Who These Terms Apply To
These Website Terms of Use apply to everyone who visits advisercrm.co.nz. If you subscribe to Adviser CRM, the Software as a Service Agreement below (Section A, Section B, the Appendices, and the Schedules) also applies and prevails over these Website Terms of Use in relation to the Services.
Acceptance of Terms
By accessing or using this website, you agree to be bound by these Website Terms of Use, provided by Adviser CRM (New Zealand Business Number 9429044102692) ("Adviser CRM", "we", "us", or "our").
If you do not agree to these terms, you must not use this website.
We may update these terms from time to time. Continued use of the website after updates constitutes acceptance of the revised terms.
Acceptable Use
You agree not to:
- Use the website for unlawful purposes
- Attempt unauthorised access to the website or our systems
- Upload or transmit malicious software
- Interfere with the performance or security of the website
- Copy, scrape, or reverse engineer the website or the Adviser CRM platform
We may restrict or block access to the website for anyone who breaches these terms.
Intellectual Property
All website content, including software, branding, logos, documentation, and design, remains the property of Adviser CRM or its licensors.
You may not copy, reproduce, or distribute website content without our permission.
Third-Party Websites
This website may link to third-party websites and services, such as the Zoho Trust Centre. We are not responsible for the content, availability, or privacy practices of third-party websites.
Privacy
Our Privacy Policy explains how we collect, use, and protect personal information, including information collected through this website.
Limitation of Liability
To the fullest extent permitted by law, Adviser CRM is not liable for any loss arising from your use of, or inability to use, this website, including loss of data, revenue, or business, or any indirect or consequential loss.
Governing Law
These Website Terms of Use are governed by the laws of New Zealand, and any disputes are subject to the jurisdiction of the New Zealand courts.
Contact Us
Questions about these terms can be sent to support@advisercrm.co.nz.
Contact UsAgreement
In this Agreement, Supplier means Adviser CRM (New Zealand Business Number 9429044102692), and Client means the subscriber named in the signed agreement or order form.
The Supplier agrees to provide, and the Client agrees to subscribe to, the Adviser CRM Software as a Service offering and related services on the terms of this Agreement, comprising:
- Section A (Agreement and Key Details); and
- Section B (General Terms), together with the Appendices and Schedules.
About the Service
Adviser CRM delivers a comprehensive suite of cloud‑based CRM, compliance, and automation tools designed for New Zealand financial advisers.
The Service unifies client management, policy administration, workflow automation, and operational reporting to support productivity and compliance obligations for professional advisory practices.
SaaS Service
Adviser CRM is a vertical cloud platform for financial‑services professionals. The core Service includes the following modules and features (as available from time to time):
- Client & Contact Management: Unified view of clients, accounts, households, and related entities.
- Leads & Opportunity Tracking: Capture, qualify, and manage opportunities through to conversion.
- Life & Health Policy Management: Manage insurer policy data, benefits, premiums, and renewals.
- Insurer Data Import Tool: Import and reconcile data received from supported insurers.
- Loan & Mortgage Management: Manage lending pipelines and mortgage renewals.
- Investment & KiwiSaver Tracking: Record investment holdings, transactions, and valuations.
- Activities & Tasks: Schedule calls, meetings, and follow‑ups with reminders and outcomes tracking.
- Automation & Workflow Builder: Design and deploy rule‑based automations for compliance and service.
- Email & Letter Templates: Generate compliant client communications and merge documents.
- Files & Document Management: Upload, tag, and securely store client files and artefacts.
- AI‑Assisted Features: Tools that help draft, summarise, and analyse content, subject to clause 5 (Artificial Intelligence Features).
- Mobile Apps: Access Adviser CRM on Apple iOS and Android devices.
- Survey & Webform Builder: Create client‑facing digital forms and feedback surveys.
- Integrations: Connect with Microsoft 365, Google Workspace, Zoom, Quotemonster, Evince, Planolitix, Akahu, and other approved third‑party tools (see Part 2 of Appendix C).
Initial Setup & Configuration Service (Included)
Included at no additional cost with each new subscription:
- User‑profile configuration and permission setup.
