The Gap Privacy Policy
Last updated: 7 September 2026
Previous version: 10 December 2024
At The Gap, we take privacy seriously. This Privacy Policy explains what personal information we collect when you use our website and services, how we use it, and what rights you have.
It applies across all websites we own and operate, and all services we provide, including The Gap Portal, The Gap App, Scribe, The Gap Academy, educational events, implementation programmes and general support (our Services).
This Policy is governed by New Zealand law, and by the EU General Data Protection Regulation (Regulation 2016/679) and the UK General Data Protection Regulation (together, the GDPR).
Defined terms have the same meaning as in our Terms of Service, which should be read together with this Policy and our Data Processing Addendum (if it applies to you).
Our Services are not intended for children under 16, and we do not knowingly collect data relating to children.
Who we are
We, our and us mean The Gap 2014 Limited. Our headquarters are in Mount Maunganui, New Zealand. We provide a web application, educational events and educational tools that our Members use to support the delivery of business advisory services to their clients.
Our role, and yours
Our role depends on whose information is involved.
We are a Controller of your personal data as a Member — the information we hold about you to run your account and our relationship with you. That means we are responsible for processing it lawfully.
We are a Processor of your Team Users' and your clients' personal data. In that relationship, you are the Controller.
If you are a Member, you are responsible for making sure that any personal information you collect from your Team Users, clients or client contacts (Clients) is collected in line with applicable data protection law. This includes getting any consent you need before giving that information to us.
You must also make sure your Clients know that The Gap will process their personal data as a Processor on your behalf, under this Policy and our DPA. This covers documents and files uploaded to the Platform, and meeting recordings and transcripts created using Scribe. You remain the Controller of that content. Where the GDPR applies, our DPA sets out our responsibilities.
Client Organisations using our Services alongside a Member account control certain aspects of their own data within the client hub. Client Users with an Admin role can manage their client hub account and add other Client Users. In that context the Client Organisation is a Controller and The Gap remains the Processor.
Meeting Participants. When Scribe records a meeting, it may capture information about people who are not Members, Team Users or Client Users — for example, a third-party adviser attending a client meeting. We call these people Meeting Participants. We process their information only as a Processor, on the instructions of the Member who arranged the meeting. That Member is responsible for telling participants that the meeting is being recorded and for obtaining their consent.
What personal data do we collect?
Information you give us
Your information. We store any information you knowingly give us, including your name, email address and job title, and anything else you choose to provide or enter into the Platform.
Team User information. When you add or manage Team Users, we store their name, email address and job title.
Your client information. To provide the Services, we store the personal data you give us about your clients, including their names and email addresses, and anything else you enter into the Platform.
Information from Client Organisations. When a Client Organisation adds or manages Client Users, we store their names and email addresses.
Information from your calendar
If you connect your Google or Microsoft calendar, we sync your upcoming meetings so you can turn them into Gap Meetings, and so Scribe can join automatically where a meeting has a Teams, Google Meet or Zoom link.
We request read-only access. We cannot create, edit or delete anything in your calendar.
| Provider | Permissions we request | What that allows |
|---|---|---|
calendar.events.readonly · userinfo.email |
Read your calendar events. Identify which Google account you connected. | |
| Microsoft | Calendars.Read · offline_access · openid · email |
Read your calendar events. Keep the connection active without asking you to sign in each time. Identify which Microsoft account you connected. |
From your calendar we receive the event title, date, time and duration, the location, the online meeting link, the attendee list including attendee email addresses, and the event description.
You stay in control. You can disconnect your calendar at any time from your account settings. We never store your Google or Microsoft sign-in tokens ourselves. Disconnecting deletes the calendar connection and the tokens held by our calendar provider, stops all syncing, and deletes the calendar data we hold, apart from events you have already turned into Gap Meetings, which stay in your meeting records until you delete them. You can also remove The Gap from your connected apps in your Google or Microsoft account.
Information from meetings
When you use Scribe, we process information about the meeting and the people in it.
