PRIVACY POLICY

Aera 22 Opco Limited

Last Updated: March 2026

1. About This Policy

This Privacy Policy explains how Aera 22 Opco Limited ('Aera', 'we', 'us', 'our') collects, uses, discloses and stores personal information about you. Aera operates an educational home-buying platform and mobile application (the 'Platform') that provides personalised financial coaching, savings tracking, educational modules, and AI-assisted guidance to help New Zealanders achieve homeownership.

This policy governs your use of our website at aera.nz, our mobile application, and any related products or services (collectively, the 'Services'). It should be read alongside any applicable terms and conditions.

We are committed to complying with the Privacy Act 2020 and the information privacy principles set out in that Act. If you have any questions about this policy or wish to access or correct information we hold about you, please contact us at support@joinaera.co.

Acceptance

By applying for, accessing or using our Services, or by providing us with personal information, you acknowledge that you have read and understood this Privacy Policy and agree to the collection, use and disclosure of your information as described here.

Amendments

We may update this Privacy Policy from time to time. We will notify you of significant changes via the Platform or by email. Continued use of our Services after the effective date of any update constitutes your acceptance of the revised policy.

2. Who Collects Your Information

Your personal information is collected and held by:

Aera 22 Opco Limited

Spaces, 110 Carlton Gore Road, Newmarket, Auckland, New Zealand

Email: support@joinaera.co

Where we share your information with related entities or third-party service providers (including mortgage brokers or financial advisers), those parties will handle your information in accordance with their own privacy policies.

3. Information We Collect

The type of information we collect depends on the Services you use and the purposes for which it is collected. We may collect:

Identity and Contact Information

  • Full name, email address, phone number
  • Residential location or region
  • Date of birth and residency status (where relevant for financial assessment)

Financial Information

  • Household income, savings balances, debt levels and monthly savings rate
  • Target property price and estimated borrowing capacity
  • Account balance and earnings data from connected savings platforms (such as Blossom)
  • Debt-to-income ratio, years to deposit, and other derived financial metrics
  • Credit history and creditworthiness information (where relevant to the Services)

Behavioural and Assessment Data

  • Results from behavioural and financial readiness assessments completed through the Platform
  • Readiness scores, coaching profiles and derived behavioural categories
  • Progress through educational modules and course completions
  • Platform usage patterns, milestone achievements and engagement data

AI Coaching Interaction Data

  • Messages and conversations with Senna, our AI-powered coaching assistant
  • Note: when you interact with Senna, we do not pass your full name, email address or phone number to the AI system. You are identified only by an anonymous identifier. If you choose to share personal details within the chat, that information may be retained as part of your conversation history.

Technical and Device Information

  • Device type, operating system, app version and device identifiers
  • Push notification tokens (used to send you alerts and updates)
  • App usage data, session information, and feature interaction logs
  • IP address and approximate geolocation derived from your device or network
  • Cookies and similar tracking technologies when you use our website

Property and Shortlist Data

  • Properties you shortlist or express interest in through the Platform

Communications

  • Messages and support requests you send to us
  • Responses to surveys, feedback forms or promotions

4. How We Collect Information

We collect personal information when you:

  • Register for or use our Platform or Services
  • Complete financial benchmarking or behavioural assessments
  • Engage with Senna, our AI coaching assistant
  • Complete educational modules or quizzes
  • Contact us by email, phone or through the app
  • Shortlist properties or interact with property features
  • Connect a savings account or provide financial data
  • Subscribe to newsletters or participate in promotions
  • Apply for employment with us

We may also collect information from third parties, including savings platforms you connect to the Platform, and from publicly available sources.

If you provide us with personal information about another person (for example, a joint applicant), you confirm that you have their consent to do so and have informed them of the terms of this Privacy Policy.

5. How We Use Your Information

We use your personal information to:

  • Assess your eligibility for and provide our Services
  • Generate personalised financial benchmarks, readiness scores and coaching recommendations
  • Power the Senna AI coaching assistant with relevant contextual information about your financial journey (using anonymised identifiers)
  • Track your progress through educational content and milestone achievements
  • Match your profile to relevant property opportunities
  • Communicate with you about your account, progress and the Services
  • Send you notifications, reminders and coaching prompts (where you have enabled these)
  • Verify your identity and conduct anti-money laundering checks as required by law
  • Refer you to mortgage advisers or related financial service providers where you request this
  • Improve, develop and test the Platform and our AI systems
  • Conduct internal analytics and research
  • Comply with our legal obligations
  • Send you marketing communications about our Services (where you have provided consent)

We will not use your personal information for any purpose that is inconsistent with this policy or that you would not reasonably expect, unless we have your consent or are required to by law.

6. Disclosure of Your Information

We may share your personal information with:

Service Providers and Technology Partners

We engage third-party service providers to operate and improve our Services. These include:

  • Supabase, Inc: Our primary database and infrastructure provider. Your data is stored on servers located in Sydney, Australia (AWS ap-southeast-2 region). Supabase processes your data under a Data Processing Addendum in accordance with applicable privacy laws.
  • OpenAI, LLC: We use OpenAI's language models to power the Senna AI assistant. Only anonymised identifiers and non-personally-identifiable context are passed to OpenAI. Conversation content may be processed on OpenAI's infrastructure subject to their data processing agreements.
  • Twilio Inc: For sending SMS notifications
  • Resend: For sending transactional emails
  • Ortto: Our customer data platform used for engagement and analytics
  • Firebase (Google LLC): For push notifications and device authentication
  • Cloudflare, Inc: For web infrastructure and content delivery

Financial and Mortgage Service Partners

Where you have requested mortgage advice or referral, we may share relevant information with licensed mortgage advisers or financial service providers. These partners handle your information under their own privacy policies and applicable regulatory obligations.