- Email and calendar synchronisation (Microsoft 365 or Google Workspace).
- Introductory training session on standard Adviser CRM features and modules.
- Technical support for issues arising from standard Adviser CRM functionality.
Additional Services (Customisation & Training) – Optional
Optional paid services (charged at Adviser CRM’s prevailing hourly rate or as quoted):
- System customisation or assisted customisation.
- Training on customised functionality.
- Data migration from external systems (provided under a separate Data Migration Agreement).
- Consultancy for complex workflows, integrations, or documentation.
Fees and Billing
Monthly licence fees are payable monthly in advance by credit/debit card or direct debit. Adviser CRM may review and adjust fees annually, with any increase limited to CPI plus up to 2%.
Reasonable costs of collection may be recovered on overdue accounts.
Websites & Notices
Websites
CRM Login: crm.advisercrm.co.nz
Website: advisercrm.co.nz | advisercrm.com
Form of Notices
All notices, requests, consents, and other communications under this Agreement must be in writing and may be delivered by hand, sent by post, sent by email, or provided via the CRM platform or associated websites.
Supplier Contact Details
The Supplier’s contact details for notices are:
- Email: support@advisercrm.co.nz
- Privacy enquiries: privacy@advisercrm.co.nz
- Address: P.O. Box 1989, Rotorua, Bay of Plenty 3010, New Zealand
Notices via Platform (In‑App Notifications)
- The Supplier may provide notices to the Client via notifications within the CRM platform or associated websites.
- The Client agrees that any such notification, including announcements, alerts, or updates made available within the platform, constitutes valid written notice under this Agreement.
Deemed Delivery
A notice will be deemed received:
if delivered by hand, at the time of delivery;
if sent by post, 3 Business Days after posting;
if sent by email, at the time of transmission, unless the sender receives an automated message indicating delivery failure; and
if provided via the CRM platform or associated websites, at the time the notice is made available to the Client within the platform.
Acceptance of Notices and Updates
Where a notice relates to changes to this Agreement, the Services, or applicable terms, the Client’s continued use of the CRM platform or Services after such notice has been provided will constitute acceptance of those changes.
Change of Details
Either party may change its contact details by giving written notice to the other party. Until such notice is given, the last notified details will be deemed correct.
Validity of Service
Service in accordance with this section is deemed valid for all purposes, including for the commencement of legal proceedings.
1. Interpretation
Definitions: Capitalised terms have the meanings set out in Schedule A (Definitions).
Interpretation: Clause and other headings are for ease of reference only and do not affect interpretation. Words in the singular include the plural and vice versa. References to a person include individuals, bodies corporate, and other legal entities. Including and similar words do not imply any limit. A statute includes regulations and amendments. No term is to be read against a party because it was first proposed or drafted by that party. If there is any conflict between Section B and Section A, Section B prevails unless expressly stated otherwise in Section A.
2. Services
General: The Supplier will use reasonable efforts to provide the Services in accordance with this Agreement and New Zealand law, exercising reasonable care, skill, and diligence with suitably qualified personnel.
Non‑exclusive: Provision of the Services is non‑exclusive. The Supplier may provide the Services to any other person.
Availability: Subject to clause 2.4:
The Supplier will use reasonable efforts to ensure the SaaS Service is available on a 24/7 basis. From time to time the SaaS Service may be unavailable to permit maintenance or development, or during a Force Majeure event. The Supplier will use reasonable efforts to publish on the Website and/or notify the Client by email advance details of any unavailability.
Through web services and APIs, the SaaS Service interoperates with third‑party service features. The Supplier does not warrant availability of those features. If a third party ceases to provide a feature, or ceases to make it available on reasonable terms, the Supplier may cease to make that feature available to the Client. The Client is not entitled to any refund, discount, or other compensation in such circumstances.
Service Levels: The Supplier will use commercially reasonable endeavours to achieve 99.5% uptime (excluding planned maintenance and Force Majeure). Planned maintenance will be notified at least 24 hours in advance. Support response targets are set out in Appendix A (Service Level Agreement).
