Terms of Use
Notice of update (14 July 2026): These Terms were updated on 14 July 2026. They apply immediately to customers who first accept them (including through a Proposal) on or after that date. For customers whose access to the Service commenced before that date, the version of these Terms in effect for your account immediately before this update continues to apply until 13 August 2026, after which these Terms apply. Earlier versions are available on request from legal@cradle.io.
1. Application of terms
1.1 These Terms apply to your access to and use of the Service.
1.2 By signing, accepting or otherwise agreeing to a Proposal referencing these Terms, or by creating an account or accessing or using the Service:
you agree to be bound by these Terms; and
where your access and use is on behalf of another person (for example, a company), you confirm that you are authorised to, and do in fact, agree to these Terms on that person’s behalf and that, by agreeing to these Terms on that person’s behalf, that person is bound by these Terms.
1.3 If you do not agree to these Terms, you are not authorised to access or use the Service, and you must immediately stop doing so.
2. Changes to terms
2.1 We may change these Terms, or make a material change to a policy incorporated into these Terms, by giving you at least 30 days’ notice by email or by posting a notice on the Website. The date on which these Terms were last updated is set out above.
2.2 If a change materially and adversely affects you, you may notify us in writing before the change takes effect that you do not accept the change. In that case:
the version of the Terms in effect immediately before the change will continue to apply to you until the end of your then-current Term; and
the updated Terms will apply from the commencement of any renewal Term.
2.3 If you do not notify us in accordance with clause 2.2, your continued access to or use of the Service after the change takes effect constitutes acceptance of the updated Terms.
2.4 Nothing in this clause obliges us to renew the Service if you elect not to accept updated Terms.
3. Interpretation
In these Terms:
AI Features means transcription, summarisation and other artificial-intelligence-assisted features of the Service, and AI Output means a transcript, summary or other output generated by an AI Feature.
Analytical Data means anonymised and aggregated statistical or analytical data derived from the Data or from use of the Service, which does not identify you or any individual.
Confidential Information means any information that is not public knowledge and that is obtained from the other party in the course of, or in connection with, the provision and use of the Service. Our Confidential Information includes Intellectual Property owned by us (or our licensors), including the Cradle Software and the Underlying Systems. Your Confidential Information includes the Data.
Country Schedule means a country-specific schedule published on the Website, or included in a Proposal, that describes service availability, emergency calling arrangements or other country-specific regulatory matters (if any).
Cradle Software means the software owned by us (and our licensors) that is used to provide the Service, including our Android, iOS, Windows, macOS and web applications.
Data means all data, content and information (including personal information) owned, held, used or created by you or on your behalf that is stored using, or inputted into, the Service, and includes Recordings and AI Outputs derived from your use of the Service.
DPA means the Data Processing Agreement set out below these Terms, as referenced in clause 10.
Export Period means the period of one month starting on the date of termination of these Terms.
Fair Use Policy means our policy regarding reasonable usage limits as described on the Website at https://www.cradle.io/knowledgebase/fair-use-policy, as updated from time to time.
Fees means the fees set out in the applicable Proposal or, if no Proposal applies, the fees set out on our pricing page on the Website at https://www.cradle.io/pricing, in each case as may be updated from time to time in accordance with clause 11.6.
Force Majeure means an event that is beyond the reasonable control of a party, excluding:
an event to the extent that it could have been avoided by a party taking reasonable steps or reasonable care; or
a lack of funds for any reason.
including and similar words do not imply any limit.
Integration means an interoperation between the Service and a third-party product or service (for example, a CRM or practice-management system) enabled by you or on your behalf.
Intellectual Property Rights includes copyright and all rights existing anywhere in the world conferred under statute, common law or equity relating to inventions (including patents), registered and unregistered trade marks and designs, circuit layouts, data and databases, confidential information, know-how, and all other rights resulting from intellectual activity. Intellectual Property has a consistent meaning, and includes any enhancement, modification or derivative work of the Intellectual Property.
Messaging Services means SMS and other messaging features of the Service, including messaging over third-party messaging platforms.
Objectionable includes being objectionable, defamatory, obscene, harassing, threatening, harmful, or unlawful in any way.
A party includes that party’s permitted assigns.
Permitted Users means your personnel who are authorised to access and use the Service on your behalf in accordance with clause 5.4.
A person includes an individual, a body corporate, an association of persons (whether corporate or not), a trust, a government department, or any other entity.
personal information has the meaning given to it in the Privacy Act 2020, being information about an identifiable individual.
personnel includes officers, employees, contractors and agents, but a reference to your personnel does not include us.
Privacy Policy means our privacy policy available on the Website, as updated from time to time.
Proposal means a proposal, quotation, order form or other written agreement between you and us that references these Terms and sets out subscription, pricing or other commercial terms for the Service.
Recording means a recording or transcript of a call, conversation or message made using the Service.
Service means the Cradle cloud-based business phone service comprising the core functionality described in the applicable Proposal or, where no Proposal applies, the core functionality of your selected plan as described on the Website at the Start Date. We may improve, update or replace features of the Service from time to time.
Start Date means the date on which you first create an account or, if earlier, the commencement date set out in the applicable Proposal.
Term means the period during which these Terms apply, as described in clause 16.
Underlying Systems means the Cradle Software, IT solutions, systems and networks (including software and hardware) used to provide the Service, including any third-party solutions, systems and networks.
We, us or our means Cradle Limited, company number 5953070.
Website means the internet site at https://cradle.io, including https://www.cradle.io and any other subdomain of cradle.io, or such other site notified to you by us.
