Legal
Privacy Policy
Effective Date: 31 August 2026 · Replaces the version dated 28 June 2026
This Privacy Policy explains how Web 3 Limited, trading as Green Weka ("we", "us", or "our"), collects, uses, stores, and protects personal information. We are a New Zealand company and the New Zealand Privacy Act 2020 is our baseline. Because we serve businesses in Australia, the United States, the United Kingdom, Canada, Singapore and elsewhere, we also apply the privacy laws of those countries where they reach us, and we meet the app-store requirements of Apple and Google. Section 11 sets out your rights country by country.
By using the Green Weka app, voice agent, and web dashboard, you agree to the collection and use of information in accordance with this policy.
1. Who We Are and Our Role
Green Weka is a business communication tool. The data flowing through it falls into two groups, and our role is different for each:
- Your account data — your name, contact details, billing and usage information. We decide how this is handled and are the controller (or equivalent term under your local law).
- Your communications data — the calls, voicemails, dictations, emails, internal chat, contacts and business records you feed into the service. This belongs to you. We process it only on your instructions to provide the service, and we act as your processor or service provider. You are responsible for having a lawful basis to collect it, including any notice you must give to the people you communicate with. Our Terms and, where required, a Data Processing Addendum set out our obligations to you.
If you are not a Green Weka customer but you have spoken with, emailed or messaged one, your side of that conversation may have been recorded, transcribed and summarised by the service on that customer's behalf. The customer is responsible for that decision and is your first point of contact for questions or requests about it. We will assist them in responding, and you may also contact us directly (section 15) if you cannot reach them.
2. Information We Collect
To provide our AI-assisted call, email, and business management services, we collect the following types of information:
- Account & Profile Information: When you sign up, we collect your first and last name, email address, mobile number, country, company name, time zone, and current telecommunications provider. If you choose to provide a business location, we use it for local context such as weather and place-name recognition.
- Communications Data: We facilitate and capture your business communications. This includes:
- Audio Recordings & Voicemails: Audio from inbound and outbound calls, dictations, voicemails, and internal voice and video calls between members of your team.
- Transcripts & Text: Transcriptions of your calls, voicemails and dictations, your internal team chat messages, and SMS text messages where your plan includes them.
- Email Data (opt-in): If you connect a Gmail or Microsoft Outlook account, we access and ingest the following data from your inbox: sender and recipient addresses, message subject lines, message body text, timestamps, and the content of attachments (such as PDFs, documents, and images) where relevant to your business. With your authorisation, we can also send new emails and replies from your connected account on your behalf — but only when you explicitly instruct our system to do so. We never send email automatically or without your direction. We do not access draft folders, and we do not access emails sent or received prior to the date you connect your account unless you explicitly request a historical backfill. For full details of how email data from Google accounts is handled, see Section 4 below.
- Contact Book Data: If you grant the app permission to access your device's contacts, we upload contact names, phone numbers, and email addresses. We do not collect contact photos, notes, physical addresses, birthdays, or other fields. This data is used solely to identify callers and message senders and to associate your communication history with the correct person. Contact data is stored securely in our Cloudflare D1 database, encrypted at rest, and is strictly private to your individual account — it is never visible to, shared with, or matched against the data of other Green Weka users. You can revoke contacts access at any time from within the app. When revoked, contacts with no associated communication history are permanently deleted; remaining contacts are retained with their history but are no longer linked to your device's address book.
- Business & CRM Data: If you connect third-party integrations — such as Fergus, Simpro, Xero, HubSpot, Asana, Microsoft To Do or Todoist — we access the job, customer, quote, invoice, task and schedule details needed to enable our system to assist you with operations. We access only what each integration's permissions allow, and you can disconnect any integration at any time.
- Device & Technical Information: We collect device identifiers and push-notification tokens (Apple Push Notification service and Firebase Cloud Messaging) to reliably route incoming calls and alerts to your device, together with app version and basic diagnostic logs needed to keep the service working.
- Device Permissions: The app requests access to your device microphone solely to enable VoIP calling, voicemail recording, and the dictation feature; it requests camera access solely for internal video calls. Neither is used in the background.
3. How We Use Your Information
We use the data we collect solely to provide and improve the Green Weka service. Specifically, we use your data to:
- Route phone calls, voicemails, and messages to your device.