Related Services: The Supplier may make available additional services to supplement the SaaS Service. At the Client’s request and subject to Fees, the Supplier may provide Additional Services on the terms of this Agreement. Data migration services are provided under a separate Data Migration Agreement, which prevails over this Agreement to the extent of any inconsistency relating to those services.
Service Changes: The Supplier may modify, update, or enhance the Services from time to time, provided that such changes do not materially reduce the overall core functionality of the Services.
3. Client Obligations
General use: The Client and its personnel must use the Services solely for the Client’s internal business and lawful purposes (including compliance with the Unsolicited Electronic Messages Act 2007) and must not resell or commercially exploit the Services.
Training & Support Process: The Client will use the Supplier’s support site and online education as a first resource; submit support tickets for requests; require users to attend structured training as agreed; educate users on what is included in subscription support versus billable time; and obtain internal approval prior to customisation requests.
Access conditions: Users must not impersonate others, share logins, or misrepresent authority; must correctly identify the sender of transmissions; must not undermine the security or integrity of Underlying Systems; and must not use the SaaS Service in a way that impairs others’ use. Users must not view or copy data beyond their authorisation. Users must not input Data that breaches third‑party rights or is Objectionable, incorrect, or misleading; and must comply with the Website terms of use.
Personnel: Only Permitted Users may access the SaaS Service. The Client must procure compliance by Permitted Users. Breach by the Client’s personnel is deemed to be a breach by the Client.
Authorisations: The Client is responsible for procuring licences, authorisations, and consents required to use the Services and to input, process, and distribute Data.
Financial‑services compliance: The Client remains responsible for compliance with its obligations under the Financial Markets Conduct Act 2013, the Code of Professional Conduct for Financial Advice Services, and related FMA guidance.
Account security: Each user must maintain the confidentiality of their credentials. Sharing logins to avoid licence costs is prohibited and may result in restriction or suspension under clause 12.6.
4. Data
Supplier access: The Supplier may require access to Data to exercise its rights and perform its obligations under this Agreement and may authorise personnel to access Data for that purpose. The Client must arrange necessary consents and approvals.
Analytical Data: The Supplier may use Data and information about use of the Services to generate anonymised, aggregated statistical and analytical data for internal research, product development, analysis, trends, and insights, and may supply Analytical Data to third parties. Title to all Intellectual Property Rights in Analytical Data remains with the Supplier. These rights survive termination.
Agent: To the extent Data contains Personal Information, the Supplier acts as the Client’s agent under section 11 of the Privacy Act 2020 when collecting, holding, and processing such information through the Services, and does not use or disclose it for its own purposes. The Client must provide all notices to, and obtain all necessary consents from, the individuals concerned.
Backups: The Supplier will take reasonable industry‑standard measures to back up Data. However, the Client remains responsible for maintaining its own independent backups of critical Data. The Supplier is not liable for any loss of Data except to the extent caused by its breach of this Agreement.
International storage and processing: The Supplier may store and process Data (including Personal Information) on secure servers in New Zealand and/or reputable international regions, including the United States, through the sub‑processors and in the locations set out in Part 1 of Appendix C, and may access that Data from those regions. The Supplier will ensure any offshore storage or processing is subject to safeguards comparable to those under New Zealand law.
Privacy events & assistance: The Supplier will notify the Client as soon as practicable of any notifiable privacy breach under the Privacy Act 2020, and will provide reasonable assistance with access and correction requests or investigations by the Privacy Commissioner.
Retention & deletion: Following termination, the Supplier retains system backups for 90 days, after which Data is permanently deleted, subject to any legal requirement to retain records.
Data indemnity: The Client indemnifies the Supplier and its technology partners against any claim, liability, or loss arising from a third‑party allegation that any Data infringes rights (including intellectual property and privacy rights) or is Objectionable, incorrect, or misleading.
Client‑enabled integrations: Where the Client enables an integration with a third‑party service under its own account with that provider (including the integrations listed in Part 2 of Appendix C), the Supplier transfers Data to and from that service on the Client’s instruction. That provider acts for the Client and is not the Supplier’s sub‑processor. Its handling of Data is governed by its terms with the Client, and the Supplier is not responsible for Data once it has been transferred to that service. The Client is responsible for ensuring it is authorised to share the Data and for telling the individuals concerned, in its privacy notices, that their information may be shared with those services.
