Legal
Privacy Policy
1. Who we are
CYBERCREST LIMITED (“CyberCrest”, “we”, “us”) is a network, connectivity and surveillance engineering practice registered in New Zealand.
| Registered company | CYBERCREST LIMITED |
|---|---|
| NZBN | 9429053871725 |
| Company number | 9450143 |
| Registered office | Held on the New Zealand Companies Register |
| Privacy contact | Jake Stamper, Director |
| jake@cybercrest.nz | |
| Telephone | 027 430 1191 |
CyberCrest is an agency under the New Zealand Privacy Act 2020. Where we handle personal information relating to individuals in the United Kingdom, we act as a controller or processor under UK GDPR and the Data Protection Act 2018, depending on the circumstances described in section 6.
2. Scope
This policy covers personal information we collect through:
- the cybercrest.nz website;
- enquiries made by phone, email or our contact form;
- the provision of engineering, installation and managed support services;
- systems we design, install, configure or maintain on client premises.
It does not cover third-party websites we link to, or the internal privacy practices of our clients.
3. What we collect
3.1 Website visitors
When you visit cybercrest.nz our hosting infrastructure and content delivery network automatically record technical information, including IP address, approximate location derived from it, browser and device type, referring page, pages viewed and timestamps. This is standard server logging and is used for security, fraud prevention and diagnostics.
We also collect usage data through Google Analytics 4. For visitors in the United Kingdom and Europe this happens only where you consent to analytics cookies. Full detail of what is set, by whom and for how long is in our Cookie Policy.
3.2 Enquiries
When you contact us we collect the information you provide: name, company, email address, telephone number, site location, property type, site size, timeframe and whatever you tell us about the site itself. We collect this to respond to the enquiry and to assess whether we are the right practice for the work.
3.3 Clients
In the course of an engagement we collect and hold:
- contact details for the individuals we deal with;
- site information — addresses, floor plans, building details, access arrangements;
- technical information about the network and systems, including device inventories, addressing, configuration and credentials held under a defined process;
- correspondence, proposals, scope documents and project records;
- billing information, invoices and payment records.
We do not collect, process or store payment card details. Clients pay by direct bank transfer, or by card through a Xero invoice — in which case the card details are handled by Xero's payment provider and never reach us.
3.4 Personal information within systems we install
Systems we design and install — particularly CCTV, access control and telephony — capture personal information about identifiable individuals. In almost all cases that information belongs to and is controlled by our client, not by CyberCrest. Section 6 sets out how that relationship works.
3.5 What we do not collect
We do not seek or knowingly collect sensitive information such as health, ethnicity, religious belief, political opinion or biometric data, except where a client's access control system uses a biometric credential and we are configuring it on their instruction. We do not conduct behavioural advertising and we do not sell personal information to anyone, in any circumstance.
4. Why we use it, and our lawful basis
| Purpose | New Zealand — Privacy Act 2020 | United Kingdom — UK GDPR lawful basis |
|---|---|---|
| Responding to enquiries | Collected for a lawful purpose connected with our functions (IPP 1) | Legitimate interests, or steps prior to entering a contract |
| Delivering contracted services | As above | Performance of a contract |
| Managing accounts and invoicing | As above | Contract and legal obligation |
| Securing our systems and website | As above | Legitimate interests |
| Meeting statutory record-keeping and tax obligations | As above | Legal obligation |
| Analytics and site improvement | As above | Consent |
| Occasional service updates to existing clients | As above; opt-out provided | Legitimate interests; opt-out provided |
We do not use personal information for automated decision-making that produces legal or similarly significant effects.
5. Who we share it with
We disclose personal information only where it is necessary, and only to the following categories of recipient:
- Hosting and infrastructure providers — Hosting.com for website and email hosting, Cloudflare for DNS, content delivery and security filtering.
- Analytics providers — Google, where analytics cookies are consented to.
- Installation partners — licensed cabling, electrical and installation contractors engaged on a specific project, who receive only the site information required to perform their part of the work and who are bound to confidentiality.
- Professional advisers — Hays' Tax Service Limited (accountant), and legal advisers where required.
- Accounting and invoicing — Xero, including its payment provider where a client pays a Xero invoice by card.
- Regulators, law enforcement or courts — where we are legally required to disclose, or where disclosure is permitted under the Privacy Act 2020 or UK GDPR.
We do not disclose client information to hardware vendors, distributors or marketing partners.
6. Client systems, footage and our role
This section matters more than any other for our clients, and most privacy policies in our industry do not address it at all.
CCTV and access control footage recorded on a client's premises is the client's personal information to control. CyberCrest designs and configures the system that captures it; the client determines the purpose for which it is collected and retained. In UK GDPR terms, the client is the controller and CyberCrest is a processor. Under the Privacy Act 2020, we hold that information as an agent of the client.
In practice this means:
- Recordings stay on the client's site. We architect for local recording to hardware on the premises, inside an isolated network segment. Footage does not route to CyberCrest, and it does not route to a cloud platform unless the client elects offsite replication.
