Translations are provided for convenience. The English version is the authoritative version.
Effective 4 October 2026.
1. Who we are
Tockly, Tockly Equine and TocklyVet are operated by Tockly Limited (company number 9459698), the New Zealand agency responsible for the personal information described here. This policy covers our public websites and account, invoicing, reminders, payment, accounting, Capture, dictation, calendar, notes, reporting and animal-management features where available.
Privacy Officer: contact@tockly.ai
Registered office: Level 6, 135 Broadway, Newmarket, Auckland 1023, New Zealand.
2. Our role
Tockly Limited determines the purposes and means of processing account, subscription, security, support and service-operation information (a controller where EU or UK law applies). For Customer Data supplied or imported by a subscribing business, including its customers, owners, staff, invoices, worksheets, notes and animal records, that business generally determines the purposes and lawful instructions, and Tockly acts as its processor. Connected providers may be separate controllers for their own services. Our Data Processing Terms describe our obligations to subscribing businesses.
3. Information we handle
- Account and business details, including names, email addresses, roles, workspace settings and authentication records.
- Subscription status, transaction identifiers and limited billing metadata.
- Customer and invoice information, including contact details, invoice numbers, amounts, dates, currency, status, notes and attachments.
- Tockly Equine information, including horse records, ownership interests, owner and supplier details, programmes, daily charges, procedures, business profiles and invoice records.
- TocklyVet information, including practice clients, animal records, consultations, clinical notes and revision history, medical alerts, weight records, hospital admissions and care tasks, diagnostic requests and results, appointments, staff access, stock batches and movements, estimates, deposits, invoices, payments, credit notes, client communications and uploaded files.
- Tockly Capture information, including worksheet photographs, extracted text, proposed charges, review decisions, approved handwriting or name matches, and the horse, client and expense catalogue context needed to interpret a worksheet.
- Information received through authorised integrations with Xero, MYOB or QuickBooks Online through Intuit, including organisation or company-file identifiers, customer contacts, authorised unpaid sales invoices, payment-status information and connection credentials.
- Reminder activity, including recipients, delivery events, email opens, link use, promises to pay, disputes and reported payment dates.
- Technical and security information, including IP address, browser, device, timestamps, session records, errors and diagnostic logs.
- First-party website analytics across Tockly’s public websites, including Tockly Equine, such as the public page visited, approximate country, region and city, referring website, timestamp, anonymous browser and session identifiers, and an automated-traffic indicator. These identifiers are used to distinguish visitors, sessions and page loads. Tockly does not store IP addresses in its page-view analytics records.
4. Where information comes from
Information may come directly from an account holder or reminder recipient; from the business using Tockly; from an authorised connected service such as Xero, MYOB or QuickBooks; automatically through use of Tockly, its emails and security systems; or from service providers needed to operate and secure Tockly.
5. How we use information
We use information to administer accounts and subscriptions; create, import and store invoices and contacts; prepare editable proposals from selected images or dictated details; maintain horse, animal, care and ownership records; save notes and calendar entries; deliver selected reports, invoices and reminders; record payments and responses; provide reports, statements and downloads; apply language preferences; support authorised integrations; secure the service; prevent misuse; meet legal obligations; and establish or defend legal rights. We do not sell personal information.
When you connect MYOB, Tockly processes the authorised customer, invoice and payment-status information needed for your selected features. When you request a supported invoice upload, Tockly sends the relevant customer details, invoice number, dates, notes, individual line descriptions, quantities, prices, tax and totals to your connected accounting service. Xero and QuickBooks can also receive the invoice PDF. MYOB uses its own invoice layout. Connected accounting services may be refreshed on Tockly’s scheduled sync as well as through Sync now. These providers handle information under their own privacy policies.
Where UK or European data-protection law applies, Tockly relies on performance of its contract to provide requested account features; legitimate interests in operating, securing and improving a business service and communicating about invoices; consent where the law or a connected service requires it; and compliance with legal obligations. The subscribing business is generally responsible for identifying the lawful basis for Customer Data it directs Tockly to process.
6. Reminder recipients and indirect collection
Tockly often receives recipient information from the business using Tockly or through Xero, MYOB or QuickBooks rather than directly from the recipient. The subscribing business must have authority to supply that information and instruct the communication. Reminders identify the business responsible for the invoice and that Tockly sends the message on its behalf. A recipient can contact that business or Tockly about a wrong recipient, privacy concern or disputed invoice.