5. Artificial Intelligence Features
AI Features: The SaaS Service includes features that use artificial intelligence services to help draft content, summarise records, transcribe and summarise meetings, and respond to support queries (AI Features). AI Features are provided by the sub‑processors identified as AI providers in Appendix C.
How Data is processed: When an AI Feature is used, the relevant Data (which may include Personal Information about the Client’s clients) is sent securely, encrypted in transit, to the relevant AI provider, processed, and the output is returned to the Services. The parties acknowledge that this processing is subject to this Agreement, the Privacy Act 2020, and Appendix B, even where the Data is held by the AI provider only momentarily.
AI provider commitments: The Supplier will only use AI providers that, under their terms with the Supplier:
process Data solely to provide the AI Features on the Supplier’s behalf;
do not use Data to train or improve their AI models, or for any other purpose of their own;
retain Data only for the period stated in Appendix C, or as required by law; and
are bound by confidentiality and security obligations no less protective than those in this Agreement.
Client‑enabled AI services: Where the Client connects or enables a third‑party service under its own account with that provider (for example, Zoom AI Companion), clause 4.9 applies and the provider’s terms with the Client govern that provider’s processing, and the Client is responsible for configuring that service appropriately.
Human review: Output from AI Features is a draft only and may be inaccurate or incomplete. The Client must ensure a suitably qualified person reviews all output before it is relied on, recorded, or sent to any person. The Client remains solely responsible for any financial advice given and for the accuracy of Personal Information it holds and uses (including under information privacy principle 8).
Client privacy notices: The Client is responsible for informing its clients, in its own privacy notices, that their Personal Information may be processed using AI services and by service providers located outside New Zealand.
Disabling AI Features: The Client may request that AI Features be disabled for its account by contacting the Supplier.
Changes to AI providers: The Supplier will give the Client at least 30 days’ notice before engaging a new AI provider to process Personal Information and will update Appendix C accordingly. If the Client reasonably objects, it may disable the relevant AI Feature under clause 5.7 or terminate under clause 12.2.
No warranty for AI output: Without limiting clause 9, the Supplier does not warrant that output from AI Features will be accurate, complete, or suitable for any purpose.
6. Fees
Fees: The Client must pay the Fees.
Invoicing and payment: The Supplier will issue valid GST tax invoices monthly in advance for the upcoming billing period unless otherwise agreed in writing. All Fees must be paid by credit card, debit card, or direct debit using the Supplier’s nominated payment systems. The Client must maintain a valid payment method at all times. No other payment methods will be accepted unless expressly agreed in writing by the Supplier.
Overdue amounts: The Supplier may charge interest on overdue amounts at the corporate overdraft reference rate (monthly charging cycle) of the Supplier’s primary trading bank plus 2% per annum from the due date to the date of payment, and may recover reasonable costs of collection.
Fee increases: The Supplier may increase Fees with at least 30 days’ notice. Additionally, the Supplier may review and adjust Fees annually by CPI plus up to 2% to reflect cost changes. If the Client does not wish to pay increased Fees, it may terminate on at least 30 days’ notice; otherwise, the increase is deemed accepted.
Payment method compliance: If the Client fails to maintain a valid payment method in accordance with this clause, the Supplier may suspend access to the Services until a compliant payment method is provided.
7. Intellectual Property
Ownership: Title to all Intellectual Property Rights in the Services, Website, and Underlying Systems remains with the Supplier (and its licensors). Title to Data remains with the Client. The Client grants the Supplier a worldwide, non‑exclusive, fully paid‑up, transferable, irrevocable licence to use, store, copy, modify, make available, and communicate the Data solely to perform this Agreement.
Know‑how: To the extent not owned by the Supplier, the Client grants the Supplier a royalty‑free, transferable, irrevocable, perpetual licence to use any know‑how, techniques, ideas, and methodologies used by the Supplier in providing the Services.
Feedback: All Intellectual Property Rights in feedback and resulting materials (including enhancements or derivative works) are owned solely by the Supplier; the Supplier may use or disclose feedback for any purpose.
