# Privacy Policy

KapsuleHost Privacy Policy: how we collect, use, hold, and protect your personal information under the New Zealand Privacy Act 2020.

Canonical page: https://kapsulehost.com/en-nz/legal/privacy

Last updated: 8 October 2026

Version 22, effective 8 October 2026

## About this Privacy Policy

This Privacy Policy explains how Kapsule Group Limited ("KapsuleHost", "we", "us", "our") collects, uses, holds, stores, discloses, and protects personal information when you use our cloud hosting, domain registration, email hosting, and related products and services (together, the "Services"). It is written to comply with the New Zealand Privacy Act 2020 and the twelve Information Privacy Principles ("IPPs") set out in that Act.

This Privacy Policy applies to our customers, our customers' personnel, visitors to kapsulehost.com and kpanel.kapsulehost.com, applicants, and any other individual whose personal information we hold. It does not apply to information you choose to store on the Services about other people; that processing is governed by the Data Processing Agreement ("DPA").

We are committed to handling your personal information openly and lawfully. If you have a concern, please contact us first at privacy@kapsulehost.com. We will work with you to resolve it. You can also complain to the Office of the Privacy Commissioner (details in clause 12).

## 1. Who we are

Kapsule Group Limited is a company incorporated in New Zealand. We are the agency for the purposes of the Privacy Act 2020 in respect of personal information we hold about you.

Contact for privacy matters: privacy@kapsulehost.com | Privacy Officer, Kapsule Group Limited, New Zealand.

## 2. What we collect

We only collect personal information that we need for one or more of the purposes set out in clause 3.

Account information: name, business name, email address, a mobile phone number (which we require and verify when you open an Account), billing address, country, and the username and hashed password you set.

Verification information: where required to prevent fraud or comply with law, government identification, proof of address, or other identity documents.

Payment information: payment method, billing history, transaction identifiers, and partial card details (last four digits and card type). Full card numbers are tokenised by Stripe and are not stored on our systems. When you pay by bank transfer, we receive from our bank-account provider the sender's name, the sender's account details and the payment reference your bank sends with the payment; and when we refund a bank transfer, we collect the account holder's name and the bank account details needed to pay it. We store these encrypted and use them only to match and refund payments.

Authentication information: hashed passwords, two-factor authentication secrets and recovery codes, session tokens, authentication logs, and password-reset audit trails.

Customer Content metadata: filenames, sizes, content types, dates of upload, access logs, and other metadata about content you store on the Services. We do not routinely inspect the substance of Customer Content.

Usage data: server resource usage (CPU, memory, storage, bandwidth, requests, queries, mail volumes), feature usage in KPanel, API call records, error logs, and aggregated metrics used for capacity planning, abuse prevention, and product improvement.

Device and connection information: IP address, browser type and version, operating system, device type, screen resolution, language, time zone, approximate geographic location derived from IP, referrer URLs, and unique device identifiers.

Communications: records of your communications with us, including support tickets, KPanel messages, conversations with Kora (our AI customer support assistant), emails, phone or video call recordings (where you consent), survey responses, feedback, and messages and comments you send to our Facebook Page or Instagram account (clause 4B).

Domain registrant information: where you register a domain through us, the registrant, administrative, technical, and billing contact information required by the relevant Registry, including name, organisation, address, email, and phone. Where you enable WHOIS privacy, public WHOIS displays a privacy proxy contact instead of your personal contact information, but we still hold the underlying information.

Mail metadata: for email Services, message headers (including sender, recipient, subject, message ID, timestamps), routing data, and reputation indicators. We do not routinely read the content of your messages, except where strictly necessary for security, abuse-prevention, or to comply with law.

Cookies and similar technologies: see our Cookie Policy at kapsulehost.com/legal/cookies.

Job applicant information: where you apply for a role with us, your CV, cover letter, references, and the information you provide during the recruitment process.

Other information: any other personal information you choose to provide to us.

## 3. Why we collect it (purposes)

We collect, use, and disclose personal information for the following purposes:

To provide the Services: including creating, operating, supporting, and maintaining your Account, provisioning resources, delivering content, hosting websites, sending and receiving email on your behalf, and registering domain names.