7. Email tracking
Reminder emails may contain a small tracking image or uniquely coded links. These may indicate that an email was opened, a link was used or a response was submitted. Tracking can be affected by email-client privacy settings and is not always accurate. We use it to show follow-up activity, support reminder workflows and protect link security.
8. When information is disclosed
We disclose information as reasonably necessary to authorised workspace users, recipients you select, connected services, the providers described below, professional advisers, regulators or parties required by law. A recovery handover currently emails the account holder an invoice and recorded follow-up summary; it is not an automatic referral to an external collector. If the business forwards that summary to a debt-collection agency or lawyer, that recipient receives the customer, invoice, communication and response information included. The business must have a lawful basis for that disclosure. Additional reminder recipients are delivered messages separately or by blind copy so their addresses are not disclosed to one another.
9. Service providers and overseas processing
Providers used for the relevant features include OpenAI for the Sites platform and, separately, its API for Help, Capture, note transcription, invoice dictation, optional note rewriting and interface translation; Cloudflare for computing, databases, file storage, security and approximate visitor location; Resend for email; Microsoft and Google for customer-connected business mailboxes and Microsoft for fallback email; ClickSend for SMS delivery; GoDaddy for domain, DNS and Microsoft 365 administration; ExchangeRate-API for indicative currency rates; Xero, MYOB and Intuit for authorised accounting integrations; and Stripe for subscriptions and supported customer payments. When an account expressly connects and uses an available WhatsApp delivery feature, Meta/WhatsApp receives the selected recipient number, template parameters and report link. A provider is used only for the applicable feature or connection. Exchange-rate requests do not include customer or account information.
Information may be processed through global infrastructure outside New Zealand, including Australia, the United States, the United Kingdom and the European Economic Area, depending on the provider and configuration. We use encrypted connections, access controls and limited feature-specific payloads. For overseas disclosures covered by New Zealand Privacy Act principle 12, we must establish reasonable grounds for comparable protection through applicable law or enforceable contractual safeguards, or another permitted basis. Overseas processors acting only on our instructions must protect the information and restrict their use and onward disclosure. Provider privacy policies alone do not replace these requirements. Where EU or UK transfer rules apply, an applicable adequacy decision or appropriate safeguards, such as EU Standard Contractual Clauses and the UK Addendum or IDTA with any required transfer assessment, must cover the transfer. Where Australian APP 8 applies, reasonable steps to ensure the overseas recipient protects the information are required, subject to statutory exceptions. Ask our Privacy Officer for information about the safeguards applicable to a particular transfer; we do not promise that all data stays in New Zealand or in your country.
Tockly uses optional first-party public-page analytics only after you enable it in the website footer. Random visitor and session identifiers, the page and approximate location can be recorded as explained in the Cookie Notice. Analytics is off by default and can be turned off again. Tockly does not currently use a third-party advertising or analytics service. For an SMS you choose to send, ClickSend and its delivery partners receive the destination number, message text, sender information and delivery metadata. Mobile carriers and recipient email or calendar services also process communications under their own arrangements.
10. AI and automated tools
Tockly Help uses a generative AI service supplied by OpenAI to answer product-support questions. Tockly sends the text a signed-in user types into the help conversation and a short portion of that conversation; it does not automatically send contacts, invoices, amounts or data from connected accounting services. Users should not enter personal, financial or confidential information into Tockly Help. Responses may be inaccurate and should be checked before relying on them. Tockly does not use Help conversations to make solely automated decisions that produce legal or similarly significant effects, and requests are made with provider-side response storage disabled.
When a user chooses Tockly Capture, Tockly sends the selected note, diary page or worksheet image to OpenAI's API together with relevant records from that user's own workspace. For general invoicing, that context may include the business's client register and saved invoice items. For Tockly Equine, it may also include horse names and pedigrees, approved handwriting or name corrections, private client interpretation notes, ownership relationships, and expense catalogue entries. For TocklyVet, the context may include that practice's animal register and the selected day sheet photo. This information is supplied to propose charges for the signed-in business or practice. Customers should avoid including unrelated personal or sensitive information in images or interpretation notes.
Invoice dictation can send a recording to OpenAI for transcription. The transcript, customer names and, in Equine mode, horse and stable names are then sent to OpenAI to propose editable invoice details. Tockly does not add the uploaded audio to retained workspace storage in this workflow; invoice text is retained when you save it. Browser-provided voice dictation is a separate option and may send audio to the device or browser provider under its privacy terms. Note Capture sends the selected image and the selected contact, horse or owner label to OpenAI; the resulting note is saved when you choose to save it. Avoid recording people without authority or including unrelated sensitive information. When you request AI polishing of an Equine departure or handover note, that note text is sent to OpenAI and the proposed wording is returned for your review.