Third‑party sites: The SaaS Service may link to third‑party websites or feeds. The Supplier excludes responsibility and liability for those sites.
Third‑party IP indemnity:
The Supplier indemnifies the Client against claims alleging that the Client’s authorised use of the SaaS Service infringes third‑party intellectual property rights (IP Claim), subject to the Client giving prompt notice, making no admissions, and giving the Supplier full authority to defend or settle the IP Claim.
The indemnity excludes claims arising from the Client’s breach, unauthorised use, or third‑party data.
The Supplier may secure continued use rights for the Client, or modify or replace the relevant items so they become non‑infringing.
Customisations: Unless agreed otherwise in writing, customisations, scripts, or configurations created by the Supplier remain the Supplier’s intellectual property. The Client receives a non‑exclusive licence to use them within its account. The Supplier’s personnel and contractors waive moral rights in such work to the extent permitted by law.
8. Confidentiality
Security: Each party must keep the other’s Confidential Information confidential, maintain adequate security measures, and disclose it only on a need‑to‑know basis to personnel and advisers who are bound by equivalent obligations.
Permitted disclosure: Confidential Information may be disclosed for performing the Agreement (including to sub‑processors under Appendix B), as required by law or stock‑exchange rules, if publicly available through no fault of the recipient, if rightfully received from a third party without restriction, or by the Supplier as part of a bona fide sale of its business (subject to equivalent confidentiality obligations).
Security standards: The Supplier will maintain industry‑standard technical and organisational measures (ISO 27001‑equivalent).
Survival: Confidentiality obligations survive termination of this Agreement.
9. Warranties
Mutual authority: Each party warrants it has full power and authority to enter into and perform this Agreement.
No implied warranties: To the maximum extent permitted by law, the Supplier’s warranties are limited to those expressly set out in this Agreement; all other conditions, guarantees, or warranties (including under Part 3 of the Contract and Commercial Law Act 2017) are excluded and, to the extent they cannot be excluded, liability for them is limited to NZD 1,000. The Supplier makes no representation that the Services will meet the Client’s requirements, be suitable for any particular purpose, or be uninterrupted or error‑free.
CGA exclusion: The parties agree the Consumer Guarantees Act 1993 does not apply, as the Services are supplied and acquired in trade for business purposes.
FTA contracting out: The parties agree to contract out of sections 9, 12A, and 13 of the Fair Trading Act 1986 and acknowledge it is fair and reasonable that this clause applies having regard to their experience, bargaining power, and the commercial nature of this Agreement (section 5D of the Fair Trading Act 1986).
10. Liability
Maximum liability: The Supplier’s maximum aggregate liability in any 12‑month period under or in connection with this Agreement, whether in contract, tort (including negligence), breach of statutory duty, or otherwise, will not exceed the Fees paid in the previous 12 months.
Unrecoverable loss: Neither party is liable for loss of profit, revenue, savings, business, use, data (including Data), or goodwill, or for any consequential, indirect, incidental, or special damage or loss.
Unlimited liability: Clauses 10.1 and 10.2 do not limit liability for personal injury or death, fraud or wilful misconduct, breach of confidentiality, or the Supplier’s indemnity under clause 7.5.
No liability for other’s failure: Neither party is liable for failures caused by the other party’s breach or negligence.
Mitigation: Each party must take reasonable steps to mitigate loss or damage it may suffer or incur.
Third‑party services: The Supplier is not liable for any failure, delay, or unavailability of the Services to the extent caused by third‑party systems or providers.
11. Updates to Agreement
The Supplier may amend, update, or replace this Agreement from time to time, including any terms, policies, pricing, or documents incorporated by reference.
The Supplier will provide notice of any material changes by:
email to the Client’s nominated email address; and/or
publication of the updated Agreement on the Website.
Any updated version of the Agreement will take effect from the date specified in the notice (Effective Date).
By continuing to access or use the Services after the Effective Date, the Client is deemed to have accepted and agreed to be bound by the updated Agreement.
If the Client does not agree to the updated Agreement, its sole remedy is to terminate this Agreement by written notice before the Effective Date.
