1. Scope and who we are
This Privacy Policy applies to HighFlyer Conductor (the Service), including its administration tools, integrations, support, and communications through a customer-selected messaging application. It does not replace the general HighFlyer website privacy policy for visitors who do not use Conductor.
The Service is provided by HighFlyer Technologies Limited (trading as HighFlyer, HighFlyer, we, us, or our), Suite 15703, Unit A, 26 Hobson Street, Auckland 1010, New Zealand.
We handle personal information in accordance with the New Zealand Privacy Act 2020 and other laws that apply to us. This policy is also intended to provide notice where Conductor receives personal information indirectly from a customer, a connected system, or another authorised user.
2. Our role and your role
Conductor is primarily a business service. A customer decides which people may use it, which systems it may access, what instructions it may carry out, and what information is submitted. For personal information contained in customer messages, connected systems, or workflows, the customer will generally be the organisation responsible for deciding why that information is handled, and HighFlyer will generally handle it to provide the Service on the customer’s instructions.
Customers must have a lawful basis and any necessary authority, notices, and consents to provide personal information to Conductor. This includes personal information about employees, clients, suppliers, message recipients, and other people obtained from connected systems or collected indirectly. Customers are responsible for complying with any notification obligations that apply to their own collection and use of that information.
HighFlyer is independently responsible for information used to administer accounts, bill customers, secure and improve the Service, meet legal obligations, and manage its customer relationship.
3. Information we collect
Depending on how Conductor is configured and used, we may collect or generate:
- Account and organisation information: names, work contact details, role, organisation, authorised users, account settings, subscription details, and support contacts.
- Conversation and instruction content: messages, attachments, prompts, responses, approvals, feedback, and other content processed inside the customer’s isolated Conductor runtime.
- Connected-system information: records retrieved from, sent to, or acted on in customer-selected systems, such as email, calendars, accounting, CRM, ERP, files, project-management, and other business software.
- Messaging information: messaging-app identifier, display name, sender and recipient details, message timestamps, delivery information, and channel metadata made available by the selected messaging provider.
- Workflow and audit information: tools called, actions proposed or completed, authorisations, approval outcomes, error records, and activity logs.
- Connection and security information: integration configuration, access scopes, tokens or credentials, authentication records, IP address, device and browser information, and security events. Secrets are handled as credentials and are not intended to be displayed in ordinary Service content.
- Usage and diagnostic information: feature usage, performance data, model and token usage, crash reports, and technical logs.
- Commercial information: orders, invoices, payments, account balances, and correspondence about the customer relationship.
Providing most information is voluntary, but Conductor cannot provide the requested workflow without the messages, permissions, connected-system information, and account details needed to perform it.
Chat content is end-to-end encrypted between the authorised user’s chat client and that customer’s isolated Conductor runtime. The chat provider and HighFlyer personnel do not hold the chat encryption keys and cannot open the conversation through a provider dashboard or shared HighFlyer inbox. Message plaintext is available only at the two endpoints: the user’s authorised client and the isolated runtime that must read the request to perform it.
4. How we collect information
We collect information:
- directly from customers and authorised users during onboarding, configuration, messaging, support, and use of the Service;
- from the end-to-end encrypted chat client that HighFlyer configures for the customer;
- from systems and data sources a customer authorises Conductor to connect to;
- from other authorised users in the same customer organisation;
- automatically when the Service is used, including through logs, security tools, and usage telemetry; and
- from service providers, business partners, and public or commercial sources where lawful and reasonably necessary.
If we collect personal information about you indirectly through a customer or connected service, this policy explains that collection. In some cases, the customer is the appropriate organisation to answer questions because it controls the underlying record and the purpose for which Conductor uses it.
Information Privacy Principle 3A has applied since 1 May 2026. Where it applies to an indirect collection by HighFlyer, we take reasonable steps to make the individual aware of the collection, its purpose, intended recipients, the collecting and holding agencies, any applicable legal authority, and access and correction rights, unless a statutory exception applies. Customers remain responsible for assessing and meeting IPP3A obligations arising from personal information they direct Conductor to collect or use in their own workflows.
5. How we use information
HighFlyer may use information where reasonably necessary to:
- provide, configure, personalise, maintain, support, and secure Conductor;
- receive instructions, generate responses, request approvals, and perform authorised actions across connected systems;
- route end-to-end encrypted messages between authorised users and the customer’s isolated Conductor runtime;
- process information through selected AI models and inference providers;
- authenticate users, apply permissions, investigate misuse, prevent fraud, and maintain audit records;
- monitor reliability, troubleshoot faults, measure usage, enforce limits, and improve features;
- administer subscriptions, issue invoices, collect payment, and manage the customer relationship;
- communicate service, support, security, billing, and policy updates;
- create aggregated or de-identified statistics that do not reasonably identify an individual; and
- comply with law, lawful requests, and HighFlyer’s legal obligations, and establish or defend legal claims.
