Privacy Policy — Comprehendly
Provider: UltraDigital Limited (“StepCare”, “Comprehendly”, “we”, “us”)
NZ company number: 9429052702303
Registered address: 15 Bristol Street, Island Bay, Wellington 6023, New Zealand
Effective date: 1 August 2026
Version: 1.1
Comprehendly is a StepCare product. It is operated by UltraDigital Limited. Privacy and security enquiries for Comprehendly use the StepCare addresses below so one team covers the product family.
This Privacy Policy explains how we collect, use, hold, and disclose personal information when you use Comprehendly (StepCare Forms), including our websites, application, voice and phone features, billing, and integration services (the Service).
This policy is designed to meet transparency obligations under:
- New Zealand: Privacy Act 2020 and the Information Privacy Principles (IPPs) — see Schedule B
- Australia: Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) — see Schedule A
Country-specific rights and regulator contacts are in those Schedules. The main body applies to all users unless a Schedule states otherwise.
1. Who we are
| Item | Detail |
|---|---|
| Legal entity | UltraDigital Limited |
| Trading names | StepCare, Comprehendly |
| NZ company number | 9429052702303 |
| Australian ABN | Not registered (update when obtained) |
| Address | 15 Bristol Street, Island Bay, Wellington 6023, New Zealand |
| Privacy / DPO contact | privacy@stepcare.app (StepCare / Comprehendly) |
| Security | security@stepcare.app (StepCare / Comprehendly) |
| General support | hello@stepcare.app |
We provide Comprehendly as a business-to-business platform under the StepCare product family. Organisations (“Customers”, “tenants”) use the Service to capture structured form data, including optional voice-assisted and phone-assisted completion.
2. Roles: controller and processor
| Situation | Our role | Your role (Customer) |
|---|---|---|
| Account registration, billing, support, security, product analytics | Controller (or equivalent under local law) | Business contact / administrator |
| Form submissions, voice sessions, audit exports, embed data about your end users (workers, applicants, residents, clients) | Processor — we process on your documented instructions | Controller — you decide purposes and lawful basis |
Where we act as processor, our Data Processing Agreement applies. You must provide your own privacy notices to individuals whose data you submit.
3. Personal information we collect
3.1 Account and tenant data
- Name, email, job title (if provided)
- Organisation name, tenant settings
- Authentication identifiers (including OAuth profile data from Google where used)
- Role and permission metadata
3.2 Billing data
Processed by Stripe as payment processor: billing contact, payment method tokens, subscription status, invoices. We receive limited billing metadata from Stripe (not full card numbers).
3.3 Service usage and technical data
- IP address, browser/device type, timestamps
- Usage metering (AI minutes, phone minutes, unit consumption)
- Integration API logs (operation, origin, scopes, success/failure)
- Security and audit event logs
- Cloudflare Turnstile challenge signals on public marketing demos (for example phone verification), which may include IP address and browser/device characteristics used to detect bots
- Vercel Analytics on the marketing website (aggregated page and interaction events)
3.4 Form and voice data (processor data)
- Form field values, attachments, submission metadata
- Voice session identifiers and consent records
- Real-time audio sent for transcription and language processing (processed by OpenAI under a no-training arrangement for customer content). Raw audio is not persisted as audio files. Twilio call recording storage is disabled.
- Optional text transcripts where the user or Customer configuration opts in
- Field-level provenance and audit trail events
- Phone numbers and call metadata when the phone channel is used (via Twilio). Population SMS / campaign messaging is not currently offered; when it is, additional consent controls will apply.
3.5 Sensitive information
Customers may submit health, disability, hardship, or other sensitive information about individuals. We treat such data as high-risk and apply additional contractual and security controls. Do not submit sensitive information unless your organisation has a lawful basis and has notified individuals appropriately.
