Privacy Policy

Inite Limited Last updated: 23 July 2026

Inite Limited (“Inite”, “we”, “us”) builds and supports integrations between business systems. In that work we handle two kinds of information: personal information about the people we deal with, and business data that moves through the systems we connect. This policy explains what we collect, how we use it, and the choices you have. We follow the New Zealand Privacy Act 2020.

The short version: we collect only what we need to work with you, we do not sell your data, we do not use your data to train AI models, and you can always ask us what we hold about you at team [at] inite.co.

1. Who we are

Inite Limited is a New Zealand company (NZBN 9429052313110), registered office at Suite 14441, Level 1, 6 Johnsonville Road, Johnsonville, Wellington 6037, New Zealand. For anything in this policy, contact team [at] inite.co.

2. What we collect

Website visitors. Our website runs on Cloudflare. Standard technical logs (IP address, browser type, pages requested) are processed to serve and protect the site. We use PostHog for website analytics and product telemetry: which pages are visited, how visitors move through the site, and how our tools perform. We use this to improve the site and our services, not to build advertising profiles. We do not run advertising trackers.

Enquiries and bookings. When you contact us or book a free assessment, we collect what you give us: your name, work email, phone number, organisation, and what you tell us about your systems and plans. Bookings are handled through our scheduling provider, and contact details are kept in our CRM so we remember who you are and what we discussed.

Client engagements. During an engagement we hold contact details of the people we work with (names, roles, work emails), plus the business information your organisation provides: system details, architecture documentation, repository details, and the like. Architecture and as-built diagrams are kept in Eraser, our diagramming tool. Agreements, billing contacts, and invoicing records are kept in Zoho Books, our accounting system, and payments are processed by Stripe. Credentials your organisation shares with us are stored in 1Password (see section 8). Business information gained in an engagement is held under the confidentiality terms of our agreement with your organisation.

Data inside your integrations. The integrations we build move your business data (orders, invoices, stock levels, customer records) between your systems. We process that data on your behalf to deliver and support the integration. It belongs to your organisation, and our agreement with your organisation governs it. Where it contains personal information about your customers or staff, your organisation remains responsible for it as the collecting agency, and we act on your instructions.

Kori conversations. Kori, our AI Integration Support Engineer, works in Microsoft Teams. Where Kori is installed, we collect:

  • Message content. The text of messages in Teams chats where Kori is installed, and direct messages sent to Kori. Important: in a group chat, Kori has permission to read all messages in that chat (via the Teams permission ChatMessage.Read.Chat), not only messages that mention Kori. Messages that do not need a response are used only for conversation routing and context, and do not trigger a reply.
  • Sender information. Your Teams display name and user identifier, and, where needed to verify you belong to a registered customer organisation, your email address or user principal name.
  • Conversation metadata. Conversation, message, and tenant identifiers and reply threading, used to route messages to the right support case.
  • Feedback. Ratings and optional comments you submit on Kori’s responses.
  • Operational platform data. When investigating a support case, Kori may query your organisation’s connected integration platform (for example, workflow and invocation status from a Restate deployment) to diagnose issues.
  • Service logs. Technical logs of routing decisions, case events, and errors, used for operations, troubleshooting, and audit.

Kori runs as its own service with its own legal terms. For the full detail of how Kori handles your data, see Kori’s separate Privacy Policy and Terms of Service.

3. How we use information

  • To respond to enquiries, run free assessments, and prepare proposals.
  • To deliver, monitor, and support your integrations, including answering support questions and investigating issues.
  • To route support messages to the correct case and keep conversational context.
  • To verify that a sender belongs to a registered customer organisation, and to refuse service to unknown senders.
  • To create and track engineering work: with your organisation’s involvement, Kori can file GitHub issues in your organisation’s designated repository, and file case feedback in Inite’s internal feedback repository.
  • To keep an audit trail of support cases and actions taken, for quality and accountability.
  • To invoice and keep the business records the law requires.
  • To improve the reliability and quality of our services.

We do not use your information for advertising, and we do not send marketing you have not asked for.

4. AI processing

Kori uses large language models (LLMs) to understand messages and generate responses. Message content and relevant case context are sent to AI models operated by our infrastructure providers (Cloudflare Workers AI, and Anthropic models accessed through Cloudflare AI Gateway, depending on configuration) for the sole purpose of generating support responses. Responses produced by AI are labelled as AI generated in Teams. We do not use your messages or your business data to train AI models. AI output can be inaccurate; our Terms of Service explain how to treat AI generated content. Your use of Kori is also governed by Kori’s own Terms of Service and Privacy Policy.

5. Who processes data for us

We rely on a set of service providers to operate. Each one has its own privacy policy, linked below, that explains how they handle data on their side.