We may use de-identified and aggregated operational information to analyse and improve Conductor. We will not attempt to re-identify that information except where reasonably necessary to verify that de-identification is effective, address a security issue, or comply with law.
6. AI inference and model training
Conductor only uses inference routes and downstream providers that do not retain prompt content and do not use Customer Content for model training. HighFlyer does not sell Customer Content or use it to train or improve a public, general-purpose, or provider model. Inference providers are authorised to process relevant Customer Content only to provide the requested Service.
Conductor sends relevant portions of a request, conversation, connected-system record, and workflow context to an AI inference provider when needed to understand an instruction or produce an output. We seek to minimise the information provided to what is reasonably required for that task, but the content necessarily depends on the customer’s instruction and configuration.
We may use separate test data, synthetic data, information a customer deliberately submits as product feedback, or de-identified operational information to evaluate and improve the Service. This does not change the restriction above on training general-purpose models with Customer Content.
7. Google Workspace data
HighFlyer’s use of information received from Google Workspace APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
This section applies when an authorised user connects a personal Gmail or Google Workspace account to Conductor. Immediately before the user continues to Google’s consent screen, Conductor presents an in-product disclosure of the access requested, the user-facing features enabled, the AI processing involved, and links to this policy and our Google Workspace Data & Controls guide.
What Conductor accesses
Conductor requests the following Google OAuth access:
- Identity: the connected account’s stable Google account identifier and verified email address, used to bind and display the correct connection.
- Gmail: the
gmail.modifyscope, which permits Conductor to search and read messages and threads, inspect headers, labels and attachments, create drafts, and change mailbox state such as archive, inbox, read, unread, starred, labelled, trashed, or untrashed. Google’s scope is technically send-capable, although Conductor’s supported Gmail workflow creates drafts for the user to review and does not expose a send command. - Google Calendar: the
calendar.events.ownedscope for the connected user’s primary calendar. Conductor may read owned events and, only after a fresh action-specific approval in the supported workflow, create, update, or cancel an event owned by the connected user. Google may notify attendees when an approved Calendar change is made.
How Google data is used, processed, and stored
Conductor accesses Google data only when needed to provide a user-requested Gmail or Calendar feature. Relevant message, attachment, label, event, attendee, and account details may be placed in the user’s private Conductor session or workspace, included in a tool result or response, and processed through Conductor’s AWS-hosted environment. Where AI is needed to understand or complete the request, the minimum relevant Google content and derived context may be sent through OpenRouter to the selected downstream model provider solely to provide that user-facing feature.
Conductor stores the Google access and refresh tokens in the connected agent’s isolated runtime credential file. The active token file is not placed in source control or ordinary chat content. Conductor does not build a separate archive or database of a user’s Gmail mailbox or Calendar. Google-derived content can nevertheless remain in a Conductor conversation, tool output, memory, audit record, or a file that the user asked Conductor to download until it is deleted under the rules below.
Google data sharing and human access
Google Workspace user data, including data derived from it, is transferred only:
- as necessary to provide the Conductor feature the user requested and that is visible to the user, with the user’s consent;
- for security purposes, such as investigating abuse or a suspected compromise;
- to comply with applicable law or regulation; or
- as part of a merger, acquisition, or sale of assets, and then only after obtaining the user’s explicit prior consent.
HighFlyer personnel and contractors are not permitted to read Google Workspace user data unless the user has given documented, explicit consent for access to specific data, access is necessary for security, or access is necessary to comply with law. Any permitted access is limited to authorised personnel with a need to know.
HighFlyer does not transfer, sell, or use Google Workspace user data for advertising, retargeting, data-broker or reseller services, credit or lending decisions, or training or improving a general-purpose AI or machine-learning model. OpenRouter and downstream model providers receive relevant Google content only as processors for the user-requested feature and not for those prohibited purposes.
Disconnecting, revoking, and deleting Google data
- Disconnect Conductor: ask the customer’s Conductor administrator to open the agent’s Connected services, select Google Gmail and Calendar, and choose Disconnect, or contact HighFlyer using the details below. A successful disconnect immediately deletes the active local Google token file and clears the current connected-account identifier, email label, and granted-scope metadata from Conductor’s connection record.
