Legal
Privacy & Data Collection Policy
How KoiZai collects, uses, shares and safeguards personal data across our website, platform and services — including how AI-assisted features handle it.
Last updated: August 17, 2026
On this page
About this Policy
Who we are
Who this Policy covers
KoiZai's role
Personal data we collect
KoiZai collects or processes only the categories reasonably relevant to the Services used, the relationship concerned and the information supplied. These may include account, contact, professional, financial-planning, client, technical, usage, support and communication information.
How we collect personal data
How we use personal data
AI, algorithms and automated processing
Customers and users must provide only personal data that they are authorised to provide, that is relevant to the intended purpose and that they reasonably believe to be accurate and complete. KoiZai will apply appropriate data-minimisation, access-control, security, retention and deletion measures to personal data processed through AI-assisted functions.
KoiZai may use aggregated or anonymised information for platform analytics, security, evaluation and service improvement where individuals cannot reasonably be identified, directly or indirectly. KoiZai will prohibit attempted re-identification.
Any other use of identifiable or re-identifiable personal data for model training or improvement requires:
- 1.the Customer’s specific written authorisation;
- 2.confirmation that the Customer is authorised to provide those instructions;
- 3.any notice to and consent from affected individuals required by applicable law; and
- 4.appropriate contractual, technical and governance safeguards.
Customer authorisation does not replace any consent or other legal requirement applicable to the individuals whose personal data is involved.
- 1.for the specified service purpose;
- 2.on KoiZai’s documented instructions;
- 3.for no longer than necessary; and
- 4.subject to appropriate confidentiality, security, access-control, retention, deletion, incident-notification and subprocessor requirements.
KoiZai will contractually prohibit external AI providers from using identifiable Customer Data, prompts or outputs to pre-train, train, fine-tune, evaluate or improve a general-purpose or shared model for the provider’s benefit or for the benefit of other customers or third parties.
Where appropriate, KoiZai will provide information about the relevant provider or provider category, the purpose of processing, the types of data involved, processing locations, retention arrangements and whether any customer-specific model configuration or evaluation is involved.
KoiZai may review the relevant inputs, outputs, system logs and user feedback only to investigate the reported issue, provide support, maintain security, meet legal obligations and improve the reliability of the relevant function. Access will be limited to authorised personnel and service providers with a need to know.
Users should not include unnecessary personal data in feedback or support reports. Where a reported issue may involve a personal-data breach, unauthorised processing or material risk to an individual, it will be escalated under KoiZai’s applicable incident-response procedures.
Cookies and website technologies
Direct marketing
Disclosure of personal data
Overseas processing and transfers
Data retention and deletion
Data security
Data incidents
Access, correction and other rights
Adviser firms and their clients
Children
Third-party websites
Complaints and contact details
Changes to this Policy
Questions about this document?
Our team is happy to help with anything unclear.
