Discovery Works Limited ("Discovery Works", "we", "our", "us") provides structured business discovery software for office technology vendors, dealers and technology service providers. This Privacy Policy applies to our website at discoveryworks.ai (the "Website"), the Discovery Works software platform (the "Service"), and our related business activities.
In providing the Website and Service, we handle information about identified or identifiable individuals ("Personal Information"), including information about Website visitors, users of the Service and people who participate in business conversations recorded or transcribed by our customers.
This Privacy Policy explains how we collect, use, disclose, retain and protect Personal Information. Use of the Website or Service is not itself treated as consent to processing. Where we rely on consent, we obtain it separately and it may be withdrawn at any time, subject to law and any processing already carried out.
We comply with the New Zealand Privacy Act 2020 and with other privacy and data-protection laws that apply to our activities ("Applicable Privacy Laws"). References in this Policy to particular rights or obligations apply only where the relevant law applies.
Unless defined here, capitalised terms have the meaning given in our Terms of Service.
We act as a controller for Personal Information we collect and use for our own business purposes, including operating the Website, administering accounts, providing support, arranging demonstrations, billing, securing and improving the Service, and business-to-business marketing. In those circumstances, we decide why and how the Personal Information is processed.
We act as a processor for content that our customers input into, upload to, or connect to the Service, including meeting transcripts, uploaded audio, analysis derived from meeting content, and the client records to which they relate ("Customer Data"). Our customer is normally the controller of that information, and we process it on the customer's documented instructions to provide the Service.
For paid pilots and subscriptions, a data processing agreement ("DPA") will be entered into where required by Applicable Privacy Laws or reasonably requested by a customer. The DPA governs our respective data-protection obligations and takes precedence on data-protection matters if it conflicts with this Policy or our Terms of Service.
The Service is designed to be used alongside a recorded and transcribed business meeting, typically a discovery conversation between one of our customer's account managers and a client organisation. Where a customer connects its Microsoft 365 environment, we retrieve the transcript after the meeting has ended using permissions granted by the customer's administrator and the signed-in user's Microsoft account. Customers may also upload a transcript or, where that feature is enabled, an audio recording.
We do not start, stop or control recording or transcription. Those functions are controlled by the meeting platform and the customer's own settings. We can retrieve only a transcript that the customer's environment has already produced, or process content the customer has chosen to upload.
Transcripts processed by the Service are normally speaker-attributed, meaning that each contribution is associated with a named participant. This enables the Service to distinguish what an account manager asked from what a client representative answered, and to associate statements with the relevant speaker. A transcript without reliable speaker attribution may not support the intended analysis.
A transcript will usually contain Personal Information about people who are not our customers and have not interacted with us directly, most often personnel of the client organisation participating in the meeting. That information may include a participant's name, job title, employer, voice-derived text, opinions, and statements about their organisation's circumstances, plans and priorities.
For this information, our customer is normally the controller and Discovery Works is the processor. Our customer is responsible for:
ensuring that recording, transcription, disclosure and subsequent processing are lawful under all Applicable Privacy Laws, recording laws, employment or workplace-monitoring requirements, and relevant internal policies;
giving participants clear notice that the meeting is being recorded and transcribed and that the transcript will be processed by a third-party service provider on the customer's behalf;
obtaining any consent or authorisation required by law; and
ensuring that it has the right to provide the transcript and its contents to us for processing.
We require customers to give these assurances in our Terms of Service.
If you believe your Personal Information is contained in a transcript processed through the Service and you wish to access, correct or delete it, the fastest route is usually to contact the organisation that arranged the meeting because it controls that data. You may also contact us at hello@discoveryworks.ai. We will assist by acting on our customer's instructions or directing you to the relevant customer, and we will explain which applies.
name, email address, company name, job title and other business contact details;
account registration, authentication and multi-factor authentication information;
details provided when booking a demonstration or requesting information;
billing and transaction information; and
communications with us, including support requests and feedback.
usage and telemetry information, including IP address, browser and device information, pages or features used, and access times;
application and security logs, including sign-in events, errors and administrative actions; and
cookies and similar technologies as described in Section 9.
meeting transcripts and any audio recordings uploaded for transcription;
structured analyses, summaries, opportunity assessments and portfolio intelligence derived from meeting content;
client organisation and contact records created by customers;
calendar and online-meeting metadata retrieved from a connected Microsoft 365 account, limited to what is reasonably needed to identify the correct meeting and transcript; and
authentication tokens and connection information required to maintain authorised integrations, stored using encryption and access controls.