- Transcribe audio and utilise Artificial Intelligence (AI) to generate call summaries, extract actionable tasks, and schedule calendar events.
- Build a searchable, private knowledge base of your business communications (via secure vector embeddings).
- Send you notifications, daily briefings, and alerts regarding your account.
- Process dictations and automatically log site notes, draft quotes or create tasks in your connected business tools.
- Classify inbound emails and internal chat messages, extract job references, and surface relevant information through your dashboard and system.
- Compose and send emails, including replies, from your connected Gmail or Outlook account — but only when you explicitly instruct the system to do so on your behalf.
- Bill you, detect fraud and abuse, keep the service secure, and comply with our legal obligations.
Legal bases (United Kingdom, European Economic Area and similar laws): we process your account data to perform our contract with you and to meet our legal obligations (for example, tax and record-keeping); we process usage and diagnostic data on the basis of our legitimate interest in operating and securing the service; and we process your communications data as your processor, on your instructions. Where we rely on consent — for example, to connect an email account or sync your device contacts — you can withdraw it at any time from within the app.
Strict Access Policy: Your data is processed entirely by automated systems. Green Weka staff do not access, listen to, or read your private communications, transcripts, or emails unless explicitly requested by you for technical support. We do not use your data to train AI models — neither our own nor any third party's — and we do not sell it or use it for advertising.
4. Google API Services — Limited Use Policy
Green Weka's use of information received from Google APIs (including the Gmail API) complies with the Google API Services User Data Policy, including the Limited Use requirements.
Limited Use Declaration: Green Weka's access to Google user data is limited to the practices described in this Privacy Policy. We do not use Google user data for any purpose other than providing and improving the features described herein that are visible to the user.
Specifically, with respect to data obtained via Google APIs, Green Weka:
- Requests only the access necessary: We request read access to your Gmail inbox (
gmail.readonly) to retrieve messages that may relate to your business operations, and send access (gmail.send) so that, at your explicit direction, our system can compose and send emails or replies from your account. Thegmail.sendpermission allows sending only — we never use it to modify or permanently delete your existing emails. Emails are sent solely when you instruct the agent to do so; we do not send email autonomously or without your request. - Does not use data for advertising: Google user data is never used to serve you advertisements, and is never used to build advertising profiles.
- Does not use data to train AI models: Data obtained from your Gmail account is not used to train any general-purpose AI or machine learning model — neither our own nor any third party's. When data is passed to AI sub-processors (such as OpenAI) for the purpose of classification or summarisation, it is processed under enterprise data processing agreements that prohibit use for model training.
- Does not sell or transfer data: Google user data is never sold, rented, or transferred to third parties except to sub-processors strictly necessary to deliver the service (listed in Section 5), and only to the extent required for that purpose.
- Does not allow humans to read your email: Access to your Gmail data by Green Weka personnel is prohibited except in the narrow circumstance where you explicitly request technical support and provide consent for us to review specific messages in order to diagnose a problem.
You may disconnect your Gmail account at any time from the Green Weka dashboard. Disconnecting immediately revokes our access token. Synced email data retained in our systems can be deleted on request — see Section 9 for details.
5. Sub-processors and Third-Party Service Providers
To provide our features, Green Weka relies on carefully selected infrastructure, telephony and AI providers. Your data is shared with these sub-processors only to the extent necessary to perform their specific functions, under contracts that require them to protect it and prohibit them from using it for their own purposes, including AI model training. The home jurisdiction of each provider is shown in brackets; the current list, with processing regions, is maintained on our Trust Centre.
- Telephony & Messaging: Twilio (USA) for call routing, phone numbers and SMS; 2Talk (New Zealand) as our carrier for New Zealand and Australian numbers.
- Transcription & AI: AssemblyAI (USA) for transcription of recorded calls, voicemails and dictations; Deepgram (USA, served from its Australian region) for real-time speech recognition in the voice assistant; OpenAI (USA) for summarisation, intent parsing and embeddings; ElevenLabs (USA) for text-to-speech voice generation.
- Real-time Audio & Video: LiveKit (USA) for the voice assistant and internal team voice and video calls; Fly.io (USA) for hosting the voice assistant.
