Summit by St James Financial

Legal

Privacy Policy

Version 1.0 · Effective 26 July 2026

St James Financial Limited (“we”, “us”, “our”) provides Summit, software used by New Zealand mortgage advisers to prepare credit-writing documents. This policy explains how personal information is handled when a firm uses Summit, in accordance with the Privacy Act 2020 (Privacy Act) and its Information Privacy Principles (IPPs).

It applies to the adviser firms, financial advice providers and their personnel who hold a Summit account (each a Subscriber), and to anyone whose personal information appears in documents a Subscriber uploads to Summit.

Summit is a distinct product from the credit-writing service St James Financial provides directly. Where we perform an engagement for you ourselves, the St James Financial privacy policy governs that work instead.

iWhat information Summit handles

1.1 Subscriber account information

We collect and hold, for each person with a Summit account:

  • name and the sign-off title used on generated documents
  • email address (the login identifier)
  • a cryptographic hash of the chosen password — never the password itself
  • the firm and role the account belongs to, and its active/disabled state
  • firm-level settings the account configures, such as firm name and letterhead

This is supplied directly by the Subscriber when an account is created or an invitation is accepted.

1.2 End-client data in uploaded documents

To produce a file assessment, diary note, client email or servicing calculation, a Subscriber uploads supporting material — statements of position, bank statements, payslips, identity documents, financial statements and similar. That material typically contains personal and financial information about the Subscriber’s own clients (End-Client Data).

Summit does not store uploaded documents or End-Client Data at all. Document processing is stateless: files are held in memory only for the duration of the request that generates the output, then discarded. There is no client record, no deal record and no document store in Summit’s database — those tables do not exist. Generated output is returned to the Subscriber’s browser and is not retained by us.

1.3 The Subscriber is the controller

As between the Subscriber and us, the Subscriber is the agency responsible for End-Client Data. The Subscriber is responsible for holding appropriate authority and consent to process that information through Summit, consistent with the Privacy Act, the Financial Markets Conduct Act 2013 and their professional obligations. Requests from an end-client about their own information should be handled by the Subscriber; because we retain no End-Client Data, we will rarely hold anything responsive, but will assist where asked.

iiHow personal information is used

  • operating Summit and generating the output a Subscriber requests
  • authenticating users, maintaining sessions and preventing abuse
  • recording aggregate usage for capacity planning and billing
  • supporting Subscribers, including diagnosing faults they report
  • meeting our legal, regulatory and record-keeping obligations

We do not use personal information for direct marketing without consent, and we do not sell, rent or trade personal information.

2.1 No use of data for AI training

We do not use End-Client Data, uploaded documents, or generated output to train, fine-tune or improve any AI model. The AI processing service described in section iv does not retain submitted content for model-training purposes under its terms with us.

iiiDisclosure of personal information

3.1 Service providers

We disclose personal information to the infrastructure providers described in section iv, who host and process it on our behalf. We take reasonable steps to ensure they handle it consistently with the Privacy Act and our obligations to Subscribers. Summit sets no third-party analytics, advertising or tracking services.

3.2 Legal requirements

We may disclose personal information where required by law, court order or a regulatory authority, or where we reasonably believe it necessary to protect the rights, property or safety of ourselves, our Subscribers or others. Where lawful and practicable we will notify the affected Subscriber first.

3.3 Business transfers

If we sell or transfer all or part of our business, personal information may be disclosed to the purchaser. We will take reasonable steps to ensure the purchaser is bound by equivalent privacy obligations, and will notify Subscribers in advance where practicable.

ivOverseas disclosure — AI processing (IPP 12)

This section is our disclosure under Information Privacy Principle 12 regarding disclosure of personal information to an overseas person.

4.1 The processing chain

  • Amazon Web Services, Inc. (AWS) — Summit runs entirely in the Asia Pacific (Sydney) region (ap-southeast-2), located in Australia. The application, its database and all document processing occur in that region.
  • Anthropic Claude — the AI model that generates credit-writing output, accessed exclusively via AWS Bedrock within the Sydney region. Summit’s hosted service does not call Anthropic’s API directly; all model invocations occur inside AWS infrastructure in Australia.

Summit’s hosted service uses no United States hosting layer. Personal information is not routed through any other country in the ordinary course of operating Summit.

4.2 Steps taken to protect information

  • All processing occurs in Australia, which has a comprehensive data protection regime substantially similar to New Zealand's.
  • Per AWS Bedrock’s terms, "AWS does not use, store, or log API content for any purpose other than the immediate processing of the API request."
  • Anthropic's terms, as applied via AWS Bedrock, likewise state that content submitted via the API is not used to train Anthropic's models.
  • All transmission is encrypted in transit (TLS 1.2 or higher), and the database is reachable only from inside our private network.
  • Because uploaded documents are never written to storage, the overseas footprint of End-Client Data is limited to the moment of processing.

