Privacy Policy
Last changed 20 August 2026
The most important thing to understand first
This Policy covers three different situations, and different rules apply to each.
Information we handle for our own purposes. Your account details, billing information, how you use the Service, and your dealings with our support team. We decide how this is used, and sections 2 to 13 of this Policy explain how.
Information inside a Brain we host for you. If you put information about people into a Brain we host, we hold and process it on your organisation's behalf and under its instructions. Your organisation decides what goes in, why, and how long it stays. We do not decide those things and we do not use that information for our own purposes. Section 14 explains this, and the Data Processing Addendum governs it.
Information inside a Brain you host yourself. If you run Telos Brain on your own infrastructure, we do not hold that information at all. It stays in your environment. We receive only metering and diagnostic data about how much the Brain is used, which does not contain your content. Section 15 explains what we do and do not receive.
In all three cases, the AI models are yours. You supply your own API keys for the model providers you use, and what those providers do with the data sent to them is governed by your agreement with them, not with us. Section 6 explains this.
This Policy is published by Telos Limited and covers the whole Telos group of companies. For Telos Brain, your contract is with Telos NZ Limited, and Telos NZ Limited is the entity responsible for your information. Section 1 sets out the structure. Our security documentation is published on the Telos Limited Trust Centre.
If you are an individual whose information is inside a customer's Brain and you want it accessed, corrected or deleted, contact that organisation. We will assist them, but we cannot act on their data without their instruction, and where the Brain is self-hosted we have no access to it at all.
1. Who we are
1.1 This Policy is published by Telos Limited (incorporated in New Zealand, company number 9429052358715) for the Telos group of companies (the "Telos Group"), and applies to all of them.
1.2 The Telos Group comprises:
| Entity | Role | Products and operations |
|---|---|---|
| Telos Limited | Parent company; publisher of this Policy; operator of the Trust Centre | Group governance, security and compliance |
| Telos NZ Limited (NZBN 9429052360978, company number 9277658) | Contracting entity for all services | Telos Brain services, custom software development |
| Telos IP Limited (NZBN 9429052360992, company number 9277905) | Intellectual Property holding and licensing | Telos Ready platform, Telos Brain |
| Telos AU Pty Ltd (ACN 613 457 935) | Australian operations | Sales, support and delivery |
1.3 Which entity is responsible for your information. For Telos Brain, Telos NZ Limited is the entity that decides how the information described in section 4 is used. It is the "agency" for the purposes of the New Zealand Privacy Act 2020 and the "controller" for the purposes of the EU and UK GDPR. Other members of the Telos Group handle that information on Telos NZ Limited's behalf and under its instructions.
1.4 For Telos Ready professional services, the responsible entity is Telos NZ Limited. That is a separate engagement, but also governed by this policy.
1.5 A single point of contact applies across the Telos Group: privacy@telosbrain.com. You do not need to work out which entity to approach.
1.6 Laws that apply to us. We are subject to the New Zealand Privacy Act 2020. Telos AU Pty Ltd is subject to the Australian Privacy Act 1988 and the Australian Privacy Principles, and section 16 of this Policy sets out how we meet those obligations. Where the EU General Data Protection Regulation or the UK GDPR applies to our processing, we comply with it in relation to that processing.
1.7 This Policy covers Telos Brain, the telosbrain.com website, the Trust Centre, and our dealings with you about the Service. It does not cover any Model Provider you connect, or any other third-party service you connect to the Service.
2. The information we collect
2.1 Information you give us:
- account information — your name, work email address, organisation name, role, and account credentials;
- billing information — billing name and address, and the information needed to process a payment. Card details are collected and held by our payment provider, not by us;
- support and correspondence — the content of your enquiries, bug reports, logs and diagnostic output you send us, and any information you choose to include; and
- preferences — settings you choose, including communication preferences.
2.2 Information we collect automatically when you use the Service:
- usage and telemetry — features used, actions taken, Usage Fees generated, volumes, timestamps, performance and error data;
- device and connection — IP address, browser and operating system, device identifiers, and approximate location derived from IP address;
- access records — authentication events, API and command line interface calls, and security logs; and
- cookies and similar technologies — see section 11.
