CyberCrest
ServicesNetworkCCTVToolsAboutContact
027 430 1191Start a conversation
ServicesNetworkCCTVToolsAboutContact
027 430 1191Start a conversation

Legal

Privacy Policy

Last updated: 9 September 2026 · Applies to cybercrest.nz and all services provided by CYBERCREST LIMITED

1. Who we are

CYBERCREST LIMITED (“CyberCrest”, “we”, “us”) is a network, connectivity and surveillance engineering practice registered in New Zealand.

Registered companyCYBERCREST LIMITED
NZBN9429053871725
Company number9450143
Registered officeHeld on the New Zealand Companies Register
Privacy contactJake Stamper, Director
Emailjake@cybercrest.nz
Telephone027 430 1191

CyberCrest is an agency under the New Zealand Privacy Act 2020. Where we handle personal information relating to individuals in the United Kingdom, we act as a controller or processor under UK GDPR and the Data Protection Act 2018, depending on the circumstances described in section 6.

2. Scope

This policy covers personal information we collect through:

  • the cybercrest.nz website;
  • enquiries made by phone, email or our contact form;
  • the provision of engineering, installation and managed support services;
  • systems we design, install, configure or maintain on client premises.

It does not cover third-party websites we link to, or the internal privacy practices of our clients.

3. What we collect

3.1 Website visitors

When you visit cybercrest.nz our hosting infrastructure and content delivery network automatically record technical information, including IP address, approximate location derived from it, browser and device type, referring page, pages viewed and timestamps. This is standard server logging and is used for security, fraud prevention and diagnostics.

We also collect usage data through Google Analytics 4. For visitors in the United Kingdom and Europe this happens only where you consent to analytics cookies. Full detail of what is set, by whom and for how long is in our Cookie Policy.

3.2 Enquiries

When you contact us we collect the information you provide: name, company, email address, telephone number, site location, property type, site size, timeframe and whatever you tell us about the site itself. We collect this to respond to the enquiry and to assess whether we are the right practice for the work.

3.3 Clients

In the course of an engagement we collect and hold:

  • contact details for the individuals we deal with;
  • site information — addresses, floor plans, building details, access arrangements;
  • technical information about the network and systems, including device inventories, addressing, configuration and credentials held under a defined process;
  • correspondence, proposals, scope documents and project records;
  • billing information, invoices and payment records.

We do not collect, process or store payment card details. Clients pay by direct bank transfer, or by card through a Xero invoice — in which case the card details are handled by Xero's payment provider and never reach us.

3.4 Personal information within systems we install

Systems we design and install — particularly CCTV, access control and telephony — capture personal information about identifiable individuals. In almost all cases that information belongs to and is controlled by our client, not by CyberCrest. Section 6 sets out how that relationship works.

3.5 What we do not collect

We do not seek or knowingly collect sensitive information such as health, ethnicity, religious belief, political opinion or biometric data, except where a client's access control system uses a biometric credential and we are configuring it on their instruction. We do not conduct behavioural advertising and we do not sell personal information to anyone, in any circumstance.

4. Why we use it, and our lawful basis

PurposeNew Zealand — Privacy Act 2020United Kingdom — UK GDPR lawful basis
Responding to enquiriesCollected for a lawful purpose connected with our functions (IPP 1)Legitimate interests, or steps prior to entering a contract
Delivering contracted servicesAs abovePerformance of a contract
Managing accounts and invoicingAs aboveContract and legal obligation
Securing our systems and websiteAs aboveLegitimate interests
Meeting statutory record-keeping and tax obligationsAs aboveLegal obligation
Analytics and site improvementAs aboveConsent
Occasional service updates to existing clientsAs above; opt-out providedLegitimate interests; opt-out provided

We do not use personal information for automated decision-making that produces legal or similarly significant effects.

5. Who we share it with

We disclose personal information only where it is necessary, and only to the following categories of recipient:

  • Hosting and infrastructure providers — Hosting.com for website and email hosting, Cloudflare for DNS, content delivery and security filtering.
  • Analytics providers — Google, where analytics cookies are consented to.
  • Installation partners — licensed cabling, electrical and installation contractors engaged on a specific project, who receive only the site information required to perform their part of the work and who are bound to confidentiality.
  • Professional advisers — Hays' Tax Service Limited (accountant), and legal advisers where required.
  • Accounting and invoicing — Xero, including its payment provider where a client pays a Xero invoice by card.
  • Regulators, law enforcement or courts — where we are legally required to disclose, or where disclosure is permitted under the Privacy Act 2020 or UK GDPR.

We do not disclose client information to hardware vendors, distributors or marketing partners.

6. Client systems, footage and our role

This section matters more than any other for our clients, and most privacy policies in our industry do not address it at all.

CCTV and access control footage recorded on a client's premises is the client's personal information to control. CyberCrest designs and configures the system that captures it; the client determines the purpose for which it is collected and retained. In UK GDPR terms, the client is the controller and CyberCrest is a processor. Under the Privacy Act 2020, we hold that information as an agent of the client.