To bill and collect payment: including processing transactions, issuing invoices, calculating taxes, retrying failed payments, processing refunds, and managing disputes and chargebacks.

To authenticate and secure the Services: including verifying your identity, enforcing two-factor authentication, detecting and preventing fraud, abuse, and unauthorised access, and protecting the integrity of the platform.

To verify your mobile number and prevent abuse: when you open an Account, or at your next sign-in for an existing Account, we send a one-time code to your mobile number by SMS or WhatsApp. Before sending it we may check the number's line type (for example mobile, landline or internet (VoIP) number) with our verification provider, and we do not accept landline, internet or other non-mobile numbers for verification. We keep a one-way hash of your verified number so we can limit how many Accounts one number can be verified on. We use your number for verification, account security and fraud and abuse prevention, not for marketing.

To communicate with you: including responding to support enquiries, providing service-related notices (billing, security, outages, policy changes), and (where you opt in) sending marketing communications.

To improve our Services: including analysing aggregated and de-identified usage data, conducting research, developing new features, and benchmarking performance.

To comply with law: including responding to lawful requests from regulators, law enforcement, or courts; meeting tax and corporate record-keeping obligations; and complying with the Privacy Act 2020, Anti-Money Laundering and Countering Financing of Terrorism Act 2009 (to the extent applicable), and other applicable laws.

To enforce our agreements: including investigating breaches of our Terms of Service or Acceptable Use Policy, exercising our rights under those agreements, and defending legal claims.

To operate automated abuse detection: we operate automated systems that analyse patterns in account activity, traffic, payments, and content to identify potential abuse or breach of our policies. Where the system flags activity as likely abusive, proportionate automated measures may be applied (such as challenge tests, rate limiting, account holds, or service suspension), subject to human review on request.

For recruitment purposes: where you apply for a role with us, to assess your suitability and to communicate with you about the application.

We do not use your personal information for any purpose other than those listed in this clause or for purposes you authorise.

Lawful basis under the EU GDPR (for EU/EEA residents). Where the EU General Data Protection Regulation applies to our processing of your personal information, we rely on the following lawful bases: (a) Contract (Article 6(1)(b)): providing the Services, billing, and Account management; (b) Legitimate interests (Article 6(1)(f)): security, fraud prevention, abuse detection, enforcing our agreements, and improving our Services - these interests do not override your rights given the technical and organisational safeguards we maintain; (c) Consent (Article 6(1)(a)): marketing communications - you may withdraw consent at any time; (d) Legal obligation (Article 6(1)(c)): tax, accounting, and regulatory requirements.

Launch Check (1 to 7 October 2026). If you ask us to check a domain, we keep the domain name, one way to reach you (an email address, or a social media or Discord handle) and the channel you asked on, only to run the check and send you its report. The check uses public information about the domain: its DNS records, its certificate and registration expiry dates, and a mobile speed test we run ourselves. Kora, our AI assistant, drafts the report from those results and never sees your contact details. A person on our support team reviews it and sends it to you. We do not use your details for marketing, and we delete them 30 days after your request. If you reply to your report, your reply reaches our support team and is kept as ordinary support correspondence.

Measuring which of our own posts, ads and links bring sign-ups. When a link carrying campaign tags brings you to kapsulehost.com, we set one first-party cookie, kh_ft, there (Cookie Policy clause 3.6); when the link brings you straight to KPanel instead, with no cookie already set, we read the same tags from the link itself. Either way, if you go on to open an Account, we read those details once, at that moment. It holds only the four campaign tags on that link (utm_source, utm_medium, utm_campaign and utm_content: the labels we add to our own posts, ads, messages and emails, or that whoever shared the link added, to say where it was published and which post or ad it belongs to), the path of the page you landed on without its query string, and the date and time of that visit. It holds no advertising click identifier, IP address, browser or device details, or referring page. A visit without campaign tags sets nothing, a later tagged visit never replaces the first, and the cookie is not set if your browser sends a Global Privacy Control (GPC) signal on that visit. If you open an Account while the cookie is held, we store those same details with your Account. We use them only to count the sign-ups, paying customers and revenue that each of our posts, ads, campaigns, networks and markets brings, and our reports show those counts only, never a name, email address or Account. We do not send these campaign details to any advertising network or other third party; the Account-opening and purchase events described under Advertising with Meta and Google below are separate, and follow the advertising choices described there. Lawful basis under the EU GDPR: legitimate interests (Article 6(1)(f)). Our interest is putting our own marketing effort and money where it brings customers. We have balanced it against your interests and consider that it does not override your rights, because the details are limited to campaign labels, a page path and a time, only we read them, we use them only as counts, nothing follows you on other websites, and a GPC signal stops the cookie being set. The cookie lasts 30 days. The details stored with your Account are Account information: they are kept while the Account is open and deleted 12 months after it closes (clause 9). You can object at any time by writing to privacy@kapsulehost.com (clause 11).