2.3 Metering Data from a self-hosted deployment. See section 15.
2.4 Information in Your Content. Your Content may contain personal information about your personnel, your customers or other individuals. Where we host your Brain, we hold this on your behalf and section 14 applies to it, not sections 2 to 13. Where you host your Brain yourself, we do not hold it at all.
2.5 Information we receive from others. We may receive personal information about you from:
- a Third-Party Service you connect to the Service;
- our payment provider, including transaction outcomes and fraud signals;
- providers of security, identity, fraud prevention and business information services;
- your organisation, where it administers your account or adds you as a Permitted User; and
- publicly available sources, where we are verifying an organisation or a business contact.
2.6 We do not seek to collect information about children through the Service. The Service is for business use and clause 1.6(a) of the Terms of Use requires you to be at least 18.
3. When we collect information indirectly
3.1 Sometimes we collect personal information about a person from a source other than that person — for example, where an organisation adds an individual as a Permitted User, or where we receive information from a Third-Party Service, our payment provider, or a security, fraud prevention or business information provider, as described in clause 2.5.
3.2 Where we collect personal information indirectly and information privacy principle 3A of the Privacy Act 2020 applies, we will take reasonable steps to ensure the individual is aware of:
- the fact that we have collected their information, and that we hold it;
- our name and address, as set out in clause 1.1;
- the purpose for which we collected it, as set out in section 4;
- the intended recipients of it, as set out in section 7;
- whether the collection is required or authorised by law; and
- their rights of access and correction, as set out in section 10.
3.3 We will do this as soon as reasonably practicable after collection, by direct notice where we hold contact details for the individual, or otherwise by making this Policy available to them.
3.4 We do not need to take those steps where an exception in principle 3A applies — for example where the individual is already aware of those matters, where they have authorised the collection, where the information is publicly available, or where notification would prejudice the purpose of collection or a lawful investigation. Where we rely on an exception we will record which one.
3.5 Information inside a Brain. Where an individual's information is inside a customer's Brain, the customer collected it, not us. The customer is responsible for its own notification obligations, including under principle 3A. Section 14 and the Data Processing Addendum apply.
4. Why we use it
4.1 We use the information described in clauses 2.1, 2.2, 2.3 and 2.5 to:
- create and administer your account, and authenticate you;
- provide, operate, maintain and support the Service;
- validate entitlement, calculate Usage Fees and process payments;
- monitor, diagnose and improve the performance, reliability and security of the Service;
- detect, investigate and prevent fraud, abuse, security incidents and breaches of the Acceptable Use Policy;
- communicate with you about the Service, including service notices, security notices and changes to our terms;
- send you information about our products where you have not opted out, and where we are permitted to do so;
- understand how the Service is used in aggregate, and develop and improve it; and
- comply with our legal obligations, and establish, exercise or defend legal claims.
4.2 We will only use this information for a purpose set out in clause 4.1, for a directly related purpose, or as permitted or required by law. If we want to use it for a materially different purpose, we will tell you and, where required, obtain your consent.
4.3 Where the GDPR or UK GDPR applies, our legal bases are: performance of our contract with you (clause 4.1(a) to (c) and (f)); our legitimate interests in operating, securing and improving the Service and in growing our business (clause 4.1(d), (e), (g) and (h)); and compliance with a legal obligation (clause 4.1(i)). Where we rely on legitimate interests, we have assessed that our interests do not override your rights. You may object to processing based on legitimate interests — see section 10.
5. Automated decision-making
5.1 Decisions we make using computer programs. We use automated security, fraud prevention, sanctions screening and entitlement controls. These can restrict, suspend or decline access to an account, which may significantly affect your rights or interests.
5.2 For those controls:
- the kinds of personal information used are: account and identity information, IP address and device information, authentication and access records, payment and transaction signals, usage and metering patterns, and fraud or sanctions signals received from the providers listed in clause 2.5;
- the kinds of decisions made solely by automated means are: temporary rate limiting or throttling; blocking a login attempt or a payment; and flagging an account for review;
- the kinds of decisions substantially and directly assisted by automated means, with a human deciding are: suspending an account under clause 18 of the Terms of Use; declining or terminating an account on sanctions or fraud grounds; and cancelling a Welcome Credit under clause 10.1 of the Terms of Use; and
- how to seek human review — contact us under section 13. A person with authority to reach a different conclusion will review the decision and tell you the outcome.
