1. Scope and who we are
This Privacy Policy applies to HighFlyer Conductor (the Service), including its administration tools, integrations, support, and communications through a customer-selected messaging application. It does not replace the general HighFlyer website privacy policy for visitors who do not use Conductor.
The Service is provided by HighFlyer Technologies Limited (trading as HighFlyer, HighFlyer, we, us, or our), Suite 15703, Unit A, 26 Hobson Street, Auckland 1010, New Zealand.
We handle personal information in accordance with the New Zealand Privacy Act 2020 and other laws that apply to us. This policy is also intended to provide notice where Conductor receives personal information indirectly from a customer, a connected system, or another authorised user.
2. Our role and your role
Conductor is primarily a business service. A customer decides which people may use it, which systems it may access, what instructions it may carry out, and what information is submitted. For personal information contained in customer messages, connected systems, or workflows, the customer will generally be the organisation responsible for deciding why that information is handled, and HighFlyer will generally handle it to provide the Service on the customer’s instructions.
Customers must have a lawful basis and any necessary authority, notices, and consents to provide personal information to Conductor. This includes personal information about employees, clients, suppliers, message recipients, and other people obtained from connected systems or collected indirectly. Customers are responsible for complying with any notification obligations that apply to their own collection and use of that information.
HighFlyer is independently responsible for information used to administer accounts, bill customers, secure and improve the Service, meet legal obligations, and manage its customer relationship.
3. Information we collect
Depending on how Conductor is configured and used, we may collect or generate:
- Account and organisation information: names, work contact details, role, organisation, authorised users, account settings, subscription details, and support contacts.
- Conversation and instruction content: messages, attachments, prompts, responses, approvals, feedback, and other content sent to or produced by Conductor.
- Connected-system information: records retrieved from, sent to, or acted on in customer-selected systems, such as email, calendars, accounting, CRM, ERP, files, project-management, and other business software.
- Messaging information: messaging-app identifier, display name, sender and recipient details, message timestamps, delivery information, and channel metadata made available by the selected messaging provider.
- Workflow and audit information: tools called, actions proposed or completed, authorisations, approval outcomes, error records, and activity logs.
- Connection and security information: integration configuration, access scopes, tokens or credentials, authentication records, IP address, device and browser information, and security events. Secrets are handled as credentials and are not intended to be displayed in ordinary Service content.
- Usage and diagnostic information: feature usage, performance data, model and token usage, crash reports, and technical logs.
- Commercial information: orders, invoices, payments, account balances, and correspondence about the customer relationship.
Providing most information is voluntary, but Conductor cannot provide the requested workflow without the messages, permissions, connected-system information, and account details needed to perform it.
4. How we collect information
We collect information:
- directly from customers and authorised users during onboarding, configuration, messaging, support, and use of the Service;
- from Telegram, Conductor’s supported v1 messaging channel, or another messaging channel that HighFlyer expressly offers and configures for the customer;
- from systems and data sources a customer authorises Conductor to connect to;
- from other authorised users in the same customer organisation;
- automatically when the Service is used, including through logs, security tools, and usage telemetry; and
- from service providers, business partners, and public or commercial sources where lawful and reasonably necessary.
If we collect personal information about you indirectly through a customer or connected service, this policy explains that collection. In some cases, the customer is the appropriate organisation to answer questions because it controls the underlying record and the purpose for which Conductor uses it.
5. How we use information
HighFlyer may use information where reasonably necessary to:
- provide, configure, personalise, maintain, support, and secure Conductor;
- receive instructions, generate responses, request approvals, and perform authorised actions across connected systems;
- route messages through the customer’s preferred messaging application;
- process information through selected AI models and inference providers;
- authenticate users, apply permissions, investigate misuse, prevent fraud, and maintain audit records;
- monitor reliability, troubleshoot faults, measure usage, enforce limits, and improve features;
- administer subscriptions, issue invoices, collect payment, and manage the customer relationship;
- communicate service, support, security, billing, and policy updates;
- create aggregated or de-identified statistics that do not reasonably identify an individual; and
- comply with law, lawful requests, and HighFlyer’s legal obligations, and establish or defend legal claims.
We may use de-identified and aggregated operational information to analyse and improve Conductor. We will not attempt to re-identify that information except where reasonably necessary to verify that de-identification is effective, address a security issue, or comply with law.