Your choices about campaign measurement, advertising and analytics. Campaign measurement (the kh_ft cookie in the paragraph above), advertising (the next paragraph) and analytics (the paragraph after it) are used only once we switch them on, and then only as your choice and where you are allow. If you are in the European Union, the European Economic Area, the United Kingdom or Switzerland, or we cannot tell your country, each stays off until you choose Accept all in our cookie banner or switch it on in Cookie settings (Cookie Policy clause 3.7), and for campaign measurement the lawful basis under the EU and UK GDPR is then your consent (Article 6(1)(a)) rather than legitimate interests. Everywhere else each is on by default, which means we measure ad clicks and sign-ups for advertising unless you turn it off. You can turn it off at any time with Reject all, by switching Advertising off in Cookie settings, or by having your browser send a Global Privacy Control signal. Cookie settings is always available from the link at the bottom of every page of kapsulehost.com, and a Global Privacy Control signal always overrides any choice made there. The advertising and analytics tags load only after the page has shown. Switching campaign measurement off deletes the kh_ft cookie. On kapsulehost.com, while campaign measurement is allowed, the four campaign tags from the link that brought you are kept in your browser session storage (kh_utm) for that browser session only, so that the sign-up and sign-in links on that site can pass them on to KPanel. We record your choices in one strictly necessary cookie, kh_consent, which lasts 12 months (Cookie Policy clause 3.1). The campaign details stored with an Account are deleted 12 months after the Account closes, like all Account information (clause 9).