In practice this means:

  • Recordings stay on the client's site. We architect for local recording to hardware on the premises, inside an isolated network segment. Footage does not route to CyberCrest, and it does not route to a cloud platform unless the client elects offsite replication.
  • We do not routinely access recorded footage. Where a managed agreement is in place, access is limited to what is required to verify the system is functioning — camera health, storage state, recording continuity — and does not extend to reviewing content.
  • Where we do access a client system, it is at the client's request or under an agreed maintenance procedure, through encrypted authenticated access, and it is logged.
  • We do not retain copies of client footage, configurations containing personal information, or exported recordings beyond what is required to complete an agreed task.
  • Credentials are handed to the client at project completion. We do not retain administrative access as a commercial lever.

At design stage we advise clients on their own obligations — camera positioning relative to areas carrying a reasonable expectation of privacy, notification signage, retention periods proportionate to purpose, and access control over recorded material. That advice is engineering guidance, not legal advice, and clients remain responsible for their own compliance.

7. Where your information is held

CyberCrest is based in New Zealand and operates in New Zealand and the United Kingdom. Some of the service providers we use store data outside those countries.

FunctionProviderLocation
Website hostingHosting.comSydney, Australia
Content delivery, DNS and securityCloudflareGlobal edge network
EmailHosting.com (cPanel mail)Sydney, Australia
AnalyticsGoogleVarious
Accounting and invoicingXeroNew Zealand and Australia

Where personal information is disclosed to a provider outside New Zealand, we take reasonable steps to satisfy ourselves that it will be protected by comparable safeguards, as required by information privacy principle 12 of the Privacy Act 2020. For transfers involving UK personal data we rely on adequacy or on standard contractual clauses as applicable.

Client CCTV footage is a deliberate exception. It is held on the client's own premises, in the client's own jurisdiction, and is not transferred anywhere by design.

8. How long we keep it

CategoryRetention
Enquiries that do not proceed24 months, then deleted
Client records and correspondenceFor the duration of the engagement and 7 years afterwards, to meet New Zealand tax and record-keeping requirements
Project and as-built documentationFor the life of the system, so it can be provided to the client on request
Financial records7 years, as required by the Tax Administration Act 1994
Website server logs30 days
Analytics dataPer the retention setting configured in Google Analytics 4 — see the Cookie Policy

Once a retention period expires, information is securely deleted or de-identified.

9. How we protect it

We apply the same engineering discipline to our own systems as we specify for clients:

  • multi-factor authentication on every business system that supports it;
  • encrypted transport for all web traffic and encrypted storage for business data at rest;
  • credentials held in a dedicated password manager, never in plain text, spreadsheets or email;
  • remote access to client systems by encrypted tunnel with named accounts, never by exposed port forwarding;
  • access limited to what is needed for the task;
  • current patching on the devices we use;
  • confidentiality obligations on installation partners.

No system is perfectly secure, and we do not claim otherwise. What we do commit to is responding properly when something goes wrong.

10. Privacy breaches

If a privacy breach occurs that we believe has caused, or is likely to cause, serious harm, we will notify the Office of the Privacy Commissioner and the affected individuals as soon as practicable, as required under Part 6 of the Privacy Act 2020. Where UK personal data is involved, we will notify the Information Commissioner's Office within 72 hours where the threshold under UK GDPR is met.

Where a breach affects a client's system, we will notify the client without delay so they can meet their own notification obligations.

11. Your rights

In New Zealand

Under information privacy principles 6 and 7 of the Privacy Act 2020 you have the right to ask what personal information we hold about you, to be given access to it, and to request correction if it is wrong. We will respond within 20 working days.

If you are not satisfied with how we have handled your information or your request, you may complain to the Office of the Privacy Commissioner at privacy.org.nz or 0800 803 909.

In the United Kingdom

Under UK GDPR you have the right to access, rectification, erasure, restriction of processing, data portability, and to object to processing based on legitimate interests. Where processing relies on consent, you may withdraw it at any time. We will respond within one month.

If you are not satisfied you may complain to the Information Commissioner's Office at ico.org.uk.

Making a request

Contact jake@cybercrest.nz. We may need to verify your identity before releasing information. There is no charge for a reasonable request.

12. Children

Our services are provided to organisations and adults. We do not knowingly collect personal information directly from children through this website.

Where we install systems for education clients, footage may capture minors. That information is controlled by the school or institution, and we work with them at design stage on positioning, signage, retention and access control appropriate to that setting.

13. Cookies

Detailed in our Cookie Policy.

14. Changes to this policy

We may update this policy as our services, systems or legal obligations change. The current version is always at cybercrest.nz/privacy-policy/ with the last-updated date at the top. Where a change materially affects how we handle information about existing clients, we will tell them directly rather than relying on this page.

15. Contact

Questions, requests or complaints about privacy:

Jake Stamper, Director
jake@cybercrest.nz
027 430 1191
CYBERCREST LIMITED, NZBN 9429053871725

← Back to cybercrest.nz
CYBERCREST

Independent IT security, network and surveillance engineering practice. Christchurch, New Zealand — supporting client sites in London, United Kingdom.

Practice

ServicesNetwork & securityCCTV & access controlCapacity calculator

Firm

AboutFAQContact

Legal

Privacy PolicyCookie PolicyTerms of Service

Enquiries

027 430 1191hello@cybercrest.nzMake an enquiry
© CYBERCREST LIMITED 2026 · NZBN 9429053871725 · Company number 9450143Developed by Jake Stamper

Analytics cookies

We use Google Analytics to see which pages are read, so we can improve the site. No advertising, no cross-site tracking. Cookie Policy