- Cloud Infrastructure: Cloudflare (USA, global network) for hosting, database and object storage; Amazon Web Services (USA) for sending transactional email; Supabase (USA) for user authentication; Stripe (USA) for payments and billing — we never see or store your full card number.
- Integrations (opt-in only): Google (Gmail, and Google Maps Platform for location and weather context), Microsoft (Outlook and Microsoft To Do), Fergus, Simpro, Xero, HubSpot, Asana and Todoist. We exchange data with an integration only after you connect it, and your use of it is also governed by that provider's own privacy policy. Additional integrations may be offered in future and will be disclosed here when available.
We will give you at least 30 days' notice, by updating this policy and the Trust Centre, before adding a new sub-processor that will handle your communications data.
6. International Transfers
We are based in New Zealand, and most of our sub-processors are in the United States, with some processing in Australia. Your data may therefore be stored or processed outside the country where you are located.
- New Zealand and Australia: we disclose personal information overseas only to providers that are bound by contract to protect it to a standard comparable to the New Zealand Privacy Act 2020 and the Australian Privacy Principles.
- United Kingdom and European Economic Area: New Zealand has been recognised as providing adequate protection for personal data, so transfers to us are permitted. Onward transfers to our sub-processors in the United States are covered by the UK International Data Transfer Addendum or the EU Standard Contractual Clauses, and, where the provider is certified, by the EU-US Data Privacy Framework and its UK extension.
- Canada and Singapore: we take contractual and technical measures so that personal information transferred outside those countries receives a comparable standard of protection, as PIPEDA and the Personal Data Protection Act 2012 require.
7. Data Sharing and Disclosure
We will never sell, rent, or trade your personal information or communication data to data brokers, marketers, or any third party, and we do not share it for cross-context behavioural advertising.
Beyond the sub-processors in Section 5, we disclose personal information only:
- to comply with valid legal process — such as a court order, warrant or subpoena — issued by a court or authority with jurisdiction over us or over the provider holding the data. Where the law allows, we will tell you before we respond and will challenge requests we consider overbroad;
- to our professional advisers (lawyers, accountants, auditors) under confidentiality obligations;
- to a buyer or successor if our business is sold or restructured, in which case this policy continues to apply to your data; or
- with your direction or consent.
Because several of our providers are United States companies, data they hold for us may be subject to United States legal process regardless of where it is stored. We have not received any government request for customer data to date; if that changes we will say so on the Trust Centre.
8. Call Recording and Recording Notices
Green Weka records and transcribes calls on behalf of the customer whose account the call belongs to. The customer is responsible for complying with the call-recording laws that apply to them and to the people they call; those laws depend on where each party to the call is located, and several countries, and several states and territories within Australia and the United States, require every party to be told, or to agree, before a call is recorded.
To help customers comply, the service works like this:
- Every new account starts with a short spoken recording notice (for example, "this call may be recorded") that plays at the start of every inbound and outbound call. Customers can change the wording and the voice.
- A customer who wants to reduce or switch off that notice must first confirm that they understand and will abide by the recording laws for their jurisdiction. We store the date and time of that confirmation, and of each subsequent change, as an audit record.
- Customers can turn recording off entirely for individual contacts, and can choose whether call audio is kept after transcription or discarded.
If you are not a customer and do not wish to be recorded when calling a Green Weka user, tell them at the start of the call. If a recording of you was made unlawfully, contact the customer first; you may also contact us at the address in Section 15.
9. Data Retention and Deletion
You retain full control over your data.
- Communications Data: Call recordings, transcripts, summaries, voicemails, dictations, chat messages and synced emails are retained for as long as your account is active, so that your searchable history keeps working, unless you delete them sooner or turn off audio retention in your settings.
- Manual Deletion: You can delete specific call records, dictations, voicemails, or contacts at any time directly through the Green Weka dashboard.
- Account Deletion: You may request complete account deletion from within the app settings. Initiating this process changes your account status to
DELETION_REQUESTED, which immediately logs you out and queues your account, personal data, and all associated media for permanent removal from our servers within 30 days. Residual copies in backups are removed on their normal rotation. We keep only the minimum billing and tax records the law requires us to hold, for the period it requires. - Email Integration Data: If you disconnect a connected email account (e.g. Gmail), your OAuth access token is immediately revoked. Email messages previously synced to Green Weka are retained in your account unless you explicitly request their deletion. To request deletion of all synced email data, contact us at the address in Section 15. We will complete this within 30 days.