5.3 We do not use automated decision-making to profile you for marketing, to score you, or to infer sensitive characteristics.
5.4 The Service itself generates AI Outputs from Your Content. Where that involves decisions about individuals, our customer is responsible for it, not us: clause 4.2 of the AI Terms prohibits using the Service as the sole basis for a consequential decision, and section 8 of the AI Terms allocates the regulatory roles. If you are an individual affected by a decision an organisation made using Telos Brain, that organisation is the one to approach, and its own privacy policy governs.
6. Model providers — an important point
6.1 Telos Brain does not include an AI model. Each customer supplies its own API keys for the model providers it chooses to use, and contracts with those providers directly.
6.2 This means that when a Brain sends content to a model provider, that provider is processing the data under the customer's agreement with it, not under ours. We do not control, and cannot make commitments about, how a model provider retains, discloses or uses that data, including whether it uses it to train its own models. Clause 5.3 of the AI Terms explains this, and clause 5.6 of the Data Processing Addendum records that model providers connected with a customer's own credentials are not our sub-processors.
6.3 Where a Brain is self-hosted, content sent to a model provider goes directly from the customer's environment to that provider and does not pass through our systems at all.
6.4 Customers should review the data usage terms of each model provider they configure, and enable any no-training or zero-retention controls it offers.
7. Who we share it with
7.1 We disclose personal information to the following categories of recipient, in each case only as necessary for the purposes in section 4:
- other members of the Telos Group, including Telos Limited, Telos IP Ltd and Telos AU Pty Ltd, where they perform part of our obligations — for example local sales, support, security operations or group governance. They act on Telos NZ Limited's instructions and are bound by intra-group data protection terms;
- cloud infrastructure and hosting providers;
- our payment provider;
- providers of support, ticketing, communications, product analytics, logging and error monitoring tools;
- security, identity and fraud prevention providers;
- our professional advisers, insurers and auditors, where they need it;
- a party to whom we transfer our business or assets, or a prospective party and its advisers, subject to confidentiality; and
- a court, regulator, law enforcement agency or other person, where we are required or authorised by law to disclose it.
7.2 We publish our current list of sub-processors, including the Telos Group entities that process customer content, on the Telos Limited Trust Centre at https://trust.telosready.com. That list is publicly accessible without a request for access. Model providers you connect using your own credentials are not on that list, because they are not our sub-processors — see section 6.
7.3 We do not sell personal information, and we do not disclose it to third parties for their own advertising purposes.
7.4 If your organisation administers your account, we may disclose your account information to it, and may transfer control of your account to it, in accordance with clause 5.5 of the Terms of Use.
8. Sending information overseas
8.1 We and our providers store and process information outside New Zealand. Our personnel and subcontractors in New Zealand may access it, including personnel of Telos Limited, Telos IP Ltd and Telos AU Pty Ltd.
8.1A Transfers within the Telos Group are made under intra-group data protection terms that impose obligations equivalent to those in our customer Data Processing Addendum, together with the standard contractual clauses where a transfer requires them. Where personal information is disclosed from Australia to Telos NZ Limited, Australian Privacy Principle 8 applies and section 16 explains how we meet it.
8.2 Before we disclose personal information to a person outside New Zealand, we take the steps required by information privacy principle 12 of the Privacy Act 2020 — generally by satisfying ourselves that the recipient is required to protect the information to a standard comparable to the Act, by contract or otherwise.
8.3 Where the GDPR or UK GDPR applies and we transfer personal information out of the European Economic Area or the United Kingdom, we rely on an approved transfer mechanism, including the European Commission's standard contractual clauses and the UK International Data Transfer Addendum, together with supplementary measures where required. Further detail is in the Data Processing Addendum. You may request a copy of the relevant safeguards by contacting us under section 13.
8.4 Transfers to a model provider are made on the customer's instruction using the customer's own credentials. The customer, not us, is the exporter of that data, and is responsible for the transfer safeguards that apply to it. See clause 6.4 of the Data Processing Addendum.