ProviderWhat we use it forTheir privacy policy
MicrosoftMicrosoft 365 (Office documents, Outlook email, Teams chat, including Kori), and Microsoft Azure, one of the platforms we host customer integrations onprivacy.microsoft.com/privacystatement
CloudflareWebsite hosting, application hosting, conversation and case state storage, the customer knowledge base, logging, AI model serving and gateway, and hosting for some customer integrationscloudflare.com/privacypolicy
RestateRestate Cloud, one of the platforms we host customer integrations onrestate.dev/privacy
Amazon Web ServicesOne of the platforms we host customer integrations onaws.amazon.com/privacy
AnthropicLLM inference, when Kori is configured to use Anthropic models via Cloudflare AI Gatewayanthropic.com/legal/privacy
GitHubCode and issue tracking (fix issues go to your organisation’s own repository; feedback issues go to an Inite repository)docs.github.com/site-policy
1PasswordSecrets management for our own credentials and credentials customers share with us (see section 8)1password.com/legal/privacy
Zoho BooksAccounting: customer billing details, agreements, and invoicing recordszoho.com/privacy
StripePayment processing for invoices and subscriptionsstripe.com/privacy
PostHogWebsite analytics and product telemetryposthog.com/privacy
EraserArchitecture and as-built diagrams for customer engagementseraser.io/privacy
AttioOur CRM, holding business contact detailsattio.com/legal/privacy
Cal.comBooking for the free assessmentcal.com/privacy

Which hosting platform (Cloudflare, Restate Cloud, Azure, or AWS) runs your integrations depends on your engagement; we agree it with you during the project, and it is shown on your live flow diagrams.

Where your data is hosted. On Cloudflare, Azure, and AWS we host integrations in your region: New Zealand customers in New Zealand and Australian customers in Australia. Restate Cloud is hosted in the United States. We are also building our own hosting offering, which will run in New Zealand and Australia. Our secrets management (1Password) and website analytics (PostHog) are hosted in the United States.

These providers store data on infrastructure that may be located outside New Zealand (including the United States, Australia, and the European Union). Where personal information is held overseas, we rely on providers that are subject to privacy safeguards comparable to the New Zealand Privacy Act, or on contractual protections, as required by the Act.

6. Sharing

We do not sell personal information and we do not share it with third parties for advertising. Information is shared only with the service providers above as needed to run our services, with your own organisation (for example, GitHub issues filed in your repository, or Kori’s responses visible to other participants in your Teams chat), and where required by law.

One thing worth knowing about how we work: we run one shared Teams chat per customer, and with your agreement, your other vendors can be in it. Anything posted in that chat is visible to everyone in it, so treat it like the shared workspace it is.

7. Retention

  • Conversation history kept for generating Kori’s responses is limited to a bounded window of recent messages per support case.
  • Support case records (triage summaries, actions taken, filed issues, and audit entries) are retained so support outcomes stay traceable while we support your organisation.
  • Contact details are kept while we have an active relationship or a live enquiry, and removed on request.
  • Invoicing and tax records are kept for at least seven years, as New Zealand tax law requires.
  • Technical logs and website analytics are retained according to the retention settings of our logging and analytics platforms.

After information is no longer needed, we delete or anonymise it. You can ask us to delete your information at any time (see section 9).

8. Security

Data in transit is encrypted with TLS. Access to customer environments uses credentials your organisation grants, on the least access needed for the job. Inbound bot traffic to Kori is authenticated against Microsoft’s Bot Framework. Actions that modify customer systems require explicit human approval and are restricted to authorised operators. Internal audit endpoints are access protected.

All secrets, ours and yours, live in 1Password. Credentials your organisation shares with us go into a dedicated 1Password vault where your team has write only access: your people can add and update credentials, but cannot read what is stored there. Read access is granted to the integration software that needs the credentials to run. This means secrets are never sent over email or chat, and no one sees a credential who does not need it.

If you believe you have found a security issue in anything we run, tell us at security [at] inite.co and we will get it sorted.

9. Your rights

Under the New Zealand Privacy Act 2020 you have the right to ask for a copy of the personal information we hold about you, and to ask us to correct it. You can also ask us to delete information we no longer need, or object to how we are handling it. Email team [at] inite.co and we will respond promptly.

If you are not happy with our response, you can complain to the Office of the Privacy Commissioner at privacy.org.nz. If you are outside New Zealand, you may have similar rights under your local law, and we will honour them.

Your organisation’s agreement with Inite may also govern how data relating to your organisation is handled.

10. Changes to this policy

We may update this policy from time to time. The “Last updated” date above reflects the current version. Material changes will be communicated to customer organisations.

11. Contact

Privacy questions and requests: team [at] inite.co Security reports: security [at] inite.co Phone: +64 4 888 1424

Inite Limited, Suite 14441, Level 1, 6 Johnsonville Road, Johnsonville, Wellington 6037, New Zealand.