Transparency
How we use AI
Deis uses generative AI in a small number of specific, bounded ways. This page is our public register of those uses — what AI does, what data goes in, and how we ensure humans remain in control of all decisions.
Our commitments
- ✓We disclose clearly when and where AI is used, at the point of interaction.
- ✓AI assists — it never makes final decisions. Humans are responsible for all outcomes.
- ✓We do not send personal data to AI providers beyond what is strictly necessary.
- ✓AI outputs are never binding — you can challenge, ignore, or correct them at any time.
- ✓We align with the NZ Government Responsible AI Guidance (digital.govt.nz) and the OECD AI Principles (transparency, accountability, human rights, robustness, safety).
Register of AI use cases
Privacy compliance chat assistant
Business portal — help sidebar; individual transparency portal
- AI model
- Anthropic Claude (claude-opus-4-8)
- What it does
- Answers questions about NZ Privacy Act compliance, DEIS features, and how to use the platform. Scripted responses are used for common questions; the Anthropic API is called for open-ended queries.
- Data sent to AI
- Your typed question and a short system context describing your role (business or individual). No personal data, lookup results, or request content is sent to Anthropic.
- Output
- Informational text displayed in the chat panel. It does not trigger any action or decision on your account.
- Human oversight
- The assistant cannot make changes to your account, submit requests, or take any action. All compliance decisions remain with you and your organisation.
- How to challenge
- If you believe a response was inaccurate or harmful, contact us through the platform.
OPC complaint coaching
Individual portal — 'File a complaint with the Privacy Commissioner' wizard (step 3)
- AI model
- Anthropic Claude (claude-opus-4-8)
- What it does
- Reviews the individual's draft complaint description and returns coaching suggestions — what is missing, what to strengthen, and which Privacy Information Principles may be engaged. It does NOT rewrite the complaint.
- Data sent to AI
- Your draft complaint text, the organisation name, complaint type, and verified dates/events from your DEIS thread record (e.g. when you submitted an access request, whether a response was received). No other personal data is sent.
- Output
- A list of numbered suggestions and a list of strengths displayed on screen. The suggestions are shown to you only — they are not sent to the OPC or to the business. You rewrite your complaint in your own words, which the OPC requires.
- Human oversight
- You review, edit, and approve everything before submission. The AI cannot submit anything on your behalf. The Office of the Privacy Commissioner asks that complaints be in your own words.
- How to challenge
- If you believe the suggestions were inaccurate or harmful, you can ignore them and continue, or contact us through the platform.
OPC form field assistance (browser extension)
privacy.org.nz — when you open the OPC self-assessment with the DEIS extension
- AI model
- Anthropic Claude (claude-opus-4-8)
- What it does
- Maps your Deis complaint draft to visible fields on the current OPC web form page. Suggests text for text areas and selections for radios/dropdowns. Cannot upload files for you.
- Data sent to AI
- Your structured complaint (organisation, complaint type, data held, request history, agency response, harm, desired outcome) and a snapshot of visible OPC form field labels/questions on the current page. Sent only when you are logged in to Deis and the extension calls our API from privacy.org.nz.
- Output
- Field fill suggestions applied in the browser on the OPC site. You can edit every value before submitting. OPC requires your final submission to be in your own words.
- Human oversight
- You control submission on privacy.org.nz. Deis does not lodge the complaint for you. Use coaching on Deis first, then review all extension-filled fields.
- How to challenge
- Disable the extension, fill the OPC form manually, or contact us if mapping was wrong.
Business contact resolution
Background — triggered when a privacy request cannot be routed to a registered business email
- AI model
- Anthropic Claude (claude-opus-4-8)
- What it does
- When a business has not registered a privacy contact email, DEIS attempts to identify a suitable contact using the business name and website (provided by the individual making the request) and publicly available information.
- Data sent to AI
- Business name and website URL only. No personal data about the individual is sent to Anthropic.
- Output
- A suggested contact email address used to route the privacy notification. A human (the DEIS system) validates the result before sending.
- Human oversight
- If no confident match is found, the notification is held and the individual is informed. The AI result is not acted upon without a plausibility check.
- How to challenge
- Businesses can register their official privacy contact email in DEIS settings to override this process.
AI provider
All generative AI features in Deis are powered by Anthropic. Anthropic's models are designed with safety and reliability in mind. Data sent to Anthropic is used only to generate the response for that request and is not used to train their models under our enterprise agreement.
Questions about our AI use? Contact us through the platform.
Last updated May 2026.