Savings Platform Partners

If you connect a savings account (such as Blossom), relevant balance and earnings data may be shared or synchronised with that platform.

CRM and Analytics

We use Pipedrive as our CRM platform and may sync certain account and progress data to it for relationship management purposes.

Legal and Regulatory Disclosure

We may disclose your information where required or permitted by law, including to government departments, regulators, law enforcement agencies, and our professional advisers (including lawyers and accountants).

Business Transfers

If we are involved in a merger, acquisition or sale of all or part of our business, your information may be transferred as part of that transaction.

7. Credit Checks

We may use credit reporting agencies to assess your financial status in connection with certain aspects of our Services, or to assist in matching you with appropriate financial services. We may share relevant information with those agencies, and they may provide us with information they hold about you. Credit reporting agencies' use of your information is governed by their own privacy policies.

8. AI-Powered Services

Our Platform includes Senna, an AI coaching assistant powered by large language models and a retrieval-augmented knowledge base. When you use Senna:

  • You are identified to the AI system only by an anonymous identifier and your first name. We do not pass your full name, email address or phone number to the AI.
  • Contextual information about your financial situation, learning progress and behavioural profile is used to personalise responses. This information is derived from your Platform data.
  • Conversation history is stored in our database and may be used to maintain context across sessions.
  • If you voluntarily share personal details (such as your full name or contact information) within a chat message, that information may be retained as part of the conversation record.
  • AI responses are generated automatically and are not reviewed by a human in real time. They are intended as general guidance only and do not constitute financial, legal or professional advice.
  • We may use anonymised conversation data to improve our AI systems and knowledge base.

9. Cookies and Tracking Technologies

Our website uses cookies and similar technologies to:

  • Maintain your session and preferences
  • Understand how visitors use our website
  • Support marketing and analytics

You may disable cookies in your browser settings. Some parts of our website may not function correctly if cookies are disabled. Our mobile application does not use browser cookies but may use equivalent device-level identifiers for analytics and session management.

10. Data Storage and Security

Where Your Data is Stored

Your personal information is stored on servers located in Sydney, Australia, operated by Supabase using Amazon Web Services (AWS ap-southeast-2 region). While this means your data is held outside New Zealand, we have ensured that appropriate contractual safeguards are in place through our Data Processing Addendum with Supabase, which requires Supabase to handle your data in a manner consistent with applicable privacy laws.

Some information may also be processed by our other service providers, who may operate in various countries. Where this occurs, we take reasonable steps to ensure those providers handle your information with an appropriate level of protection.

Security Measures

We take reasonable steps to protect your personal information against unauthorised access, loss, misuse or alteration. Our security measures include:

  • All data encrypted at rest using AES-256 encryption
  • All data transmitted over encrypted connections (TLS)
  • Access controls based on the principle of least privilege
  • Row-level security on our database to ensure users can only access their own data

Despite these measures, no transmission of data over the internet is completely secure. You use our Services and transmit information at your own risk.

11. Data Retention

We retain your personal information for as long as necessary to provide our Services and fulfil the purposes outlined in this policy. Retention periods are also influenced by our legal obligations, dispute resolution needs and enforcement of our agreements.

In general:

  • Account data is retained for the duration of your account and for a reasonable period after closure
  • Financial benchmark data is retained while you are an active user and for a period thereafter in accordance with our legal obligations
  • Behavioural assessment results are retained to support longitudinal coaching and progress tracking
  • AI conversation history is retained to maintain coaching continuity
  • Transactional and legal records are retained for the periods required by applicable law

You may request deletion of your personal information at any time. We will action such requests subject to any legal requirements to retain certain data.

12. Push Notifications and Marketing

We may send you push notifications through our mobile app and email communications about your account, progress and our Services. You can manage notification preferences within the app settings at any time.

Where you have consented to receiving marketing communications, we may send you information about our Services and related offerings. You may withdraw this consent at any time by contacting us at support@joinaera.co or by using the unsubscribe function in any of our marketing emails. We comply with the Unsolicited Electronic Messages Act 2007 in relation to commercial electronic messages.

13. Your Rights

Under the Privacy Act 2020, you have the right to:

  • Request access to the personal information we hold about you
  • Request correction of information that is inaccurate, out of date or incomplete
  • Request deletion of your personal information (subject to legal retention requirements)
  • Lodge a complaint if you believe we have breached our obligations under the Privacy Act 2020

To exercise any of these rights, please contact us at support@joinaera.co. We will respond within a reasonable timeframe and in accordance with the requirements of the Privacy Act 2020.

If you are not satisfied with our response, you may contact the Office of the Privacy Commissioner:

Office of the Privacy Commissioner

PO Box 10-094, The Terrace, Wellington 6143

Phone: 0800 803 909

Website: https://www.privacy.org.nz

14. Children

Our Services are intended for adults aged 18 and over. We do not knowingly collect personal information from individuals under 18. If you believe we have inadvertently collected information from a minor, please contact us at support@joinaera.co and we will take steps to delete that information.

15. Links to Third-Party Sites

Our Platform may contain links to third-party websites or services. This Privacy Policy does not apply to those sites. We are not responsible for the privacy practices of third parties and encourage you to review their privacy policies before providing any personal information.

16. Contact Us

If you have any questions about this Privacy Policy or the way we handle your personal information, please contact:

Aera 22 Opco Limited

Level 9, 55 Shortland Street, Auckland 1010, New Zealand

Email: support@joinaera.co

Website: aera.nz

How much can I borrow?
What's a First home finder?
Am I too late to Join?
What are Aera Credits?