- Revoke Google’s grant: separately visit Google Account → third-party connections, select HighFlyer Conductor, and remove access. Disconnecting in Conductor does not revoke Google’s provider-side grant; revoking at Google stops future API access and may affect every Conductor connection using the same Google account and OAuth project.
- Request deletion: email hello@highflyerglobal.com with the subject “Conductor Google data deletion”, identify the connected organisation and account, and state whether the request covers only Google-derived content or the whole Conductor account. We verify the requester’s identity and authority before deletion.
Disconnecting does not undo mailbox changes, delete Gmail drafts, delete or restore Calendar events, remove copies held by Google or recipients, or automatically erase Google-derived content already included in Conductor sessions, memories, audit records, or downloaded files. The user must manage provider-side records in Google and use the deletion request above for Conductor-held historical content.
8. Hosting, inference, and other providers
HighFlyer uses specialist providers to operate Conductor. Providers receive only the access reasonably required for their role and are subject to their own legal obligations and contractual terms with HighFlyer or the customer.
| Provider category | Current or typical provider | Purpose |
|---|---|---|
| Cloud hosting | Amazon Web Services (AWS) | Application hosting, compute, databases, storage, backups, networking, security, and related infrastructure. |
| AI inference | OpenRouter is Conductor’s current inference router. OpenRouter sends a request only to a configured downstream route and provider that does not retain prompt content or use Customer Content for model training. The eligible provider may vary by model, availability, and customer configuration. | Processing prompts and relevant context to generate responses, classify requests, plan workflows, and support authorised actions. |
| Messaging | The E2EE-enabled chat client configured for the customer. | Transmitting encrypted messages, attachments, delivery events, and replies between an authorised user and that customer’s isolated Conductor runtime. |
| Connected services | Services selected and authorised by the customer. | Retrieving information and carrying out customer-requested workflows in business systems. |
| Operational services | Selected identity, monitoring, security, communications, billing, and support providers. | Operating, protecting, supporting, and administering the Service. |
Providers and locations change as the Service evolves. HighFlyer may add, replace, or remove providers where reasonably required for performance, security, availability, functionality, or commercial reasons. Where required by law or contract, we will provide notice of a material change.
HighFlyer enables only inference routes and downstream providers whose applicable settings and terms prohibit prompt-content retention and model training with Customer Content. HighFlyer reviews those conditions when selecting or changing an eligible route. Providers may still process limited operational metadata for routing, security, billing, and abuse prevention where permitted by the agreement and applicable law. The stricter Google Workspace restrictions above apply whenever Google Workspace user data is involved.
9. End-to-end encrypted communication
Conductor communicates through an E2EE-enabled chat client configured for the customer. Message content is encrypted on the authorised user’s device and can be decrypted only by that user’s client and the customer’s isolated Conductor runtime. The chat provider and HighFlyer’s ordinary operational systems carry ciphertext and limited delivery metadata; they do not receive the keys needed to read the message body.
E2EE protects the communication path; it does not mean the agent can act without processing the request. Once a message reaches the isolated runtime, Conductor decrypts it in that environment so it can authenticate the instruction, ask for approval, use connected tools, and prepare a response. When AI inference is required, Conductor sends the minimum relevant request and context through OpenRouter to the selected downstream model provider as described in sections 6 and 8.
HighFlyer does not provide personnel with chat decryption keys or a shared inbox containing customer conversations, and message bodies are not intended to be written to ordinary infrastructure logs. Customers remain responsible for protecting authorised endpoint devices, controlling user access, and avoiding content their organisation has prohibited from the Service.
10. How we share information
We may disclose information:
- to the providers described above so they can perform services for HighFlyer or the customer;
- within the customer’s organisation and to its administrators, authorised users, recipients, and connected services as directed by the customer;
- to professional advisers, insurers, auditors, financiers, and prospective purchasers or investors, subject to appropriate confidentiality protections;
- in connection with a merger, acquisition, financing, reorganisation, sale of assets, or transfer of the Service;
- where reasonably necessary to protect HighFlyer, a customer, users, third parties, or the public from fraud, misuse, security threats, or harm; and
- where required or permitted by law, court order, or a lawful request from an authority.
HighFlyer does not sell personal information or Customer Content.
The general sharing permissions in this section do not expand the permitted use or transfer of Google Workspace user data. Google Workspace user data is subject to the stricter transfer and human-access limits in section 7, including the requirement for explicit prior user consent before a merger, acquisition, or asset-sale transfer.
11. Overseas processing and disclosure
Conductor uses global cloud, inference, messaging, and software providers. Personal information may therefore be processed or stored outside New Zealand, including in AWS regions, inference-provider locations, messaging-provider networks, or connected services selected by the customer.