Year means a 12-month period starting on the Start Date or the anniversary of that date.
You or your means you or, if clause 1.2.2 applies, both you and the other person on whose behalf you are acting.
Words in the singular include the plural and vice versa. A reference to a statute includes references to regulations, orders or notices made under or in connection with the statute or regulations and all amendments, replacements or other changes to any of them.
4. Provision of the service
4.1 We must use reasonable efforts to provide the Service:
in accordance with these Terms and New Zealand law, as well as other applicable laws where appropriate;
exercising reasonable care, skill and diligence; and
using suitably skilled, experienced and qualified personnel.
4.2 Our provision of the Service to you is non-exclusive. Nothing in these Terms prevents us from providing the Service to any other person.
4.3 Subject to clauses 4.4 and 4.5, we must use reasonable efforts to ensure the Service is available on a 24/7 basis. However, it is possible that on occasion the Service may be unavailable to permit maintenance or other development activity to take place, or in the event of Force Majeure. We must use reasonable efforts to publish on the Website and/or notify you by email advance details of any planned unavailability.
4.4 Through the use of web services and APIs, the Service interoperates with a range of third-party service features, including Integrations. We do not make any warranty or representation on the availability, continuity or performance of those features. Without limiting the previous sentence, if a third-party feature provider ceases to provide that feature or ceases to make that feature available on reasonable terms, we may cease to make that feature available to you. To avoid doubt, if we exercise our right to cease the availability of a third-party feature, you are not entitled to any refund, discount or other compensation.
4.5 The Service interoperates with a range of third-party telecommunications carriers, specifically for the provision of origination and termination calling services and the provision of phone numbers. We do not make any warranty or representation on the availability of those services. Without limiting the previous sentence, if a third-party telecommunications carrier ceases to provide a number, origination or termination services, or imposes conditions that you are unwilling or unable to meet, we may cease to make available the associated services, including any existing phone numbers. If a third-party telecommunications carrier discontinues or removes access to a phone number, calling origination or termination, or other services, you are not entitled to any refund, discount or other compensation.
4.6 Where a Country Schedule applies to a country in which you use the Service, the Country Schedule describes country-specific service availability and regulatory matters, and forms part of these Terms.
5. Your obligations
5.1 You and your personnel must:
use the Service in accordance with these Terms solely for:
your own internal business purposes as they relate to making and receiving phone calls and messages from your suppliers, customers and associates, and between your personnel; and
lawful purposes;
not resell, sublicense or make available the Service to any third party, or otherwise commercially exploit the Service;
not engage in any unsolicited advertising, marketing or other activities prohibited by any applicable law or regulation covering anti-spam, telemarketing, data protection or privacy in any applicable jurisdiction, including the New Zealand Unsolicited Electronic Messages Act 2007, the Australian Spam Act 2003 and Do Not Call Register Act 2006, and the United States CAN-SPAM Act of 2003, Telephone Consumer Protection Act and Do-Not-Call Implementation Act;
not use the Service in connection with unsolicited, deceptive or harassing communications (commercial or otherwise), including unsolicited or unwanted phone calls, messages or voicemail; and
comply with the Fair Use Policy and any other usage limits and policies described on the Website.
5.2 When accessing or using the Service, you and your personnel must:
not impersonate another person or misrepresent authorisation to act on behalf of others or us;
correctly identify the sender of all electronic transmissions;
not attempt to undermine the security or integrity of the Underlying Systems;
not use, or misuse, the Service in any way which may impair the functionality of the Underlying Systems or impair the ability of any other user to use the Service;
not attempt to view, access or copy any material or data other than:
that which you are authorised to access; and
to the extent necessary for you to use the Service in accordance with these Terms; and
neither use the Service in a manner, nor transmit, input or store any Data, that breaches any third-party right (including Intellectual Property Rights and privacy rights) or is Objectionable, incorrect or misleading.
5.3 You must ensure that all information you provide to us in your dealings with us (including when setting up an account) is true, current and complete, and promptly update that information as required so that it remains true, current and complete.
5.4 Without limiting clause 5.2, no individual other than a Permitted User may access or use the Service. You may authorise any member of your personnel to be a Permitted User, in which case you must provide us with the Permitted User’s name, email address and any other information we reasonably require, by adding them as a user or administrator in the Service. You must procure each Permitted User’s compliance with clauses 5.1 and 5.2 and any other reasonable condition notified by us to you.
5.5 A breach of any of these Terms by your personnel (including, to avoid doubt, a Permitted User) is deemed to be a breach of these Terms by you.
5.6 You are responsible for procuring all licences, authorisations and consents required for you and your personnel to use the Service, including to use, store and input Data into, and process and distribute Data through, the Service and any Integration.
5.7 Where you enable an Integration, you are responsible for ensuring that the sharing of Data (including Recordings and AI Outputs) with the third-party product or service is authorised, and the third party’s handling of that Data is governed by your agreement with the third party, not by these Terms.
6. Emergency calling
6.1 The Service is not a replacement for a traditional fixed-line or mobile telephone service, and you and your personnel must not rely on the Service for making emergency calls to 111, 000, 999, 911, 112 or other emergency services.
6.2 Emergency calling is addressed further in Schedule 1 (Emergency calling disclosure), which forms part of these Terms, and in any applicable Country Schedule.
6.3 Where applicable law requires us to provide access to emergency organisations as part of the Service, we will provide that access in accordance with applicable law. You must provide, and keep current, any service-address or location information that we or our carriers reasonably request for this purpose, and must inform all Permitted Users of the limitations of emergency calling described in Schedule 1.