Advertising with Meta and Google: measurement, remarketing and audiences. If advertising is switched on and you allow it, we load the Meta Pixel and the Google tag for Google Ads on kapsulehost.com only; KPanel loads neither. From those tags, Meta (Facebook and Instagram) and Google receive the address of the page and the page you came from, your IP address, your browser's user agent, screen size and language, their own cookie identifiers (_fbp and _fbc for Meta, _gcl_au, _gcl_aw and _gcl_gb for Google, and any cookies of their own that your browser already holds, such as Meta's fr cookie if you are signed in to Facebook or Instagram), and the click identifier when you arrived from one of their ads (fbclid for Meta; gclid, gbraid or wbraid for Google). These tags send page visits only. When you open an Account, or a payment is captured, we send that event only from our servers, under the same rules as the tags, set out at the end of this paragraph; it is never sent when your browser sends a Global Privacy Control signal. To Meta (Conversions API) we send the kind of event, its time and identifier, the address of the page without its query string, your email address hashed with SHA-256 after being lower-cased and trimmed (Meta cannot read it back, but can match it to a Meta account that holds the same address), Meta's two cookie values (_fbp and _fbc) if your browser holds them, and your browser's user agent, and for a purchase its value and currency; we never send Meta your IP address from our servers. To Google Ads we send, only if you arrived from a Google ad, the Google click identifier (gclid, gbraid or wbraid), the conversion, its time and identifier, and for a purchase its value and currency; we never send Google your email address. Event identifiers are derived from our own records in a way that cannot be reversed. We never send your name, postal address, phone number, payment details or anything about the services you host, and we upload no customer list to either. Meta and Google use these visits and conversions to measure our ads, to show you our ads on their services and on other sites and apps that carry their ads (remarketing), and to build advertising audiences for us: people who visited our site, people who viewed our pricing, people who started to sign up but did not buy, and our customers, whom we use to stop showing ads for services they already have. Each visitor stays in an audience for 180 days after their last matching visit (30 days for the sign-up audience). Meta also finds people it judges similar to our customers (a lookalike audience), and Google may also use audiences built in Google Analytics for visitors who allowed analytics as well. Nobody at KapsuleHost can see who is in an audience: Meta and Google show us only its approximate size. We keep a record of each event we send: its kind, identifier, Account and order, value and currency, the campaign, ad set and ad it came from, why it was allowed, and whether each network accepted it. The Meta cookie values, the Google click identifier and the user agent are kept in it only until the event is sent or given up, and at most 7 days; your email address, its hash and your IP address are never stored. Each record is deleted 12 months after the event, all of them are deleted when your Account is erased, and a record for a purchase that is never paid is deleted after 30 days. Meta and Google are recipients who use what they receive under their own terms as independent controllers, including to measure and improve their advertising services, and keep it for the periods those terms set. In the European Union, the European Economic Area, the United Kingdom and Switzerland, or where we cannot tell your country, this happens only after you choose Accept all or switch Advertising on in Cookie settings, and the lawful basis under the EU and UK GDPR is your consent (Article 6(1)(a)). Elsewhere we measure ad clicks and sign-ups for advertising unless you turn it off: it happens unless you choose Reject all, switch Advertising off in Cookie settings, or your browser sends a Global Privacy Control signal, and we rely on our legitimate interest in advertising our services. You can withdraw your consent or opt out at any time in Cookie settings (the link at the bottom of every page of kapsulehost.com); this stops the tags and any further server events and deletes the Meta and Google cookies on kapsulehost.com, but does not undo what was sent before. Where a law treats this as sharing personal information for targeted advertising, that opt-out is your right to opt out of it.

Analytics with Google Analytics. If analytics is switched on and you allow it, we load Google Analytics on kapsulehost.com and on the KPanel sign-up, welcome, onboarding and checkout pages, to understand how visitors use them. It sends Google each page view with the page address (its query string removed, except for our campaign tags), the page title and the page you came from, your screen size and language, a random identifier for your browser and for your session, how long you engaged, whether you scrolled to the end of the page, clicks on links that leave our site, and when you open an Account or complete a purchase, with our event identifier and, for a purchase, its value and currency. Google derives an approximate country and city from your IP address and does not store the IP address in Google Analytics. We send no email address, user identifier, form contents or keystrokes, and form, site search, video and file-download tracking are off. Its cookies, _ga and _ga_ followed by our property identifier, last 13 months, and the event data is kept for 14 months. Google signals and advertising personalisation are used only if you have also allowed advertising, and only then can audiences built in Google Analytics be used for our Google ads. Google is a recipient under its own terms, as for advertising above. In the European Union, the European Economic Area, the United Kingdom and Switzerland, or where we cannot tell your country, it runs only after you choose Accept all or switch Analytics on in Cookie settings, and the lawful basis under the EU and UK GDPR is your consent (Article 6(1)(a)). Elsewhere it runs unless you choose Reject all, switch Analytics off, or your browser sends a Global Privacy Control signal, and we rely on our legitimate interest in understanding how our sites are used. Switching it off stops Google Analytics and deletes its cookies on kapsulehost.com. Plausible, our own cookieless analytics on kapsulehost.com, is separate and is described in clause 3.3 of our Cookie Policy.

Heatmaps with PostHog. If analytics is switched on and you allow it, PostHog, which processes this for us in the EU, records heatmaps of the public pages of kapsulehost.com; it never runs in KPanel or on sign-up, sign-in, checkout, cart, order, account, password or billing pages. It receives where on the page you click and move the pointer, repeated clicks, how far you scroll, the size of your window and screen, the page address (its query string removed, except for our campaign tags), the website you came from (not the page), your browser, operating system and type of device, and a random identifier that is kept in memory for that page load only. It records nothing you type, no form contents, no page text and no recording of your visit. It sets no cookie and stores nothing on your device, and the IP address is discarded before processing; PostHog counts visitors with a hash on its own servers. PostHog keeps these heatmap points for up to 7 years. They contain no cookie, no IP address and no identifier for you, and nothing you type. The regional rule, the lawful basis and how to switch it off are the same as for Google Analytics in the paragraph above; switching Analytics off stops it at once, and there is nothing to delete on your device.

