← Trust Centre/ Compliance

What we comply with today,
and what we're working toward.
In writing.

Enterprise partners ask three questions: what do we comply with, why does it matter, and how can it be verified? This page answers all three — the current compliance posture of Whaitiri Black Limited (trading as GIWAHS), dated, in writing, and backed by the documents in the Trust Centre library.

Open the pre-signed DPA
/ 01 — Status board
Aligned frameworks
10 in force today — detailed below
DPA status
Published v1.0 — pre-signed by GIWAHS
Standardised questionnaires
Supported on request — see §06
/ 02 — Frameworks we comply with

Aligned today.

FrameworkStatusReference
EU GDPR (Regulation (EU) 2016/679) AlignedPrivacy Policy · DPA · Security Policy
UK GDPR + Data Protection Act 2018 AlignedPrivacy Policy · DPA · Security Policy
Swiss FADP (revised 2023) AlignedData Processing Agreement
NZ Privacy Act 2020 AlignedPrivacy Policy · Security Policy
Australian Privacy Act 1988 + APPs AlignedPrivacy Policy · Security Policy
California CCPA / CPRA AlignedPrivacy Policy
Colorado · Virginia · Connecticut · Utah · Texas AlignedPrivacy Policy
ePrivacy Directive + PECR (UK) AlignedCookie Policy
PCI-DSS (via Stripe outsourcing — SAQ-A scope) AlignedSecurity Policy
CAN-SPAM · CASL · NZ UEMA · AU SPAM Act AlignedPrivacy Policy
/ 03 — Working toward

Honest roadmap, with dates.

FrameworkTargetStatus
SOC 2 Type I Year 1–2Planning — scope being defined
SOC 2 Type II Year 2Following Type I
ISO/IEC 27001 Year 2–3Gap analysis after SOC 2 Type I
FedRAMP Not in scope
/ 04 — Data residency & transfer mechanisms

Where your data lives, and how it travels.

Data categoryPrimary residencyMechanism (EU/UK/CH origin)Mechanism (NZ/AU origin)
Application data (DB, auth, storage) Supabase / AWS (region configurable)EU SCCs · UK IDTANZ IPP 12 · APP 8
Payment metadata Stripe (USA primary)EU SCCs · UK IDTA · PCI-DSS L1Contractual safeguards
Email content + delivery metadata Resend (USA primary)EU SCCs · UK IDTAContractual safeguards
Edge / network logs Cloudflare (global POPs)EU SCCs · UK IDTAContractual safeguards
Corporate email & files Google Workspace (USA primary)Google DPA + EU SCCsContractual safeguards
LLM API (gated, currently disabled) OpenAI (USA primary)OpenAI DPA + EU SCCsContractual safeguards

Full Subprocessor Register — available in the Trust Centre document library.

/ 05 — Data Processing Addendum (DPA)

Three paths.

  1. 1. Self-serve. Open the Data Processing Agreement from the document library. Customer countersigns by reply email.
  2. 2. Email-back countersignature. Send your signed copy to legal@giwahs.com; we counter-sign and return within 2 business days.
  3. 3. Custom DPA. Enterprise tier — we accept reasonable amendments. Material changes extend turnaround to 5–7 business days.
Email legal@giwahs.com
/ 06 — Enterprise procurement support

SLAs you can plan around.

  • Acknowledgement: within 2 business days.
  • 250-Q standard questionnaire: 5 business days (Enterprise) · 10 business days (Gold / Elite).
  • NDA: mutual same-day countersignature; ours available on request.
Email security@giwahs.com
Compliance & questionnaires
security@giwahs.com
Privacy & DPA
privacy@giwahs.com
/ Companies Office verification

Verify us independently.

Whaitiri Black Limited (trading as GIWAHS) is a registered New Zealand company. Company details may be independently verified via the New Zealand Companies Office and the NZBN Register.

IdentifierValueVerify on
NZ Companies Office number6860633 Companies Office Aotearoa NZ
NZBN9429046803306 NZBN Register
NZ GST number125-955-886 Whaitiri Black Limited is NZ GST-registered. Tax invoices via Stripe Tax.

NZ GST № 125-955-886. Director: Jay Elkington (100% shareholder). Company registration details are available via the NZ Companies Office register linked above.

© Whaitiri Black Limited · trading as GIWAHS. Registered in New Zealand.NZ Company № 6860633·NZBN 9429046803306·NZ GST 125-955-886·Companies Office NZBN Register