7. Telephone numbers and porting
7.1 Telephone numbers are allocated to you for use with the Service and are not owned by you. Your right to use a number is subject to applicable numbering rules, carrier requirements and continued provision of the number by the relevant carrier.
7.2 You must provide accurate identity, address and other regulatory information reasonably required by us or our carriers in connection with the allocation or use of a number, and must keep that information current.
7.3 We may withdraw or replace a number where required by law, a regulator or a carrier. Where practicable, we will provide reasonable notice and reasonable assistance with replacement or porting.
7.4 You must not transmit false, misleading or unauthorised caller identification information.
7.5 We will provide reasonable assistance with porting numbers into or out of the Service, and will not obstruct a port-out request. You must ensure that porting requests are duly authorised and that the account information supporting a port is accurate. Porting timeframes depend on third-party carriers and are estimates only; we do not warrant that a port will complete by any particular date or at all.
7.6 Porting a number out of the Service does not itself terminate these Terms or your subscription. If you intend to stop using the Service, you must complete any port-out request before your account is closed. A number that has not been ported out within the Export Period may be returned to the relevant carrier and may cease to be available.
7.7 We may charge reasonable porting fees where permitted by applicable law.
7.8 Nothing in these Terms limits any mandatory number-portability right you have under applicable law.
8. Call recording, transcription and messaging
8.1 The Service includes optional call recording and transcription features. You control whether and how those features are enabled and configured for your organisation, and you are the party that determines the purposes for which Recordings are made.
8.2 Where you or your personnel use recording or transcription features, you warrant that you will:
establish and maintain a lawful basis for recording and transcribing each conversation;
give any notices, and obtain any consents, required by applicable law before or during recording;
comply with applicable employment and workplace-monitoring requirements in respect of your personnel;
restrict access to Recordings to personnel who need that access;
configure retention and deletion settings appropriately for your legal and industry obligations;
not record payment-card verification data or other information that applicable law or industry rules prohibit recording;
comply with any industry-specific recording or record-keeping requirements that apply to your business; and
ensure that sharing a Recording through an Integration is authorised.
8.3 Where you or your personnel use Messaging Services, you must:
hold any recipient consents required by applicable law before sending a message;
honour opt-out and unsubscribe requests promptly;
accurately identify the sender of each message;
not send content prohibited by applicable law or by the policies of the relevant carrier or messaging platform;
comply with applicable do-not-call and do-not-contact registers; and
comply with reasonable volume, frequency and content requirements notified by us or imposed by the relevant carrier or messaging platform.
9. AI features
9.1 The availability of AI Features may depend on your plan or Proposal. We may improve, update or replace the models and systems used to provide AI Features from time to time.
9.2 AI Outputs are generated automatically and may be incomplete, inaccurate or misleading. You must ensure that an appropriately qualified person reviews an AI Output before it is relied on. AI Outputs are not professional, legal, financial, medical or regulatory advice.
9.3 You must not use an AI Output as the sole basis for a decision that produces legal or similarly significant effects concerning an individual.
9.4 You warrant that you have all notices, consents and other lawful authority required to record, transcribe and process communications and other Data using the AI Features.
9.5 As between the parties, AI Outputs derived from your Data are Data and are owned by you in accordance with clause 10.1. The models, systems and Underlying Systems used to provide AI Features remain our property (and our licensors’ property).
9.6 We will not use your Data (including Recordings and AI Outputs) to train a general-purpose AI model, or a model made available to other customers, unless you expressly opt in. We contractually require the third-party AI providers we use to not use your Data to train their models.
9.7 Data processed by AI Features (including transcripts and AI Outputs) is handled in accordance with clause 10 and the DPA, and the third-party providers involved are listed in the subprocessor register referenced in the DPA.
10. Data, privacy and security
10.1 As between the parties, title to, and all Intellectual Property Rights in, the Data remains your property.
10.2 You grant us a worldwide, non-exclusive, royalty-free, transferable licence to use, store, copy, modify, transmit and otherwise process the Data as necessary to:
provide, support and maintain the Service;
comply with applicable law;
exercise our rights and perform our obligations under these Terms, including enforcing these Terms; and
generate Analytical Data in accordance with clause 10.5.
10.3 You acknowledge that:
we may require access to the Data to exercise our rights and perform our obligations under these Terms; and
to the extent that this is necessary, but subject to clause 13, we may authorise a member or members of our personnel to access the Data for this purpose.
10.4 You must arrange all consents and approvals that are necessary for us to access and process the Data as described in this clause 10, including obtaining any necessary consents and authorisations from the individuals concerned.
10.5 You acknowledge and agree that:
we may use the Data, and information about your and your end users’ use of the Service, to generate Analytical Data, and may use Analytical Data for our internal research and product development purposes, to conduct statistical analysis and to identify trends and insights;
we may supply Analytical Data to third parties;
title to, and all Intellectual Property Rights in, Analytical Data is and remains our property; and
our rights under this clause 10.5 survive termination or expiry of these Terms.
10.6 Each party must comply with all applicable privacy and data protection laws, including (in our case) the Privacy Act 2020.
10.7 Our Privacy Policy describes how we collect, use and disclose personal information for our own purposes. The Privacy Policy is provided as a transparency notice and does not form part of these Terms.
10.8 Where we process personal information on your behalf in connection with providing the Service, the Data Processing Agreement set out below forms part of these Terms and applies in addition to the Privacy Policy. As set out in clause 19, the DPA prevails over these Terms in relation to the processing of personal information on your behalf.
