Privacy Policy
AppFactory
Legal Company Name: KCD International LTD
Website: appfactory.co.nz
Email: [email protected]
Effective Date: 26 July 2026
Last Updated: 26 July 2026
AppFactory is committed to protecting your privacy and handling personal information responsibly.
This Privacy Policy explains how KCD International LTD, trading as AppFactory, collects, uses, stores, processes, shares and protects personal information when you use our website, software platform, CRM functionality, automation services, artificial intelligence features, communications services and related products and services.
AppFactory is based in New Zealand and provides SaaS software and related services to customers in New Zealand and internationally.
Important Privacy and Messaging Notice
AppFactory does not sell, rent or trade personal information or customer contact databases.
We do not sell or provide mobile phone numbers, SMS opt-in information or messaging consent records to third parties or affiliates for their own independent marketing or promotional purposes.
Information may be provided to technology, communications, infrastructure and payment providers where reasonably necessary to provide AppFactory services.
Our primary disclosed providers currently include:
SMSGateway for SMS communications
Stripe for payments and subscription billing
Other third-party cloud, AI, email, communications and software infrastructure providers required to operate AppFactory
These providers may process information where reasonably necessary to provide their services, subject to applicable privacy, security and contractual requirements.
1. Scope of This Privacy Policy
This Privacy Policy applies to information processed through:
AppFactory websites
AppFactory SaaS software
CRM and customer management systems
Lead management systems
Forms and lead capture
Online booking systems
Calendars
Email communications
SMS and text messaging
Telephone and messaging services
Social media integrations
Review and reputation management
Workflow automation
Marketing automation
Artificial intelligence and AI-assisted services
Customer support
Billing and subscriptions
Third-party integrations
Other products and services provided by AppFactory
Depending on the circumstances, AppFactory may process personal information for its own business purposes or process information on behalf of an AppFactory customer.
2. Information We Collect
The information we collect depends on how you interact with AppFactory and which services are being used.
Personal and Contact Information
We may collect:
Name
Email address
Mobile or telephone number
Physical or postal address
Job title
Company or organisation name
Account information
Username
Profile information
Communication preferences
Information you voluntarily provide
Business Information
We may collect:
Business name
Business contact information
Industry
Website information
Business processes
CRM requirements
Sales and marketing information
Customer communication requirements
Information required to configure AppFactory services
Account and Subscription Information
We may collect:
Subscription details
Products and services purchased
Billing information
Transaction details
Invoice information
Account status
Subscription history
Usage information
Full payment card information is generally processed directly by our payment provider, Stripe.
Technical and Usage Information
We may automatically collect:
IP address
Browser type
Device information
Operating system
Login activity
Date and time information
Referring pages or URLs
Approximate geographic location
Platform usage
Feature usage
Diagnostic information
Log information
Cookies
Session information
Communications
We may collect records of:
Emails
SMS messages
Telephone communications
Chat conversations
Website enquiries
Form submissions
Support enquiries
Appointments
Customer service communications
Feedback
Communication preferences
Where telephone, video or AI-assisted conversations are recorded or transcribed, appropriate notice will be provided where required.
3. Consent and Communication Records
AppFactory may maintain information relating to consent and communication preferences.
This may include:
Date and time consent was provided
Method of consent
Website or form through which consent was provided
SMS consent
Email marketing consent
Consent wording presented at the time
Opt-in information
Opt-out information
Unsubscribe requests
Withdrawal of consent
Communication preference history
These records may be maintained to operate our services, honour communication preferences and assist AppFactory customers with their compliance obligations.
4. Customer Data
AppFactory customers may use the platform to collect, upload, import, connect or process information relating to their own:
Customers
Prospects
Leads
Employees
Contractors
Suppliers
Members
Clients
Business contacts
We refer to this information as Customer Data.
Customer Data may include:
Names
Email addresses
Telephone numbers
Contact details
CRM records
Sales opportunities
Appointments
Enquiries
Communication history
Message history
Purchase information
Form submissions
Customer preferences
Notes
Business records
Where AppFactory processes Customer Data on behalf of an AppFactory customer, that customer generally determines why and how the information is collected and used.