6. AI inference and model training
Customer Content is used to fulfil the customer’s requests, not to train general-purpose AI models. HighFlyer does not sell Customer Content or use it to train a public or general-purpose model. HighFlyer authorises an inference provider to process Customer Content only to provide the requested Service and does not authorise that provider to use Customer Content to train or improve a general-purpose model. This purpose restriction is not a promise that every route has zero data retention; section 8 explains the separate retention point.
Conductor sends relevant portions of a request, conversation, connected-system record, and workflow context to an AI inference provider when needed to understand an instruction or produce an output. We seek to minimise the information provided to what is reasonably required for that task, but the content necessarily depends on the customer’s instruction and configuration.
We may use separate test data, synthetic data, information a customer deliberately submits as product feedback, or de-identified operational information to evaluate and improve the Service. This does not change the restriction above on training general-purpose models with Customer Content.
7. Google Workspace data
HighFlyer’s use of information received from Google Workspace APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
This section applies when an authorised user connects a personal Gmail or Google Workspace account to Conductor. Immediately before the user continues to Google’s consent screen, Conductor presents an in-product disclosure of the access requested, the user-facing features enabled, the AI processing involved, and links to this policy and our Google Workspace Data & Controls guide.
What Conductor accesses
Conductor requests the following Google OAuth access:
- Identity: the connected account’s stable Google account identifier and verified email address, used to bind and display the correct connection.
- Gmail: the
gmail.modifyscope, which permits Conductor to search and read messages and threads, inspect headers, labels and attachments, create drafts, and change mailbox state such as archive, inbox, read, unread, starred, labelled, trashed, or untrashed. Google’s scope is technically send-capable, although Conductor’s supported Gmail workflow creates drafts for the user to review and does not expose a send command. - Google Calendar: the
calendar.events.ownedscope for the connected user’s primary calendar. Conductor may read owned events and, only after a fresh action-specific approval in the supported workflow, create, update, or cancel an event owned by the connected user. Google may notify attendees when an approved Calendar change is made.
How Google data is used, processed, and stored
Conductor accesses Google data only when needed to provide a user-requested Gmail or Calendar feature. Relevant message, attachment, label, event, attendee, and account details may be placed in the user’s private Conductor session or workspace, included in a tool result or response, and processed through Conductor’s AWS-hosted environment. Where AI is needed to understand or complete the request, the minimum relevant Google content and derived context may be sent through OpenRouter to the selected downstream model provider solely to provide that user-facing feature.
Conductor stores the Google access and refresh tokens in the connected agent’s isolated runtime credential file. The active token file is not placed in source control or ordinary chat content. Conductor does not build a separate archive or database of a user’s Gmail mailbox or Calendar. Google-derived content can nevertheless remain in a Conductor conversation, tool output, memory, audit record, or a file that the user asked Conductor to download until it is deleted under the rules below.
Google data sharing and human access
Google Workspace user data, including data derived from it, is transferred only:
- as necessary to provide the Conductor feature the user requested and that is visible to the user, with the user’s consent;
- for security purposes, such as investigating abuse or a suspected compromise;
- to comply with applicable law or regulation; or
- as part of a merger, acquisition, or sale of assets, and then only after obtaining the user’s explicit prior consent.
HighFlyer personnel and contractors are not permitted to read Google Workspace user data unless the user has given documented, explicit consent for access to specific data, access is necessary for security, or access is necessary to comply with law. Any permitted access is limited to authorised personnel with a need to know.
HighFlyer does not transfer, sell, or use Google Workspace user data for advertising, retargeting, data-broker or reseller services, credit or lending decisions, or training or improving a general-purpose AI or machine-learning model. OpenRouter and downstream model providers receive relevant Google content only as processors for the user-requested feature and not for those prohibited purposes.
Disconnecting, revoking, and deleting Google data
- Disconnect Conductor: ask the customer’s Conductor administrator to open the agent’s Connected services, select Google Gmail and Calendar, and choose Disconnect, or contact HighFlyer using the details below. A successful disconnect immediately deletes the active local Google token file and clears the current connected-account identifier, email label, and granted-scope metadata from Conductor’s connection record.
- Revoke Google’s grant: separately visit Google Account → third-party connections, select HighFlyer Conductor, and remove access. Disconnecting in Conductor does not revoke Google’s provider-side grant; revoking at Google stops future API access and may affect every Conductor connection using the same Google account and OAuth project.