The Supplier may make non‑material changes (including corrections, clarifications, or administrative updates) at any time, which take effect immediately upon notice.
To the extent of any inconsistency between this clause and any other provision of this Agreement (including any variation clause), this clause prevails.
12. Term, Termination, and Suspension
Duration: Unless terminated, the Agreement starts on the Start Date and continues month‑to‑month (or for 12 months for annual contracts) unless a party gives 30 days’ notice of termination to take effect at the end of the then‑current term.
No‑fault termination: Either party may terminate on at least 30 days’ prior notice. Subscription payments falling within the notice period must be paid.
Other termination rights: Either party may terminate immediately for a material breach not remedied within 10 days of notice, insolvency events, or inability to perform a material obligation for 30 days or more due to Force Majeure. If the remedies in clause 7.5(c) are exhausted without resolving an IP Claim, the Supplier may terminate immediately.
Consequences: Termination does not affect accrued rights. The Client must pay Fees for Services provided up to termination. Each party must, on request and subject to clause 12.5, return or destroy the other party’s Confidential Information.
Data on termination: Within 30 days after termination, the Client may request a copy of Data (at the Supplier’s reasonable cost) in a common electronic form (compatibility not warranted) and/or deletion of Data. The Supplier will use reasonable efforts to promptly delete Data when requested, subject to clause 4.7.
Rights to restrict: Without limiting other remedies, the Supplier may restrict or suspend access to the SaaS Service and/or delete, edit, or remove Data if the Supplier considers the Client has undermined security or integrity; used the SaaS Service for improper purposes or in a way that materially reduces performance; shared login details to avoid licensing costs; transmitted or stored Data that breaches rights or is Objectionable, incorrect, or misleading; or otherwise materially breached this Agreement. The Supplier will notify the Client of any restriction or suspension.
Supplier convenience termination: The Supplier may terminate for convenience on 60 days’ written notice.
13. Disputes
Good‑faith negotiations: Before court action, the parties will use best efforts to resolve disputes through good‑faith negotiations.
Mediation: If a dispute is unresolved within 15 Business Days, either party may refer it to mediation administered by the Arbitrators’ and Mediators’ Institute of New Zealand (AMINZ). This does not prevent urgent injunctive relief.
Continuity: Each party must continue to perform its obligations to the extent possible during a dispute.
14. General
Force Majeure: A party is not liable for failure to perform to the extent caused by Force Majeure, provided it promptly notifies the other party, uses best efforts to overcome it, and continues performance to the extent practicable.
Rights of third parties: No person other than the parties has a right to a benefit under or to enforce this Agreement.
Waiver: A waiver must be in writing and signed.
Independent contractor: The Supplier is an independent contractor; no partnership or joint venture is created. Nothing in this clause limits clause 4.3.
Notices: Notices must be given in accordance with the Websites & Notices provisions in Section A.
Severability: If a provision is illegal, unenforceable, or invalid, it is deemed modified to the extent necessary to remedy the defect; if that is not possible, it is severed without affecting the remaining provisions.
Variation by signature: Except as provided in clause 11, any variation must be in writing and signed by both parties.
Entire agreement and hierarchy: This Agreement sets out everything agreed by the parties and supersedes prior discussions. The parties have not relied on any representation not expressly set out in it. If there is an inconsistency, the following order of precedence applies: (1) Section B; (2) Section A; (3) Appendices; (4) Schedules; (5) documents incorporated by reference.
Subcontracting and assignment: The Client may not assign, novate, subcontract, or transfer any right or obligation without the Supplier’s prior written consent (not to be unreasonably withheld). A change of control of the Client is deemed an assignment. The Client remains liable for its obligations despite any approved assignment. Any assignment or transfer must be in writing.
Law and venue: This Agreement is governed by New Zealand law. The parties submit to the non‑exclusive jurisdiction of the Courts of New Zealand, with venue in Auckland.
Counterparts and electronic signatures: This Agreement may be signed in counterparts (including electronically), each an original and together the same instrument.
Appendix A – Service Level Agreement
Scope: This Appendix sets out the support response targets referred to in clause 2.4. It applies unless the Client and the Supplier have agreed a custom service level agreement under item 6.