10.9 You agree that we may store Data (including any personal information) on secure servers in New Zealand, Australia, the United States, Canada, Singapore, Japan, Taiwan or the European Union, and may access that Data (including any personal information) from those jurisdictions and New Zealand from time to time. Where personal information is stored or handled outside New Zealand, we will comply with the requirements of the Privacy Act 2020 that apply to that storage or handling, including information privacy principle 12 where it applies.
10.10 While we will take standard industry measures to back up all Data stored using the Service, you agree to keep a separate back-up copy of all Data uploaded by you onto the Service.
10.11 You indemnify us against any liability, claim, proceeding, cost, expense (including the actual legal fees charged by our solicitors) and loss of any kind to the extent arising from any third-party claim or allegation that any Data infringes the rights of that third party (including Intellectual Property Rights and privacy rights) or that the Data is Objectionable, incorrect or misleading, except to the extent that the claim arises from our breach of these Terms or from our modification of the Data other than on your instructions or as permitted by these Terms.
10.12 The indemnity in clause 10.11 is subject to the following:
we must notify you promptly after becoming aware of the claim, although a failure to do so only relieves you of your obligations to the extent you are prejudiced by the failure;
we retain control of the defence and settlement of the claim, and must not settle the claim in a manner that admits liability on your part without your prior written consent (not to be unreasonably withheld);
you must provide reasonable cooperation and assistance in relation to the claim; and
we must take reasonable steps to mitigate the relevant loss.
11. Fees and payment
11.1 You must pay us the Fees.
11.2 We will provide you with valid GST tax invoices on a monthly basis prior to the due date for payment, by email. Unless otherwise agreed in a Proposal, subscription Fees are payable in advance and variable usage charges are payable in arrears.
11.3 The Fees exclude GST, which you must pay on taxable supplies at the rate applying at the time of supply.
11.4 You must pay the Fees:
by direct debit using our nominated direct debit service, on or after the seventh day after the invoice date; or
automatically by credit card, on the day of the invoice, together with a surcharge equal to our direct cost of accepting your credit card, such cost not to exceed 3.7% of the total invoice amount or any lower limit imposed by applicable law; or
if agreed in writing, in accordance with the payment terms set out in that written agreement,
and in each case electronically in cleared funds without any set-off or deduction.
11.5 We may charge interest on overdue amounts at an annual rate equal to the Official Cash Rate published by the Reserve Bank of New Zealand as at the due date plus 10% per annum, calculated daily from the due date until payment is received.
11.6 We may increase the Fees by giving you at least 30 days’ notice. If you do not wish to pay the increased Fees, you may terminate these Terms and your right to access and use the Service on no less than 10 days’ notice, provided the notice is received by us before the effective date of the Fee increase. This right applies even if a minimum or contracted Term would otherwise apply. If you do not terminate in accordance with this clause, you are deemed to have accepted the increased Fees.
11.7 We may increase the Fees on reasonable notice if your use of the Service exceeds the terms of the Fair Use Policy and you fail to adjust your usage within 10 days of being asked to do so.
12. Intellectual property
12.1 Subject to clause 10.1, title to, and all Intellectual Property Rights in, the Service, the Website, and all Underlying Systems is and remains our property (and our licensors’ property). You must not contest or dispute that ownership, or the validity of those Intellectual Property Rights.
12.2 Except as expressly permitted by these Terms or applicable law, you must not copy, modify, adapt, reverse engineer, decompile or create derivative works of the Service or the Cradle Software.
12.3 To the extent not owned by us, you grant us a royalty-free, transferable, irrevocable and perpetual licence to use for our own business purposes any know-how, techniques, ideas, methodologies and similar Intellectual Property used by us in the provision of the Service.
12.4 If you provide us with ideas, comments or suggestions relating to the Service or Underlying Systems (together feedback):
all Intellectual Property Rights in that feedback, and anything created as a result of that feedback (including new material, enhancements, modifications or derivative works), are owned solely by us; and
we may use or disclose the feedback for any purpose.
12.5 You acknowledge that the Service may link to third-party websites or feeds that are connected or relevant to the Service. Any link from the Service does not imply that we endorse, approve or recommend, or have responsibility for, those websites or feeds or their content or operators. To the maximum extent permitted by law, we exclude all responsibility or liability for those websites or feeds.
13. Confidentiality
13.1 Each party must, unless it has the prior written consent of the other party:
keep confidential at all times the Confidential Information of the other party;
effect and maintain adequate security measures to safeguard the other party’s Confidential Information from unauthorised access or use; and
disclose the other party’s Confidential Information to its personnel or professional advisors on a need-to-know basis only and, in that case, ensure that any personnel or professional advisor to whom it discloses the other party’s Confidential Information is aware of, and complies with, clauses 13.1.1 and 13.1.2.
13.2 The obligation of confidentiality in clause 13.1 does not apply to any disclosure or use of Confidential Information:
for the purpose of performing a party’s obligations, or exercising a party’s rights, under these Terms;
required by law (including under the rules of any stock exchange);
which is publicly available through no fault of the recipient of the Confidential Information or its personnel;
which was rightfully received by a party from a third party without restriction and without breach of any obligation of confidentiality; or
by us if required as part of a bona fide sale of our business (assets or shares, whether in whole or in part) to a third party, provided that we enter into a confidentiality agreement with the third party on terms no less restrictive than this clause 13.
14. Warranties and consumer law
14.1 Each party warrants that it has full power and authority to enter into, and perform its obligations under, these Terms.
