Privacy Policy

1. Data Controller

ENORBY ("we", "us", "our") is a managed IT services and cybersecurity firm operating in Auckland, New Zealand. This policy governs the collection, processing, storage, and protection of personal information obtained through enorby.co.nz.

2. Information We Collect

Provided directly by you

Collected automatically

Information we do not collect

3. Purpose of Processing

4. Lawful Basis

Under the Privacy Act 2020 (Information Privacy Principles), we process personal information on the following bases:

5. Security Measures

6. Data Breach Protocol

In the event of a notifiable privacy breach as defined under Part 6A of the Privacy Act 2020:

Target notification window: 72 hours from confirmed discovery. Internal incident response plan maintained and reviewed quarterly.

7. Sub-Processors & Third Parties

We do not sell, rent, trade, or disclose personal information to any third party for their independent use. A list of current sub-processors is available upon request to info@enorby.co.nz.

8. Your Rights

Under the Privacy Act 2020, you may exercise the following at any time:

Contact info@enorby.co.nz to exercise any right. We respond within 20 working days as required by statute.

9. Data Retention

Upon expiry, data is purged from all systems including backups within 30 days.

10. Children's Privacy

Our services are intended exclusively for businesses and individuals aged 18 and over. We do not knowingly collect information from persons under 18.

11. Policy Amendments

This policy may be revised to reflect changes in our practices or regulatory obligations. Material changes affecting your rights will be communicated with 14 days' advance notice via the website or email.

12. Contact & Complaints