4. How we collect information
| Method | Examples |
|---|---|
| Directly from you | Signup, settings, support tickets, website demo |
| Automatically | Necessary cookies/session storage, logs, metering (see Cookie Policy) |
| From Customers about their users | Form fill, voice capture, phone capture, embed/API |
| Indirectly | Partner embed where the partner passes identifiers or form data — see embed collection notice and Schedule B (IPP 3A) |
5. Purposes of use
We use personal information to:
- Provide, operate, and improve the Service
- Authenticate users and enforce tenant isolation
- Process AI-assisted transcription and field mapping (via OpenAI)
- Deliver SMS one-time codes and phone-based form completion (via Twilio)
- Meter usage, enforce plan caps, and bill via Stripe
- Maintain audit trails and export evidence packs
- Secure the Service, detect abuse, and investigate incidents
- Comply with law and respond to lawful requests
- Send service communications (not marketing without consent)
We do not use Customer form content to train public foundation models.
6. Disclosure of personal information
We may disclose personal information to:
| Recipient | Purpose |
|---|---|
| Sub-processors listed in our sub-processor list | Hosting, AI, telephony, payments, analytics |
| Professional advisers | Legal, accounting, insurance — under confidentiality |
| Authorities | Where required by law or to protect rights and safety |
| Successors | Merger, acquisition, or asset sale — with notice where required |
We do not sell personal information.
7. Overseas disclosure
Personal information may be disclosed to recipients outside New Zealand and Australia. In particular:
- OpenAI processes voice and language prompts in the United States
- Vercel hosts application and CDN infrastructure globally, including the United States
- Stripe processes payments with United States and local entities as applicable
- Primary application databases are hosted on Supabase in Frankfurt (EU) and Sydney (Australia)
We take steps reasonably required under applicable law, including contractual safeguards with sub-processors. See Schedule A (APP 8) and Schedule B (IPP 13).
Primary database residency does not mean that all processing stays in that region. AI language processing (OpenAI, United States) and several supporting services may occur overseas, as disclosed above.
8. Security
We implement technical and organisational measures appropriate to the risk, including encryption in transit, access controls, tenant-scoped data isolation, multi-factor authentication support, and audit logging. No method of transmission or storage is completely secure. See our Security overview.
9. Retention
| Data type | Retention |
|---|---|
| Account data | While account active, then up to 1 year after closure (unless longer retention is required) |
| Billing records | 7 years or as required by tax law |
| Form submissions | Per Customer configuration or until tenant deletion |
| Voice consent records | At least 3 years for audit defensibility (Customer may configure longer) |
| Integration logs | 90 days rolling |
| Security logs | As needed for security and legal requirements |
Customers may export or request deletion subject to the DPA and technical limits. See the Retention schedule.
10. Access, correction, and complaints
Contact privacy@stepcare.app for access or correction requests relating to data we control (account/billing).
For data we process on behalf of a Customer, contact that organisation first; we will assist the Customer as required by our DPA.
Complaints: see Schedule A (OAIC) and Schedule B (Office of the Privacy Commissioner).
11. Notifiable breaches
We maintain procedures to assess and, where required, notify regulators and affected individuals of privacy breaches under:
- Australia: Notifiable Data Breaches scheme — Schedule A
- New Zealand: Notifiable Privacy Breach scheme — Schedule B
Report suspected incidents to security@stepcare.app.
12. AI and automated processing
Our use of artificial intelligence and automated systems is described in the AI processing disclosure.
Summary: Voice and text inputs may be processed by automated systems to suggest form field values. Humans should review outputs before reliance in regulated or high-stakes contexts. We do not make solely automated decisions that produce legal or similarly significant effects about individuals without explicit disclosure.
13. Children
The Service is intended for use by organisations. Customers must not submit children’s personal information without appropriate authority and notices.
14. Changes to this policy
We may update this policy. Material changes will be notified via the Service or email to account administrators. The effective date at the top will change.
15. Contact
privacy@stepcare.app
UltraDigital Limited
15 Bristol Street, Island Bay, Wellington 6023, New Zealand
Schedule A — Australia
A.1 Application
This Schedule applies to personal information handled in connection with individuals located in Australia or where Australian privacy law applies to UltraDigital Limited (including where we have an Australian link under the Privacy Act 1988).
