Disclosure
Service disclosure
A structured account of how this service is run — who we are, where your data sits, who else touches it, what happens when you leave, and what we don’t yet offer. Written so a procurement or security review can be done without a meeting.
Our Trust & security page is the readable version of this material. This is the reference version: the same facts in the order a reviewer needs them, including the parts that are unflattering.
Why we publish this
There is no live New Zealand code of practice for cloud providers to sign up to. The industry CloudCode scheme — the NZ Cloud Computing Code of Practice — has been dormant since around 2016 and its register went offline in late 2025, so a badge linking to it would be worth less than nothing.
The scheme’s disclosure schedule was still a good checklist, though: it asks the questions professional buyers actually ask, in an order that surfaces gaps rather than hiding them. So we kept the structure and publish our own answers against it. Nobody audits this page. It is worth exactly as much as our willingness to write down the awkward answers, which is why they are here rather than omitted.
1. Corporate identity and applicable law
| Legal entity | Glint Limited |
| Trading name | Legible™ |
| Country of incorporation | New Zealand |
| NZ company number | 6112095 |
| NZBN | 9429043335480 |
| Registered office | Recorded on the Companies Register, along with our directors and shareholding |
| Website | legible.nz |
| Application | app.legible.nz |
| General contact | support@legible.nz |
| Privacy contact | privacy@legible.nz |
| Security contact | security@legible.nz |
| Ownership | Privately held, New Zealand owned |
| Governing law of the customer contract | New Zealand |
| Jurisdiction for disputes | New Zealand courts |
| Other jurisdictions whose law may apply | Germany and the European Union (hosting and backups — GDPR); Ireland (EU) and New Zealand (payments); United States (transactional email) |
2. Ownership of information, including metadata
Your content is yours. Watchlists, lists, notes, saved searches and generated reports belong to you. Glint Limited claims no ownership of them and uses them for nothing beyond delivering the service to you.
Register data belongs to neither of us. Company, director and shareholder information originates from official New Zealand government registers and is accessed under agreement with MBIE and the Companies Office. You get a right to use it inside the service, subject to our terms, which pass through the restrictions in our own access agreements. You do not acquire a right to redistribute or resell the underlying datasets.
Usage metadata. We hold records of which companies were looked up, which searches and reports were run, quota counts and account audit events. These are used for service delivery, quota enforcement, billing accuracy, support, security investigation, and answering MBIE audit requests under our access agreements. They are not sold, not licensed to third parties, and never used to build advertising or marketing profiles.
Aggregated and derived data. Two categories, two different answers, because they are not the same question.
- Statistics derived from the public registers — company formation and failure rates, sector and regional patterns, insolvency activity — may be published and may form part of what we sell. Those facts are public at source and owned by neither of us. We publish the method and its limitations alongside the numbers, we suppress any figure small enough to identify a single company or person, and we publish statistics rather than datasets: nothing we release amounts to an extract that reconstitutes a register.
- Nothing derived from your activity is ever published, sold, licensed or productised — in any form, including anonymised or aggregated. That covers watchlists, notes, saved searches, lookup history, reports run and usage counts. There is no “trending companies” panel and there will not be one: what you look up would disclose that a company is under diligence, and aggregating it does not change that. If you ever want benchmarking against your own organisation’s activity, that is something you opt into, not something we do by default.
3. Data access and use
- Who can see your content: members of your own organisation. No other Legible customer, ever.
- Our access: limited to the operator of the service, for support, incident response and billing correction. There is no broad internal support team with standing access to your account.
- Third parties: none beyond the sub-suppliers in section 9, each handling only what its function requires.
- Legal compulsion: we may disclose information where New Zealand law requires it, or to investigate a suspected breach of our terms.
- Marketing: we do not sell personal information or share it for anyone else’s marketing.
- Tracking: no advertising or tracking cookies. This marketing site carries no analytics at all and makes no third-party network requests — even the fonts are served from our own domain. Browser session storage is used only for functional purposes.