## 4. Sources

Most personal information we hold about you is collected directly from you when you sign up, log in, contact support, or use the Services.

We also collect personal information from our Sub-processors and other service providers (for example, Stripe provides payment status); fraud prevention databases and third-party verification services; public sources (including WHOIS records and government registers); referrals (for example, where another customer refers you and you accept the referral); Meta, when you send a message to, or comment on, our Facebook Page or Instagram account (clause 4B); and your interactions with our website (including via cookies; see Cookie Policy).

## 4A. Contacts you bring from Google or Microsoft

This clause applies when, as part of moving your email to KapsuleHost, you choose to have us copy your contacts from a Google account (Gmail or Google Workspace) or a Microsoft account (Outlook.com or Microsoft 365). You start this yourself in KPanel, and you sign in at Google or Microsoft to give us permission. We ask only for read-only access to your contacts, and for your account's email address so that we can check you signed in to the account you are moving: from Google, the People API scope contacts.readonly, with openid and email; from Microsoft, the Microsoft Graph permissions Contacts.Read, User.Read and offline_access.

How we use it: we read your contacts (names and nicknames, email addresses, phone numbers, postal addresses, organisation, department and job title, birthdays, notes and photos, and, from Microsoft, categories) and write them into the address book of your own KapsuleHost mailbox. From Google we copy your saved contacts, not the "other contacts" Gmail collects automatically; from Microsoft we copy your Contacts folder and the folders inside it. Making that copy, and showing you its progress, is the only thing we use this data for, and we use your account's email address only for the check described above. We never change or delete your contacts or anything else in your Google or Microsoft account, other than asking Google to end our own access as described below.

How we store it and when we delete it: the access tokens Google or Microsoft give us are stored encrypted and used only by that migration. We delete them as soon as the copy of your contacts finishes, whether or not every contact could be copied, and in any case when the migration completes, fails or is cancelled; at that point we also ask Google to revoke its token. You can withdraw our access yourself at any time in your Google or Microsoft account's security settings (for Google, at myaccount.google.com/permissions). The copied contacts are held in your KapsuleHost address book, which you control, and follow that mailbox's retention and deletion, including its backups (see clause 9).

How we share it: we do not sell, rent or share this data, we do not transfer it to anyone except where needed to make the copy you asked for or where the law requires, we do not use it for advertising, and we do not use it to develop, improve or train artificial intelligence or machine learning models. No KapsuleHost staff member reads it unless you ask us to for a support request, for security reasons, or where the law requires.

KapsuleHost's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.

If you choose Sign in with Microsoft for a Microsoft 365 or Outlook.com mailbox you are moving, we ask Microsoft for the delegated permissions IMAP.AccessAsUser.All and offline_access, and User.Read to confirm that the account you sign in with is the mailbox being moved. Microsoft describes IMAP.AccessAsUser.All as read and write access to your mailbox over IMAP; we use it only to read. We open each folder read-only and copy each message, with its flags and date, into your KapsuleHost mailbox, and we never change, move, delete or mark as read anything in your Microsoft mailbox. Messages pass through our migration service in memory on their way to your new mailbox and are not written anywhere else. The token Microsoft gives us is stored encrypted, used only by that migration, and deleted when the migration completes (for a migration that switches your mail over, at the end of the 24 hours after the switch in which we collect late mail), fails or is cancelled, and as soon as that mailbox can no longer be copied. Microsoft offers no way for us to revoke it ourselves; you can remove KapsuleHost's access in your Microsoft account settings at any time.

## 4B. Messages and comments on our social accounts

This clause applies when you send a message to, or comment on a post of, the KapsuleHost Facebook Page or Instagram account. We receive this information through Meta, which runs Facebook and Instagram.

What we receive: your name or username, the identifier Meta gives your account for our Page or Instagram account, the text of your message or comment, a link to your comment, and when you sent it.

