SoluPrivacy Policy
Legal

Privacy Policy

This Privacy Policy explains how Solu Limited (“Solu”, “we”, “us”) collects, uses, discloses, and safeguards your personal information in accordance with the New Zealand Privacy Act 2020 and the Information Privacy Principles (“IPPs”) contained therein.

Last updated: April 2026

01

Who We Are

Solu Limited is a New Zealand registered company providing a digital end-of-life planning platform (“Solu” or the “Service”). Our platform enables users to organise, document, and share their end-of-life wishes, assets, contacts, and instructions with chosen executors and family members.

Solu is the “agency” for the purposes of the Privacy Act 2020. References to “you” or “user” refer to the person who creates and manages a Solu account.

02

Data We Collect

We collect personal information in the following categories:

  • Account information: name, email address, and password hash at registration.
  • Plan content: any information you choose to record in your Solu Plan, including assets, instructions, preferences, and wishes.
  • Third-party contact details: names, email addresses, phone numbers, and roles of executors, family contacts, and professional advisors you nominate within your plan (see Section 04).
  • Subscription and payment information: billing details processed securely via Stripe; we do not store raw card numbers.
  • Technical and usage data: IP address, browser type, device identifiers, and anonymised event logs collected automatically to maintain service reliability and security.

We collect only the minimum personal information necessary for the purposes described in this policy (IPP 1).

Data Usage Summary

Data CategoryCollection MethodPurposeProcessing Trigger
Account & IdentityDirect (from you)Create and maintain your Solu accountAccount registration
Plan ContentDirect (from you)Store and organise your end-of-life planPlan creation / editing
Third-Party ContactsIndirect (via User)To notify executors/contacts of their role and share the Solu PlanUpon user-initiated Share trigger
Usage DataAutomatic (system logs)Improve service reliability and detect errorsContinuous, anonymised
Payment DataDirect (via Stripe)Process subscription billingCheckout / renewal
03

How We Use Your Information

We use personal information to:

  • Create, maintain, and secure your Solu account.
  • Store and display your Solu Plan to you during active sessions.
  • Share your plan with nominated third parties when you initiate the Share trigger.
  • Process subscription payments and send billing-related communications.
  • Send transactional notifications (e.g., account confirmations, security alerts).
  • Detect, investigate, and prevent fraudulent or unlawful activity.
  • Improve the reliability, performance, and safety of the Service using anonymised aggregate analytics.

We do not sell, rent, or trade your personal information to third parties. We do not use your information for behavioural advertising or profiling.

04

Third-Party Contacts & IPP 3A

We collect certain personal information about third parties where provided by a user (such as nominated executors, family contacts, or professional advisors). We collect only the information necessary to identify and contact the relevant person for the purposes of the Solu Plan.

This practice constitutes indirect collection under Information Privacy Principle 3A of the Privacy Act 2020. We handle such information in full compliance with IPP 3A, including our notification obligations described below.

We take reasonable steps to notify those individuals at the point of plan sharing. In most cases, we will not notify third parties at the time their details are entered, as this may reveal private planning information about the user. We may use this delayed notification approach to preserve user confidentiality during the sensitive planning phase.
We do not use third-party contact details provided by our users for marketing or any purpose other than facilitating the Solu Plan as directed by the user.

Third parties whose details appear in a Solu Plan retain full rights under the Privacy Act 2020, including the right to request access to information held about them and to request correction of that information. Such requests should be directed to privacy@solu.co.nz.

05

Storage & Security

All data is stored on infrastructure located within the New Zealand / Australia (ANZ) region. We do not transfer personal information outside this region except where required by law or with your explicit consent.

We apply the following technical and organisational safeguards:

  • Encryption at rest: AES-256 encryption on all databases and storage volumes.
  • Encryption in transit: TLS 1.2 or higher on all connections.
  • Access controls: Principle of least privilege; staff access requires multi-factor authentication and is logged and audited.
  • Backup integrity: Encrypted off-site backups with a standard 30-day rotation cycle (see Section 06).
  • Incident response: We will notify affected users and the Office of the Privacy Commissioner of any notifiable privacy breach within 72 hours of becoming aware.

No method of transmission or storage is 100% secure. We continually review and update our security practices proportionate to the sensitivity of the information we hold.

06

Deletion & Backup Window

When you (or a user) request to delete an account or specific contact details, your data is removed from our active production systems immediately. Please note that for security and disaster recovery purposes, it may take up to 30 days for data to be fully cleared from our encrypted, off-site backups in accordance with our standard rotation cycle.

To request deletion of your account or specific data, please email privacy@solu.co.nz with the subject line Deletion Request. We will confirm completion of the active-system deletion within 5 business days.

07

Cookies & Tracking

We use strictly necessary session cookies to maintain authenticated sessions. We do not use third-party advertising cookies or cross-site tracking technologies.

We use a single first-party analytics tool with IP anonymisation to understand aggregate usage patterns. No personally identifiable event data is shared with third-party analytics providers.

08

Data Retention

We retain personal information only as long as necessary:

  • Active accounts: for the duration of your subscription and a 90-day grace period following cancellation.
  • Billing records: 7 years, as required by the New Zealand Tax Administration Act 1994.
  • Security logs: 12 months, then permanently deleted.
  • Third-party contact details: deleted from active systems upon account deletion or upon written request; backup window applies (Section 06).
09

Your Rights Under the Privacy Act 2020

Under the New Zealand Privacy Act 2020, you have the right to:

  • Access the personal information we hold about you (IPP 6).
  • Correct any personal information that is inaccurate, incomplete, or misleading (IPP 7).
  • Know why we are collecting your information, how it will be used, and to whom it may be disclosed (IPP 3).
  • Request deletion of your information, subject to our lawful retention obligations.
  • Complain to the Office of the Privacy Commissioner if you believe we have breached the Privacy Act 2020: privacy.org.nz.

To exercise any of these rights, contact us at privacy@solu.co.nz. We will respond within 20 working days as required by the Act.

10

Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be notified to you by email at least 14 days before they take effect. Continued use of the Service after the effective date constitutes acceptance of the revised policy.

Archived versions of this policy are available upon request to privacy@solu.co.nz.

11

Contact Us

For all privacy enquiries, access requests, correction requests, or complaints, please contact our Privacy Officer:

Solu Limited

Privacy Officer

privacy@solu.co.nz

New Zealand registered company. We aim to respond to all privacy requests within 20 working days.

© 2026 Solu Limited. All rights reserved.