A.2 APP privacy policy content (APP 1.4)
This policy addresses the matters required by APP 1.4, including kinds of information collected, how we collect and hold it, purposes, access/correction, complaints, and overseas recipients (Section 7 and the sub-processor list).
A.3 Sensitive information (APP 3)
Health information and other sensitive information require heightened care. Customers must ensure lawful collection and, where required, consent before submission.
A.4 Overseas disclosure (APP 8)
Before disclosing personal information overseas, we take reasonable steps to ensure recipients handle the information consistently with the APPs, including reviewing sub-processor commitments and contractual terms. Customers remain accountable for overseas disclosures they instruct or enable through their use of the Service.
A.5 Security (APP 11)
We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification, or disclosure. Those steps include technical and organisational measures.
A.6 Automated decision-making transparency (from 10 December 2026)
If we use a computer program to make, or substantially and directly support, decisions that could reasonably be expected to significantly affect an individual’s rights or interests, and personal information about the individual is used in that process, this policy will disclose:
- Kinds of personal information used
- Kinds of decisions made solely by the program
- Kinds of decisions for which the program substantially and directly supports the decision
Current position: Comprehendly primarily assists users to complete forms. It does not typically make eligibility, employment, clinical, or regulatory decisions about individuals without human review. If product features change, this Schedule will be updated before such features are offered.
A.7 Notifiable Data Breaches
Where we are an APP entity and an eligible data breach occurs in relation to information we hold as controller, we will notify the Office of the Australian Information Commissioner (OAIC) and affected individuals as required. For Customer Personal Data we process as processor, we notify the Customer so the Customer can meet its own NDB obligations.
| Regulator | Contact |
|---|---|
| OAIC | https://www.oaic.gov.au — enquiries@oaic.gov.au |
A.8 Complaints
You may complain to us at privacy@stepcare.app. If unresolved, you may contact the OAIC.
Schedule B — New Zealand
B.1 Application
This Schedule applies to personal information handled in connection with individuals located in New Zealand or where the Privacy Act 2020 applies to UltraDigital Limited (including overseas agencies carrying on business in New Zealand).
B.2 Information Privacy Principles
We aim to comply with the 13 IPPs, including purpose limitation, collection transparency, security, access/correction, and limits on disclosure and overseas disclosure.
B.3 Collection notices (IPP 3)
When we collect personal information from the individual, we provide notice at or before collection (see collection notices).
B.4 Indirect collection (IPP 3A)
When personal information about an individual is collected from someone else (for example a partner embed submitting data about a worker or applicant), we take reasonable steps — and require Customers to take reasonable steps — so that the individual is aware of the fact of collection, purposes, intended recipients, our identity and contact details, and their access and correction rights, unless an exception applies.
Partners must not use embed/API unless they have provided appropriate notice to individuals or rely on another valid basis. See the embed collection notice.
B.5 Health information
Customers that are health agencies under the Health Information Privacy Code 2020 remain responsible for HIPC compliance. We support Customers through the DPA but are not a substitute for their health privacy programme.
B.6 Overseas disclosure (IPP 13)
We only disclose to overseas persons where permitted under IPP 13, including comparable safeguards or authorised exceptions. Using overseas technology providers that process information solely on our instructions is addressed in our sub-processor arrangements; if a provider uses information for its own purposes, additional disclosure analysis applies.
B.7 Notifiable Privacy Breaches
If a privacy breach has caused or is likely to cause serious harm, we will notify the Office of the Privacy Commissioner and affected individuals as soon as practicable where we are the agency responsible. For Customer Personal Data processed as processor, we notify the Customer promptly so the Customer can meet its obligations.
| Regulator | Contact |
|---|---|
| OPC | https://www.privacy.org.nz |
B.8 Complaints
You may complain to us at privacy@stepcare.app. If unresolved, you may contact the Office of the Privacy Commissioner.
End of Privacy Policy