AppFactory processes Customer Data as reasonably necessary to provide the requested services and according to applicable agreements, instructions and legal requirements.
Individuals seeking access to information held by an AppFactory customer should normally contact that business directly.
Where appropriate, AppFactory may assist its customers in responding to valid privacy requests.
5. Information Received From Other Sources
AppFactory may receive personal information indirectly rather than directly from an individual.
This may happen where information is:
Provided by an AppFactory customer
Imported into a CRM
Migrated from another system
Provided through an integration
Submitted through a referral
Supplied by an authorised third party
Obtained from publicly available business information
Connected from another software application
Provided through a business transaction or customer relationship
Where AppFactory is responsible for collecting personal information indirectly, we will take reasonable steps to provide appropriate privacy information where required by applicable law.
6. How We Use Personal Information
AppFactory may use personal information to:
Create and manage customer accounts
Provide AppFactory services
Operate CRM functionality
Manage leads and sales opportunities
Configure customer systems
Provide customer support
Respond to enquiries
Schedule appointments
Send email communications
Send SMS communications
Operate workflow automation
Provide AI-assisted functionality
Manage customer relationships
Provide review and reputation services
Process subscriptions and payments
Provide reporting and analytics
Maintain communication preferences
Process consent and unsubscribe requests
Improve AppFactory services
Diagnose technical problems
Maintain platform performance
Prevent fraud and misuse
Maintain security
Administer contracts
Maintain business records
Comply with applicable law
Send marketing communications where legally permitted
We will not intentionally use personal information for materially unrelated purposes unless permitted by applicable law or appropriate permission has been obtained.
7. Legal Basis for Processing
Where applicable privacy legislation requires AppFactory to identify a lawful basis for processing personal information, that basis may include:
Providing Our Services
Processing may be necessary to provide services requested by you or fulfil our obligations under an agreement.
Consent
We may rely on consent for certain activities, including particular electronic marketing communications where consent is required.
Where processing is based on consent, consent may generally be withdrawn for future processing.
Legitimate Business Purposes
Where permitted by applicable law, information may be processed for legitimate business purposes including:
Operating AppFactory
Maintaining security
Preventing fraud
Improving services
Providing customer support
Managing customer relationships
Legal Requirements
We may process personal information where necessary to comply with applicable legal or regulatory obligations.
8. Artificial Intelligence
AppFactory provides features that may use artificial intelligence, machine learning and automated processing.
AI functionality may be used to:
Respond to enquiries
Operate AI-assisted chat
Operate AI-assisted telephone services
Qualify leads
Schedule appointments
Summarise conversations
Generate suggested responses
Create business or marketing content
Analyse customer interactions
Categorise leads or opportunities
Trigger workflows
Assist customer service
Automate repetitive processes
When an AI feature is used, relevant information may be processed by technology providers required to deliver that functionality.
Information may include:
Names
Contact information
Enquiry information
Conversation history
CRM information
Appointment information
Customer instructions
Information submitted to an AI assistant
AppFactory does not sell Customer Data to AI providers.
AppFactory does not provide Customer Data to AI providers for their own independent advertising or marketing purposes.
Customers should avoid submitting sensitive information to AI functionality unless that processing is necessary, appropriate and lawful for their business purposes.
9. Automated Processing
Certain AppFactory features may automatically:
Categorise leads
Assign opportunities
Trigger communications
Schedule follow-ups
Summarise information
Suggest responses
Route enquiries
Perform workflow actions
Customers remain responsible for configuring and reviewing automated processes appropriately.
Where applicable law provides rights relating to automated decisions that have legal or similarly significant effects, individuals may exercise those rights as applicable.
10. SMS and Text Messaging
AppFactory may provide SMS and text messaging functionality.
AppFactory uses SMSGateway to support SMS transmission and delivery.
Information necessary to provide SMS services may be processed by SMSGateway and relevant telecommunications providers.
This may include:
Telephone numbers
Message content
Delivery information
Replies
Message status
Consent information
Opt-out information
11. SMS Consent
Where required by applicable law, marketing SMS messages should only be sent where appropriate consent or another lawful basis exists.