We may obtain business contact information from publicly available sources, professional networks, event organisers, referrals and business partners to identify organisations that may benefit from the Service. You may ask where we obtained your information, request access or correction, or object to further marketing by contacting us.
The Service is not designed for the intentional processing of health records, payment-card information, government identification numbers, account passwords or authentication secrets, or other highly sensitive Personal Information unrelated to the business discovery purpose. Customers must not intentionally upload or solicit that information unless we have expressly agreed in writing that the Service may be used for that purpose. Customers should promptly remove sensitive information that is included inadvertently.
Where the EU or UK GDPR applies, we rely on the following lawful bases, as appropriate:
performance of a contract - providing and administering the Website and Service;
legitimate interests - securing, supporting and improving the Service, managing our business, and conducting proportionate business-to-business marketing;
legal obligation - meeting tax, accounting, regulatory and law-enforcement obligations; and
consent - where consent is required, including for certain cookies or marketing communications.
Where we act as processor, our customer is responsible for identifying the lawful basis for the underlying processing. If you are in the EU or UK, you may have a right to object to processing based on legitimate interests.
We use Personal Information to:
provide, operate, secure, maintain and administer the Website and Service;
create and administer accounts and authenticate users;
retrieve, transcribe and analyse meeting content to generate the outputs subscribed to by customers;
provide support and send service, security, billing and administrative notices;
communicate about our products and services where permitted. Marketing recipients may opt out at any time using the unsubscribe mechanism or by contacting us; opting out does not stop service, security or billing communications;
measure usage, test functionality and improve the reliability, usability and security of the Service;
prevent, investigate and respond to fraud, misuse, security incidents or unlawful activity;
establish, exercise or defend legal claims; and
comply with legal and regulatory obligations.
We do not use Customer Data to train our own general-purpose artificial intelligence models. We select and configure AI sub-processors so that Customer Data is not used to train their general-purpose models, except where a customer expressly authorises a different arrangement in writing.
We may create statistical, technical and usage information that has been irreversibly de-identified and aggregated so that it cannot reasonably identify an individual or customer. We may use that information to operate, secure and improve the Service. It is not used to reconstruct customer content or train general-purpose AI models.
We use carefully selected service providers to operate and support the Website and Service. Depending on the features used, these providers may include:
cloud hosting, database, storage and authentication providers;
artificial intelligence processing providers;
speech-to-text providers where audio transcription is enabled;
website hosting and content-delivery providers; and
business communications, support and scheduling providers.
Some of these providers process Personal Information or Customer Data on our behalf. We require providers that process Personal Information for us to protect it appropriately, use it only for the agreed purposes, and comply with applicable contractual and legal requirements.
Paid customer environments are provisioned in the United States unless the applicable Order Form states otherwise. Trial, evaluation and demonstration environments may be hosted in another region, and the current hosting region for any environment is available on request. Personal Information may also be processed in New Zealand and in other countries in which our providers maintain appropriately safeguarded infrastructure. The precise processing location may depend on the customer environment, the features used and the arrangements specified in the relevant Order Form or Data Processing Agreement.
Customers may connect their own Microsoft 365 environment to the Service. Microsoft remains the customer's provider for that environment. Information transmitted from that environment to Discovery Works is processed by us and our service providers as described in this Policy.
We maintain a current list of the sub-processors that handle Customer Data, naming each provider and its processing region. That list is available to customers and prospective customers on request by emailing hello@discoveryworks.ai, and is provided as part of our security documentation and as an annex to our Data Processing Agreement. We may add or replace providers as the Service develops, and will notify paid customers of material new sub-processors in accordance with the applicable Data Processing Agreement or Terms of Service.
Where Personal Information is processed outside the individual's country, we use safeguards required by Applicable Privacy Laws. These may include contractual protections requiring comparable privacy safeguards, adequacy decisions, approved standard contractual clauses or another lawful transfer mechanism.
We may disclose Personal Information:
to the service providers and sub-processors described in Section 7;
to professional advisers, including lawyers, auditors, insurers and accountants, under confidentiality obligations;
in connection with a proposed or actual investment, financing, sale, merger, reorganisation or acquisition, subject to appropriate confidentiality protections;
where reasonably necessary to protect the security, integrity, legal rights or property of Discovery Works, our customers or others;
to a regulator, court, law-enforcement agency or other person legally entitled to require it; and
to another person where the relevant individual or customer authorises the disclosure.
We do not sell Personal Information and do not share it for cross-context behavioural advertising.
We use cookies and similar technologies to authenticate users and maintain sessions, remember preferences, secure the Website and Service, and understand how they are used. Where Applicable Privacy Laws require consent for non-essential cookies, we seek that consent. You may also control cookies through your browser settings, although disabling essential cookies may prevent parts of the Service from working.