14.2 To the maximum extent permitted by law:
our warranties are limited to those set out in these Terms, and all other conditions, guarantees or warranties, whether expressed or implied by statute or otherwise (including any warranty under Part 3 of the Contract and Commercial Law Act 2017), are expressly excluded and, to the extent that they cannot be excluded, our liability for them is limited to NZD 1,000; and
we make no representation concerning the quality of the Service and do not promise that the Service will:
meet your requirements or be suitable for a particular purpose, including that the use of the Service will fulfil or meet any statutory role or responsibility you may have; or
be secure, free of viruses or other harmful code, uninterrupted or error-free.
14.3 You agree and represent that you are acquiring the Service, and accepting these Terms, for the purposes of trade. The parties agree that:
to the maximum extent permitted by law, the Consumer Guarantees Act 1993 and any other applicable consumer protection legislation do not apply to the supply of the Service or these Terms; and
it is fair and reasonable that the parties are bound by this clause 14.3.
14.4 Where legislation or rule of law implies into these Terms a condition or warranty that cannot be excluded or modified by contract, the condition or warranty is deemed to be included in these Terms. However, our liability for any breach of that condition or warranty is limited, at our option, to:
supplying the Service again; and/or
paying the costs of having the Service supplied again.
15. Liability
15.1 Our maximum aggregate liability under or in connection with these Terms or relating to the Service, whether in contract, tort (including negligence), breach of statutory duty or otherwise, must not in any Year exceed an amount equal to the Fees paid by you relating to the Service in the previous Year (which in the first Year is deemed to be the total Fees paid by you from the Start Date to the date of the first event giving rise to liability). The cap in this clause 15.1 includes the cap set out in clause 14.2.1.
15.2 Neither party is liable to the other under or in connection with these Terms or the Service for any:
loss of profit, revenue, savings, business, use, data (including Data), and/or goodwill; or
consequential, indirect, incidental or special damage or loss of any kind.
15.3 Clauses 15.1 and 15.2 do not apply to limit our liability under or in connection with these Terms for:
personal injury or death;
fraud or wilful misconduct;
a breach of clause 13; or
our breach of applicable privacy or data protection laws caused by our failure to comply with those laws, which is instead subject to the cap in clause 15.4.
15.4 Our total aggregate liability under clause 15.3.4 is capped at the lesser of:
NZD 100,000; or
two times the Fees paid by you in the 12 months preceding the first event giving rise to that liability.
15.5 Clause 15.2 does not apply to limit your liability:
to pay the Fees;
under the indemnity in clause 10.11; or
for those matters stated in clauses 15.3.1 to 15.3.3.
15.6 Neither party will be responsible, liable, or held to be in breach of these Terms for any failure to perform its obligations under these Terms or otherwise, to the extent that the failure is caused by the other party failing to comply with its obligations under these Terms, or by the negligence or misconduct of the other party or its personnel.
15.7 Each party must take reasonable steps to mitigate any loss or damage, cost or expense it may suffer or incur arising out of anything done or not done by the other party under or in connection with these Terms or the Service.
16. Term and renewal
16.1 These Terms and your right to access and use the Service start on the Start Date and continue for the Term.
16.2 Where a Proposal specifies an initial term, renewal mechanics or pricing, those provisions apply. Unless otherwise stated in the Proposal:
subscriptions renew automatically for successive 12-month terms;
the billing anniversary, renewal dates and notice periods are calculated by reference to the date of the first invoice issued for the subscription; and
to avoid renewal, you must give at least 30 days’ written notice before the billing anniversary.
16.3 Where no Proposal specifies an initial term, the Service continues on a month-to-month basis and either party may terminate these Terms and your right to access and use the Service by giving at least 30 days’ written notice.
16.4 Subject to clause 11.6, if the subscription option you have selected includes a minimum initial term or contracted period, the earliest date for termination under clause 16.2 or 16.3 is the expiry of that initial term or current contracted period.
17. Suspension
17.1 Without limiting any other right or remedy available to us, we may restrict or suspend your access to and use of the Service, and/or remove or disable access to the relevant Data, if:
any Fees are more than 14 days overdue; or
we reasonably consider that you or any of your personnel have:
undermined, or attempted to undermine, the security or integrity of the Service or any Underlying Systems;
used, or attempted to use, the Service for improper purposes, or in a manner, other than for normal operational purposes, that materially reduces the operational performance of the Service;
transmitted, inputted or stored any Data that breaches or may breach these Terms or any third-party right (including Intellectual Property Rights and privacy rights), or that is or may be Objectionable, incorrect or misleading; or
otherwise materially breached these Terms.
17.2 We will use reasonable efforts to notify you before, or as soon as reasonably practicable after, any restriction or suspension under clause 17.1.
17.3 We will not delete Data because of a suspension, except where the Data itself gives rise to the grounds for suspension or deletion is required by law, and in either case we will give you notice where practicable. Access may be restored once the grounds for suspension are remedied.
17.4 Suspension does not relieve you of your obligation to pay the Fees.
17.5 If a suspension under clause 17.1.1 continues for more than 60 days due to non-payment or lack of response from you, we may terminate these Terms and your right to access and use the Service by notice to you.
18. Termination
18.1 Either party may, by notice to the other party, immediately terminate these Terms and your right to access and use the Service if the other party:
breaches any material provision of these Terms and the breach is not:
remedied within 10 days of the receipt of a notice from the first party requiring it to remedy the breach; or
capable of being remedied; or
becomes insolvent, liquidated or bankrupt, has an administrator, receiver, liquidator, statutory manager, mortgagee’s or chargee’s agent appointed, becomes subject to any form of insolvency action or external administration, or ceases to continue business for any reason.
18.2 You may also terminate these Terms and your right to access and use the Service in accordance with clause 11.6, and either party may terminate in accordance with clause 16.
