How your information is handled

AI and Data Policy

Version: 18 August 2026

Why this exists

Wyvern builds and advises on AI systems. Clients hand over access to their business, and sometimes to information about their own customers. This policy says what happens to that information, which tools touch it, and where the lines are.

It is written to be shown to a client, a client’s compliance adviser, or an insurer. The full edition, including anything currently in progress, is available to clients and their advisers on request.

Nothing here is a substitute for the Terms of Engagement or the Confidentiality and Data Handling Agreement. Those are the contract. This explains how the contract is met in practice.

Who I am

Entity Wyvern Services Limited, trading as Wyvern AI
NZBN 9429032320565
Company number 2225792
People One. Andrew Hunt, Director and sole consultant
Subcontractors None. If that changes, clients are told before it affects their work
Accountable for this policy Andrew Hunt
Reviewed Annually, and whenever a tool or a material practice changes

The five rules

  1. A person is accountable for every deliverable. How something was made does not change who answers for it.
  2. Client information is classified before it is used, and the classification decides which tools may touch it.
  3. Nothing goes to a client’s customers automatically. Drafts are prepared for a human to review and send.
  4. Controls are built, not promised. Where this policy says something cannot happen, there is a mechanism stopping it, and I will show it to you.
  5. I say what I use. Tools, tiers and where data sits are disclosed on request, and listed in the tool register.

1. How client information is classified

Everything a client gives me falls into one of three tiers. The tier decides what may touch it.

Tier What it is Where it may go
Restricted Personal information about a client’s own customers or staff. Financial account details. Credentials and keys. Never enters any AI service. Held locally, encrypted, processed by software with no AI in it. Enforced by automated controls
Confidential The client’s own business information: correspondence, processes, commercial figures, documents, code May be processed in AI environments I operate, on business or individual tiers with model training disabled, under the confidentiality agreement
General Public information, non-identifying material, my own methods and research No restriction

I do not claim that no client information ever reaches an AI service. That claim would be false for any AI consultancy. The enforced claim is narrower: Restricted information never does.

Tier is assigned per engagement, recorded in the Confidentiality and Data Handling Agreement schedule, and can be tightened at a client’s request. It cannot be loosened without the client agreeing in writing.

2. Where information is held

Location New Zealand, on equipment Wyvern controls, unless a client’s schedule says otherwise
Encryption Full-disk encryption on every machine holding client information
Backups Automatic hourly backup to an encrypted local drive, with code and business records also held in cloud services as second copies. Specifics, the off-site arrangement and test dates are in the Disaster Recovery Plan
Credentials In a password manager, never in files, never in email. Any credential that has passed through plain email is treated as compromised and reissued
Access Andrew Hunt only. No staff, no subcontractors
Offshore Where an AI service processes Confidential-tier information offshore, that is disclosed. Restricted information does not move offshore, or anywhere else

Client systems. Where I am given access to a client’s own systems, I take the narrowest access that does the job, read-only wherever possible, and I say so if the access I am granted turns out to be wider than the work needs.

3. What I will never do

These are absolute.

  • Never train a model on client information, or use a service that does.
  • Never put Restricted information into a general AI conversation.
  • Never present unverified AI output as though it has been checked.
  • Never build a system that sends to a client’s customers without a person approving each one.
  • Never record a meeting without saying so.
  • Never move client information offshore without written consent.
  • Never use a free or personal-account AI tool for client work.
  • Never sign, commit, pay, or send on a client’s behalf. I prepare; a person at the client acts.

4. Human review, and what it actually means

Much of what I build produces drafts for a person to check before they are used. Where a system is designed that way, the review has to be real.

Review screens show the source alongside the output. Where a system extracts a figure from a document, the reviewer sees the extracted figure and the document it came from, not just a finished draft.

The reviewer must be competent to judge the output. I will say who that needs to be. Where a client’s own regulator sets that bar, theirs applies.

5. Which AI tools I use

The current list, the tier each is approved for, and where it processes, is maintained in the tool register and provided on request. In summary:

  • Development and general work runs on business-grade AI subscriptions with model training disabled.
  • Client AI environments, where I set one up, are licensed to the client, on the client’s own accounts, and configured so their content is not used for training.
  • I will not add a tool to client work without it meeting the tier rules in section 1.

On the difference between a setting and a contract. On some individual-tier subscriptions, “do not train on my content” is a setting the account holder switches off. On business tiers it is part of the commercial agreement with the provider. Where a client requires the contractual version, I will say honestly which of my tools currently meet that bar and which do not.

6. Meeting recordings

I record meetings so that notes and actions are accurate.

  • It is disclosed in writing at the start of every engagement, in the Terms of Engagement, and that disclosure covers the engagement’s meetings.
  • When someone is in a meeting who has not seen that disclosure, I say so before recording.
  • Anyone can ask me not to record, at any time, without giving a reason, and I will not.
  • Recordings and transcripts are Confidential tier, used only for that engagement, not shared outside Wyvern, and deleted with the rest of the client’s information.
  • Where a recording would capture a client’s customers’ personal information, it is Restricted tier, which means it does not go through an AI note-taker at all.

Recording a conversation you are part of is lawful in New Zealand. Telling people is a Privacy Act obligation.

7. Telling clients I use AI

  • I disclose it once, up front, in the Terms of Engagement. It covers the whole engagement.
  • I do not label individual deliverables. I am accountable for the work either way.
  • I do tell a client specifically where a deliverable contains material AI-generated content I have not checked myself, or where the client’s own obligations require AI use to be recorded or disclosed.

8. If something goes wrong

  • The client hears first, in writing, within 24 hours of me becoming aware of any actual or suspected unauthorised access to, loss of, or disclosure of their information.
  • I give them what they need to decide whether it is a notifiable privacy breach.
  • The client makes the notification decision. They are the responsible agency under the Privacy Act; I do not notify their customers or the Privacy Commissioner unless asked in writing.
  • Full detail is in the Incident Response Plan.

9. How long I keep things

What How long
A client’s own customer information Deleted or returned within 30 days of the engagement ending, or sooner on request, confirmed in writing
My working records: what I did, what I advised, the correspondence Seven years. I need them to answer a claim and to meet tax record-keeping requirements. They stay confidential for as long as I hold them
Backups Overwritten on the normal cycle; obligations continue to apply while they exist

10. Insurance

Wyvern holds professional indemnity cover of NZ$1,000,000, public liability of NZ$2,000,000, and statutory liability of NZ$1,000,000, with a specialist technology insurer. Cover is written for New Zealand territory and jurisdiction. A certificate of currency is available on request.

11. Working inside a client’s own policy

Where a client has its own AI policy, tools register or approval process, I work inside it. In practice that means:

  • I tell you which of my tools touch your work, and at which tier, so you can record them;
  • I ask for approval before adding anything new;
  • I accept conditions attached to that approval; and
  • I tell you if I cannot meet a requirement, rather than signing up to it and hoping.

If a client’s policy conflicts with my Terms of Engagement, I raise it before the work starts.


Wyvern Services Limited, trading as Wyvern AI. Questions: andrew@wyvernai.co.nz