- Contacts Sync Revocation: When you revoke contacts sync permission, contacts imported from your device that have no communication history in Green Weka are permanently deleted. Contacts with existing call, email, or message history are retained but downgraded to system-inferred contacts and are no longer linked to your device address book.
- Contacts Retention Period: Contact data (names, phone numbers, and email addresses imported from your device) is retained for the duration of your active subscription. Upon account deletion, all contact data is permanently removed from our servers within 30 days as part of the standard account deletion process described above. You may also request deletion of all contact data at any time without requiring full account deletion by contacting us at the address in Section 15.
10. Security
We take the security of your data seriously. All communications between your device and our servers, as well as data at rest (including audio archives and databases), are encrypted. We utilise Cloudflare Turnstile to prevent automated abuse during signup and secure, short-lived tokens for all API and Voice Agent authentication. Access to production systems is restricted to the minimum number of people needed to run the service.
OAuth access tokens for connected email and business accounts are stored encrypted at rest and are never logged or transmitted in plain text. Token refresh and revocation are handled automatically in accordance with each provider's security requirements.
Data breaches: if we become aware of a security breach that is likely to cause you harm, we will notify you without undue delay and, where the law requires it, notify the relevant privacy regulator — for example within 72 hours under the UK GDPR, and as required under the New Zealand Privacy Act 2020 and the Australian Notifiable Data Breaches scheme. Where the breach affects communications data we process on your behalf, we will notify you so that you can meet your own obligations. Our security practices are described in more detail on our Trust Centre.
11. Your Privacy Rights
Wherever you are, you can ask us to:
- give you a copy of the personal information we hold about you;
- correct it if you think it is wrong;
- delete it, or delete specific categories of data (such as synced email data) without requiring full account deletion;
- restrict or object to particular processing, or receive your data in a portable format, where your local law provides for it; and
- revoke access to any connected integration at any time from within the app.
To exercise these rights, contact us at the address in Section 15. We will respond within the time your local law requires (usually 20 working days in New Zealand and 30 days elsewhere), and we may need to verify your identity first. We will not discriminate against you for exercising them. Where we hold data as a processor for a customer, we will refer your request to that customer and help them respond.
You also have the right to complain to a privacy regulator if you believe we have not handled your information properly and we have been unable to resolve your concern:
- New Zealand: the Office of the Privacy Commissioner, privacy.org.nz.
- Australia: the Office of the Australian Information Commissioner, oaic.gov.au. We handle personal information in accordance with the Australian Privacy Principles.
- United Kingdom: the Information Commissioner's Office, ico.org.uk. UK GDPR rights of access, rectification, erasure, restriction, portability and objection apply. We will name a UK representative here when we are required to appoint one.
- United States: residents of states with comprehensive privacy laws (such as California) may exercise the rights above. We do not sell personal information and do not share it for targeted advertising, so there is nothing to opt out of.
- Canada: the Office of the Privacy Commissioner of Canada, priv.gc.ca. We handle personal information in accordance with PIPEDA.
- Singapore: the Personal Data Protection Commission, pdpc.gov.sg. We handle personal data in accordance with the Personal Data Protection Act 2012.
12. Cookies and Analytics
Our public website (greenweka.com) uses Google Analytics to understand how visitors use the site; this sets analytics cookies and sends anonymised usage data to Google. The app and dashboard (app.greenweka.com) use only the cookies and local storage strictly necessary to keep you signed in and remember your settings; they contain no advertising or third-party tracking. You can block cookies in your browser settings; the app will still work, though you may need to sign in more often.
13. Children
Green Weka is a business service and is not directed at anyone under 18. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.
14. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our technology, features, or legal requirements. We will notify you of material changes by email or in-app notice at least 30 days before they take effect, and by posting the new Privacy Policy here with an updated "Effective Date".
15. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or your data, please contact us at:
Privacy and security: security@greenweka.com
General support: support@greenweka.com
Web 3 Limited, Mount Maunganui, New Zealand