How we use it: only to read and answer you. Kora, our AI assistant, reads each message or comment to sort it (for example, a question, thanks or a complaint) and to draft a reply; this is AI processing under clause 5, and clause 5.3 applies to it. A person on our team reviews and sends replies, and simple routine answers (a thank-you, or a link to our help centre or to our Launch Check) may be sent automatically only where we have switched that on, after an automatic check of their facts. Messages about billing, account access, security or legal matters, and complaints, always go to a person.

Who receives it: our reply goes back to you through Meta, and a reply to a comment is public on that post, as your comment is. Meta handles these messages and comments under its own terms and privacy policy, as an independent controller.

How long we keep them: 12 months after the conversation ends, and then we delete them, with our replies. If our team escalates a message internally, the note in our audit log may quote it and is kept as part of that log.

To have them deleted: write to privacy@kapsulehost.com with your name or username on Facebook or Instagram, and we delete them within 30 days (clause 11). This deletes them from our systems; to remove a comment or message from Facebook or Instagram itself, use Meta's own tools.

## 4C. Our own social media accounts.

Our internal staff tool, KApex, connects to KapsuleHost's own accounts on LinkedIn, YouTube, TikTok, Threads, Facebook, Instagram and X, so that one authorised member of our team can schedule and publish our own marketing posts. The access tokens these platforms give us are stored encrypted, used only to publish to our own account and to confirm a post we made is still there, and are never used to read, follow, message or act on any other account. We delete a token when the connection is disconnected, or when it expires and nobody renews it.

Where a platform is Google (our YouTube channel), KapsuleHost's use and transfer of information received from the YouTube API Services will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements, and to the YouTube API Services Terms of Service (https://www.youtube.com/t/terms).

## 5. How we use AI to provide the Services

5.1 Kora. Kora is our AI customer-support assistant, built on Anthropic Claude. Kora may read your support messages, recent ticket history, basic Account context, and any information you specifically include in a support chat (for example, log excerpts) in order to respond to your enquiries.

5.2 Memory. Kora keeps a memory of your earlier support conversations, as short summaries and the facts you have told it, so that it can answer follow-up questions in context. This memory is stored in our own database with the rest of your account data, and no third-party memory service receives it.

5.3 Limitations on AI processing. We do not authorise our AI sub-processors to use Customer Content or your support communications to train their general models. AI processing is for the purpose of providing the Services only.

5.4 No automated decision-making with legal effect. Kora does not make decisions with legal or similarly significant effects on you. Decisions about suspension, termination, refunds, or account changes are made by humans, or by automated systems that are reviewed by humans on request.

5.5 Human review. You may request that your support interaction be handled by a human at any time by emailing privacy@kapsulehost.com or support@kapsulehost.com.

## 6. Disclosure to Sub-processors and other recipients

6.1 We disclose personal information only: (a) to our Sub-processors (clause 7), who are bound by contractual confidentiality and security obligations and permitted to use the information only to provide services to us; (b) to integration partners and other third parties where you have directed or authorised us to do so; (c) to professional advisers (lawyers, accountants, auditors, insurers) under duties of confidentiality; (d) to law enforcement, regulators, courts, registries, or other authorities where required by New Zealand law or by foreign law applicable to a Sub-processor; (e) to acquirers in connection with a merger, acquisition, or sale of all or substantially all of our assets (we will notify you of any such change); (f) where reasonably necessary to enforce our agreements, protect our rights or those of others, or prevent harm; (g) with your express consent; and (h) to Meta, when we reply to a message or comment you sent to our Facebook Page or Instagram account (clause 4B).

6.2 We do not sell, rent, or trade personal information.

## 7. Sub-processors

We rely on Sub-processors to provide the Services. Each is subject to a written contract and to security and confidentiality obligations no less protective than those in this Privacy Policy. Our current Sub-processors, with their purpose and location, are listed in the Sub-processors List at kapsulehost.com/legal/sub-processors, which forms part of this Privacy Policy.