9. How long we keep it
9.1 We keep personal information only as long as we need it for the purposes in section 4, or as required by law. In general:
| Category | Retention | Notes |
|---|---|---|
| Account information | Life of the account, then 12 months | |
| Billing and transaction records | 7 years | Tax and record-keeping requirements |
| Usage, telemetry and access logs | 12 months | Longer where retained for a security investigation |
| Metering Data from self-hosted deployments | 24 months | Needed to substantiate billing |
| Support correspondence | 24 months | Including logs you send us |
| Prompts, retrieved context and AI Outputs (hosted Brains only) | 12 months | Held within your Brain; deleted with it under clause 19.6 of the Terms of Use |
| Your Content in a hosted Brain | Per clause 19.6 of the Terms of Use | 30 days after termination, then deleted |
| Your Content in a self-hosted Brain | Not held by us | Retention is entirely under your control |
9.2 We may keep information for longer where we need it to establish, exercise or defend a legal claim, or where we are required to.
10. Your rights
10.1 Under the Privacy Act 2020 you may ask us for access to the personal information we hold about you, and may ask us to correct it. We will respond as soon as reasonably practicable and within 20 working days of receiving your request.
10.2 Where the GDPR or UK GDPR applies, you also have rights to erasure, restriction of processing, data portability, to object to processing based on legitimate interests or to direct marketing, and to withdraw consent where we rely on it. We will respond within one month, and will tell you if we need longer.
10.3 We may need to verify your identity before acting on a request, and there are limited grounds on which we may decline one. If we decline, we will tell you why.
10.4 You can opt out of marketing communications at any time using the unsubscribe link in the message or by contacting us. You cannot opt out of service, security and legal notices while you hold an account.
10.5 To exercise any of these rights, contact privacy@telosbrain.com.
11. Cookies and similar technologies
11.1 We use cookies and similar technologies on our website and in the Service to keep you signed in, remember your preferences, keep the Service secure, and understand how it is used.
11.2 Strictly necessary cookies are required for the Service to work. Analytics and performance cookies are optional and, where required by law, we will ask for your consent before setting them. You can manage cookies through your browser and through the controls we provide.
11.3 We also collect product telemetry inside the Service. This is described in clause 2.2(a) and is used for the purposes in clauses 4.1(d) and (h).
12. How we protect it
12.1 We maintain technical and organisational security measures appropriate to the nature of the information and the risk, including access controls, encryption of data in transit and at rest, logging and monitoring, personnel confidentiality obligations, and review of our providers. Our contractual commitment is set out in Annex 2 of the Data Processing Addendum. Further detail, our current certifications and supporting evidence are published on the Telos Limited Trust Centre at https://trust.telosready.com; some evidence there requires you to request access.
12.2 Where you run Telos Brain on your own infrastructure, the security of that environment is your responsibility, as set out in clause 14.2 and clause B6 of the Terms of Use. We are responsible for the security of the software as we deliver it.
12.3 No system is completely secure. If a privacy breach occurs that has caused or is likely to cause serious harm, we will notify the Office of the Privacy Commissioner and affected individuals as required by the Privacy Act 2020, and will notify affected customers in accordance with clause 13.6 of the Terms of Use and clause 8 of the Data Processing Addendum. Where the GDPR or UK GDPR applies, we will meet the notification timeframes it requires.
13. Contact and complaints
13.1 For any privacy question, request or complaint about any Telos Group company, contact privacy@telosbrain.com, or write to the Privacy Officer, Telos NZ Limited, Level 4, 40 Taranaki Street, Wellington, New Zealand. If your enquiry concerns Telos AU Pty Ltd, you may also write to C/- Scendar Pty Ltd, 526/368 Sussex Street, Sydney, NSW 2000.
13.2 We will acknowledge a complaint promptly and tell you how we intend to deal with it.
13.3 If you are not satisfied with our response, you may complain to:
- the Office of the Privacy Commissioner in New Zealand (privacy.org.nz);
- the Office of the Australian Information Commissioner (oaic.gov.au), if your complaint concerns Telos AU Pty Ltd or information handled in Australia; or
- your local supervisory authority in the European Economic Area, or the Information Commissioner's Office in the United Kingdom.