Capture and dictation produce proposals for human review, not autonomous accounting decisions. Review the original and every proposed match, quantity, price, tax and description before saving, approving or sending. Equine retains selected worksheets and review history until deletion; general invoice and note Capture do not add the source image to that retained worksheet history. Responses API requests disable response storage, but this is not a guarantee of zero retention: OpenAI describes abuse-monitoring logs that may contain prompts and outputs and are normally retained for up to 30 days, with longer retention for legal or safety reasons. Its audio-transcription endpoint currently lists no application-state or abuse-monitoring retention. OpenAI states that API data is not used to train its models by default unless the API customer opts in. Tockly does not use these workflows to make solely automated decisions with legal or similarly significant effects. Interface translation sends registered product wording, not customer invoices or notes; language changes do not automatically translate customer-entered descriptions.
11. Security
New passwords are uniquely salted and hashed using bcrypt. Older PBKDF2-SHA-256 password records are upgraded after a successful login, and passwords are not stored in readable form. Tockly uses encrypted connections, access controls, credential protection and restricted administrative access. Users are automatically signed out after 60 minutes of inactivity. No online system can be guaranteed completely secure.
12. Retention and deletion
Account owners can permanently delete their own account through Account settings → Delete account or request deletion by emailing contact@tockly.ai. Download and check your account export first if you need the records. Deletion closes the same login across Tockly, Equine and Vet, cancels the linked subscriptions and revokes its sessions and sharing feeds. A staff account cannot delete another business’s practice records. Uploaded files are removed after database deletion; failed file cleanup is queued for retry. A minimal receipt containing an account identifier and cleanup status is retained for cleanup and recovery-control purposes, without invoice or customer content.
- Open invoice records remain available until deleted by the user or the account is closed. Paid invoices, their attachments and their invoice-specific activity history that were imported from a connected accounting service are ordinarily deleted from active storage 30 days after payment is recorded, unless a longer period is required below.
- Removing an invoice created and issued through Tockly, including a sent, paid or void invoice, from the normal workspace view archives its audit record rather than erasing it. These records are an exception to the ordinary 30-day cleanup for paid imported invoices. Businesses may need to retain tax and audit records for at least seven tax years, or longer where law requires. Permanent account deletion is different from hiding an invoice and can remove the workspace records, including issued invoices; export invoices, attachments and audit history before requesting permanent deletion. Tockly is not a substitute for your own legally required archive. Records that Tockly must retain for its own legal obligations are excepted from erasure and restricted to those purposes.
- Deleted items are removed from active application storage, subject to reasonable processing time and provider recovery systems.
- Tockly Equine Capture worksheet photographs and their review records remain available in that business's Capture history until an authorised user deletes the worksheet or the account is closed. General-invoicing Capture images are processed for the current proposal and are not added to that retained history. Deleting an Equine worksheet removes its active image and review record, but does not reverse charges already approved into horse or invoice records. Approved handwriting or name corrections may remain to support future Capture matching until the relevant record or account is deleted.
- TocklyVet day sheet photographs and review records remain in the practice's private Capture history during testing, until the account is closed or the records are removed on request. Approved charges remain in the practice's billing records.
- Provider-managed database recovery and infrastructure backups are separate from Tockly-managed snapshots. Their account-specific retention and final-erasure timeframes are being confirmed with the hosting operator. The 30-day Tockly snapshot window is not a guarantee that every provider copy is erased within 30 days.
- On verified permanent account deletion, reminders stop and active workspace records are removed through the account-deletion process. Cancellation of a subscription alone does not delete the account. Recovery or backup copies can outlast removal from the active service and are restricted to recovery, security and legal purposes; any restoration must respect deletion requests. Tockly-managed database snapshots and file manifests use a 30-day rolling retention window. Archived versions of changed or deleted files expire after 30 days; the current version of a file remains protected while it is in active use. Permanent account deletion also removes that account’s archived files, with failed cleanup retried. Cleanup runs through the scheduled service cycle; failures are recorded for operational attention. Provider-managed recovery history follows the separate limitations described above. Recovery preparation must use a current deletion ledger to exclude deleted accounts and their files, and revoke historical sessions. This does not promise erasure of legally required provider records or copies held independently by recipients. Ask our Privacy Officer about the status and applicable retention of a particular deletion request.