Online meetings. Scribe joins as a visible participant named "Scribe", displaying a "Transcribing" indicator. Someone in the meeting must admit it before it can join, and any participant can remove it at any time. Our meeting capture provider, Recall.ai, records the meeting audio and video and produces the transcript, along with the participant list and speaker labels.
In-person meetings. When you start Scribe on your own device, we record the meeting audio and use Amazon Transcribe to produce the transcript.
What happens to the recording. The transcript is what we keep and use. Recordings are held only for a short period (7-14 days) so we can investigate technical problems, and are then deleted automatically. In-person recordings are held in our own storage; online recordings are held by Recall.ai.
We also keep a record of the confirmations you give us in the Platform about obtaining participant consent.
Information we collect automatically
When you use our website or Services, we automatically receive information from your browser, using cookies and similar technologies. This includes your device, IP address, browser type, the site you came from, the pages you visit and how long you spend on them. We use it to understand how our website and Services are used, and to improve them.
Information from third parties
Most information we collect comes directly from you. Sometimes we collect information about you from other sources, such as publicly available material or trusted partners including our marketing partners. We use it to supplement what we already hold, to improve and personalise our Services, and to check the information you have given us.
Our legal bases
Where we collect personal data as a Controller, we process it only:
- to perform our contract with you;
- where we have a legitimate interest that is not overridden by your rights;
- to meet a legal obligation; or
- with your consent.
Where we act as a Processor, we process personal data on the Member's documented instructions, and the Member is responsible for the legal basis.
How we use your personal data
To provide our Services. We need your name and email address to give you access to the Platform and deliver the Services you have subscribed to.
To support you. We use your information to help resolve technical and other issues by email, phone or support ticket.
To communicate with you. We may send you notifications about new or updated services, invitations to training webinars and events, marketing communications, requests for feedback or research participation, and information you have asked for.
To improve our Services. We track how our Services and website are used so we can see what works, what needs improvement, and how to optimise your experience. We do not use your content to train artificial intelligence models.
To market to you. We use your information to send marketing communications. We may obtain your name, email address and place of employment from publicly available sources and contact you where we have a legitimate interest. You can unsubscribe at any time.
To monitor usage. We monitor use of the Platform to make sure Members are getting value from our support services, to protect our intellectual property, to check compliance with our Acceptable Use Policy, and to understand which features matter most.
AI and your information
In short: we use AI to provide tools to facilitate end-to-end delivery of advisory meetings. Your content is never used to train AI models, and is never shared with model providers for their own purposes.
Our Services use artificial intelligence to aid meeting preparation, to generate meeting deliverables and coaching feedback, and to build client context for future meetings from your meetings and the information you enter into the Platform.
Which AI we use. We use Anthropic's Claude models through Amazon Bedrock, a service operated by Amazon Web Services, to generate pre-work summaries, meeting minutes and other deliverables. Speech-to-text is handled by Recall.ai for online meetings and by Amazon Transcribe for in-person meetings.
Where AI processing happens. Generation of your deliverables happens in Sydney for the AU/NZ environment, London for the EU/UK environment. Speech-to-text for in-person meetings also happens in the above regions. Speech-to-text for online meetings is handled by Recall.ai, in Germany for the EU/UK environment and in the United States for the AU/NZ environment.
We do not train AI models on your information. We do not use your content — including recordings, transcripts, documents, calendar data or AI-generated outputs — to train, fine-tune or improve any AI or machine learning model, whether ours or a third party's, and we require our providers to do the same. Amazon Bedrock does not use the information we send it to train models, and does not share it with the model provider. We have configured our AWS account so that content processed by Amazon Transcribe is not used for service improvement.
AI features are part of the Services. AI processing is integral to how the Platform works and cannot currently be switched off. We rely on the performance of our contract with you as the basis for this processing, not consent.
AI output should always be reviewed. AI-generated content can contain errors or omissions. It is not professional advice, and it is not a substitute for your own judgement. You remain responsible for reviewing anything you rely on or give to a client.
