Privacy statement
This statement explains how Legible collects, holds, uses and discloses personal information — both information about you, our user, and personal information that passes through our platform about other people (such as company directors and shareholders) because it appears on official New Zealand registers. It is structured around the 13 Information Privacy Principles (IPPs) in the Privacy Act 2020.
1. Who this statement covers
This statement applies to everyone who uses Legible, and to the people whose information appears in the official register data we display. Legible is provided by Glint Limited, a New Zealand company, trading as “Legible” (“Legible”, “we”, “us”, “our”).
2. Personal information we collect about you
When you create and use a Legible account, we collect:
- Account details: name, email address, and organisation name, linked to your Keycloak identity (the authentication subject).
- Billing details: when you subscribe to a paid plan, your billing email and organisation name are shared with Stripe, our payment processor, to create and manage your subscription. We do not store payment card details ourselves.
- Usage information: which companies you look up, the searches and reports you run, and the watchlists, lists and notes you create. This is recorded for billing and quota purposes (for example, monthly lookup counts), service delivery, and account administration (such as an audit trail of account changes).
- Free-text notes: if you add notes to a watchlisted company, that text is stored as you wrote it. Notes you write about a company may incidentally name or describe individuals (for example, a director) — you are responsible for the content of your own notes, and they are visible to other members of your organisation, not to other Legible customers.
We do not currently collect IP addresses, device identifiers, or browsing analytics, and we do not use cookies for tracking or advertising. If this changes (for example, if request logging or analytics tooling is added), we will update this statement first.
3. Personal information about other people, sourced from public registers
Legible displays information about company directors, shareholders, and other officeholders that we obtain from official New Zealand government registers — including the NZBN / Companies Register, the Companies Entity Role Search, the Disqualified Directors register, the Personal Property Securities Register (PPSR), the Insolvency Register, the NZ Gazette, and WorkSafe enforcement notices — under access arrangements with the New Zealand Ministry of Business, Innovation and Employment (MBIE).
This information is already public on those registers. We do not collect it directly from the individuals concerned, and we are not the original source of it. We display it for the purpose of lawful business research and due diligence, consistent with the terms under which we access it. We do not use this information for direct marketing, the creation of marketing lists, or for profiling, harassment or stalking of any individual, and our Terms of Service prohibit our users from doing so.
Residential addresses sourced from the Companies Register are stored but not prominently displayed; they appear only in a collapsible section behind an explicit user action.
If you are an individual who appears in register data shown on Legible and you wish to correct that information, please contact the relevant register directly (for example, the Companies Office) — as the data originates there, corrections must be made at the source. We will refresh our records once the source register is updated.
4. Why we collect and use personal information
We use personal information to:
- create and administer your account, and authenticate you via Keycloak;
- provide the core service — company search, watchlists, change alerts, and due-diligence reports;
- process payments and manage subscriptions via Stripe;
- enforce usage limits tied to your plan;
- investigate and respond to support requests, and maintain an audit trail for account security and billing accuracy;
- meet our legal and regulatory obligations, including responding to MBIE audit requests under our data access agreements.
5. Who we share personal information with
- Stripe (payment processing): your billing email, name, and organisation details are sent to Stripe to create a customer record and manage your subscription. Stripe is a third-party data processor; it may process this information outside New Zealand. See section 8 below.
- MBIE / Companies Office: we do not send your personal account information to MBIE. We do send queries (for example, an NZBN or company name) to MBIE’s APIs in order to retrieve register data on your behalf; MBIE may log these queries for audit purposes under our access agreement.
- We do not sell personal information, and we do not share it with anyone else for their own marketing purposes.
- We may disclose personal information if required by law, or to investigate a suspected breach of our Terms of Service.
Our sub-processors. We rely on a small number of third-party providers (“sub-processors”) to run the service. Each handles personal information only to provide its service to us, under a data processing agreement, and not for its own purposes:
- Netcup GmbH (Germany, EU) — hosts our application database and self-hosted Keycloak authentication service. GDPR; Article 28 data processing agreement.
- Hetzner Online GmbH (Germany, EU) — stores encrypted off-site backups of our databases. GDPR; Article 28 data processing agreement. Backups are encrypted by us before they leave our servers, so Hetzner holds only encrypted data.
- Stripe (Stripe New Zealand Limited and Stripe Payments Europe, Limited — New Zealand and Ireland, EU) — processes payments and manages subscriptions. GDPR; processing necessary to provide your subscription.
