Last updated: 19 August 2026
Rapid Ready AI ("we", "us", "our") operates rapidreadyai.com and supplies hosting, domain, security and private AI infrastructure services. This policy explains what personal information we collect, why we collect it, what we do with it, and the rights you have.
We handle personal information in accordance with the New Zealand Privacy Act 2020, including the information privacy principles (IPPs) and the indirect collection notification requirements in IPP 3A which took effect on 1 May 2026. Where the General Data Protection Regulation (GDPR) or the UK GDPR applies to our processing, we also comply with those. Where the Australian Privacy Act 1988 applies, we comply with the Australian Privacy Principles.
1. Who is responsible
Rapid Ready AI is the agency (and, for GDPR purposes, the controller) responsible for personal information collected through our website and client area. Where we host or process personal information on your behalf as part of a service you have purchased, you are the controller and we act as processor on your instructions.
2. Information we collect
2.1 Information you give us
- Account details — name, business name, email address, postal address, phone number.
- Billing details — billing address, tax or GST number, transaction records and invoices. Card numbers are entered directly into our payment provider's systems; we do not store full card numbers.
- Verification details — where we are required to verify identity for domain registration, fraud prevention or regulatory reasons.
- Support communications — tickets, live chat transcripts, emails and call notes.
- Content you upload — data you store on our infrastructure, which may itself contain personal information about your own customers or users.
2.2 Information we collect automatically
- IP address, browser type, device information, operating system and referring page.
- Pages visited, time on site and interaction events, collected using cookies and similar technologies.
- Server, network, access and security logs generated by the Services.
2.3 Information we collect indirectly (IPP 3A)
Sometimes we obtain personal information about you from a source other than you. This includes:
- Domain registries and registrars — registrant, administrative and technical contact records, for domains you register, transfer or manage through us.
- Payment providers and card networks — payment confirmation, fraud and chargeback signals.
- Credit and identity verification services — where we assess a business credit application or verify identity.
- Abuse and security feeds — reputation, blocklist and threat intelligence data relating to IP addresses, domains or accounts.
- Your organisation — where a colleague or authorised representative adds you as a contact on an account.
- Publicly available sources — such as company registers and WHOIS records.
We collect this information to provide and administer the Services, to meet registry and regulatory obligations, to prevent fraud and abuse, and to protect the security of our network. The intended recipients are described in section 5. We collect it under the Privacy Act 2020 and, where applicable, on the basis of our legitimate interests or to perform a contract with you. You have the rights of access and correction described in section 8.
Where the law requires us to notify you about indirect collection and it is reasonably practicable to do so, we will notify you at or before the time of collection, or as soon as practicable afterwards. Where notification would prejudice the purpose of collection, would prejudice the safety of any person, is not reasonably practicable, or an exception in the Privacy Act applies, we may not notify you individually — this policy serves as notice in those cases.
3. Why we collect and use personal information
- To create and administer your account and supply the Services you have ordered.
- To take payment, issue invoices and manage renewals.
- To provide technical support and respond to your enquiries.
- To register, renew, transfer and manage domain names on your instructions.
- To monitor, secure and maintain our infrastructure, including detecting and responding to abuse, fraud and security incidents.
- To send service notices — outages, maintenance, security advisories, billing and renewal notices. These are not marketing and you cannot opt out of them while you hold an active service.
- To send marketing communications, where you have consented or where we are otherwise permitted to do so. You can unsubscribe at any time.
- To improve our services and website, using aggregated and de-identified analytics.
- To comply with legal, tax, registry and regulatory obligations, and to establish, exercise or defend legal claims.
4. Your content and AI services
4.1 Content you store on our infrastructure remains yours. We access it only where necessary to operate, secure or support the Service, at your request, or where we are legally required to.
4.2 We do not use your content, your prompts, your model inputs or your model outputs to train any model of ours, and we do not sell or share them with third parties for their own purposes.
4.3 Where you run AI models on our infrastructure and those models process personal information, you are the controller of that information. You are responsible for having a lawful basis, for providing privacy notices to the individuals concerned, and for honouring their rights. We will assist you as processor to the extent reasonably required.