A current and dated list is maintained at kapsulehost.com/legal/sub-processors. We will notify you of any new Sub-processor that will process personal information, and of any material change to an existing one, at least thirty days before it takes effect, so you can object on reasonable grounds. If you object and we cannot resolve your concern, you may terminate the affected Service and receive a pro rata refund of any prepaid Fees.

## 8. International transfers

8.1 Some Sub-processors are located outside New Zealand. Where personal information is transferred overseas, we ensure that the recipient is required (by contract or operation of law) to apply protections comparable to those in the Privacy Act 2020. This includes ensuring that the recipient is bound by privacy laws that, in our view, provide comparable safeguards (for example, the EU General Data Protection Regulation), or by contractual safeguards we put in place.

8.2 By using the Services, you authorise the transfer of your personal information to the jurisdictions in which our Sub-processors operate, as listed in clause 7 and at kapsulehost.com/legal/sub-processors.

8.3 You may withdraw this authorisation by terminating the Services. Withdrawal of authorisation may make it impossible for us to continue to provide the Services.

## 9. Retention

We retain personal information only for as long as we need it for the purposes set out in clause 3, or as required by law.

Account information: retained for the life of the Account plus 12 months after closure.

Your verified mobile number, its hash and its line-type result are account information and follow the rule above. If you remove your number from your Account, we delete the number, its hash and its line-type result.

Billing and tax records: 7 years from the date of the transaction (Tax Administration Act 1994).

Customer Content: retained for the duration of the subscription and until its Services stop, plus a 30-day Grace Period, after which it is deleted.

Off-site backups (Customer Content): 30-day rolling retention minimum (longer for higher Plans). Backups become unrecoverable within 31 days of deletion from live systems.

Support communications: 3 years after the ticket is closed.

Kora chat logs: 12 months from the date of the conversation, then aggregated and de-identified.

Authentication and security logs: 12 months (longer where needed for an active investigation).

Marketing consent records: life of the consent plus 7 years after withdrawal (to evidence the consent).

Recruitment information: 12 months after the recruitment decision (unless you ask us to retain it longer for future opportunities).

WHOIS Data: for the duration of the domain registration plus any period required by ICANN or the relevant Registry.

We may extend retention where required to comply with law, to defend a legal claim, or to investigate or remedy a security incident.

## 10. Storage and security

10.1 We protect personal information using a layered approach, including: TLS encryption for all data in transit; encryption at rest for backups and sensitive databases; encrypted backups: backups of hosted websites and their databases are stored in Europe, on the hosting server in Germany and off-site in Finland; backups of managed servers, of our own account and billing databases, of online shop databases, of our object storage service and of email are stored off-site in Finland; and whole-server backups of our control panel, which also runs online shops, are kept with it in the Asia-Pacific region; strict role-based access controls and least-privilege principles; mandatory two-factor authentication for all personnel with access to production systems; regular security patching, vulnerability scanning, and periodic penetration testing; segregation of customer data; logging of authentication events and configuration changes to a centralised audit trail, with system-level logs retained locally on each server; documented incident response and breach notification procedures; and personnel confidentiality undertakings and ongoing privacy and security training.

10.2 A more detailed description of our technical and organisational measures is available at kapsulehost.com/legal/security.

10.3 No system is perfectly secure. If a notifiable privacy breach occurs, we will notify the Office of the Privacy Commissioner and affected individuals as soon as practicable, and in any event within seventy-two hours of becoming aware of the breach, as required by sections 112 and 114 of the Privacy Act 2020.

10.4 KPanel, our control panel, runs on servers in the Asia-Pacific region. So do the database that holds your account information, including your billing and support records, and the online shops you run with us, with their data. Off-site backups of this data are stored in Finland, as clause 10.1 sets out. The Sub-processors List at kapsulehost.com/legal/sub-processors sets out where each Sub-processor processes personal information.

## 11. Your rights

Under the Privacy Act 2020 you have the following rights in relation to personal information we hold about you.

Right of access (IPP 6): you may request a copy of the personal information we hold about you.

Right to correct (IPP 7): you may request that we correct personal information that is inaccurate, incomplete, out of date, irrelevant, or misleading. Where we do not agree to make a correction, we will attach a statement of the correction sought, if you request.