- Resend, Inc. (United States) — sends our transactional email, such as account verification, password resets, and watchlist or account notifications. Data processing agreement incorporating standard contractual clauses.
MBIE / the Companies Office is addressed separately above: it is the source of the register data we display, not a processor of your account information — we send it search queries, not your personal account details. We will update this list when we add or change a sub-processor. Overseas transfers are covered in section 8.
6. Storage and security
Account and usage data is stored in a database we operate, hosted on infrastructure provided by Netcup, a German hosting provider. Authentication is handled by a self-hosted Keycloak instance on the same infrastructure; we do not rely on a third-party identity provider. We take reasonable steps to protect personal information against loss, unauthorised access, use, modification or disclosure, including access controls limiting who within our organisation can view account data. We take regular backups of this data for resilience; the backups are encrypted before they leave our servers and are stored off-site with a separate provider (see the sub-processors in section 5 and overseas disclosure in section 8).
Netcup acts solely as our infrastructure provider under a data processing agreement governed by Article 28 of the EU General Data Protection Regulation (GDPR): it processes data only to deliver the hosting service to us and does not use it for its own purposes.
7. How long we keep personal information
We keep different categories of information for different periods, based on why we hold them:
- Billing and account-audit records (such as subscription history, invoices, and the account-change audit trail) are kept for 7 years after your account closes, in line with our obligations to retain financial records under the Tax Administration Act 1994.
- Working content — watchlists, watchlist notes, search history, and generated reports — is deleted when your account closes. There is no legal requirement for us to keep this content, and keeping it longer than needed would be inconsistent with Information Privacy Principle 9 (information must not be kept longer than required for the purpose it was collected for).
8. Overseas disclosure (Information Privacy Principle 12)
Some personal information we hold is stored or processed outside New Zealand:
- Hosting: our application database and Keycloak authentication service are hosted with Netcup, a hosting provider based in Germany. Germany, as an EU member state, operates under the GDPR, which provides privacy safeguards comparable to, and in some respects more stringent than, those required by the Privacy Act 2020. We also have a GDPR Article 28 data processing agreement with Netcup confirming it does not use our data for its own purposes. We rely on this as the basis for any overseas storage of personal information under Information Privacy Principle 12.
- Backups: encrypted backups of our databases are stored with Hetzner Online GmbH, a hosting provider based in Germany (EU), under a GDPR Article 28 data processing agreement. The backups are encrypted by us before they leave our servers, so Hetzner holds only encrypted data. We rely on the same GDPR comparable-safeguards basis as for hosting, under Information Privacy Principle 12.
- Email: we send transactional email (such as account verification and password-reset messages, and account notifications) through Resend, Inc., based in the United States. This involves disclosing your email address and name to Resend for the purpose of delivering that email. Resend is bound by a data processing agreement incorporating standard contractual clauses; we rely on that contractual protection as the basis for this overseas disclosure under Information Privacy Principle 12.
- Billing: you contract with Stripe New Zealand Limited for payment processing. Stripe Payments Europe, Limited (incorporated in Ireland) is also a party to that agreement solely for the purpose of processing personal data, under GDPR safeguards. We rely on this — and on the disclosure being necessary to give effect to your subscription contract — as the basis for any overseas processing of billing information under Information Privacy Principle 12.
9. Your rights — access and correction
Under the Privacy Act 2020, you have the right to ask us what personal information we hold about you, and to ask us to correct it. To make a request, contact us at privacy@legible.nz. We will respond within 20 working days, as required by the Act.
If you are an individual whose information appears in register data displayed on Legible (rather than a Legible account holder), see section 3 above — we will direct you to the relevant official register, as that is where the information originates and where corrections take effect.
10. Cookies and tracking
Legible does not use cookies for tracking or advertising. We use browser session storage only for functional purposes (such as resuming an in-progress login action) — not to track you across sites or build an advertising profile.
11. If something goes wrong
If we become aware of a privacy breach that has caused, or is likely to cause, serious harm, we will notify the Office of the Privacy Commissioner and affected individuals as soon as practicable, as required by the Privacy Act 2020.
12. Complaints
If you have a concern about how we handle personal information, please contact us first at privacy@legible.nz. If you are not satisfied with our response, you can complain to the Office of the Privacy Commissioner:
- Web: privacy.org.nz
- Phone: 0800 803 909
13. Changes to this statement
We may update this statement from time to time. We will post the updated version here with a new version date.
14. Contact us
Glint Limited, trading as Legible
Email: privacy@legible.nz
Registered office: 26 Waima Crescent, Titirangi, Auckland 0604