Where express SMS opt-in is used:
Consent should be clearly presented
Consent should be knowingly provided
Consent checkboxes should not be pre-selected where affirmative consent is required
Marketing SMS consent should generally be optional
Consent records may be maintained
Individuals should be provided with an appropriate method to withdraw consent
Consent to marketing communications is not normally required as a condition of purchasing AppFactory services unless the relevant communication is reasonably necessary to provide the requested service.
12. SMS Privacy
Mobile information, telephone numbers and SMS opt-in information will not be sold or shared with third parties or affiliates for their own independent marketing or promotional purposes.
Information may be provided to:
SMSGateway
Telecommunications carriers
Messaging aggregators
Communications infrastructure providers
Technology providers supporting delivery of the service
This sharing is limited to purposes reasonably necessary to send, receive, route, secure or manage SMS communications.
13. SMS Opt-Out
Recipients may withdraw from marketing SMS communications.
Where supported, recipients may reply:
STOP
to unsubscribe.
Where supported, recipients may reply:
HELP
for assistance.
Valid opt-out requests will be processed in accordance with applicable law and as quickly as reasonably practicable.
A person who has unsubscribed should not be added back to marketing SMS communications unless there is a new lawful basis or renewed consent where required.
Standard telecommunications, message or data charges may apply.
14. Email Communications
AppFactory may provide email communication and automation functionality.
Marketing email communications should only be sent where permitted by applicable law.
Marketing communications should:
Identify the sender appropriately
Provide accurate sender information
Include an appropriate unsubscribe mechanism
Comply with applicable consent requirements
For email marketing communications, use the Unsubscribe link contained in the relevant email.
Service, security, billing, account and transactional communications may still be sent where reasonably necessary to provide a requested service or manage an existing account.
15. Payment Processing
AppFactory uses Stripe to process payments, subscriptions and recurring billing.
When you make a payment, payment-related information may be provided directly to Stripe.
Stripe may process information including:
Name
Email address
Billing address
Payment card information
Bank information where applicable
Transaction amount
Subscription information
Payment history
Transaction identifiers
Fraud prevention information
Information required to authenticate or process payments
AppFactory does not generally store complete credit or debit card numbers where payment information is processed directly by Stripe.
AppFactory may receive limited payment information such as:
Payment status
Transaction reference
Payment method
Subscription status
Invoice information
Limited card information provided by Stripe
We may use this information to:
Process payments
Administer subscriptions
Issue invoices
Manage recurring billing
Identify failed payments
Process refunds
Prevent fraud
Maintain financial records
Stripe processes personal information in accordance with its own privacy, security and regulatory obligations.
16. Our Technology Providers
AppFactory uses third-party providers to operate and support our SaaS platform.
These providers may include:
Cloud infrastructure providers
Hosting providers
Artificial intelligence providers
SMS providers
Telecommunications providers
Email providers
Payment processors
Analytics providers
Cybersecurity providers
Authentication providers
Software integration providers
Customer support providers
Professional advisers
Our primary disclosed providers currently include:
SMSGateway
Used for SMS transmission, message delivery, routing, replies and related telecommunications services.
Stripe
Used for payment processing, subscription billing, recurring payments, transaction processing, fraud prevention and refunds.
Additional providers may be used where reasonably necessary to operate, secure or improve AppFactory.
17. Information Sharing
AppFactory does not sell or rent personal information or Customer Data.
We may share information where reasonably necessary with authorised service providers that help us operate AppFactory.
Information may also be disclosed:
Where required by applicable law
In response to a valid court order
In response to an appropriate regulatory request
To protect AppFactory's legal rights
To investigate fraud or misuse
To maintain security
To protect users or other individuals
As part of an authorised business transaction
We aim to disclose only information reasonably necessary for the relevant purpose.
18. Do Not Sell Personal Information
AppFactory does not operate a business model based on selling personal information, customer contact databases or leads.
AppFactory does not sell:
Customer Data
Lead databases
Personal information
Telephone numbers
SMS consent information
Email marketing consent records
AppFactory does not provide SMS opt-in information to unrelated third parties for their own independent marketing or promotional purposes.
Information may still be processed by authorised service providers where reasonably necessary to provide AppFactory services.
