security and privacy
Where your data lives, plainly.
Every claim on this page is one we will put in your proposal in writing. Where something is Anthropic's commitment rather than ours, we link their published policy instead of paraphrasing it.
Stored in your systems, processed by Anthropic.
Your files and email stay stored where they already are: your Google Drive or SharePoint, your Gmail or Outlook. Nothing is bulk-copied into a new database. The Brain reads your systems live through secure connections, so answers reflect the current version of a document, and cancelling leaves your data exactly where it always was.
Processing is a different thing, and we say it plainly: when your team asks the Brain a question, that question and the relevant content are processed by Anthropic on their infrastructure, primarily in the United States, under commercial terms. Most NZ businesses already run their email and files on offshore cloud services, so this is rarely a new exposure, but you should know it, not discover it.
Not used to train AI models.
On commercial Claude plans, your content is not used to train models by default. That is Anthropic's published commitment, and your proposal links it directly (see Anthropic's commercial terms and privacy documentation) rather than asking you to take our word for it.
Everyone sees only what they already see.
Connectors authenticate per person. Each staff member signs in with their own work account, and the Brain can only read what that login already allows. Nobody can use the Brain to open the directors' folder by asking nicely. Org-wide, your admin controls which connectors are permitted at all, and we verify the permission boundary with a test account in week one before your team ever uses it.
Some things are never connected.
Before anything is switched on, we agree a never-connect list in writing, signed by your decision maker and enforced at folder and permission level: payroll and remuneration, HR files and disputes, medical information, legal matters in progress, plus anything specific to your business. Your governance policy also bans pasting that material into any AI tool, ours or otherwise.
We never hold your credentials.
All connector setup happens screen-sharing with your admin present. Passwords are typed by your side only. There is no service account with broad access sitting in our hands, and when a staff member leaves, the offboarding checklist revokes their seat and their connections on their last day.
The Privacy Act 2020, for your adviser.
Paragraph to hand to your lawyer or privacy officer: personal information processed through Claude is disclosed to Anthropic, a US-based provider, for processing on the business's behalf. IPP 12 (disclosure outside New Zealand) is addressed through the contractual safeguards in Anthropic's commercial terms, under which the provider is bound to protect the information and not use it for its own purposes, including model training, by default. The business remains the agency for Privacy Act purposes and retains its access, correction and security obligations.
We are consultants, not lawyers, so we give you that paragraph to take to your adviser rather than legal advice. Happy to join the call.
Wrong answers, and the control for them.
AI output can be wrong. The control is procedural and human: high-stakes playbooks (quotes, pricing, anything contractual) always show their sources so a person verifies in seconds, and your adopted governance policy names what always needs human sign-off. The Brain drafts; your people decide, and that rule is written into your policy and our agreement, not just this page.
If you cancel.
Everything keeps working. Your Claude subscription is in your name and billed by Anthropic to you directly. Your data was never anywhere else. The documentation, playbooks and policy are handed over at week five and licensed for your internal use for good. There is no lock-in through us, deliberately.
Questions we have not answered here.
Ask them: kale@joinesdigital.com. If your IT provider wants the technical detail, we have a one-page brief written for exactly them, and if the honest answer to a question is "that depends on Anthropic", we will say so and show you where their policy states it.