakaps Limited (trading as .tic) collects, uses, holds, and protects personal information. Written to comply with the New Zealand Privacy Act 2020 — and written in plain language, because if you can’t understand it, it doesn’t protect you.

Version 1.0 Effective 17 May 2026 Last reviewed 17 May 2026 Governing law · New Zealand
01

Who we are.

The legal entity behind .tic is Yakaps Limited, a New Zealand limited liability company.

  • Legal name: Yakaps Limited
  • Trading name: .tic
  • Privacy contact: percy@ticnz.com

In this policy, "we", "us", and "our" mean Yakaps Limited. "You" means any individual whose personal information we hold — which may be a client contact, a prospective client, an employee or contractor of a client, a sub-consultant, a visitor to our website, or anyone else whose information we have collected directly or indirectly in the course of our work.

02

What we collect.

The categories of personal information we typically collect, in plain terms:

Identification and contact details

Name, job title, employer, work email address, work phone number, postal address where relevant for invoicing.

Professional and engagement information

Information about your role, decision rights, and the questions you are working through, where relevant to the engagement. Notes from meetings and working sessions in which you have participated.

Commercial and billing information

For clients: invoicing contact, billing entity, GST number, payment records, bank account details for receiving payment. We do not collect or store individual credit card or debit card information.

Website information

If you visit ticnz.com or write to us through the site or by email: IP address (in aggregated form), browser and device type, referring URL, pages visited, and the contents of any message you send. See section 9.

Information you choose to share

Anything else you choose to share with us in writing, in person, or by phone — including in working documents you provide to us during an engagement.

We try not to collect sensitive personal information (health information, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, etc.) and where it appears in materials you share with us, we treat it with extra care under section 10.

03

Why we collect it.

We collect personal information for the following purposes — and only for these purposes:

  • To respond to enquiries, including those submitted through ticnz.com or by email.
  • To assess fit and scope a potential engagement.
  • To enter into and perform Statements of Work and the Master Service Agreement.
  • To invoice for fees, receive payment, and meet our tax and accounting obligations.
  • To communicate with you about an engagement in progress.
  • To improve our frameworks and methodologies through the use of anonymised, aggregated patterns (as described in section 5).
  • To comply with our legal, regulatory, and professional obligations.

We do not collect or use personal information for direct marketing without your specific consent. We do not run advertising campaigns. We do not sell, rent, or trade personal information.

04

Indirect collection. (IPP 3A)

Sometimes we receive personal information about you from someone other than you — typically because our client has provided us with information about its employees, contractors, customers, or partners in the course of an engagement.

Where this happens, under Information Privacy Principle 3A of the New Zealand Privacy Act 2020 we are required to take reasonable steps to make sure you are aware that we have collected the information, who we are, what we are collecting, why we are collecting it, who else holds the information, and your right to access and correct it. This policy is the standing record of that information. Where the engagement involves direct contact with you (for example, you participate in a working session we facilitate for our client), we will identify ourselves and the purpose of the work at the start.

Our client is responsible for ensuring it has the right to share your information with us under the Privacy Act and any agreement it has with you. We will only use information shared with us by a client for the purposes of the engagement with that client, in accordance with section 5 below.

05

How we use information.

Personal information collected from or about you is used only for the purpose for which it was collected, or for a directly related purpose you would reasonably expect — in accordance with Information Privacy Principle 10 of the Privacy Act.

In particular:

  • Information you provide in the course of an engagement is used solely for that engagement, unless you give us specific permission to use it for something else.
  • We may use anonymised, aggregated patterns from our engagements (sufficiently de-identified that you and our client cannot reasonably be re-identified) to develop our frameworks and methodologies, in accordance with the Master Service Agreement with our client.
  • We will not use personal information for any new purpose that is not directly related to the original purpose without first obtaining your authorisation, except where the Privacy Act otherwise permits.
06

Who we share information with.

We share personal information only in the following circumstances:

With our client (in the context of an engagement)

Information collected in the course of an engagement is shared with our client — that is the point of the engagement. The Master Service Agreement governs how the client must in turn protect that information.

With sub-consultants we have specifically engaged

We may, with the client's prior written consent, engage sub-consultants to assist with an engagement. Sub-consultants are bound by written confidentiality obligations no less protective than those in our Master Service Agreement.

With service providers we rely on

We use a small number of third-party providers to operate our business — for example, cloud document storage, email, accounting and invoicing, payment receipt, and the AI tools described in section 7. Each provider is selected with privacy and security as material criteria, and we only share what is reasonably necessary for them to provide the service.

With government, regulatory, or legal bodies

Where we are required to disclose information by law (for example, to the Inland Revenue Department in the course of tax obligations, or in response to a lawful court order), we will do so to the minimum extent required.

In connection with a sale or transfer of our business

If we sell or transfer all or substantially all of our business, personal information may be transferred as part of that transaction, subject to the buyer agreeing to be bound by terms no less protective than this policy.

We do not sell, rent, or trade personal information. We do not share personal information for the purposes of advertising.

07

Use of AI tools.

We use business-grade generative AI tools — including Claude (Anthropic) and Gemini (Google) — which provide enterprise-level data protections. These tools are configured to ensure that your data is never used for model training and remains isolated within our secure professional environment. These tools are used to assist with synthesis, drafting, research, modelling, and analysis. We use them on contracted accounts where, by contract with the AI provider:

  • our inputs and outputs are not used to train the provider's generative AI models;
  • our inputs and outputs are not subject to routine human review by the provider's personnel.

