Legal
Version 1.0 · Effective 26 July 2026
St James Financial Limited (“we”, “us”, “our”) provides Summit, software used by New Zealand mortgage advisers to prepare credit-writing documents. This policy explains how personal information is handled when a firm uses Summit, in accordance with the Privacy Act 2020 (Privacy Act) and its Information Privacy Principles (IPPs).
It applies to the adviser firms, financial advice providers and their personnel who hold a Summit account (each a Subscriber), and to anyone whose personal information appears in documents a Subscriber uploads to Summit.
Summit is a distinct product from the credit-writing service St James Financial provides directly. Where we perform an engagement for you ourselves, the St James Financial privacy policy governs that work instead.
We collect and hold, for each person with a Summit account:
This is supplied directly by the Subscriber when an account is created or an invitation is accepted.
To produce a file assessment, diary note, client email or servicing calculation, a Subscriber uploads supporting material — statements of position, bank statements, payslips, identity documents, financial statements and similar. That material typically contains personal and financial information about the Subscriber’s own clients (End-Client Data).
Summit does not store uploaded documents or End-Client Data at all. Document processing is stateless: files are held in memory only for the duration of the request that generates the output, then discarded. There is no client record, no deal record and no document store in Summit’s database — those tables do not exist. Generated output is returned to the Subscriber’s browser and is not retained by us.
As between the Subscriber and us, the Subscriber is the agency responsible for End-Client Data. The Subscriber is responsible for holding appropriate authority and consent to process that information through Summit, consistent with the Privacy Act, the Financial Markets Conduct Act 2013 and their professional obligations. Requests from an end-client about their own information should be handled by the Subscriber; because we retain no End-Client Data, we will rarely hold anything responsive, but will assist where asked.
We do not use personal information for direct marketing without consent, and we do not sell, rent or trade personal information.
We do not use End-Client Data, uploaded documents, or generated output to train, fine-tune or improve any AI model. The AI processing service described in section iv does not retain submitted content for model-training purposes under its terms with us.
We disclose personal information to the infrastructure providers described in section iv, who host and process it on our behalf. We take reasonable steps to ensure they handle it consistently with the Privacy Act and our obligations to Subscribers. Summit sets no third-party analytics, advertising or tracking services.
We may disclose personal information where required by law, court order or a regulatory authority, or where we reasonably believe it necessary to protect the rights, property or safety of ourselves, our Subscribers or others. Where lawful and practicable we will notify the affected Subscriber first.
If we sell or transfer all or part of our business, personal information may be disclosed to the purchaser. We will take reasonable steps to ensure the purchaser is bound by equivalent privacy obligations, and will notify Subscribers in advance where practicable.
This section is our disclosure under Information Privacy Principle 12 regarding disclosure of personal information to an overseas person.
Summit’s hosted service uses no United States hosting layer. Personal information is not routed through any other country in the ordinary course of operating Summit.
A desktop build of Summit exists for internal St James Financial use. Where it is configured with a direct Anthropic API key rather than AWS Bedrock, document content is processed by Anthropic in the United States rather than Australia. This build is not distributed to Subscribers, and Subscriber or end-client material is not processed through it. If that ever changes, this policy will be updated first and affected Subscribers notified.
By using Summit, the Subscriber acknowledges that uploaded documents are processed in Australia (AWS Sydney) on infrastructure operated by United States-headquartered companies, and that it is the Subscriber’s responsibility to ensure their end-clients are appropriately informed that personal and financial information may be processed overseas by an AI service, where the Subscriber’s own obligations require it.
Uploaded documents and End-Client Data are not stored after the request that processes them. We maintain no content logs, archives or backups containing document content. This is a deliberate design choice: the data that would be most damaging to lose is never written down.
If a privacy breach occurs that is reasonably likely to cause serious harm, we will notify the Office of the Privacy Commissioner and affected individuals as required by Part 6 of the Privacy Act 2020, and will notify affected Subscribers as soon as reasonably practicable so they can meet any obligations to their own end-clients.
Under IPPs 6 and 7 you may request access to personal information we hold about you and correction of anything inaccurate, incomplete or misleading. Contact our Privacy Officer (section ix). We will respond within 20 working days as the Privacy Act requires. Where we decline a request in circumstances the Act permits, we will give reasons and explain your right to complain to the Privacy Commissioner.
You may request deletion of personal information we hold about you at any time by emailing hello@stjamesfinancial.co.nz with the subject line “Data Deletion Request”, including your name, contact email and the firm you are associated with. Because uploaded documents and End-Client Data are never retained, there will generally be no document content to delete. We may need to keep limited information where a lawful reason applies, such as tax records or the defence of legal claims.
If you are not satisfied with our response, you may complain to the New Zealand Privacy Commissioner (details in section ix).
Summit sets a single cookie, summit-session, which holds the signed session that keeps you logged in. It is HTTP-only, Secure and SameSite-restricted, and is not readable by scripts in the page.
Summit sets no advertising, analytics or tracking cookies, and embeds no third-party trackers. Because the only cookie we set is strictly necessary to provide a service you have asked for, no consent banner is presented.
We may update this policy from time to time. Where changes are material we will notify active Subscribers by email at least 14 days before they take effect. The version number and effective date appear at the top of this page.
Privacy Officer · St James Financial Limited
Email: hello@stjamesfinancial.co.nz
Registered address: 7 Waituna Street, Pegasus 7612, New Zealand
Companies Office number: 9330894 · NZBN: 9429052742569
PO Box 10094, The Terrace, Wellington 6143
Phone: 0800 803 909 · privacy.org.nz
© 2026 St James Financial Limited · Aotearoa New Zealand