Where the Privacy Act 2020 applies to an overseas disclosure by HighFlyer, we take steps intended to satisfy Information Privacy Principle 12, such as using providers that are subject to comparable safeguards, contractual privacy protections, or another permitted basis. A customer’s selected messaging provider or connected service may also make independent overseas disclosures for which that customer or provider is responsible.
12. Retention and deletion
We keep personal information only for as long as reasonably necessary for the purpose for which it was collected, including to provide the Service, maintain security and auditability, resolve disputes, enforce agreements, and comply with tax, accounting, and other legal requirements.
Retention varies by data type, customer configuration, plan, and legal need. Active account, workflow, and audit information may be retained while the account is in use. Unless a signed Order states a shorter period, the following maximum periods apply after a verified deletion request or termination:
- OAuth tokens: deleted from the active runtime immediately when a managed disconnect succeeds, or within 30 days after a verified deletion request if manual intervention is required.
- Google connected-account metadata: the current Google subject, account label, and scope list are cleared when a managed disconnect succeeds. Minimal event, status, security, and transaction records that do not contain OAuth tokens may be retained for up to 90 days for audit, incident response, and reconciliation.
- Google-derived content and tool outputs: active Conductor sessions, memories, workspace files, and downloaded attachments identified in a verified request are deleted or de-identified within 30 days. Copies in backups, where they exist, expire or are overwritten within 90 days unless restoration is required for security or disaster recovery, in which case the deletion instruction is reapplied.
- Other Customer Content: deleted or de-identified from active systems within 30 days after termination or a verified deletion request, and from ordinary backup cycles within 90 days, unless a signed Order specifies another period.
- Commercial and legal records: invoices, payment records, contracts, and records required for tax, fraud prevention, dispute, or legal compliance may be retained for up to seven years or longer where law requires. HighFlyer minimises Google Workspace user data in these records.
A legal hold or binding legal obligation may delay deletion of a specific record. We isolate it from ordinary use, retain it only for the required period, and delete it when the obligation ends. Aggregated information that no longer identifies a person or customer may be retained.
Deletion from Conductor does not delete encrypted copies held by the chat service, copies on authorised endpoint devices, or records held independently by a connected service, recipient, or customer system. Customers must manage those copies through the relevant service or device.
13. Security and privacy incidents
We use technical and organisational safeguards appropriate to the nature of the Service, including end-to-end encryption for chat content, encryption in transit and at rest for supporting systems, access controls, credential protection, logging that is designed to exclude message bodies, monitoring, backups, and separation of customer environments. No online service or transmission method is completely secure, and HighFlyer cannot guarantee that unauthorised access, loss, or disruption will never occur.
Customers are responsible for limiting connected-system permissions, maintaining secure devices and messaging accounts, reviewing authorised users, and promptly telling HighFlyer about suspected compromise. HighFlyer may suspend a connection or account to contain a suspected security risk.
If HighFlyer becomes aware of a privacy breach affecting information for which it is responsible, it will assess and respond to the incident and make notifications required by applicable law. Where HighFlyer handles affected information on a customer’s behalf, it will provide reasonable information to help the customer meet its own notification obligations.
14. Your choices and privacy rights
Subject to applicable law, individuals may ask HighFlyer to confirm whether we hold personal information about them, request access to that information, and ask us to correct it. You may also ask a customer organisation to exercise controls over information it submitted to Conductor.
We may need to verify identity and authority before responding. If the information is controlled by a customer, we may refer the request to that customer or respond on its instructions. Access may be withheld where the law permits or requires it.
Customers and authorised users can stop optional marketing from HighFlyer using the unsubscribe method provided, without affecting essential service, billing, or security communications. A customer may disconnect a messaging app or connected service, but doing so may prevent Conductor from functioning. Google Workspace users should follow the separate disconnect, provider-side revocation, and deletion steps in section 7.
If you believe your privacy rights have been breached, contact us first so we can try to resolve the issue. You may also complain to the Office of the Privacy Commissioner.
15. Changes and contact
We may update this policy to reflect changes to Conductor, its providers, our practices, or the law. We will post the updated version here and change the effective date. Where required by law or contract, we will give additional notice of a material change.
Privacy questions, access or correction requests, and complaints may be sent to:
Privacy Officer — HighFlyer Technologies Limited
Suite 15703, Unit A, 26 Hobson Street
Auckland 1010, New Zealand
Email: hello@highflyerglobal.com
Phone: +64 9 883 6868