Privacy Policy
How Cianaa Technologies collects, uses, shares and protects your personal information — for individuals in New Zealand, Australia, the European Union & UK, and the United States.
- Who we are
- Information we collect
- How we use it
- Legal bases (EU/UK)
- Cookies & tracking
- How we share information
- International transfers
- Data retention
- Security & data-breach notification
- Direct marketing & your choices
- Automated decision-making
- Your privacy rights
- Children’s privacy
- Changes
- Contact, Privacy Officer & complaints
1. Who we are
Cianaa is an independent cybersecurity certification and assessment body operating across New Zealand and Australia through two related entities, which are responsible (as “data controller” / “agency”) for the personal information described in this policy:
- New Zealand — Cianaa Technologies (NZBN 9429041553831). Head office: Level 1/69 Ben Lomond Crescent, Pakuranga Heights, Auckland, New Zealand.
- Australia — Cianaa Assurance Pty Ltd (ABN 87 685 534 838). 420 Victoria Street, Brunswick VIC 3056, Australia.
- Privacy contact: Our Privacy Officer — privacy@cianaatech.com · +64 9 390 4252
2. Information we collect
Information you give us
- Contact & enquiry details — name, work email, phone, organisation, and the content of your message when you complete a form (e.g. a scoping/contact request, complaint or appeal) or contact us.
- Engagement information — information you provide in the course of an assessment, audit or certification engagement.
- Chat — messages you send via our website chat.
Information collected automatically
- Usage & device data — IP address, browser/device type, pages viewed, referring page, and similar analytics data, collected via cookies and similar technologies (see Cookies).
Information from third parties
We may receive information from service providers such as our CRM and analytics tools, and from publicly available sources, where relevant to our services.
Sensitive information
We do not generally seek or collect “sensitive information” (such as health, racial or ethnic origin, or biometric data) in the ordinary course of our services. Where sensitive information is genuinely necessary, we collect it only with your consent or as permitted by law.
3. How we use your information
- To respond to enquiries and provide quotes and information you request;
- To deliver and administer our assessment, audit and certification services;
- To manage complaints and appeals;
- To send service communications and, where permitted, marketing you can opt out of at any time (see Direct marketing);
- To operate, secure and improve our website;
- To comply with legal, regulatory and accreditation obligations.
4. Legal bases for processing (EU/UK)
Where the GDPR applies, we rely on: your consent; performance of a contract with you; our legitimate interests (e.g. responding to enquiries, securing our site, direct marketing to business contacts); and compliance with legal obligations. You may withdraw consent at any time.
5. Cookies & tracking
We use cookies and similar technologies for essential site functionality, analytics and (where applicable) marketing. Non-essential cookies are only set with your consent where required (e.g. in the EU/UK), managed through our cookie-consent banner and your browser settings. We use third-party tools — HubSpot (forms, chat and CRM) and Google Analytics — that may set their own cookies; these load only in line with your consent choices.
6. How we share information
We do not sell your personal information. We share it only with:
- Service providers who process data on our behalf under contract and only on our instructions — including website hosting (WP Engine), CRM, email and chat (HubSpot), email delivery, and analytics (Google). These providers are bound to protect your information and use it only to provide their service to us;
- Regulators, accreditation and scheme bodies where required for our certification activities;
- Authorities and advisers where required or permitted by law, or to establish or defend legal claims.
7. International data transfers
As we operate across New Zealand and Australia and use reputable global service providers, your information may be stored or processed outside your country — principally in the United States (where providers such as HubSpot, Google and WP Engine operate), and potentially in other countries where our providers maintain infrastructure. Where we transfer personal data internationally (including out of the EU/UK, or overseas under NZ IPP 12 and Australian APP 8), we take reasonable steps to ensure it is protected to a comparable standard, using safeguards such as Standard Contractual Clauses and contractual data-protection commitments.
8. Data retention
Cianaa is a business-to-business provider. The personal information we hold is limited to business-contact details (such as the name, work email, phone and organisation of the people we deal with) — we do not build or retain personal profiles of individuals. We keep this information only for as long as necessary for the purpose it was provided and to meet legal, regulatory and accreditation obligations, after which it is securely deleted or anonymised. In general terms:
- Enquiry and marketing contacts — kept while you remain an active business contact, and removed when you unsubscribe, ask us to delete your details, or the contact is no longer current;
- Certification, audit and engagement records — these relate to organisations rather than individuals, and are retained for the period required by the relevant certification scheme and our accreditation obligations;
- Records needed for legal, tax or dispute purposes — retained only for the period required by applicable law.
9. Security & data-breach notification
We apply appropriate technical and organisational measures to protect personal information against loss, misuse and unauthorised access. No method of transmission or storage is completely secure, but we work to protect your information and to detect and respond to incidents.
If a data breach occurs that is likely to cause serious harm, we will notify affected individuals and the relevant regulator as required by law — the Office of the Privacy Commissioner in New Zealand (under the Privacy Act 2020), and the Office of the Australian Information Commissioner under the Notifiable Data Breaches scheme — and take steps to contain and remedy the incident.
10. Direct marketing & your choices
Where permitted, we may send you service updates and marketing about our certification, audit and training services. You can opt out at any time by using the unsubscribe link in any marketing email, adjusting your cookie-consent choices, or contacting our Privacy Officer. We will action opt-out requests promptly. We do not use your information for marketing by third parties.
11. Automated decision-making
We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing. Certification and assessment outcomes are determined by qualified human assessors and auditors.
12. Your privacy rights
New Zealand
Under the Privacy Act 2020 you may request access to, and correction of, your personal information. If you are not satisfied with our response, you may complain to the Office of the Privacy Commissioner — privacy.org.nz · 0800 803 909.
Australia
Under the Privacy Act 1988 and the Australian Privacy Principles you may request access and correction, and complain to us first and then, if unresolved, to the Office of the Australian Information Commissioner — oaic.gov.au · 1300 363 992.
European Union & United Kingdom
Under the GDPR you have the right to access, rectify, erase, restrict, port and object to processing of your personal data, to withdraw consent, and to not be subject to solely automated decisions with legal effects. You may lodge a complaint with your local supervisory authority (in the UK, the ICO — ico.org.uk).
United States (California & other states)
Where the CCPA/CPRA applies, you have the right to know, access, delete and correct your personal information, to opt out of the “sale” or “sharing” of personal information, and to limit the use of sensitive personal information, without discrimination for exercising these rights. We do not sell or share personal information as those terms are defined under California law. Residents of other US states with privacy laws have comparable rights.
To exercise any right, contact our Privacy Officer (below). We will verify your identity and respond within the timeframe required by the applicable law.
13. Children’s privacy
Our services are directed to businesses and not to children. We do not knowingly collect personal information from children.
14. Changes to this policy
We may update this policy from time to time. The “last updated” date above shows the latest version, and material changes will be notified on this page.
15. Contact, Privacy Officer & complaints
For any privacy question, to make a privacy request, or to raise a privacy concern, please contact our Privacy Officer via our contact form or email privacy@cianaatech.com. We aim to acknowledge privacy requests promptly and respond within the timeframe required by the applicable law.
For complaints about our certification or assessment services, see our Complaints & Appeals page. If we cannot resolve your privacy concern, you may escalate to the relevant regulator listed in section 12.