14. Personal information inside a hosted Brain
14.1 Where a customer puts personal information into a Brain we host, we hold and process it on that customer's behalf and on their instructions. The customer decides what information goes in, for what purpose, and how long it stays. Under the GDPR the customer is the controller and we are the processor.
14.2 We do not use that information for our own purposes. We access it only where reasonably necessary to provide, secure and support the Service, as set out in clause 7.6 of the Terms of Use, or where required by law.
14.3 Our obligations in relation to that information are set out in the Data Processing Addendum, including security, sub-processors, transfers, assistance with individuals' requests, breach notification, and deletion.
14.4 If you are an individual and you believe an organisation holds your information in a Brain, direct your request to that organisation. If you contact us, we will tell you to approach them and, where we can identify the customer, we will pass your request on. We cannot access, correct or delete a customer's data on your instruction.
15. Self-hosted Brains and Metering Data
15.1 Where a customer runs Telos Brain on infrastructure it controls, we do not host, store, back up or have access to the information in that Brain. It never reaches our systems. We are not a processor of it.
15.2 A self-hosted Brain connects to our control plane to validate entitlement and report usage. In doing so it sends us Metering Data, being records of the volume, type and timing of operations, instance and organisation identifiers, software version and configuration identifiers, and technical health, error and diagnostic information.
15.3 Metering Data does not include the content of a Brain, and specifically does not include documents, records, messages, prompts, retrieved context, AI Outputs, or the customer's model provider credentials. Clause B4 of the Terms of Use records this as a contractual commitment.
15.4 Metering Data may contain limited personal information, such as the identifier of the account that operates an instance. We handle that as controller data under sections 2 to 13 of this Policy.
15.5 If a customer sends us logs or diagnostic output in a support request, that material may contain personal information. We handle it under clause 2.1(c) and, where it contains the customer's own content, under the Data Processing Addendum.
16. Australia — additional information
This section applies to Telos AU Pty Ltd and to personal information handled in Australia. It supplements the rest of this Policy and prevails over it in the event of inconsistency, in relation to Australian obligations.
16.1 Our status. Telos AU Pty Ltd is an APP entity for the purposes of the Australian Privacy Act 1988 and is bound by the Australian Privacy Principles.
16.2 What we collect and why. Sections 2, 3 and 4 of this Policy apply. The kinds of personal information we collect, the purposes for which we collect, hold, use and disclose it, and how you may access and correct it are as set out there.
16.3 Sensitive information. We do not seek to collect sensitive information. The Service is not intended for it, and clauses 2.2 and 2.3 of the Acceptable Use Policy restrict what customers may input.
16.4 Cross-border disclosure (APP 8). We disclose personal information to Telos NZ Limited in New Zealand, and to the providers listed in section 7, in the territories listed in section 8. Before disclosing personal information overseas we take reasonable steps to ensure the recipient does not breach the Australian Privacy Principles, generally by binding the recipient contractually to standards equivalent to the APPs.
16.5 Automated decision-making. Section 5 sets out the personal information we use in automated decision-making, the kinds of decisions made solely by automated means, the kinds of decisions substantially and directly assisted by automated means, and how to seek human review. This is provided to meet Australian Privacy Principles 1.7 to 1.9.
16.6 Data breaches. Where we suspect an eligible data breach, we will carry out an assessment within 30 days and, if the breach is likely to result in serious harm, notify the Office of the Australian Information Commissioner and affected individuals as soon as practicable, in accordance with the Notifiable Data Breaches scheme. Section 12 and clause 8 of the Data Processing Addendum also apply.
16.7 Anonymity. Where it is lawful and practicable to deal with us anonymously or under a pseudonym, you may do so. It is not practicable in relation to a Telos Brain account, because we must be able to identify the account holder, bill for usage and meet our security obligations.
16.8 Government identifiers. We do not adopt, use or disclose government-related identifiers as our own identifier of an individual.
16.9 Complaints. Section 13 applies. You may complain to the Office of the Australian Information Commissioner at oaic.gov.au.
17. Changes to this Policy
17.1 We may change this Policy from time to time. We will publish the updated Policy at https://trust.telosready.com and update its version and effective date. Where a change materially affects how we handle your personal information, we will notify you in accordance with clause 2 of the Terms of Use. Superseded versions are archived at https://trust.telosready.com.