- Request deletion: email hello@highflyerglobal.com with the subject “Conductor Google data deletion”, identify the connected organisation and account, and state whether the request covers only Google-derived content or the whole Conductor account. We verify the requester’s identity and authority before deletion.
Disconnecting does not undo mailbox changes, delete Gmail drafts, delete or restore Calendar events, remove copies held by Google or recipients, or automatically erase Google-derived content already included in Conductor sessions, memories, audit records, or downloaded files. The user must manage provider-side records in Google and use the deletion request above for Conductor-held historical content.
8. Hosting, inference, and other providers
HighFlyer uses specialist providers to operate Conductor. Providers receive only the access reasonably required for their role and are subject to their own legal obligations and contractual terms with HighFlyer or the customer.
| Provider category | Current or typical provider | Purpose |
|---|---|---|
| Cloud hosting | Amazon Web Services (AWS) | Application hosting, compute, databases, storage, backups, networking, security, and related infrastructure. |
| AI inference | OpenRouter is Conductor’s current inference router. OpenRouter sends a request to the downstream model provider selected for the configured model or route; that downstream provider may vary by model, availability, and customer configuration. | Processing prompts and relevant context to generate responses, classify requests, plan workflows, and support authorised actions. |
| Messaging | Telegram is Conductor’s supported v1 messaging provider. Another channel applies only if HighFlyer expressly offers and configures it for the customer. | Transmitting messages, attachments, delivery events, and replies between an authorised user and Conductor. |
| Connected services | Services selected and authorised by the customer. | Retrieving information and carrying out customer-requested workflows in business systems. |
| Operational services | Selected identity, monitoring, security, communications, billing, and support providers. | Operating, protecting, supporting, and administering the Service. |
Providers and locations change as the Service evolves. HighFlyer may add, replace, or remove providers where reasonably required for performance, security, availability, functionality, or commercial reasons. Where required by law or contract, we will provide notice of a material change.
OpenRouter’s published service settings distinguish its own prompt handling from the practices of downstream model providers. HighFlyer does not represent Conductor as universally “zero data retention”: downstream retention can vary by route and provider. HighFlyer authorises providers to process Customer Content only for the requested Service and applies the stricter Google Workspace restrictions above whenever Google Workspace user data is involved.
9. Communication through your messaging app
Conductor v1 communicates through Telegram. If HighFlyer later offers and expressly configures another supported channel for a customer, the same principles in this section apply to that channel. HighFlyer processes incoming and outgoing messages so Conductor can authenticate the channel, understand requests, seek approval, report results, and provide service notices.
A message is handled by the selected messaging provider before it reaches Conductor and again when Conductor replies. That provider may collect content and metadata, process it in other countries, retain it under its own settings, and apply its own privacy policy and terms. HighFlyer does not control the provider’s independent processing, security, retention, encryption, or availability.
Customers should select a messaging application appropriate for the sensitivity of their information, configure its privacy and security settings, protect authorised accounts and devices, and avoid sending information that their organisation has prohibited from that channel.
10. How we share information
We may disclose information:
- to the providers described above so they can perform services for HighFlyer or the customer;
- within the customer’s organisation and to its administrators, authorised users, recipients, and connected services as directed by the customer;
- to professional advisers, insurers, auditors, financiers, and prospective purchasers or investors, subject to appropriate confidentiality protections;
- in connection with a merger, acquisition, financing, reorganisation, sale of assets, or transfer of the Service;
- where reasonably necessary to protect HighFlyer, a customer, users, third parties, or the public from fraud, misuse, security threats, or harm; and
- where required or permitted by law, court order, or a lawful request from an authority.
HighFlyer does not sell personal information or Customer Content.
The general sharing permissions in this section do not expand the permitted use or transfer of Google Workspace user data. Google Workspace user data is subject to the stricter transfer and human-access limits in section 7, including the requirement for explicit prior user consent before a merger, acquisition, or asset-sale transfer.
11. Overseas processing and disclosure
Conductor uses global cloud, inference, messaging, and software providers. Personal information may therefore be processed or stored outside New Zealand, including in AWS regions, inference-provider locations, messaging-provider networks, or connected services selected by the customer.