- We do not routinely access recorded footage. Where a managed agreement is in place, access is limited to what is required to verify the system is functioning — camera health, storage state, recording continuity — and does not extend to reviewing content.
- Where we do access a client system, it is at the client's request or under an agreed maintenance procedure, through encrypted authenticated access, and it is logged.
- We do not retain copies of client footage, configurations containing personal information, or exported recordings beyond what is required to complete an agreed task.
- Credentials are handed to the client at project completion. We do not retain administrative access as a commercial lever.
At design stage we advise clients on their own obligations — camera positioning relative to areas carrying a reasonable expectation of privacy, notification signage, retention periods proportionate to purpose, and access control over recorded material. That advice is engineering guidance, not legal advice, and clients remain responsible for their own compliance.
7. Where your information is held
CyberCrest is based in New Zealand and operates in New Zealand and the United Kingdom. Some of the service providers we use store data outside those countries.
| Function | Provider | Location |
|---|---|---|
| Website hosting | Hosting.com | Sydney, Australia |
| Content delivery, DNS and security | Cloudflare | Global edge network |
| Hosting.com (cPanel mail) | Sydney, Australia | |
| Analytics | Various | |
| Accounting and invoicing | Xero | New Zealand and Australia |
Where personal information is disclosed to a provider outside New Zealand, we take reasonable steps to satisfy ourselves that it will be protected by comparable safeguards, as required by information privacy principle 12 of the Privacy Act 2020. For transfers involving UK personal data we rely on adequacy or on standard contractual clauses as applicable.
Client CCTV footage is a deliberate exception. It is held on the client's own premises, in the client's own jurisdiction, and is not transferred anywhere by design.
8. How long we keep it
| Category | Retention |
|---|---|
| Enquiries that do not proceed | 24 months, then deleted |
| Client records and correspondence | For the duration of the engagement and 7 years afterwards, to meet New Zealand tax and record-keeping requirements |
| Project and as-built documentation | For the life of the system, so it can be provided to the client on request |
| Financial records | 7 years, as required by the Tax Administration Act 1994 |
| Website server logs | 30 days |
| Analytics data | Per the retention setting configured in Google Analytics 4 — see the Cookie Policy |
Once a retention period expires, information is securely deleted or de-identified.
9. How we protect it
We apply the same engineering discipline to our own systems as we specify for clients:
- multi-factor authentication on every business system that supports it;
- encrypted transport for all web traffic and encrypted storage for business data at rest;
- credentials held in a dedicated password manager, never in plain text, spreadsheets or email;
- remote access to client systems by encrypted tunnel with named accounts, never by exposed port forwarding;
- access limited to what is needed for the task;
- current patching on the devices we use;
- confidentiality obligations on installation partners.
No system is perfectly secure, and we do not claim otherwise. What we do commit to is responding properly when something goes wrong.
10. Privacy breaches
If a privacy breach occurs that we believe has caused, or is likely to cause, serious harm, we will notify the Office of the Privacy Commissioner and the affected individuals as soon as practicable, as required under Part 6 of the Privacy Act 2020. Where UK personal data is involved, we will notify the Information Commissioner's Office within 72 hours where the threshold under UK GDPR is met.
Where a breach affects a client's system, we will notify the client without delay so they can meet their own notification obligations.
11. Your rights
In New Zealand
Under information privacy principles 6 and 7 of the Privacy Act 2020 you have the right to ask what personal information we hold about you, to be given access to it, and to request correction if it is wrong. We will respond within 20 working days.
If you are not satisfied with how we have handled your information or your request, you may complain to the Office of the Privacy Commissioner at privacy.org.nz or 0800 803 909.
In the United Kingdom
Under UK GDPR you have the right to access, rectification, erasure, restriction of processing, data portability, and to object to processing based on legitimate interests. Where processing relies on consent, you may withdraw it at any time. We will respond within one month.
If you are not satisfied you may complain to the Information Commissioner's Office at ico.org.uk.
Making a request
Contact jake@cybercrest.nz. We may need to verify your identity before releasing information. There is no charge for a reasonable request.
12. Children
Our services are provided to organisations and adults. We do not knowingly collect personal information directly from children through this website.
Where we install systems for education clients, footage may capture minors. That information is controlled by the school or institution, and we work with them at design stage on positioning, signage, retention and access control appropriate to that setting.
13. Cookies
Detailed in our Cookie Policy.
14. Changes to this policy
We may update this policy as our services, systems or legal obligations change. The current version is always at cybercrest.nz/privacy-policy/ with the last-updated date at the top. Where a change materially affects how we handle information about existing clients, we will tell them directly rather than relying on this page.
15. Contact
Questions, requests or complaints about privacy:
Jake Stamper, Director
jake@cybercrest.nz
027 430 1191
CYBERCREST LIMITED, NZBN 9429053871725