18.3 Termination of these Terms does not affect either party’s rights and obligations that accrued before that termination.
18.4 On termination of these Terms, you must pay all Fees for the provision of the Service prior to that termination, and all outstanding Fees become immediately payable.
18.5 No compensation is payable by us to you as a result of termination of these Terms for whatever reason, and you will not be entitled to a refund of any Fees that you have already paid.
18.6 Except to the extent that a party has ongoing rights to use Confidential Information, at the other party’s request following termination of these Terms but subject to clause 18.7, a party must promptly return to the other party or destroy all Confidential Information of the other party that is in the first party’s possession or control.
18.7 Offboarding proceeds as follows:
Porting. Any port-out of telephone numbers should be completed before termination or during the Export Period, in accordance with clause 7.6.
Export. At any time during the Export Period, you may request a copy of any Data stored using the Service, provided that you pay our reasonable costs of providing that copy. On receipt of that request, we must provide a copy of the Data in a common electronic form. We do not warrant that the format of the Data will be compatible with any software.
Return or deletion. At any time during the Export Period, you may elect the return or the deletion of the Data (including personal information processed under the DPA). To avoid doubt, we are not required to comply with clause 18.7.2 to the extent that you have previously requested deletion of the Data.
Deletion. Following the Export Period, we will delete the Data within 30 days (or, if you elected return under clause 18.7.3, promptly after return), subject to the DPA and clause 18.8.
Backups. Copies of Data held in backups are deleted or put beyond use in the ordinary operation of our backup cycle, and in any event within 90 days after deletion under clause 18.7.4.
18.8 We may retain Data to the extent required by law, provided that the retained Data remains protected in accordance with these Terms and the DPA.
19. Order of precedence
19.1 If there is any inconsistency between:
a Proposal, but only in respect of commercial and service-specific terms;
any applicable Country Schedule;
the DPA, in relation to the processing of personal information on your behalf;
these Terms; and
any policy incorporated into these Terms by reference,
the documents apply in that order, but only to the extent of the inconsistency.
19.2 A Proposal only overrides the DPA, clause 15 (Liability) or a Country Schedule if the Proposal expressly identifies the provision that it overrides. A general statement that the Proposal prevails is not sufficient.
20. General
20.1 Neither party is liable to the other for any failure to perform its obligations under these Terms (other than an obligation to pay money) to the extent caused by Force Majeure, provided that the affected party promptly notifies the other party and uses reasonable efforts to resume performance.
20.2 No person other than you and us has any right to a benefit under, or to enforce, these Terms, including under subpart 1 of Part 2 of the Contract and Commercial Law Act 2017.
20.3 For us to waive a right under these Terms, that waiver must be in writing and signed by us.
20.4 Except as set out in the DPA, we are your independent contractor, and no other relationship (for example, joint venture, agency, trust or partnership) exists under these Terms.
20.5 If we need to contact you, we may do so by email or by posting a notice on the Website. You agree that this satisfies all legal requirements in relation to written communications. You may give notice to us under or in connection with these Terms by emailing legal@cradle.io.
20.6 These Terms, and any dispute relating to these Terms or the Service, are governed by and must be interpreted in accordance with the laws of New Zealand. Each party submits to the non-exclusive jurisdiction of the Courts of New Zealand in relation to any dispute connected with these Terms or the Service.
20.7 Clauses which, by their nature, are intended to survive termination of these Terms, including clauses 10.5, 10.11, 10.12, 12, 13, 15, 18.3 to 18.8 and 20.6, continue in force.
20.8 If any part or provision of these Terms is or becomes illegal, unenforceable or invalid, that part or provision is deemed to be modified to the extent required to remedy the illegality, unenforceability or invalidity. If modification is not possible, the part or provision must be treated for all purposes as severed from these Terms. The remainder of these Terms will be binding on you.
20.9 Subject to clauses 2 and 11.6, any variation to these Terms must be in writing and signed or otherwise agreed in writing by both parties.
20.10 These Terms, together with any applicable Proposal, Country Schedule, the DPA and the Schedules, set out everything agreed by the parties relating to the Service, and supersede and cancel anything discussed, exchanged or agreed prior to the Start Date. The parties have not relied on any representation, warranty or agreement relating to the Service that is not expressly set out in these Terms, and no such representation, warranty or agreement has any effect from the Start Date. Without limiting the previous sentence, the parties agree to contract out of sections 9, 12A and 13 of the Fair Trading Act 1986, and agree that it is fair and reasonable that the parties are bound by this clause 20.10.
20.11 You may not assign, novate, subcontract or transfer any right or obligation under these Terms without our prior written consent, that consent not to be unreasonably withheld. You remain liable for your obligations under these Terms despite any approved assignment, subcontracting or transfer. We may assign or novate these Terms as part of a bona fide sale or reorganisation of our business, provided the assignee agrees to be bound by these Terms.
Schedule 1 – Emergency calling disclosure
The Service is not a replacement for a traditional fixed-line or mobile telephone service.
You must not rely on the Service for making emergency calls. Calls to emergency services (including 111, 000, 999, 911 or equivalent numbers) may not connect, may be delayed, may be misrouted, or may not provide accurate location or caller information, depending on jurisdiction, configuration, network conditions and third-party carrier capabilities.
Emergency calling availability varies by country and carrier and may change over time.
We strongly recommend that all users use a mobile phone or other alternative telephone service to contact emergency services wherever possible.
You are solely responsible for ensuring that reliable alternative means of contacting emergency services are available and for informing all users of the Service of the nature and limitations of emergency calling using VoIP services.