Right to request deletion: you may ask us to delete personal information we hold about you by writing to privacy@kapsulehost.com. We will delete it, except what the law requires us to keep (see clause 9), and reply within the time set out at the end of this clause. Messages and comments you sent to our Facebook Page or Instagram account (clause 4B) are deleted within 30 days of your request; tell us your name or username there so we can find them. We also delete personal information when we no longer need it.

Right to receive a portable copy: where reasonably practicable, we will provide your data in a structured, commonly used, machine-readable format (such as CSV or JSON).

Right to withdraw consent: where we rely on your consent (for example, for marketing communications), you may withdraw consent at any time without affecting the lawfulness of earlier processing.

Right to complain: you may complain to us at privacy@kapsulehost.com. If you are not satisfied with our response, you may complain to the Office of the Privacy Commissioner (see clause 12).

Additional rights under the EU GDPR (for EU/EEA residents). If the EU GDPR applies to our processing of your personal information, you also have: (a) Right to restriction of processing (Article 18): request that we pause processing of your information while a dispute is resolved; (b) Right to object (Article 21): object to processing based on legitimate interests or for direct marketing (we will stop unless we have compelling legitimate grounds); (c) Right to lodge a complaint with a supervisory authority: in addition to the Office of the Privacy Commissioner, you may complain to the EU data protection supervisory authority in your country of residence or in the EU member state where the alleged breach occurred. A list of EU supervisory authorities is available at edpb.europa.eu.

To exercise any of these rights, contact privacy@kapsulehost.com. We may need to verify your identity before responding. We will respond within twenty working days or thirty calendar days of receiving your request, whichever is sooner. We do not charge for these requests, except where a request is manifestly unfounded, excessive, or repetitive.

## 12. Office of the Privacy Commissioner

If you are not satisfied with our response to a privacy concern, you may contact: Office of the Privacy Commissioner, PO Box 10094, Wellington 6143, New Zealand. Phone: 0800 803 909. Website: privacy.org.nz.

## 13. International customers

We do not specifically target the Services to residents of any particular jurisdiction outside New Zealand.

We endeavour to respect rights granted to you under your local law (including, where applicable, the EU General Data Protection Regulation, UK General Data Protection Regulation, and Australian Privacy Act 1988).

Where you believe a specific local right applies to you and is not addressed by this Privacy Policy, please contact privacy@kapsulehost.com. We will respond to your specific request to the extent it is applicable to our processing.

## 14. Children

The Services are not directed at children under 18, and we do not knowingly collect personal information from anyone under 18. If you believe we have collected personal information from a person under 18, contact privacy@kapsulehost.com so we can promptly delete it.

## 15. Cookies and similar technologies

Our use of cookies, pixels, local storage, and similar technologies is described in our Cookie Policy at kapsulehost.com/legal/cookies.

## 16. Marketing communications

16.1 We may send you service-related communications (for example, billing notices, security alerts, outage notifications, policy updates). These are not marketing communications and you cannot opt out of them while you have an active Account.

16.2 Where you have opted in, we may send you marketing communications (such as product updates, offers, and event invitations). You may opt out at any time by clicking the unsubscribe link in any marketing email, by updating your preferences in KPanel, or by emailing privacy@kapsulehost.com.

16.3 Our marketing complies with the Unsolicited Electronic Messages Act 2007. We will identify ourselves clearly, include a functional unsubscribe mechanism, and only send marketing where we have your express, inferred, or deemed consent under that Act.

## 17. Links to third parties

The Services may contain links to third-party websites and services. We are not responsible for the privacy practices of those third parties. You should review their privacy policies before providing personal information to them.

## 18. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or in the law. Material changes will be notified by email or KPanel notice at least thirty days before they take effect. Non-material changes (such as typographical corrections or contact updates) take effect on posting. The "Last updated" date at the top of this Policy indicates the most recent change.

## 19. Contact

Privacy Officer, Kapsule Group Limited, New Zealand.

Email: privacy@kapsulehost.com

---

This is the Markdown rendition of https://kapsulehost.com/en-nz/legal/privacy, published for AI readers and agents. For the full interactive page, visit the canonical URL above.