We retain Personal Information only for as long as reasonably necessary for the purposes for which it was collected, to provide the Service, to resolve disputes, and to meet legal, accounting, security and regulatory requirements.
Invoice, tax and financial records are normally retained for seven years. Business contact and account administration information may be retained for a reasonable period after the relationship ends where needed for support, recordkeeping, fraud prevention, legal claims or permitted business communications.
Customer Data is retained for the duration of the customer's subscription. Unless an Order Form or DPA states otherwise, Customer Data is deleted from active systems within 30 days after expiry or termination, and residual copies in routine encrypted backups are overwritten or expire within 90 days. Backup copies are isolated from ordinary use and are restored only where reasonably necessary for disaster recovery or legal compliance.
Customer Data in a trial or evaluation environment is deleted from active systems within 30 days after the trial ends unless the customer converts to a paid subscription or we agree otherwise in writing. Customers may request deletion of specific records during a subscription, subject to technical feasibility, legal obligations and the customer's own retention instructions.
Personal Information that is no longer required is securely deleted or irreversibly anonymised.
We apply administrative, technical and organisational safeguards appropriate to the sensitivity of the information we hold. These include:
encryption in transit using TLS and encryption at rest;
tenant-level access controls and database row-level security designed to restrict a customer's data to authorised members of that customer's tenant;
multi-factor authentication for privileged accounts and where offered to users;
least-privilege access controls, protected integration credentials and logging of administrative and security-relevant actions;
automated security and dependency scanning, vulnerability management and secure development practices;
backups and recovery controls appropriate to the Service; and
incident-response procedures and access by personnel only where reasonably necessary for their role.
No method of transmission, processing or storage is completely secure, and we cannot guarantee absolute security.
If we become aware of a privacy or security breach affecting Personal Information, we will investigate and assess it promptly.
Where we act as processor, we will notify the affected customer without undue delay, provide information reasonably available to us, and assist the customer with its assessment and legally required notifications. Where we act as controller, we will notify affected individuals and relevant regulators where required by Applicable Privacy Laws.
The Service uses artificial intelligence to analyse meeting transcripts and produce structured summaries, opportunity assessments and portfolio-level intelligence. These outputs are intended to support human decision-making about business opportunities and organisational priorities.
The Service is not designed to make decisions about an individual's employment, eligibility, credit, health, legal rights or treatment. Customers must not use Outputs as the sole basis for a decision that produces legal effects concerning an individual or similarly significantly affects them.
AI-generated Outputs may contain errors, omissions or misinterpretations and must be reviewed by a person before being relied upon or shared externally.
You may have rights to access Personal Information we hold about you and to request correction if it is inaccurate. Depending on the Applicable Privacy Laws, you may also have rights to request deletion, restrict processing, obtain data portability, object to certain processing, withdraw consent, opt out of marketing, or complain to a regulator.
To exercise a right, contact hello@discoveryworks.ai with the subject "Privacy Request". We may need to verify your identity and may ask for information needed to locate the relevant records.
We will respond within the period required by Applicable Privacy Laws. For requests governed by New Zealand law, this is as soon as reasonably practicable and generally no later than 20 working days. Under the EU or UK GDPR, the usual period is one month, subject to any lawful extension.
Where a request concerns Customer Data for which we act as processor, we will refer the request to the relevant customer and assist that customer in responding.
The Website and Service are accessible internationally. Personal Information may be processed in New Zealand, the United States and the other countries described in Section 7, subject to the safeguards described in that section and any customer-specific commitments in an Order Form or DPA.
The Service is a business tool and is not directed at children. We do not knowingly create accounts for, or market the Service to, anyone under 18. If you believe that we have collected Personal Information from a child in circumstances where we should not have done so, contact us and we will investigate and take appropriate action.
We may update this Policy from time to time to reflect changes in the Service, our providers, our practices or Applicable Privacy Laws. Changes take effect when the updated Policy is posted on the Website. If a change materially affects how we process Customer Data, we will notify affected customers by email, through the Service, or as required by the applicable DPA.
Privacy Officer
Discovery Works Limited
215 Victoria Road
Devonport, Auckland 0624
New Zealand
hello@discoveryworks.ai
Please contact us first if you have a privacy concern or complaint. You may also complain to the privacy or data-protection authority responsible for your location, including:
New Zealand - Office of the Privacy Commissioner: privacy.org.nz
Australia - Office of the Australian Information Commissioner: oaic.gov.au
EU or UK - the supervisory authority responsible for your country or region; or
United States - the state regulator or Attorney General responsible for an applicable state privacy law.