5. Who we share information with
We do not sell personal information. We share it only as follows:
- Infrastructure and data centre providers who host the servers your services run on.
- Payment processors to take payment and manage refunds and chargebacks.
- Domain registries and registrars, including ICANN-accredited registries and the .nz registry, where required to register or manage a domain. Some registry data may be published or made available under registry policy.
- Third-party vendors whose products you have purchased through us, to the extent needed to provision and support them.
- Professional advisers — accountants, auditors and lawyers, under duties of confidence.
- Law enforcement, regulators and courts, where we are legally required to disclose, or where disclosure is necessary to prevent or lessen a serious threat to public health or safety or to the life or health of any individual.
- An acquirer, if our business or part of it is sold or reorganised, subject to equivalent privacy protections.
6. Sending information overseas
6.1 Our infrastructure and some of our suppliers are located outside New Zealand, including in Australia, the European Union, the United Kingdom, the United States and Singapore.
6.2 Before disclosing personal information to a recipient outside New Zealand we take the steps required by IPP 12 — we satisfy ourselves that the recipient is subject to privacy laws providing comparable safeguards, is bound by contractual obligations to comply with comparable standards, or that another basis under IPP 12 applies.
6.3 Where GDPR applies, transfers outside the EEA or UK are made under an adequacy decision or standard contractual clauses with appropriate supplementary measures.
6.4 Where a service is provisioned in a specific region at your request, we will use reasonable efforts to keep your content within that region, but administrative and support data may still be processed in New Zealand.
7. Storage, security and retention
7.1 We use technical and organisational measures appropriate to the risk, including encryption in transit, access controls, network segregation, logging, monitoring and least-privilege administrative access.
7.2 No system is completely secure. We cannot guarantee that personal information will never be accessed without authorisation, but we will act promptly if it is.
7.3 If a privacy breach occurs that it is reasonable to believe has caused, or is likely to cause, serious harm, we will notify the Office of the Privacy Commissioner and the affected individuals as required by the Privacy Act 2020. Where GDPR applies, we will notify the relevant supervisory authority within 72 hours where required.
7.4 We keep personal information only as long as needed for the purposes above, or as required by law. Financial and tax records are retained for at least seven years under New Zealand tax law. Server and security logs are typically retained for up to 12 months. Account records are retained for the life of the account and for a reasonable period afterwards to handle disputes and legal obligations.
8. Your rights
8.1 Under the Privacy Act 2020 you have the right to ask for confirmation of whether we hold personal information about you, to access it, and to request correction if it is wrong. We will respond within 20 working days.
8.2 Where GDPR applies, you also have rights to erasure, restriction of processing, data portability, and to object to processing based on legitimate interests, and the right not to be subject to solely automated decision-making with legal or similarly significant effects.
8.3 You can withdraw consent to marketing at any time using the unsubscribe link or by contacting us.
8.4 We may need to verify your identity before acting on a request. We may decline a request where the Privacy Act or GDPR permits, and we will tell you why.
8.5 If you are unhappy with how we have handled your information, contact us first. If you are not satisfied, you may complain to the Office of the Privacy Commissioner (privacy.org.nz) or, if GDPR applies to you, to your local supervisory authority.
9. Cookies and tracking
9.1 We use strictly necessary cookies to operate the site, keep you signed in and secure your session. These cannot be turned off.
9.2 We use analytics and preference cookies to understand how the site is used and to remember your settings. Where required by law we ask for your consent before setting non-essential cookies.
9.3 You can control cookies through your browser settings. Blocking strictly necessary cookies may stop parts of the site from working.
10. Children
Our services are not directed at children and we do not knowingly collect personal information from anyone under 16. If you believe we have, contact us and we will delete it.
11. Third-party sites
Our website and client area may link to third-party sites. We are not responsible for their privacy practices. Read their policies before providing information.
12. Changes to this policy
We may update this policy. The current version is always published on this page with the date it was last updated. Where a change materially affects how we handle your personal information, we will notify you by email or through your account.
13. Contact
To make a privacy request, ask a question, or raise a concern, use our contact page (/contact-us) or open a ticket from your account. Please mark privacy requests clearly so they reach the right person.