The practitioner remains professionally accountable for every deliverable. AI-assisted outputs are reviewed, edited, and quality-assured by the practitioner before they reach our client.

Personal information and AI. We do not enter personal information into AI tools unless (a) the use of the AI tool is itself part of the agreed engagement deliverables; (b) we have the client's prior written consent; or (c) the personal information has been de-identified to a standard reasonably calculated to prevent re-identification.

Our client may, by written notice, request that AI tools not be used on their engagement, or that specified categories of confidential information not be processed by AI tools. We will comply with any such request.

08

Cross-border disclosure.

Some of the service providers we rely on (notably cloud document storage, email, and AI tools) are based outside New Zealand and may process information on servers located in other jurisdictions, including the United States.

Under Information Privacy Principle 12 of the Privacy Act, we will only disclose personal information to an overseas recipient where one of the following applies: the recipient is subject to comparable privacy safeguards (whether by law or by the contract under which we have engaged them); you have expressly authorised the disclosure after being informed that comparable safeguards may not apply; or another of the exceptions in IPP 12 applies.

In practice, the providers we rely on operate under contracts that bind them to confidentiality, security, and (where relevant) data-handling commitments equivalent to or stronger than those required in New Zealand. We review these arrangements before engaging a new provider.

09

Cookies and website analytics.

ticnz.com uses the minimum amount of tracking necessary to operate the site. We do not use advertising cookies. We do not track visitors across other websites.

  • Essential cookies: we may use small amounts of local storage to remember your theme preference (light or dark). This is stored only in your browser and is not transmitted to us.
  • No advertising or cross-site tracking: we do not run advertising. We do not embed third-party advertising or social-media tracking pixels.

Most browsers allow you to refuse or delete cookies through their settings. Doing so will not prevent you from using the site.

10

Storage, security, and cyber posture.

Under Information Privacy Principle 5, we are required to take reasonable safeguards against loss, unauthorised access, use, modification, or disclosure of personal information. The safeguards we maintain include:

  • Device-level encryption on laptops and removable media.
  • Multi-factor authentication on email, cloud storage, and other critical services.
  • Maintained, patched operating systems and applications.
  • Reputable endpoint protection.
  • Cloud storage and email through providers we have assessed as offering security commensurate with the sensitivity of the information held.
  • Access controls so that personal information is accessible only to those who need it for the purpose for which it was collected.
  • Cyber liability insurance.

No security regime is perfect, and we will not pretend otherwise. We work to a standard appropriate to the size of our business and the sensitivity of the information we hold, and we review our controls when our circumstances change.

11

Retention.

We retain personal information only for as long as is necessary for the purpose for which it was collected, or as required by law (in particular, tax and accounting records, which we retain for a minimum of seven years from the end of the relevant financial year, as required by New Zealand law).

At the end of an engagement, we return or securely destroy client confidential information (including personal information held on behalf of the client) in accordance with the Master Service Agreement, save for materials we are required to retain for legal, regulatory, or insurance reasons.

We periodically review the personal information we hold and delete what is no longer required.

12

Your rights — access and correction.

Under the Privacy Act, you have the right to:

  • Access the personal information we hold about you (Information Privacy Principle 6).
  • Request correction of any personal information we hold about you that is inaccurate, incomplete, irrelevant, or misleading (Information Privacy Principle 7). If we cannot agree on a correction, you may ask us to attach a statement of correction to the relevant information.

To make either request, write to percy@ticnz.com. We will need to verify your identity before releasing personal information.

We aim to respond to access and correction requests within twenty (20) working days, in line with the timeframe set out in the Privacy Act. If we cannot respond within that period, we will let you know in writing and explain why.

The Privacy Act allows us to withhold personal information in certain circumstances (for example, where disclosure would breach the privacy of another person, or where the information is subject to legal privilege). Where we withhold information, we will let you know the reason and, where the law requires, your right to seek a review through the Office of the Privacy Commissioner.

13

Notifiable privacy breaches.

Under the Privacy Act, a "notifiable privacy breach" is a privacy breach that it is reasonable to believe has caused, or is likely to cause, serious harm to an affected individual.

If we become aware of an actual or suspected notifiable privacy breach affecting your personal information, we will:

  • notify you (or our client, where the information was held on the client's behalf) as soon as reasonably practicable after becoming aware of the breach;
  • notify the Office of the Privacy Commissioner as required by section 114 of the Privacy Act;
  • take reasonable steps to contain the breach and prevent further harm;
  • cooperate in good faith on any investigation and remediation.
14

Complaints.

If you believe we have not handled your personal information in accordance with this policy or the Privacy Act, we want to know. Please write to percy@ticnz.com. We will acknowledge your complaint within five (5) working days and aim to provide a substantive response within twenty (20) working days.

If we cannot resolve your concern

You can refer the matter to the Office of the Privacy Commissioner, the independent body responsible for the Privacy Act in New Zealand:

Website: privacy.org.nz
Phone: 0800 803 909
Email: enquiries@privacy.org.nz

15

Changes to this policy.

We may update this policy from time to time. The version number and effective date at the top of the page reflect the current version. If we make a material change, we will take reasonable steps to bring it to the attention of clients with whom we have an active engagement.

16

Contact us.

For any question about this policy, or about how we handle personal information, write to:

Percy Kapadia, Founding Partner and Director
Yakaps Limited (trading as .tic)
percy@ticnz.com

Engagements start with a coffee, not a contract.

If something here maps to a decision you're weighing, book a conversation or write directly. Replies come from the practitioner.