Data Processing Agreement
This Data Processing Agreement ("Agreement") forms part of the contract for services under the Cradle Terms of Use ("Principal Agreement") between the customer accepting the Principal Agreement ("Controller") and Cradle Limited ("Processor").
In the course of providing the Services under the Principal Agreement, the Processor may Process Personal Data on behalf of the Controller. This Agreement reflects the parties’ agreement with regard to the Processing of Personal Data.
1. Background
A. The Controller acts as a Data Controller in respect of Personal Data Processed in connection with the Services.
B. The Controller wishes to subcontract certain Services to the Processor which involve the Processing of Personal Data.
C. The parties wish to implement a data processing agreement that complies with applicable Data Protection Laws.
D. The parties agree as follows.
2. Definitions and interpretation
Unless otherwise defined in this Agreement, capitalised terms have the meanings given in the Principal Agreement.
2.1 Definitions
Agreement means this Data Processing Agreement and its Schedules.
Company Personal Data means any Personal Data Processed by the Processor on behalf of the Controller pursuant to or in connection with the Principal Agreement.
Data Protection Laws means all applicable data protection and privacy laws, including:
- Regulation (EU) 2016/679 (General Data Protection Regulation) ("GDPR");
- the GDPR as retained in United Kingdom law pursuant to the Data Protection Act 2018 ("UK GDPR");
- the New Zealand Privacy Act 2020;
- the Australian Privacy Act 1988; and
- any other applicable data protection or privacy laws, as amended or replaced from time to time.
EEA means the European Economic Area.
Personal Data, Processing, Controller, Processor, Data Subject, Personal Data Breach and Supervisory Authority have the meanings given in the GDPR or, where the GDPR does not apply, the equivalent concepts under applicable Data Protection Laws.
Services means the services provided by the Processor to the Controller as described in the Principal Agreement and Schedule 1.
Standard Contractual Clauses means the standard contractual clauses for the transfer of personal data to processors established in third countries approved by European Commission Implementing Decision (EU) 2021/914 (Module Two: controller to processor), and UK Addendum means the International Data Transfer Addendum to those clauses issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018.
Subprocessor means any third party appointed by or on behalf of the Processor to Process Personal Data on behalf of the Controller.
3. Processing of Company Personal Data
3.1 The Processor shall:
comply with all applicable Data Protection Laws when Processing Company Personal Data; and
Process Company Personal Data only on documented instructions from the Controller, including as set out in the Principal Agreement and this Agreement, unless required to do otherwise by applicable law.
3.2 The Controller instructs the Processor to Process Company Personal Data for the purposes of providing the Services.
3.3 The subject matter, duration, nature and purpose of the Processing, and the categories of Personal Data and Data Subjects, are set out in Schedule 1.
4. Processor personnel
4.1 The Processor shall take reasonable steps to ensure the reliability of any employee, contractor or agent who may have access to Company Personal Data.
4.2 Access to Company Personal Data shall be limited to those individuals who require access for the purposes of the Principal Agreement and who are subject to appropriate confidentiality obligations.
5. Security
5.1 Taking into account the state of the art, costs of implementation, and the nature, scope, context and purposes of Processing, the Processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including measures referred to in Article 32 of the GDPR and the measures described in Schedule 3.
5.2 In assessing security measures, the Processor shall take account of the risks presented by Processing, in particular from a Personal Data Breach.
6. Subprocessing
6.1 The Controller authorises the Processor to engage Subprocessors for the provision of the Services.
6.2 The Processor shall ensure that it enters into a written agreement with each Subprocessor imposing data protection obligations that provide at least the same level of protection as this Agreement and comply with Article 28(3) of the GDPR, where applicable.
6.3 The Processor's current Subprocessors are listed in the subprocessor register referenced in Schedule 2, which records each Subprocessor's name, purpose, processing location and transfer mechanism.
6.4 The Processor may update the list of Subprocessors from time to time and will give the Controller at least 30 days’ written notice of any new Subprocessor, except where an Emergency Replacement is required.
6.5 Emergency Replacement means the sudden replacement of a Subprocessor where the change is outside the Processor’s reasonable control. In such cases, the Processor will notify the Controller as soon as reasonably practicable.
6.6 If the Controller objects to a new Subprocessor, the Controller may terminate the Principal Agreement without penalty by written notice, provided the notice is received before the effective date of the new Subprocessor. If the Controller does not terminate, it is deemed to have accepted the Subprocessor.
6.7 The Processor remains liable for the acts and omissions of its Subprocessors to the same extent as if the Processor had performed the services directly, subject to the limitations of liability in the Principal Agreement.
7. Data subject rights
7.1 Taking into account the nature of the Processing, the Processor shall provide reasonable assistance to the Controller to enable it to respond to requests from Data Subjects exercising rights under Data Protection Laws.
7.2 The Processor shall:
promptly notify the Controller if it receives a request from a Data Subject relating to Company Personal Data; and
not respond to such request except on the Controller’s documented instructions or as required by law.
8. Personal Data Breach
8.1 The Processor shall notify the Controller without undue delay and, where reasonably practicable, within 48 hours after becoming aware of a Personal Data Breach affecting Company Personal Data.
8.2 The notification shall include the information reasonably available to the Processor at the time concerning the nature of the breach, the categories of data and Data Subjects affected, the likely consequences, and the containment and remediation measures taken or proposed. Notification may be provided in phases as information becomes available, and is not an admission of fault or liability.
8.3 The Processor shall reasonably cooperate with the Controller in the investigation, mitigation and remediation of any Personal Data Breach.
