Privacy

How Clerq handles personal information

Last updated 29 July 2026

The short version

  • This website collects nothing about you. No cookies, no analytics, no tracking pixels, no third-party fonts.
  • Client files are stored in New Zealand.
  • We are not the owner of your clients' information — your practice is. We handle it on your instruction and for no purpose of our own.
  • Nothing you put in Clerq is used to train AI models, to benchmark, or for product analytics.

That summary is accurate but not complete. The detail is below.

Two different things, and the difference matters

This statement covers two situations that people often blur together, and the answers are different in each.

  • Visiting clerq.nz. You are reading a web page. Covered in the next section.
  • Information inside Clerq. A licensed immigration practice uses Clerq to run its files. The personal information in those files belongs to the relationship between that practice and its clients. Clerq acts as the practice's agent — we hold and process that information on the practice's instruction and may not use it for our own purposes. If you are an applicant whose adviser uses Clerq, your privacy relationship is with that practice, and its privacy statement governs.

This website

clerq.nz sets no cookies and loads nothing from a third party. There is no analytics tag, no advertising pixel, no embedded video, no chat widget, and no social button. The typeface is served from our own domain rather than from a font provider, specifically so that reading this page does not disclose your visit to anyone else.

Our hosting provider records standard technical request logs (an IP address, a timestamp, the page requested) in the ordinary course of serving the site. We do not combine those logs with anything else, and we do not use them to build a profile of you. If we ever add analytics, this page will say so before we do.

If you email us, we hold your message and your address so we can reply to you and keep a record of the conversation.

When your practice uses Clerq

What is held

Whatever the practice puts in: client contact details, matter and case records, deadlines, documents and their extracted text, correspondence and messages, appointments, file notes, engagement agreements, and the practice's own staff and licensing records. Immigration files routinely contain identity documents, health information, relationship evidence and financial records, and the system is built on that assumption rather than hardened for it afterwards.

Where it is held

On servers in New Zealand, in Amazon Web Services' Auckland region. Each practice's data is isolated from every other practice's, and that isolation is enforced by the database on every query rather than by application code remembering to filter.

Some services are not offered in New Zealand yet. Where that affects a practice — for example, if it takes up hosted email — we state it plainly in that practice's terms rather than leaving it to be discovered.

Who else is involved

We use a small number of service providers, and only these categories:

  • Cloud infrastructure — Amazon Web Services, in New Zealand, for storage, databases and compute.
  • An AI provider, outside New Zealand, for drafting assistance — under commercial terms that prohibit training on customer content and require deletion after termination. See the next section for what it actually receives.
  • Communication and payment services a practice chooses to connect, such as its own email provider or messaging accounts.

We do not sell personal information. We do not disclose it for marketing. We do not share one practice's information with another.

What the AI provider actually sees

Before any text is sent for drafting assistance, identifying details are replaced with placeholder tokens inside our own infrastructure, and the real values are restored on the way back. If that step is unavailable, the request fails rather than proceeding unprotected.

We are deliberate about what this does and does not achieve. Tokenising names and dates reduces risk; it does not, on its own, make a detailed file note anonymous, because identity in free text is often carried by a combination of attributes rather than by a name. We have tested this against realistic material, and the document types that do not survive the test are not sent at all.

Content sent for drafting assistance is not used to train any model. That is a contractual term with our provider, not an assurance we are asking you to take on trust.

How long it is kept

Retention of client files is the practice's decision, not ours — a practice has its own professional obligations, and we hold the files under its instruction. Clerq provides the tools to state and apply a retention period, and our suggested wording is ten years from the closure of a file.

When a practice leaves Clerq, we destroy the encryption key for that practice's data, which makes the stored information unreadable rather than merely marked as deleted.

Security

  • Data encrypted in transit and at rest, with a separate encryption key per practice.
  • Tenant isolation enforced at the database layer, so a defect in one feature cannot expose another practice's file.
  • Personal information held separately from operational records, with the operational side referring to people by opaque identifiers rather than by name.
  • A tamper-evident audit log, hash-chained so that a record altered or removed after the fact is detectable.
  • Access limited to the smallest set of people who need it, for the shortest time.

No system is beyond compromise. If a notifiable privacy breach occurs, we will notify the affected practice promptly so it can meet its own obligations under sections 114 and 115 of the Privacy Act 2020, and we will notify the Office of the Privacy Commissioner where we are required to.

Your rights

Under the Privacy Act 2020 you have the right to ask for access to personal information about you, and to ask for it to be corrected.

If you are an applicant or a client of a practice that uses Clerq, please direct that request to your adviser. They hold the information; we hold it for them, and it would not be right for us to release or change it without their instruction. We will support them in responding to you.

If you contacted us directly — for example, by emailing us about the product — write to privacy@clerq.nz and we will deal with it.

Complaints

If you think we have mishandled personal information, tell us first at privacy@clerq.nz. If you are not satisfied with how we respond, you may complain to the Office of the Privacy Commissioner at privacy.org.nz.

Changes

If we change this statement we will change the date at the top. Where a change materially affects how we handle information for practices using Clerq, we will tell those practices directly rather than relying on them to notice.

Contact

Clerq is a product of Trailblazer Labs Limited, New Zealand.
Privacy enquiries: privacy@clerq.nz
Anything else: hello@clerq.nz