Privacy Policy

Last updated 1 October 2024

app.cybersystem.io (the ‘Site’) is owned and operated by CyberSystem NZ Limited (the 'Company', ‘we', ‘us, or ‘our') and is a cyber security management platform.

CyberSystem NZ Limited is the data controller and can be contacted at [email protected]

1. Purpose

The purpose of this Privacy Policy is to inform users of our Site of the following:

·       The personal data we will collect

·       Use of collected data

·       Who has access to the data collected

·       The rights of Site users

·       The Site's cookie policy

This Privacy Policy applies in addition to the Terms &Conditions of our Site.

2. GDPR

For users in the European Union, we adhere to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016, known as the General Data Protection Regulation (the ‘GDPR’). For users in the United Kingdom, we adhere to the GDPR as enshrined in the Data Protection Act 2018.

3. Consent

By using our Site users agree that they consent to the conditions set out in this Privacy Policy.

When the legal basis for us processing your personal data is that you have provided your consent to that processing, you may withdraw your consent at any time. If you withdraw your consent, it will not make processing which we completed before you withdrew your consent unlawful.

You can withdraw your consent by contacting the Data Protection Officer.

4. Legal Basis For Processing

We collect and process personal data about users in the EU only when we have a legal basis for doing so under Article 6 of the GDPR.

We rely on the following legal basis to collect and process the personal data of users in the EU: Users have provided their consent to the processing of their data for one or more specific purposes.

5. Personal Data We Collect

We only collect data that helps us achieve the purpose set out in this Privacy Policy. We will not collect any additional data beyond the data listed below without notifying you first.

If you choose not to provide us with the personal data listed below, or if we are unable to collect that data, we may not be able to provide you with certain services or information, or may not be able to carry out an activity you have requested.

6. Data Collected Automatically

When you visit and use our Site, we may automatically collect and store the following information:

·       IP address

·       Location

·       Hardware and software details

·       Clicked links

·       Content viewed

7. Data Collected In A Non-Automatic Way

We may also collect the following data when you perform certain functions on our Site such as creating an account or making a support request:

·       First and last name

·       Email address

·       Organisation name

·       Organisation addresses

·       Further organisation details that you may optionally provide

·       Any relationships between your organisation and other organisations in the Site

·       Payment information

·       Support queries

8. How We Use Personal Data

Data collected on our Site will only be used for the purposes specified in this Privacy Policy or indicated on the relevant pages of our Site. We will not use your data beyond what we disclose in this Privacy Policy.

The data we collect automatically is used for the following purposes:

·       The proper operation of the Site

·       To help us understand how you’re using our Site so we can provide the best service possible

The data we collect when the user performs certain functions may be used for the following purposes:

·       The proper operation of the Site

·       To communicate with you

·       To provide support

·       To enhance our Site and services and improve and develop these

·       To help us detect and prevent malicious or fraudulent use of our Site

9. Who We Share Personal Data With
Staff

We may disclose user data to any member of our organisation who reasonably needs access to user data to achieve the purposes set out in this Privacy Policy.

Third Parties

We may share user data with the following third parties:

·       Service providers and partners who may support the delivery of or provide functionality on the Site

We may share the following user data with third parties:

·       Links clicked while using the Site

We may share user data with third parties for the following purposes:

·       Providing support for use of the Site

Third parties will not be able to access user data beyond what is reasonably necessary to achieve the given purpose.

Other Disclosures

We will not sell or share your data with other third parties without your consent, except if the law requires it; it is required for any legal proceeding; to prove or protect our legal rights; and to buyers or potential buyers of the Company in the event that we seek to sell the Company.

If you follow hyperlinks from our Site to another site, please note that we are not responsible for and have no control over their privacy policies and practices.

10. How Long We Store Personal Data

User data will be stored until the purpose the data was collected for has been achieved. Following that period, we’ll make sure it’s deleted or anonymised. You will be notified if your data is kept for longer than this period.

11. How We Protect Your Personal Data

As a cyber security management software service, security and privacy are key priorities for our Company. In order to protect your data, we follow and are independently assessed against the strongest security and privacy practices for data transmission, processing, and storage. All data is only accessible to our staff and potentially authorised Third Parties who are subject to this Privacy Policy and may be provided with essential access on a least privilege basis.