How we handle Google and Microsoft data
Google. The Gap's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular, we do not use data obtained through Google Workspace APIs to develop, improve or train generalised or non-personalised artificial intelligence or machine learning models. Data accessed through Google APIs is used solely to provide and improve the calendar and meeting features you have authorised, is never sold, and is never used for advertising.
Microsoft. We do not use data obtained through Microsoft 365 APIs to develop, improve or train generalised or non-personalised artificial intelligence or machine learning models. Data accessed through Microsoft APIs is used solely to provide the calendar and meeting features you have authorised.
We share calendar data with Recall.ai, our meeting capture provider, only to the extent needed to sync your calendar and allow Scribe to join meetings you have chosen to record. Recall.ai processes this data on our instructions and may not use it for any other purpose.
Meeting recording and consent
In short: recording laws vary by country and by state. The Member who arranges a meeting is responsible for obtaining consent from everyone in it.
Recording and transcribing a conversation is regulated differently in different places. Some Australian states require the consent of every participant.
If you are a Member, you must obtain consent from all participants before recording or transcribing a meeting, and you must comply with the law that applies to you. We provide tools to help — Scribe appears as a visible, named participant in online meetings and can be removed by anyone, and we display reminders in the Platform — but these do not replace your obligation to obtain consent.
Meeting Participants who do not wish to be recorded should raise this with the meeting organiser, or remove Scribe from the meeting.
Where do we store your personal data?
Your data is stored in the region matching your Platform environment. You are allocated to an environment based on your location when your account is created.
| AU/NZ environment | EU/UK environment | |
|---|---|---|
| Platform data, documents, transcripts, AI outputs | AWS, Sydney | AWS, London |
| AI generation (Amazon Bedrock) | Sydney | London |
| In-person meeting audio and transcription (Amazon Transcribe, AWS S3) | Sydney | London |
| Online meeting capture, transcription and calendar sync (Recall.ai) | United States (Oregon) | Frankfurt |
| Transactional email (Amazon SES) | Sydney | London |
We also use customer relationship management, marketing automation, analytics and email tools to communicate with you and understand how our Services are used. Some of these process personal data outside your region. Our full list is at https://thegaphq.com/sub-processors
Do we share your personal data?
We share personal data only with:
- Service providers and partners who help us deliver, support or promote our Services. They may use the data only as needed to assist us, and only in line with this Policy. Our list of sub-processors, with the nature and purpose of their processing, is at www.thegaphq.com/sub-processors.
- Regulators, law enforcement, government agencies and courts, where necessary to comply with the law or to establish, exercise or defend legal rights. We will tell you where we can.
- A buyer or potential buyer, and their advisers, in connection with a merger, acquisition or sale of part of our business.
- Others, with your consent.
We do not sell your personal data.
International transfers
We are based in New Zealand, and some of our providers are based overseas, so your personal data may be transferred outside the country you are in.
If you are in the United Kingdom or the European Economic Area, we transfer personal data only to countries the European Commission recognises as providing adequate protection — including New Zealand — or where a secure transfer mechanism is in place, such as the EU Standard Contractual Clauses or the UK International Data Transfer Addendum.
If you are in Australia or New Zealand and use our online meeting features, your recordings, transcripts and calendar data are processed in the United States by Recall.ai under contractual protections requiring them to handle it only on our instructions and to a comparable standard.
How long do you keep my information?
In short: your meeting records last as long as you need them, and you can delete them yourself at any time. Everything else we keep only for as long as we have a reason to.
We retain personal data for as long as we need it to provide the Services and deliver what you have asked for, to meet our legal obligations, to resolve disputes, to enforce our agreements, and for other legitimate and lawful business purposes.
Those needs differ across the different parts of our Services, so our actual retention periods vary. What we take into account includes the sensitivity of the information, what you would reasonably expect, whether you have tools to delete the information yourself, our legal and contractual obligations, and how long the information remains useful for the purpose it was collected for.