Where the Privacy Act 2020 applies to an overseas disclosure by HighFlyer, we take steps intended to satisfy Information Privacy Principle 12, such as using providers that are subject to comparable safeguards, contractual privacy protections, or another permitted basis. A customer’s selected messaging provider or connected service may also make independent overseas disclosures for which that customer or provider is responsible.
12. Retention and deletion
We keep personal information only for as long as reasonably necessary for the purpose for which it was collected, including to provide the Service, maintain security and auditability, resolve disputes, enforce agreements, and comply with tax, accounting, and other legal requirements.
Retention varies by data type, customer configuration, plan, and legal need. Active account, workflow, and audit information may be retained while the account is in use. Unless a signed Order states a shorter period, the following maximum periods apply after a verified deletion request or termination:
- OAuth tokens: deleted from the active runtime immediately when a managed disconnect succeeds, or within 30 days after a verified deletion request if manual intervention is required.
- Google connected-account metadata: the current Google subject, account label, and scope list are cleared when a managed disconnect succeeds. Minimal event, status, security, and transaction records that do not contain OAuth tokens may be retained for up to 90 days for audit, incident response, and reconciliation.
- Google-derived content and tool outputs: active Conductor sessions, memories, workspace files, and downloaded attachments identified in a verified request are deleted or de-identified within 30 days. Copies in backups, where they exist, expire or are overwritten within 90 days unless restoration is required for security or disaster recovery, in which case the deletion instruction is reapplied.
- Other Customer Content: deleted or de-identified from active systems within 30 days after termination or a verified deletion request, and from ordinary backup cycles within 90 days, unless a signed Order specifies another period.
- Commercial and legal records: invoices, payment records, contracts, and records required for tax, fraud prevention, dispute, or legal compliance may be retained for up to seven years or longer where law requires. HighFlyer minimises Google Workspace user data in these records.
A legal hold or binding legal obligation may delay deletion of a specific record. We isolate it from ordinary use, retain it only for the required period, and delete it when the obligation ends. Aggregated information that no longer identifies a person or customer may be retained.
Deletion from Conductor does not delete copies held independently by a messaging provider, connected service, recipient, or customer system. Customers must manage those copies through the relevant provider.
13. Security and privacy incidents
We use technical and organisational safeguards appropriate to the nature of the Service, which may include encryption in transit and at rest, access controls, credential protection, logging, monitoring, backups, and separation of customer environments. No online service or transmission method is completely secure, and HighFlyer cannot guarantee that unauthorised access, loss, or disruption will never occur.
Customers are responsible for limiting connected-system permissions, maintaining secure devices and messaging accounts, reviewing authorised users, and promptly telling HighFlyer about suspected compromise. HighFlyer may suspend a connection or account to contain a suspected security risk.
If HighFlyer becomes aware of a privacy breach affecting information for which it is responsible, it will assess and respond to the incident and make notifications required by applicable law. Where HighFlyer handles affected information on a customer’s behalf, it will provide reasonable information to help the customer meet its own notification obligations.
14. Your choices and privacy rights
Subject to applicable law, individuals may ask HighFlyer to confirm whether we hold personal information about them, request access to that information, and ask us to correct it. You may also ask a customer organisation to exercise controls over information it submitted to Conductor.
We may need to verify identity and authority before responding. If the information is controlled by a customer, we may refer the request to that customer or respond on its instructions. Access may be withheld where the law permits or requires it.
Customers and authorised users can stop optional marketing from HighFlyer using the unsubscribe method provided, without affecting essential service, billing, or security communications. A customer may disconnect a messaging app or connected service, but doing so may prevent Conductor from functioning. Google Workspace users should follow the separate disconnect, provider-side revocation, and deletion steps in section 7.
If you believe your privacy rights have been breached, contact us first so we can try to resolve the issue. You may also complain to the Office of the Privacy Commissioner.
15. Changes and contact
We may update this policy to reflect changes to Conductor, its providers, our practices, or the law. We will post the updated version here and change the effective date. Where required by law or contract, we will give additional notice of a material change.
Privacy questions, access or correction requests, and complaints may be sent to:
Privacy Officer — HighFlyer Technologies Limited
Suite 15703, Unit A, 26 Hobson Street
Auckland 1010, New Zealand
Email: hello@highflyerglobal.com
Phone: +64 9 883 6868