While we take all reasonable precautions to ensure that user data is secure and that users are protected, there always remains the risk of harm. The Internet as a whole can be insecure at times and therefore we are unable to guarantee the security of user data beyond what is reasonably practical.

12. International Data Transfers

We may transfer user personal data to countries other than the country you live in, such as countries where our data hosting provider’s servers are located.

When we transfer user personal data we will protect that data as described in this Privacy Policy and comply with applicable legal requirements for transferring personal data internationally.

If you are located in the United Kingdom or the European Union, we will only transfer your personal data if the country your personal data is being transferred to has been deemed to have adequate data protection by the European Commission or, if you are in the United Kingdom, by the United Kingdom adequacy regulations; or we have implemented appropriate safeguards in respect of the transfer. For example, the recipient is a party to binding corporate rules, or we have entered into standard EU or United Kingdom data protection contractual clauses with the recipient.

13. Your Rights As A User

Under the GDPR, you have the following rights:

·       Right to be informed (i.e. know what personal data we hold about you)

·       Right of access (i.e. request a copy of your personal data)

·       Right to rectification (i.e. to make sure it’s correct and up to date)

·       Right to erasure (i.e. ask us to delete your personal data)

·       Right to restrict processing (i.e. ask us to restrict processing your personal data)

·       Right to data portability (i.e. ask to obtain and reuse your personal data for your own purposes across other services)

·       Right to object (i.e. object to our continued processing of your personal data)

14. Children

We do not knowingly collect or use personal data from children under 16 years of age. If we learn that we have collected personal data from a child under 16 years of age, the personal data will be deleted as soon as possible. If a child under 16 years of age has provided us with personal data their parent or guardian may contact our data protection officer.

15. How To Access, Modify, Delete Or Challenge The Data Collected

If you would like to know if we have collected your personal data, how we have used your personal data, if we have disclosed your personal data and to whom we disclosed your personal data, if you would like your data to be deleted or modified in any way, or if you would like to exercise any of your other rights under the GDPR, please feel free to contact the CyberSystem Data Protection Officer on [email protected].

As a technology company, we prefer to communicate by email to ensure you’re put in contact with the right person, in the right location, and in accordance with any regulatory time frames.

16. Do Not Track Notice 

Do Not Track (‘DNT’) is a privacy preference that you can set in certain web browsers. We do not track the users of our Site over time and across third party websites and therefore do not respond to browser-initiated DNT signals. We are not responsible for and cannot guarantee how any third parties who interact with our Site and your data will respond to DNT signals.

17. Cookie Policy

A cookie is a small file, stored on a user's hard drive by a website. Its purpose is to collect data relating to the user's browsing habits. You can choose to be notified each time a cookie is transmitted. You can also choose to disable cookies entirely in your internet browser, but this may decrease the quality of your user experience.

We use the following types of cookies on our Site:

·       Session cookies - used to remember your authentication and login state between visits to the Site

·       Functional cookies - used to remember the selections you make on our Site so that your selections are saved for your next visits

·       Analytical cookies - allow us to improve the design and functionality of our Site by collecting data on how you access our Site, for example data on the content you         access, and how long you stay on our Site

·       Targeting cookies - collect data on how you use the Site and your preferences. This allows us to personalise the information you see on our Site for you.

18. Modifications

This Privacy Policy may be amended from time to time in order to maintain compliance with the law and to reflect any changes to our data collection process. When we amend this Privacy Policy we will update the ‘Effective Date’ at the top of this Privacy Policy. We recommend that our users periodically review our Privacy Policy to ensure that they are notified of any updates. If necessary, we may notify users by email of changes to this Privacy Policy.

19. Complaints  

If you have any complaints about how we process your personal data, please contact the CyberSystem Data Protection Officer on [email protected] so that we can, where possible, resolve the issue. If you feel we have not addressed your concern in a satisfactory manner you may contact a supervisory authority. You also have the right to directly make a complaint to a supervisory authority. You can do so by contacting the relevant authority such as the Office of the Privacy Commissioner in New Zealand, or the Information Commissioner's Office in the UK.

20. Contact Information

If you have any questions, concerns or complaints, you can contact the CyberSystem Data Protection Officer at [email protected]