4. Data location
| Data | Location | Provider |
|---|---|---|
| Application database — accounts, watchlists, notes, reports, register cache | Nürnberg, Germany (EU) | Netcup GmbH |
| Authentication data — users, credentials, realm configuration | Nürnberg, Germany (EU) | Self-hosted Keycloak on Netcup infrastructure |
| Off-site encrypted backups | Germany (EU) | Hetzner Online GmbH |
| Payment and subscription data | New Zealand and Ireland (EU) | Stripe |
| Transactional email in transit | United States | Resend, Inc. |
Customer data is stored in the European Union, not in New Zealand. The server sits in Netcup’s Nürnberg data centre. Germany operates under the GDPR, and our hosting and backup providers are engaged under GDPR Article 28 data processing agreements confirming they process our data only to deliver their service to us. That is the basis on which we rely for overseas storage under Information Privacy Principle 12 of the Privacy Act 2020.
Customers cannot currently choose a data region.
5. Security
In transit. All access to the marketing site, the application and the authentication service is over HTTPS/TLS, with certificates renewed automatically.
At rest. Off-site backups are encrypted by us before they leave our infrastructure, so the off-site provider holds only encrypted data, and the passphrase is kept separately from the server.
The live database volume is not separately encrypted at rest, and we would rather say so than let you assume it either way. Full-disk encryption protects a drive that has left our control — stolen, or decommissioned without being wiped. On a running server the key sits in memory, so it is no defence against what is actually likely: a compromised credential or a flaw in the application. The physical risk it does address is handled at the data centre, which operates alarmed, chip-card and video-monitored access control, RAID storage, and physical destruction of decommissioned drives to DIN 66399 level H-4, under ISO 27001 and ISO 27701 certification. We will adopt volume encryption at the next rebuild of the server, where it is an install-time choice rather than a retrofit — adding it to a live single-operator service would introduce a boot-time unlock step and an outage risk larger than the one it removes.
Authentication and access control. Sign-in runs through a self-hosted Keycloak instance rather than a third-party identity provider, and the application itself never stores your password. Card details are never seen or stored by us — payment data is handled entirely by Stripe. Your data is scoped to your organisation.
Logging and audit. We keep internal audit records of account changes, report generation and scheduled data jobs, and monitor production for duplicate application instances.
Certifications. Glint Limited holds no SOC 2 or ISO 27001 certification. We maintain the practices underneath them — least-privilege access, encrypted and restore-tested backups, audit logging, a documented recovery procedure — and will seek certification when a customer’s requirements justify it rather than as marketing. If you have a security questionnaire, send it and we will complete it.
Penetration testing. No external penetration test has been conducted to date. We would rather disclose that than let you assume otherwise.
Reporting a vulnerability. Email security@legible.nz. We acknowledge within two working days, keep you informed while we fix it, and will not pursue anyone who reports a genuine issue in good faith without accessing, altering or retaining other customers’ data.
6. Backup and maintenance
Backups run nightly, in three layers, because the three things that can go wrong fail differently:
| Layer | Contents | Retention | Location |
|---|---|---|---|
| Logical database dumps | Application and authentication databases | 3 days locally, plus a copy inside every off-site archive | Server, and off-site archive |
| Deduplicated, client-side encrypted archive | The nightly dumps | 7 daily, 4 weekly, 6 monthly | Hetzner Storage Box, Germany (EU) |
| Whole-disk provider snapshots | The entire server | Managed in the provider console | Netcup, Germany (EU) |
Are restorations tested? Yes. A restore of the latest dump into a throwaway database, with row counts verified against the original, is part of the documented procedure and has been exercised. The regime has run in production since 3 July 2026.
Recovery objectives. Because backups run nightly, worst-case data loss in a total-failure scenario is up to 24 hours. We do not publish a recovery-time commitment, because we have not measured a full restore against a clock — an invented figure would be worse than an absent one.
