Privacy
How Verafi handles personal information, and what you can ask of us.
Last updated 19 August 2026 · Governed by the New Zealand Privacy Act 2020
Who we are
Verafi is software for producing and keeping New Zealand electrical compliance certificates. It is run by Iain Colville, a registered electrician in Tauranga. Verafi is currently in early access and is not yet an incorporated company.
For anything on this page — including a request to see, correct or delete your information — email info@verafi.co.nz.
Two kinds of information, and they are treated differently
This distinction matters more than anything else on the page.
| What | Whose it is | Why we hold it |
|---|---|---|
| Your account name, email, phone, EWRB registration, signature |
Yours | To run the service, and because the regulations require a certifying person to be identified on the documents they sign. |
| Your customers' details names, addresses, contact details, site information |
Your customers' — you are responsible for it, and we hold it on your behalf | So you can produce certificates. We do not use it for anything else, and we never contact your customers. |
If you visit this website without an account, we collect nothing except what you type into the support form.
The support form on this site
It collects your name, email address and whatever you write in the message. We use them only to answer you, and we reply by email.
Please don't paste customer details into the message. A description of the problem is enough — you don't need to include a real client's name or address for us to help.
Support messages are kept while the matter is open and for a reasonable period afterwards so we can pick up a conversation you return to. There is no mailing list; we don't add you to one and there is nothing to unsubscribe from.
Where your information is stored
Certificates and account data are held in a Supabase database hosted in Sydney, Australia. Issued certificate PDFs are stored in Cloudflare R2. The website and application are served through Cloudflare.
Australia has privacy protections comparable to New Zealand's, as required by principle 12 of the Privacy Act. Information is encrypted while travelling and while stored.
Those certificate PDFs are held in Cloudflare R2's Oceania region, which covers Australia and New Zealand — the location Cloudflare reports for the bucket. It is not assigned to any other jurisdiction.
Who can see it
No other company using Verafi can see your information. That is enforced by the database itself, not by hiding buttons in the interface — a request for another company's data is refused at the point the data is read.
Iain can see it, because supporting the product and fixing faults sometimes requires it. We would rather tell you that than claim otherwise. It is not shared with anyone else, not sold, and not used for advertising or analytics profiling.
We keep a record of that access — when it happened and what was looked at — and you can ask us for it. We don't claim it is a complete or permanent log, because it isn't: it depends on a scheduled export, and a query that looks up records by reference notes the table rather than the individual row. We would rather describe what we actually have than a stronger version of it.
Information is disclosed outside Verafi only where the law requires it, or where you ask us to — for example, emailing a certificate to your client on your instruction.
We use these providers to run the service, and they hold information only to do so: Supabase (database and sign-in), Cloudflare (hosting and file storage), Resend (sending email). If you connect simPRO or Fergus, job details move between them and Verafi at your instruction.
How long we keep it
Issued certificates are kept for seven years and cannot be deleted, including by us. That is not a choice — regulation 74E of the Electricity (Safety) Regulations 2010 requires the record to be retained, and the storage is deliberately write-once so that it cannot be quietly altered.
Deleting a certificate from your list removes it from your working view. The archived copy remains for the retention period, because the duty attaches to the record rather than to your view of it.
Drafts, saved customers and account information are kept while your account is open. If you close your account we remove what we are not required to keep, and you can export everything you have issued at any time.
Keeping it safe
- Encrypted in transit and at rest.
- Separation between companies enforced by the database, and tested.
- Optional two-step sign-in, with recovery codes so a lost phone doesn't lock you out.
- Integration keys stored so that they cannot be read back — not by you, and not through the application.
- Issued documents written to storage that cannot be overwritten.
No system is perfectly secure, and we won't claim otherwise. What we can say is what we do, and the list above is checked rather than aspirational.
If something goes wrong
If a privacy breach happens and it is likely to cause serious harm, we will notify the Office of the Privacy Commissioner and the people affected as soon as we practicably can, as the Privacy Act requires. We will tell you what happened, what information was involved and what to do about it — in plain terms, not a legal notice.
What you can ask for
To see what we hold about you
Email us and we will tell you, normally within 20 working days, which is the maximum the Privacy Act allows. Most of it you can see in the app already.
To correct something
Account details you can change yourself under My account, or ask your administrator. Customer records you can edit directly.
An issued certificate cannot be changed — by you or by us. It is a legal record of what was certified on the day it was signed. If something on one is wrong, tell us: we will attach a statement of the correction you sought to the record, which is what the Privacy Act provides for where information cannot be altered. The usual remedy for a mistake on a certificate is to issue a corrected one, which your obligations as a certifying person may require anyway.
To complain
Tell us first — we would rather fix it. If you are not satisfied you can complain to the Office of the Privacy Commissioner at privacy.org.nz, 0800 803 909. Complaining to us does not stop you complaining to them.
Cookies and tracking
This website sets no advertising or analytics cookies and does not track you across other sites. The application stores what it needs to keep you signed in.
Changes to this page
If we change anything that materially affects how your information is handled, we will tell account holders by email rather than quietly editing this page. The date at the top always reflects the current version.