- Security, delivery, suppression and anti-abuse records may be kept for up to 12 months, or longer where needed for an investigation or legal obligation.
- Tockly’s own billing, tax and legally required business records may also be kept for at least seven tax years.
Disconnecting Xero, MYOB or QuickBooks stops future access through that connection. Imported open invoices remain until deleted or paid; paid imported invoices ordinarily follow the 30-day deletion rule above. Issued Tockly invoices are excepted from ordinary paid-import cleanup; their archive and permanent account-deletion treatment is explained above.
ClickSend support has advised that full message content and attached media are normally retained for four months, after which content is removed and limited delivery metadata, including to/from numbers, dates and delivery status, remains. The maximum retention of that metadata and expiry of provider backups after account deletion have not yet been confirmed. Removing an SMS record in Tockly does not itself erase carrier or provider copies. Contact our Privacy Officer for a request concerning a specific message.
13. Your choices and rights
You may ask for access to or correction of personal information Tockly holds about you. Depending on applicable law, you may also have rights to deletion, portability, restriction, objection or complaint. Some requests about Customer Data must be handled first by the business that supplied it. Email contact@tockly.ai with enough information for us to identify the relevant account, invoice or communication.
14. Children
Tockly is a business service and is not directed to children under 18. Contact us if you believe a child’s information has been supplied without proper authority.
15. Breaches and complaints
We investigate suspected privacy and security incidents and make notifications required by applicable law. You may complain to our Privacy Officer or to the privacy regulator in your country, including the New Zealand Office of the Privacy Commissioner.
16. Changes
We may update this policy as Tockly’s features, providers or legal obligations change. We will publish the current version and provide additional notice where a change materially affects how information is used or disclosed.
17. Calendars, notes, reports and sharing
Calendar and note records can contain dates, customer, horse or owner names, dictated or transcribed text and the reports you choose to share. A calendar subscription sends selected entry titles and dates, and note details only when you enable them, to the calendar service or device you choose, including Apple, Google or Outlook. It is a subscription feed, not access to all of your external calendar data. Anyone with the subscription URL can access the selected feed without signing in to Tockly. Treat it as a secret and disconnect it if it is exposed; previously downloaded copies may remain with the recipient.
Report links likewise give anyone holding the link access to the report permitted by that link. Check recipients and ownership details before sending. A downloaded or printed invoice, statement, report or handover, and copies saved in another service, are outside Tockly’s deletion controls. Saved notes and reports remain as workspace records until deleted where controls allow, or permanent account deletion, subject to applicable legal retention. Sent stable reports are kept as issued and may require a new report to correct the information.
Google and Microsoft mailbox connections use the permissions you approve for the requested sending and delivery features. Connection credentials and relevant sender or delivery records are held to operate the connection. Disconnecting stops further authorised access; it does not recall emails already delivered. Calendar, email and payment recipients may be in countries different from your own.
18. EU, UK and Australian users
Where EU GDPR or UK GDPR applies, you may request access, correction, erasure, restriction, portability for eligible information and objection to processing based on legitimate interests. You can withdraw consent at any time without affecting earlier lawful processing. You can object to direct marketing at any time. Rights have legal exceptions, including required records and legal claims. Providing account and billing information is necessary to provide the contract; without it, the requested service may not work. Optional connections, Capture and dictation can be left unused. Requests are normally answered within one month under EU or UK law, subject to permitted extensions and identity checks.
You may complain to your local EU supervisory authority or the UK Information Commissioner’s Office (ico.org.uk), without first exhausting our complaint process. For New Zealand matters you may contact the Office of the Privacy Commissioner (privacy.org.nz). Where Australia’s Privacy Act applies, we handle access and correction requests and privacy complaints under the Australian Privacy Principles, and serious eligible breaches under the Notifiable Data Breaches scheme; you may contact the Office of the Australian Information Commissioner (oaic.gov.au). We will acknowledge complaints and explain the outcome or next steps within a reasonable time. Contact our Privacy Officer at contact@tockly.ai.
Animal health records are not human health records, but associated owner, client and staff information can be personal information. Do not supply human health, biometric, criminal-offence or other specially protected information unless the feature and your lawful authority permit it. Worldwide availability and translated pages do not remove local privacy, tax, consumer or record-keeping requirements.
Read this policy with our Cookie Notice and Data Processing Terms.