Logging requests: Support requests must be logged as a support ticket through the Supplier’s support site or by email to support@advisercrm.co.nz, in accordance with clause 3.2.
Response times: The Supplier will respond to each support ticket within a maximum of 2 Business Days of receipt. The Supplier aims to respond to most support tickets within 4 hours on a Business Day.
Meaning of response: A response means an acknowledgement and initial assessment of the request by a member of the Supplier’s support team. Resolution times depend on the nature and complexity of the issue and are not guaranteed.
Availability: Service availability targets for the SaaS Service are set out in clause 2.4.
Custom service levels: A Client that requires different response times may request a custom service level agreement. Any custom service level agreement must be agreed in writing, may incur additional Fees, and prevails over this Appendix for that Client to the extent of any inconsistency.
Appendix B – Data Processing Addendum (Privacy Act 2020)
Scope: This Data Processing Addendum (DPA) applies to Personal Information processed by the Supplier on behalf of the Client.
Purpose: Processing is solely to provide the Services (including AI Features) and for security, support, and continuity. The Supplier does not use Personal Information for its own purposes.
Sub‑processors: The Supplier may engage the sub‑processors listed in Part 1 of Appendix C, subject to written agreements imposing protections equivalent to those in this DPA. The Supplier remains responsible for their acts and omissions and will give the Client at least 30 days’ notice of any new sub‑processor of Personal Information.
International transfers: Personal Information may be stored or accessed in the locations set out in Part 1 of Appendix C, including the United States, with safeguards comparable to those under New Zealand law.
AI processing: Personal Information processed through AI Features is subject to clause 5 of Section B. AI providers may not use Personal Information to train or improve their models or for their own purposes.
Security measures: The Supplier maintains industry‑standard technical and organisational measures (ISO 27001‑equivalent), including encryption of Data in transit.
Breach notification: The Supplier will notify the Client as soon as practicable after becoming aware of a notifiable privacy breach and will cooperate in remediation.
Assistance: The Supplier will provide reasonable assistance to respond to access and correction requests and regulator inquiries.
Retention and deletion: Personal Information is retained only as necessary for the Services and legal obligations. After termination, backups are retained for 90 days and then permanently deleted.
Audit: On reasonable notice, the Supplier will make available information necessary to demonstrate compliance with this DPA (for example, policy summaries and certifications) without disclosing confidential security details or other customers’ information.
Appendix C – Sub‑processors and Integrations
Part 1 – Sub‑processors
The Supplier uses the following sub‑processors to provide the Services. Providers marked AI provider supply AI Features under clause 5 of Section B and, under their terms with the Supplier, may not use Data to train or improve their AI models or for their own purposes.
| Provider | Service and purpose | Data processed | Processing location |
|---|---|---|---|
| Zoho Corporation | Hosting of the Adviser CRM platform (Zoho Developer Platform / Vertical Studio), including databases, files, and backups | All Data | United States (Zoho US data centres) |
| Zoho Corporation AI provider | Zia AI features within the platform (for example drafting, summarising, and predictions) | Data included in the AI request | United States (Zoho US data centres). Zia runs on models hosted by Zoho, so data does not leave Zoho’s infrastructure. Data is processed only to generate the response, is not stored, and is not used to train the models |
| Zoho Corporation | Zoho Desk support ticketing | Support communications and any Data included in tickets | United States (Zoho US data centres) |
| Anthropic, PBC AI provider | Claude AI models used for AI Features, including drafting support replies and content | Data included in the AI request | United States. Accessed through the Claude API under Anthropic’s Commercial Terms: requests and responses are automatically deleted within 30 days and are not used to train Anthropic’s models |
| API2PDF (Austin, Texas) | PDF generation for documents and reports created in the Services (for example letters, advice documents, and client reports) | Document content sent for conversion and the resulting PDF | United States (Google Cloud, us-central1). Generated files are automatically deleted within 24 hours; request content is not stored or logged |
Part 2 – Integrations enabled by the Client
The following integrations transfer Data to or from third‑party services only when the Client enables them under its own account with that provider. These providers act for the Client, not the Supplier, and are not sub‑processors (see clause 4.9).
