Privacy Policy
Last updated: 24 June 2026
Welcome to Res Ipsa Limited (“we”, “us”, “our”). We are committed to protecting your personal information and handling it with transparency and care. Our service (the “Service”) is a legal research platform that lets you search a corpus of case law and legislation, either through our web library or through an AI assistant you connect to our Model Context Protocol (MCP) connector.
We have built the Service to hold as little of your information as possible. We do not store the content of your searches, we accept no document uploads, and we do not build a profile of the substance of your legal research. The only records we keep of your use are your account information and access audit logs.
This Privacy Policy explains how we collect, use, store, and disclose your personal information in compliance with New Zealand’s Privacy Act 2020. By accessing or using the Service, you consent to the collection, use, and disclosure of your information as described in this policy.
1. Definitions
- “Personal Information” means information about an identifiable individual, as defined in the Privacy Act 2020.
- “Queries” means the search terms you submit to the Service, whether through the web library or through a connected AI assistant.
- “Audit Logs” means the records we keep of access to the Service: which account made a request, which tool or feature was used, when, and whether it succeeded. Audit Logs do not contain the content of your Queries.
2. What information we collect
Information you provide directly
- Account Information: When you register for an account, our identity provider collects Personal Information such as your name, email address, and professional details (e.g., law firm or organisation name). Your password and login credentials are managed by that identity provider, not by us.
- Billing Information: If you subscribe to a paid plan, we collect payment information. This is processed securely by our third-party payment processor, and we do not store your full credit card details.
- Communications: When you contact us for support or other enquiries, we collect your name, contact details, and the content of your message.
Information we process to run a search
When you run a search, your Query is processed in real time — including by a third-party embedding provider — to return results. We do not store the content of your Queries after the request is served. The Service does not accept document uploads.
Information we collect automatically
- Audit Logs: We automatically record access metadata each time the Service is used — the account involved, the tool or feature invoked, the time, and the outcome. We use this for security, abuse-prevention, billing accuracy, and to show you your own activity. Audit Logs do not include the text of your Queries.
- Cookies: We use a small number of strictly necessary cookies to operate the Service (for example, to keep you signed in). We do not use third-party advertising or cross-site tracking cookies.
3. How we use your information
Our primary purpose for collecting information is to provide and secure the Service.
- To Provide the Service: We use your Account Information to manage your account, and we process your Queries in the moment to return research results.
- To Secure the Service: We use Audit Logs to detect and prevent abuse, enforce rate limits, investigate security incidents, and maintain the integrity of the Service.
- To Bill You: We use your Billing Information to process payments for your subscription.
- To Communicate with You: We use your Account Information to send you service-related updates (e.g., maintenance, security alerts), respond to your support requests, and (if you opt in) provide marketing communications.
- To Show You Your Activity: We use Audit Logs to display a record of your own recent use within the Service.
Our commitments
- We do not store the content of your Queries, and we do not use your research activity to train any indexing, embedding, or other machine-learning models.
- We do not sell your Personal Information or Audit Logs.
- Human access is strictly limited. Our personnel do not access your account data or Audit Logs unless strictly necessary to resolve a technical support issue you have reported, or if required to comply with a legal obligation. All such access is controlled and subject to strict confidentiality agreements.
4. How we share and disclose information
We will not disclose your Personal Information except in the limited circumstances described here:
- Service Providers: We share information with trusted third-party providers who help us operate the Service — for example, cloud hosting providers, our identity provider, our payment processor, and the indexing and embedding provider that processes your Queries in real time to generate results. These providers are contractually bound to only use the information for the specific purpose we have engaged them for, and to implement security measures comparable to our own.
- Legal Obligations: We may disclose your information if required to do so by New Zealand law, or in response to a valid legal request (e.g., a court order or subpoena). We will attempt to notify you of such requests unless prohibited by law.
- Business Transfer: If we are involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change in ownership or control.
- With Your Consent: We may share your information in other ways if you have given us your explicit consent to do so.
5. Data storage, security, and retention
Security
We take our security obligations under Privacy Principle 5 seriously. We implement robust technical and organisational safeguards to protect your Personal Information from loss, unauthorised access, use, modification, or disclosure. These measures include encryption of data at rest and in transit, strict access controls and authentication, regular security audits and vulnerability assessments, and staff training on data privacy and security.
International data transfers
The Service may be hosted by, or rely on, third-party providers with servers located outside of New Zealand. If we transfer your Personal Information offshore, we will comply with Privacy Principle 12 by ensuring it is protected by safeguards that are at least comparable to those in the Privacy Act 2020.
Retention
We comply with Privacy Principle 9 by not keeping your information for longer than is necessary for the purposes for which it may be lawfully used.
- We retain your Account Information for as long as your account is active and for a reasonable period afterwards for legal or auditing purposes.
- We retain Audit Logs for a limited period for security, abuse-prevention, billing, and legal purposes.
- We do not retain the content of your Queries after a request is served.
- We may retain anonymised and aggregated data indefinitely.
Security breach notification
If we experience a breach of security leading to any accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or unauthorised access to your Personal Information (“Personal Data Breach”), we will notify you and the Office of the Privacy Commissioner without undue delay after becoming aware of it, where required to do so under the Privacy Act 2020.
6. Your rights: access, correction, and deletion
You have rights under the Privacy Act 2020 to access, correct, and request the deletion of your Personal Information.
- Access and Correction: You can access and update most of your Account Information directly through your identity provider’s portal, linked from your account page. For any other information, or if you need assistance, please contact our Privacy Officer.
- Deletion: You may request the deletion of your account and associated Personal Information by contacting us. We will process your request in accordance with our legal obligations. Because we do not store the content of your Queries, there is no research content for us to delete.
Where you use the Service as an organisation (e.g., a law firm) and we receive a legally binding request for disclosure of your information from a law enforcement authority, or a notice or inquiry from a supervisory authority such as the Office of the Privacy Commissioner, we will — to the extent legally permitted — inform you before responding.
7. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. If we make significant changes, we will notify you by email (at the address associated with your account) or by posting a prominent notice within the Service. We encourage you to review this policy periodically.
8. Contact us
If you have any questions, concerns, or complaints about this Privacy Policy or our privacy practices, please contact our Privacy Officer:
Res Ipsa Privacy Officer
Email: [email protected]
If you are not satisfied with our response, you have the right to lodge a complaint with the New Zealand Office of the Privacy Commissioner (www.privacy.org.nz).