Monitoring. Production monitoring covers application availability, the outcome of every scheduled data job (recorded in an internal job run log), and duplicate-instance detection.
7. Service levels and support
| Availability commitment | None. We offer no contractual uptime SLA. We would rather say so than publish a 99.9% figure nothing backs |
| Support channel | Email — support@legible.nz |
| Support hours | New Zealand business hours |
| Service credits or remedies | None offered; see our Terms of service |
8. Exit, data portability and end of service
- Cancelling: you may cancel at any time. On account closure, working content — watchlists, notes, search history, generated reports — is deleted. Billing and account-audit records are kept for 7 years under the Tax Administration Act 1994.
- Register data: not exportable as a dataset. You may use register information inside the service and in your own professional work product, but not extract or redistribute the underlying datasets — a restriction that flows from our access agreements with MBIE.
- Backups after deletion: deleted content persists in encrypted backup archives until those archives age out under the retention schedule in section 6 — a maximum of six months for monthly archives.
- If we change hosting provider: under our agreement with Netcup, on completion of processing they delete or return all personal data at our election, and any copies surviving in their own backups are deleted within a maximum of 14 days.
9. Sub-suppliers
| Sub-supplier | Function | Location | Safeguard |
|---|---|---|---|
| Netcup GmbH (Anexia group) | Application and database hosting; hosts our Keycloak instance | Germany (EU) | GDPR; Article 28 data processing agreement. ISO 27001 and ISO 27701 certified |
| Anexia Holding GmbH | Support services to Netcup — regulatory enquiries, billing | Austria (EU) | Sub-processor under our Netcup agreement |
| Anexia Cloud Solutions GmbH | Data-centre infrastructure and personnel for Netcup | Austria and Germany (EU) | Sub-processor under our Netcup agreement |
| Hetzner Online GmbH | Encrypted off-site backup storage | Germany (EU) | GDPR; Article 28 agreement. Data encrypted by us before transfer |
| Stripe — Stripe New Zealand Limited; Stripe Payments Europe, Limited | Payment processing and subscription management | New Zealand; Ireland (EU) | GDPR; processing necessary to perform the subscription contract |
| Resend, Inc. | Transactional email — verification, password reset, notifications | United States | Data processing agreement incorporating standard contractual clauses |
MBIE and the Companies Office are not sub-suppliers for this purpose — they are the source of the register data we display. We send them search queries, not customer account information, and they may log those queries for audit purposes under our access agreements.
We update this list when a sub-supplier is added or changed. Our hosting agreement gives us written notice before a new sub-processor is engaged, with 14 calendar days to object.
10. Legal terms
Acceptance. Accepting the Terms of service is a condition of holding an account, and is captured when you first sign in. That is what passes the restrictions in our MBIE access agreements through to end users, as those agreements require. When the terms change materially, the same mechanism asks you to accept the new version at sign-in.
What Legible is not. It is a research and intelligence tool. It does not provide credit scores, financial advice, or AML/CFT certification; it collects no identity documents and verifies no natural person. New Zealand operates no accreditation scheme for AML/CFT technology vendors, and we hold no Digital Identity Services Trust Framework accreditation because we provide no digital identity service.
11. Privacy and breach notification
Do you follow the Privacy Commissioner’s breach-notification guidance? Yes. Glint Limited is subject to the Privacy Act 2020. Where a privacy breach has caused or is likely to cause serious harm, we notify the Office of the Privacy Commissioner and affected individuals as Part 6 of the Act requires, following OPC guidance. We hold an internal breach-response plan setting out containment, severity assessment, notification timelines and who else must be told.
- Privacy statement: structured around the 13 Information Privacy Principles, in the format the OPC recommends.
- Privacy impact assessments: we hold a whole-product PIA and a separate assessment covering the display of registered-office addresses.
- Access and correction: privacy@legible.nz, answered within the 20 working days the Act allows. Individuals who appear in register data are directed to the originating register, because corrections have to take effect at source.