Some examples of how this works in practice:
- Your meeting workspaces are a record of the meeting, in the same way an accountant keeps a file on a matter. Because you are the Controller of that record, you decide how long to keep it. We keep meetings, transcripts and AI outputs for as long as your subscription is active, and for a limited period afterwards so you can pick up where you left off if you return.
- Recordings are kept only briefly (7-14 days), so we can investigate technical problems, and are then deleted automatically. The transcript is what we keep.
- Calendar events you have not turned into a meeting are deleted after 60 days. If you disconnect your calendar, we delete your calendar data and revoke your access tokens straight away, apart from meetings you have already created.
- Billing records are kept for as long as tax and financial reporting law requires.
You can delete your information yourself. You can delete any meeting, transcript or AI output from the Platform at any time, and disconnect your calendar whenever you choose. You can also ask us to delete your personal data.
What rights do you have?
You have a number of rights over your personal data. You can make a request verbally or in writing using the contact details at the end of this Policy. We respond within 30 days. There is no charge unless a request is clearly unfounded or excessive. We may ask you to verify your identity first.
Right of access. You can ask for a copy of the personal data we hold about you, confirmation that we are processing it, and further information about that processing.
Right to rectification. You can ask us to correct inaccurate data and complete incomplete data. Members can edit some of their own information in the Platform, including their name and email address. Some of this may be restricted to your firm's Platform Administrator.
Right to erasure. You can ask us to delete the personal data we hold about you. You can also delete meetings, transcripts and AI outputs yourself in the Platform, and disconnect your calendar at any time.
Right to restrict processing. You can ask us to stop using your personal data in certain circumstances, while we continue to store it.
Right to data portability. You can ask for your personal data in a structured, commonly used, machine-readable format.
Right to object. You can object to processing based on legitimate interests or direct marketing. If you ask us to stop using your data for direct marketing, we will suppress your details from our marketing lists. Every marketing email includes an unsubscribe link.
If you are a Meeting Participant and want to exercise a right over a recording or transcript, contact the Member who arranged the meeting. They are the Controller of that record. If you contact us instead, we will pass your request to them.
How we keep your personal data secure
We are committed to protecting your personal data and have technical and organisational measures in place to keep it secure. These include encryption of data in transit and at rest, access controls limiting access to authorised personnel, secure credential storage, and monitoring of our systems. We take all reasonable steps to protect our Services from unauthorised access, modification or disclosure.
Changes to this Privacy Policy
We may update this Policy from time to time. The date of the last update is at the top. The use we make of personal data is subject to the Policy in effect when it was collected.
We will tell you about changes to this Policy, and to how we use personal data, by email and/or by posting an announcement in the Platform or on our website before the changes take effect. You are bound by changes once you use our website or Services after they have been announced.
UK Data Representative
If you need to discuss your data privacy or exercise your rights under UK law, contact our UK Data Representative at debbie@thegaphq.com.
Questions or concerns
We have appointed a data protection officer. If you have questions or concerns about our personal data practices, or you are outside the UK and want to exercise your privacy rights, contact:
- Jeremy Caughey
- dpo@thegaphq.com
- Data Protection Office, The Gap, PO Box 10453, Bayfair 3152, New Zealand
- 0800 275 848 (NZ) · 1800 839 246 (Aus) · +64 7 574 3474 (Int'l)
You also have the right to complain to your local Data Protection Authority — the Office of the Privacy Commissioner in New Zealand, the Information Commissioner's Office in the United Kingdom, or your national supervisory authority in the European Union. If you are based elsewhere, you can complain to the supervisory authority in your country or to the New Zealand Office of the Privacy Commissioner.
How to contact us
- Email hello@thegaphq.com
- Call 0800 275 848 (NZ) · 1800 839 246 (Aus) · +64 7 574 3474 (Int'l)
- Write to The Gap, PO Box 10453, Bayfair 3152, New Zealand
- Complete the enquiry form on our website
Members can also contact us by submitting a Support Ticket.