4.3 Desktop edition

A desktop build of Summit exists for internal St James Financial use. Where it is configured with a direct Anthropic API key rather than AWS Bedrock, document content is processed by Anthropic in the United States rather than Australia. This build is not distributed to Subscribers, and Subscriber or end-client material is not processed through it. If that ever changes, this policy will be updated first and affected Subscribers notified.

4.4 Subscriber acknowledgement

By using Summit, the Subscriber acknowledges that uploaded documents are processed in Australia (AWS Sydney) on infrastructure operated by United States-headquartered companies, and that it is the Subscriber’s responsibility to ensure their end-clients are appropriately informed that personal and financial information may be processed overseas by an AI service, where the Subscriber’s own obligations require it.

vStorage, security and retention

5.1 What is not retained

Uploaded documents and End-Client Data are not stored after the request that processes them. We maintain no content logs, archives or backups containing document content. This is a deliberate design choice: the data that would be most damaging to lose is never written down.

5.2 What is retained

  • account records — name, sign-off title, email, hashed password, role and status
  • firm records and firm-level settings, including any knowledge overrides a firm configures
  • session records, so a session can be revoked
  • an audit log of administrative actions (who did what, and when) — it records the action taken, not document content
  • aggregate usage counters per firm and period — counts only, no content
  • failed-login records containing the submitted email address and originating IP address, used solely to throttle brute-force attempts

5.3 Retention periods

  • Uploaded documents and End-Client Data: not retained (see 5.1).
  • Failed-login records: retained only for the 15-minute throttling window, then deleted automatically.
  • Session records: until expiry or sign-out.
  • Account and firm records: for as long as the subscription is active, and for seven years afterwards where needed to meet tax and record-keeping obligations under New Zealand law.
  • Audit log and usage counters: for as long as reasonably necessary for security monitoring, billing and dispute resolution, typically up to three years.

5.4 Security measures

  • Each firm's data is isolated at the database level by row-level security, enforced through a non-privileged database role — a query cannot reach another firm's rows even if application code is wrong.
  • The firm a request belongs to is derived only from the signed session cookie, and can never be supplied by the browser.
  • Passwords are stored using scrypt with per-password salts and compared in constant time.
  • Sessions are signed, expiring and individually revocable; cookies are HTTP-only, Secure and SameSite-restricted.
  • State-changing requests are checked against their origin to prevent cross-site submission.
  • Invitations are single-use, expiring, and stored only as a hash.
  • The database is not reachable from the public internet.
  • Application logs are written free of document content.

5.5 Privacy breaches

If a privacy breach occurs that is reasonably likely to cause serious harm, we will notify the Office of the Privacy Commissioner and affected individuals as required by Part 6 of the Privacy Act 2020, and will notify affected Subscribers as soon as reasonably practicable so they can meet any obligations to their own end-clients.

viYour rights

6.1 Access and correction

Under IPPs 6 and 7 you may request access to personal information we hold about you and correction of anything inaccurate, incomplete or misleading. Contact our Privacy Officer (section ix). We will respond within 20 working days as the Privacy Act requires. Where we decline a request in circumstances the Act permits, we will give reasons and explain your right to complain to the Privacy Commissioner.

6.2 Deletion

You may request deletion of personal information we hold about you at any time by emailing hello@stjamesfinancial.co.nz with the subject line “Data Deletion Request”, including your name, contact email and the firm you are associated with. Because uploaded documents and End-Client Data are never retained, there will generally be no document content to delete. We may need to keep limited information where a lawful reason applies, such as tax records or the defence of legal claims.

6.3 Complaints

If you are not satisfied with our response, you may complain to the New Zealand Privacy Commissioner (details in section ix).

viiCookies

Summit sets a single cookie, summit-session, which holds the signed session that keeps you logged in. It is HTTP-only, Secure and SameSite-restricted, and is not readable by scripts in the page.

Summit sets no advertising, analytics or tracking cookies, and embeds no third-party trackers. Because the only cookie we set is strictly necessary to provide a service you have asked for, no consent banner is presented.

viiiChanges to this policy

We may update this policy from time to time. Where changes are material we will notify active Subscribers by email at least 14 days before they take effect. The version number and effective date appear at the top of this page.

ixContact and complaints

9.1 Privacy Officer

Privacy Officer · St James Financial Limited
Email: hello@stjamesfinancial.co.nz
Registered address: 7 Waituna Street, Pegasus 7612, New Zealand
Companies Office number: 9330894 · NZBN: 9429052742569

9.2 Office of the Privacy Commissioner

PO Box 10094, The Terrace, Wellington 6143
Phone: 0800 803 909 · privacy.org.nz

© 2026 St James Financial Limited · Aotearoa New Zealand