19. International Data Processing
AppFactory is based in New Zealand and provides services internationally.
Because AppFactory uses global technology infrastructure, personal information may be stored, transmitted or processed in countries outside New Zealand.
This may include processing associated with:
Cloud infrastructure
AI services
SMSGateway
Stripe
Email infrastructure
Telecommunications services
Software integrations
Other authorised technology providers
These organisations may also use authorised subprocessors located internationally.
Where required by applicable privacy law, AppFactory will take reasonable steps to ensure appropriate safeguards apply to international processing and disclosure.
These safeguards may include:
Data processing agreements
Contractual privacy obligations
Confidentiality requirements
Recognised international transfer mechanisms
Technical security safeguards
Other legally recognised protections
20. Data Security
AppFactory takes reasonable technical and organisational measures designed to protect personal information against:
Unauthorised access
Loss
Misuse
Unauthorised alteration
Unauthorised disclosure
Destruction
Cybersecurity threats
Security measures may include:
Encrypted connections
Encryption where appropriate
Authentication
Access controls
Password controls
Restricted administrative access
System monitoring
Security updates
Backups
Logging
Incident response processes
Supplier security controls
No internet-based service or electronic storage system can be guaranteed to be completely secure.
Users are responsible for protecting their passwords, login credentials and access to their AppFactory accounts.
21. Privacy and Data Breaches
If AppFactory becomes aware of a privacy or security incident, we will investigate and take reasonable steps to:
Identify the incident
Contain the incident
Assess potential harm
Address security vulnerabilities
Take appropriate remedial action
Where required by applicable law, AppFactory may notify:
Affected customers
Affected individuals
Privacy regulators
Other relevant authorities
Where AppFactory processes information on behalf of a customer, we may notify that customer so they can meet their own privacy obligations.
22. Data Retention
AppFactory retains personal information for as long as reasonably necessary for the purposes for which it was collected.
This may include retention required to:
Provide AppFactory services
Maintain accounts
Maintain Customer Data
Meet legal requirements
Maintain tax and financial records
Resolve disputes
Prevent fraud
Maintain security
Enforce agreements
When information is no longer reasonably required, AppFactory may securely:
Delete it
Anonymise it
De-identify it
Customer Data may also be retained according to subscription settings, contractual obligations, backup processes and applicable legal requirements.
23. Cookies and Tracking Technologies
AppFactory may use cookies and similar technologies to:
Operate our website
Authenticate users
Maintain sessions
Remember preferences
Analyse website usage
Analyse platform usage
Improve functionality
Diagnose technical issues
Prevent fraud
Measure marketing performance
Depending on your location, we may request consent before certain non-essential cookies are used.
You may control cookies through browser settings or cookie controls made available through our website.
Disabling certain cookies may affect website or platform functionality.
24. Your Privacy Rights
Privacy rights vary depending on your location and applicable law.
Subject to applicable legal requirements, you may have rights to:
Request access to personal information
Request correction of inaccurate information
Request deletion
Request restriction of processing
Object to certain processing
Withdraw consent
Request data portability
Opt out of direct marketing
Request information about how data is processed
Exercise rights concerning certain automated processing
Make a complaint to an appropriate privacy regulator
These rights are not absolute and may be subject to legal exceptions.
AppFactory may need to verify your identity before responding to a privacy request.
25. New Zealand Privacy Rights
AppFactory is operated in New Zealand by KCD International LTD.
Where the New Zealand Privacy Act 2020 applies, individuals may have rights relating to their personal information, including rights to request access to and correction of personal information held about them.
AppFactory will handle applicable overseas disclosures of personal information in accordance with relevant New Zealand privacy requirements.
Individuals who believe their privacy rights have been breached may also have the right to make a complaint to the New Zealand Office of the Privacy Commissioner.
26. International Privacy Rights
Where applicable, individuals outside New Zealand may have additional rights under privacy legislation applying in their jurisdiction.
This may include rights under:
European Union privacy legislation
United Kingdom privacy legislation
Australian privacy legislation
Applicable United States state privacy legislation
Other national or regional privacy frameworks
Where such legislation applies to AppFactory's processing activities, AppFactory will respond to valid privacy requests in accordance with applicable requirements.