9. Data protection impact assessments
The Processor shall provide reasonable assistance to the Controller with data protection impact assessments and any required consultations with Supervisory Authorities, to the extent required by Data Protection Laws and relating solely to Processing under this Agreement.
10. Deletion or return of Company Personal Data
10.1 Following the Export Period described in clause 18 of the Principal Agreement, the Processor shall, at the Controller’s election made during the Export Period, delete or return to the Controller all Company Personal Data, and delete existing copies, within 30 days, save to the extent that applicable law requires storage of the Company Personal Data. If the Controller makes no election, the Processor shall delete the Company Personal Data.
10.2 The Processor shall confirm deletion in writing upon request.
10.3 Copies of Company Personal Data held in backups shall be deleted or put beyond use in the ordinary operation of the Processor’s backup cycle, and in any event within 90 days after deletion under clause 10.1, and shall remain protected by this Agreement until deleted.
10.4 The Processor may retain Company Personal Data where required by law, provided such data remains protected in accordance with this Agreement.
11. Audit rights
11.1 The Processor shall make available to the Controller information reasonably necessary to demonstrate compliance with this Agreement.
11.2 The Controller may conduct audits on reasonable notice, not more than once per year, and subject to reasonable confidentiality and security requirements.
12. Data transfers
12.1 The Processor may transfer Company Personal Data outside New Zealand, the EEA or the UK, including to the jurisdictions listed in clause 10.9 of the Principal Agreement.
12.2 Where such a transfer is subject to Data Protection Laws, the parties shall ensure appropriate safeguards are in place, including:
where the New Zealand Privacy Act 2020 applies, ensuring the transfer complies with the requirements of that Act, including information privacy principle 12 where it applies;
where the GDPR applies to a transfer to a country without an adequacy decision, the Standard Contractual Clauses, which are incorporated into this Agreement by reference and are deemed completed with the details in Schedule 1 and the parties’ details in the Principal Agreement; and
where the UK GDPR applies to such a transfer, the UK Addendum, incorporated and completed in the same manner.
13. Government and law-enforcement requests
13.1 If the Processor receives a request from a government agency, law-enforcement body or other third party to disclose or provide access to Company Personal Data, the Processor shall, unless legally prohibited from doing so:
promptly notify the Controller of the request;
redirect the requester to the Controller where practicable;
disclose only the minimum Company Personal Data legally required; and
take reasonable steps to challenge a request that the Processor reasonably considers to be overbroad or unlawful.
14. Confidentiality
Each party shall keep confidential all information received in connection with this Agreement, except where disclosure is required by law or the information is already public.
15. Notices
All notices under this Agreement must be in writing and sent by email.
Processor notices: privacy@cradle.io
16. Governing law and jurisdiction
This Agreement is governed by the laws of New Zealand.
The courts of New Zealand have non-exclusive jurisdiction.
Schedule 1 – Processing details
Subject matter of Processing: provision of the Cradle cloud-based business phone service, including calling, messaging, call recording, transcription, AI-assisted summarisation, integrations and customer support.
Duration of Processing: the Term of the Principal Agreement, plus the offboarding and deletion periods described in clause 18 of the Principal Agreement and clause 10 of this Agreement.
Nature and purpose of Processing: hosting, storage, transmission, routing, recording, transcription, summarisation, display, analysis for service operation, backup, and deletion of communications and related data, for the purpose of providing and supporting the Services.
Categories of Data Subjects:
- the Controller’s personnel and Permitted Users;
- callers and call participants (including the Controller’s customers, suppliers and other contacts);
- message senders and recipients;
- individuals whose details appear in contact records, CRM records or other content synchronised through an Integration.
Categories of Personal Data:
- names, email addresses, phone numbers and role information of Permitted Users;
- contact records, including names, phone numbers, email addresses and organisation details;
- call metadata (numbers, timestamps, duration, routing, outcome);
- call and voicemail Recordings and transcripts;
- AI prompts, transcripts, summaries and other AI Outputs;
- message content and metadata for Messaging Services;
- support communications and diagnostic data;
- CRM and practice-management data synchronised through Integrations enabled by the Controller.
Special categories of Personal Data: none required by the Services. The content of communications is determined by the Controller and its callers and may incidentally include any category of information; the Controller is responsible for its use of the Services in respect of such content.
Retention: as configured by the Controller within the Services (where configurable), and otherwise per the Principal Agreement, this Agreement and the retention periods published in the Processor's help centre.
Schedule 2 – Subprocessors
The Processor's subprocessor register is published at https://www.cradle.io/subprocessors and records, for each Subprocessor, its name, purpose, processing location and transfer mechanism. The register is updated in accordance with clause 6 of this Agreement.
Schedule 3 – Security measures
The Processor maintains technical and organisational security measures including:
- Access control — role-based access, unique credentials, multi-factor authentication for administrative access, and least-privilege permissions;
- Encryption — encryption of Company Personal Data in transit over public networks and at rest;
- Logging and monitoring — logging of administrative and data access, and monitoring for anomalous activity;
- Vulnerability management — patch management, dependency updates, and periodic security review of systems and code;
- Incident response — a documented incident-response process, including the breach-notification obligations in clause 8;
- Resilience and recovery — redundancy, backups and tested recovery procedures;
- Personnel — confidentiality obligations, background screening where lawful, and security awareness training; and
- Deletion — secure deletion processes consistent with clause 10.
Version Information
Document hash: 6298042ac2cc428cf08801bfb7f98b9d2a2e30c2ab66d05f9503126901a97efc
This hash uniquely identifies this version and is recorded when you accept our terms.