| Provider | Purpose | Data exchanged | Notes |
|---|---|---|---|
| Microsoft Corporation | Microsoft 365 email and calendar synchronisation | Email, calendar, and contact data | Processed in the Client’s Microsoft 365 tenant region |
| Google LLC | Google Workspace email and calendar synchronisation | Email, calendar, and contact data | Google data centres (global) |
| Zoom Video Communications, Inc. | Video meetings, recordings, and Zoom AI Companion transcripts and summaries | Meeting content, recordings, transcripts, and participant details | United States. AI Companion meeting summaries are kept while the Zoom account is active, unless the account administrator turns on auto‑deletion. Zoom does not use meeting content to train its own or third‑party AI models |
| Quotemonster | Insurance quoting and comparison | Client details needed to prepare quotes (for example age, gender, smoker status, occupation, and cover requirements) | Governed by the Client’s terms with Quotemonster |
| Evince (Partners Life) | Online advice and needs‑analysis tool | Client and policy details needed for the advice process | Governed by the Client’s terms with Partners Life |
| Planolitix | Financial planning and advice software | Client details needed for planning and advice | Governed by the Client’s terms with Planolitix |
| Akahu | Open finance connection that retrieves bank account and transaction data with the individual’s consent | Client identifiers sent; bank account and transaction data received | Governed by the Client’s and the individual’s terms with Akahu |
This Appendix is current as at the Effective Date of this version of the Agreement. The Supplier will notify changes to Part 1 in accordance with clause 5.8 and Appendix B. The Supplier may add integrations to Part 2 from time to time.
Schedule A – Definitions
Additional Services has the meaning given in Section A (Additional Services (Customisation & Training)).
Administrator means a non‑sales user who does not directly create revenue or provide regulated advice.
Adviser means any individual registered with a relevant regulator (including the Financial Markets Authority) for providing financial advice.
Agreement means this SaaS Agreement, comprising Section A, Section B, the Appendices, and the Schedules.
AI Features has the meaning given in clause 5.1.
Analytical Data means anonymised, aggregated statistical and analytical data derived from Data or Service usage.
Business Day means a day other than a Saturday, Sunday, or public holiday in New Zealand.
Confidential Information means the terms of this Agreement and any non‑public information obtained in connection with it, including the Supplier’s intellectual property and the Client’s Data.
Data means all information (including Personal Information) owned, held, used, or created by or on behalf of the Client that is stored using, or inputted into, the Services.
Data Migration Agreement means the separate agreement between the Supplier and the Client that governs data migration services.
Fees means the charges payable by the Client as set out in Section A and clause 6.
Force Majeure means an event beyond a party’s reasonable control (excluding lack of funds).
Intellectual Property Rights includes copyright, patents, trademarks, designs, circuit layouts, data and databases, confidential information, know‑how, and all similar rights anywhere.
IP Claim has the meaning given in clause 7.5(a).
Objectionable includes defamatory, obscene, harassing, threatening, harmful, or unlawful content.
Permitted Users means the Client’s personnel authorised and licensed to access and use the Services.
Personal Information has the meaning given in the Privacy Act 2020.
SaaS Service means the core functionality described in Section A and as further described on the Website from time to time.
Services means the SaaS Service and any Related Services.
Start Date means the date of this Agreement set out in Section A, unless otherwise agreed in writing.
Underlying Systems means the Adviser CRM software, IT solutions, systems, and networks (including third‑party solutions) used to provide the Services.
Website means advisercrm.co.nz (or such other site notified by the Supplier).
Schedule B – Customisation and Configuration Examples
For clarity:
- Guidance‑only requests (for example, showing a user how to edit a picklist) – not a customisation; no charge.
- Assisted customisation (for example, a screen‑share to help modify a layout) – billable at the prevailing hourly rate in 15‑minute minimum blocks.
- Full customisation (the Supplier makes the change) – billable at the prevailing hourly rate in 15‑minute minimum blocks.
- Training on default features is included for standard features only; training on customisations is billable.
- Any change beyond default settings is considered a customisation, except initial setup and configuration.