CostDesk

Legal

Privacy Policy

1. Introduction

This Privacy Policy describes how CostDesk collects, uses, stores, and protects information when you use the CostDesk platform — a SaaS project financial management solution for businesses.

CostDesk is operated by CHIPI LIMITED, registered in New Zealand. This policy complies with the New Zealand Privacy Act 2020 and applicable data protection regulations in the countries where the Service is offered.

By accessing or using CostDesk, you confirm that you have read and agree to this Privacy Policy.

2. Definitions

  • CostDesk / we / us — The CostDesk software platform and its operator, CHIPI LIMITED
  • Organisation — A business or entity that has subscribed to CostDesk (B2B customer)
  • User / you — An individual granted access to CostDesk by an Organisation
  • Account Data — Minimum information required to create and manage an account
  • Business Data — Financial, project, and operational data entered into the system by the Organisation

3. Data Processing Roles

CostDesk acts in two distinct roles depending on the type of data involved:

Data Controller: For account data (email address, authentication credentials) — CostDesk determines the purpose and means of processing.

Data Processor: For business data entered by the Organisation — CostDesk processes this data only within the scope of the software's features. The Organisation is responsible for the lawfulness of its own business data.

4. Data We Collect

4.1 Account Data

Required: Email address — this is the only information CostDesk requires to create and authenticate an account. Without providing an email address, you cannot register for or use the Service.

Optional: Full name, phone number, job title, and other personal details. Collection of this information depends on the Organisation's configuration — the Organisation's Administrator determines which fields are required for users within their organisation.

4.2 Authentication Credentials

CostDesk supports login via email/password and PIN-based authentication. All passwords and PINs are hashed using a one-way algorithm (bcrypt) before being stored in the database. CostDesk does not store passwords or PINs in plaintext.

4.3 Business Data

Includes cost records, revenue entries, project data, purchase orders, financial reports, and operational configurations entered by the Organisation or its Users. This data is owned by the Organisation.

4.4 Technical Data

System access logs, IP addresses, browser type, device information, login timestamps, and feature usage behaviour. This data is collected automatically to support system operations, security, and product improvement.

4.5 Payment Information

Payment processing is handled directly by authorised third-party payment gateway providers. CostDesk does not store full payment card details. CostDesk retains only billing information (name, billing address) and transaction status.

4.6 Data Processed by AI Features

When the Organisation uses AI Features (for example extracting data from invoices), the document content the Organisation provides (including invoice files, images, or text) is sent to a third-party AI model provider to be processed and returned as a result. Data is sent only to deliver the feature at the Organisation's request.

5. Purpose of Processing

Data is collected and processed for the following purposes:

  • Creating, authenticating, and managing user accounts
  • Providing, operating, and maintaining Service features
  • Providing AI and Machine Learning features at the Organisation's request
  • Processing payments and managing subscriptions
  • Technical support and customer service
  • Error detection, system security, and prevention of unauthorised access
  • Aggregate analytics for product improvement
  • Compliance with legal obligations

CostDesk does not use data for advertising purposes and does not sell personal information to any third party.

6. Data Storage and Location

Data is stored on servers located in Singapore, operated by a cloud infrastructure provider. Each Organisation uses an isolated database — data across organisations is not co-mingled and cannot be cross-accessed.

All connections between the browser and the system use HTTPS (TLS). Personally identifiable information (PII) is encrypted at the application layer. Business data is protected by role-based authentication and access control, ensuring only authorised users can access their organisation's data.

Legal basis for storing data outside New Zealand (IPP 12): CostDesk only engages infrastructure providers that have entered into a Data Processing Agreement with protections equivalent to or exceeding the NZ Privacy Act 2020 standard. Prior to transferring data outside New Zealand, CostDesk performs due diligence to ensure appropriate safeguards are in place and maintained.

Customer-hosted deployment option: On request, the database may be deployed on infrastructure managed by the Organisation. In this case, responsibility for infrastructure security and data residency compliance rests with the Organisation. CostDesk's responsibility is limited to the application software.

7. Third-Party Data Sharing

CostDesk may use trusted third-party service providers — including cloud infrastructure, transactional email delivery, and payment processing — to support the operation of the Service. These providers are permitted to process data only within the scope of their authorised role and must maintain equivalent security obligations.

CostDesk does not share data with third parties beyond what is required to operate the Service, and does not sell or use data for advertising.

When the Organisation uses AI and Machine Learning Features, CostDesk engages a third-party AI model provider as a sub-processor. Data sent to this provider is used only to process and return results for the feature at the Organisation's request, within the scope of the data processing agreement with the provider. Processing may take place on servers located outside Singapore, including the United States; CostDesk only engages providers that have committed to data protection at an equivalent or higher standard.

Personal information may be disclosed where required by a lawful request from a competent authority, and only to the extent permitted by law.

8. Data Retention and Deletion

  • During active use: Data is retained in full to operate the Service.
  • After account termination: Business data is retained for up to 30 days to support data export on request, after which it is securely deleted. Technical logs are retained for up to 90 days for security and audit purposes.
  • Data may be retained for longer periods where required by law.

9. User Rights

Depending on the laws applicable in your country, you may have the following rights over your personal data:

  • Access: Request a copy of the personal data CostDesk holds about you
  • Correction: Request that inaccurate information be updated
  • Deletion: Request deletion of your account data, to the extent not in conflict with legal obligations
  • Restriction: Request that processing be paused in certain circumstances
  • Withdrawal of consent: For processing based on consent

To exercise any of these rights, contact us using the details in Section 12. CostDesk will respond within 20 working days of receiving the request.

Note: For business data under the control of the Organisation, Users should contact their Organisation's Administrator directly.

10. Cookies and Sessions

CostDesk uses cookies and session tokens for the following purposes:

  • Session management: Maintaining authenticated state throughout a working session
  • Security: Protection against cross-site request forgery (CSRF)
  • UI preferences: Remembering interface settings within a session

CostDesk does not use tracking cookies and does not integrate third-party advertising cookies. Disabling cookies in your browser will prevent you from logging into the Service.

11. Changes to This Policy

CostDesk may update this Privacy Policy from time to time. For material changes that affect user rights, we will provide notice via registered email or an in-platform notification at least 14 days before the change takes effect.

The current version of this Privacy Policy is always available at costdesk.co/privacy.

12. Contact and Privacy Officer

For any questions, data access requests, or privacy concerns, please contact:

CHIPI LIMITED — Privacy Officer
Silverdale, Auckland, New Zealand
Email: [email protected]

CostDesk will respond within 20 working days of receiving your request.

13. Legal Basis

This Privacy Policy is built on:

  • New Zealand Privacy Act 2020 (governing CHIPI LIMITED's operations)
  • Internationally recognised data protection principles (GDPR-aligned)

Where conflict exists between applicable legal frameworks, CostDesk applies the higher standard of protection for the User.

Version: 1.1 · Effective date: 02 April 2026 · Last updated: 09 July 2026

Operated by: CHIPI LIMITED, Silverdale, Auckland, New Zealand

Contact: [email protected] · Website: costdesk.co