Skip to content

Legal & policies

Data processing terms

What we commit to when we hold personal information for you. These terms form part of your agreement and are the document your privacy officer will want.

Last updated 7 September 2026

These terms apply where PaaS HQ Limited processes personal information on behalf of an institution using Pallara. They form part of the terms of service. Terms defined there have the same meaning here.

1. Roles

Under the Privacy Act 2020, you are the agency in respect of learner and staff information held in your tenant, and we hold it as your service provider under section 11. We are not the agency for that information and we do not determine the purposes for which it is collected.

Where an institution is subject to the Privacy Act's information privacy principles, nothing in these terms displaces those obligations.

2. Processing on your instruction

We process personal information only:

  • to provide, secure and support the service;
  • on your documented instructions, including instructions given through the platform itself — enabling a module, configuring an integration, or a staff member submitting a return; and
  • where required by New Zealand law, in which case we will tell you unless the law forbids it.

We will tell you if in our opinion an instruction breaches the Privacy Act 2020.

3. Scope of processing

ItemDetail
Subject matterProvision of the Pallara platform.
DurationThe subscription term, plus the export and deletion periods in clause 8.
Nature and purposeHosting, storage, retrieval, analysis, transmission, backup and deletion in order to deliver the service and prepare statutory returns.
Categories of personLearners, applicants and enquirers; teaching and administrative staff; emergency contacts; agents, employers and other stakeholders the institution records.
Categories of informationIdentity and contact details, National Student Number and IRD number, demographic information including ethnicity, iwi affiliation and disability, enrolment and academic records, attendance, financial records, pastoral and wellbeing information, communications, and system audit records.

4. Confidentiality and personnel

We limit access to personal information to personnel who need it to perform their duties. Those people are bound by confidentiality obligations that survive the end of their engagement, and access is role-based and logged.

5. Security

We maintain technical and organisational measures appropriate to the risk, described on the security page. In summary: database-enforced tenant isolation, encryption in transit and at rest for credentials and integration secrets, role-based access control, append-only tamper-evident audit logging, and regular backups.

We will not materially reduce these measures during your term.

6. Sub-processors

You authorise us to engage the sub-processors listed at pallara.app/sub-processors. Each is under a written contract imposing data protection obligations no less protective than these terms, and we remain responsible for their performance.

We will give at least 30 days' notice before adding or replacing a sub-processor that processes personal information. If you reasonably object on data protection grounds within that period, we will work with you to find an alternative; if none is available you may terminate the affected part of the service without penalty for the remainder of its term.

7. Overseas processing

Some sub-processors process personal information outside New Zealand. This is disclosed per provider on the sub-processors page. Where we send personal information overseas we take reasonable steps under information privacy principle 12 to ensure the recipient is subject to comparable safeguards, through contractual protections.

8. Return and deletion

For 60 days after termination we make your tenant data available for export in a machine-readable format. No later than 90 days after termination we delete it from active systems. Backup copies age out on their normal retention cycle and are not restored for any other purpose.

We will certify deletion in writing on request.

9. Privacy requests

Where we receive a request from an individual about information we hold for you, we will not respond substantively; we will refer them to you and tell you promptly. We will give you reasonable assistance to respond, including through the platform's own search, export and correction tools.

10. Breach notification

If we become aware of a privacy breach affecting your data we will notify you without undue delay and in any case within 72 hours of becoming aware, with the information we hold at that point: what happened, the categories and approximate number of people and records affected, the likely consequences, and what we are doing about it. We will update you as we learn more, and assist your assessment and any notification to the Office of the Privacy Commissioner and affected individuals.

11. Information and audit

We will make available the information reasonably necessary to demonstrate compliance with these terms, and respond to reasonable written security questionnaires no more than once in any 12 month period. Where you require an on-site or third-party audit, the parties will agree scope, timing and cost in advance, and it will be conducted so as not to disrupt the service or other customers.

12. Artificial intelligence

We process information through AI features on your institution's instructions. Depending on the enabled feature, this may include questions, course content, attachments and selected records, which can contain personal information. Redaction is applied in supported workflows; not all content sent to a model is de-identified.

We will not use your personal information to train or fine-tune models or permit our sub-processors to do so. Where your institution connects a provider under its own account, you are responsible for approving that provider's terms and data-handling settings.

Feature-specific data handling is described in the privacy policy. Our listed model providers appear on the sub-processors page. Changes to this published description do not override protections in an existing customer agreement.

13. Precedence

Where these terms conflict with the terms of service in respect of the processing of personal information, these terms prevail.