Nothing in this Privacy Policy is intended to remove rights that cannot legally be excluded.
27. Exercising Your Privacy Rights
Privacy requests may be sent to:
Privacy Officer
AppFactory
KCD International LTD
Website: appfactory.co.nz
Email: [email protected]
Please provide sufficient information for us to understand your request and, where reasonably necessary, verify your identity.
Where the requested information is controlled primarily by an AppFactory customer, we may direct you to that customer or assist the customer in responding.
28. Customer Responsibilities
Businesses using AppFactory remain responsible for how they collect and use personal information through their accounts.
Customers are responsible for ensuring that they:
Have an appropriate legal basis for collecting information
Have authority to upload Customer Data
Maintain an appropriate privacy policy
Provide required privacy notices
Obtain marketing consent where required
Maintain consent records where required
Provide appropriate unsubscribe mechanisms
Honour valid opt-out requests
Respond appropriately to privacy requests
Maintain lawful marketing databases
Protect login credentials
Restrict access to authorised personnel
Use AI appropriately
Comply with applicable privacy and electronic messaging laws
Customers must not use AppFactory to unlawfully collect, process or distribute personal information.
29. Third-Party Integrations
AppFactory may integrate with third-party software, services and platforms.
These may include:
Social media platforms
Email providers
Calendar services
Accounting platforms
Telecommunications providers
Artificial intelligence providers
Payment services
Marketing platforms
Business applications
When you connect a third-party service, information may be exchanged according to:
The integration selected
Your instructions
Permissions granted
The relevant third-party terms and policies
Third-party providers operate under their own terms and privacy policies.
AppFactory is not responsible for the independent privacy practices of third-party websites or services.
30. Children's Privacy
AppFactory is primarily a business software platform and is not intended to be purchased directly by children.
We do not knowingly market AppFactory directly to individuals under 18.
An AppFactory customer may operate a business that provides services to children or young people.
In those circumstances, the customer is responsible for ensuring that its collection and processing of children's personal information complies with applicable privacy and consent requirements.
If you believe information relating to a child has been improperly collected through AppFactory, contact us at:
31. Business Transfers
If KCD International LTD or AppFactory is involved in a:
Merger
Acquisition
Financing
Restructure
Sale of business
Sale of assets
Transfer of services
Similar corporate transaction
personal information may be transferred where reasonably necessary in connection with that transaction.
Appropriate confidentiality and privacy protections will apply where required.
32. Legal Disclosures
AppFactory may disclose personal information where reasonably necessary to:
Comply with applicable law
Respond to a valid court order
Respond to a lawful government or regulatory request
Establish or defend legal claims
Protect AppFactory's rights
Investigate fraud
Prevent misuse
Maintain system security
Protect users or other individuals
Prevent serious harm
33. Changes to This Privacy Policy
AppFactory may update this Privacy Policy from time to time.
Changes may reflect:
New services
New technology
New features
Changes to service providers
Changes to privacy requirements
Changes to AppFactory's business operations
The current version will be published on:
appfactory.co.nz
The date at the top of this Privacy Policy identifies when it was last updated.
Where a material change significantly affects how personal information is handled, additional notice may be provided where appropriate or required.
34. Contact AppFactory
For privacy questions, requests or complaints, contact:
Privacy Officer
AppFactory
KCD International LTD
Website: appfactory.co.nz
Email: [email protected]
SMS
To unsubscribe from eligible marketing SMS communications:
Reply STOP
Where supported, for assistance:
Reply HELP
For email marketing communications, use the Unsubscribe link contained in the relevant email.
AppFactory Privacy Commitment
AppFactory is committed to protecting personal information and providing technology that businesses can use responsibly.
We do not sell customer databases.
We do not sell Customer Data.
We do not sell SMS consent information.
We do not provide mobile opt-in information to unrelated businesses for their own independent marketing.
Personal information is processed only where reasonably necessary to provide AppFactory services, operate and secure our platform, meet applicable legal requirements or fulfil legitimate and lawful business purposes.
We make getting new customers easier, while respecting the privacy of the people behind the data.