Privacy Policy

Last Updated: 7 January 2025

 

ZenContract ("we," "our," or "us") is committed to protecting the privacy and security of your Personal Information. This Privacy Policy outlines how we collect, use, store, and disclose your information when you use our software platform and related services ("Services"). By accessing or using our Services, you acknowledge that you have read and understood this Privacy Policy.

Personal Information is information that identifies, or can reasonably be linked directly or indirectly to, an identifiable person. It does not include anonymous, de-identified, or aggregated information.

INFORMATION WE COLLECT

Information You Provide

We collect Personal Information directly from you when you use our Website and Services. This may include the following scenarios:

  • When you create, administer, or operate an account with ZenContract, such as providing your name, email address, phone number, and company details.

  • When you request information about our Services or sign up to receive communications from ZenContract, including newsletters, product updates, or invitations to webinars or events.

  • If you participate in ZenContract marketing initiatives, such as case studies, testimonials, or content campaigns.

  • When you contact us directly via phone, email, Website enquiry forms, or live chat, including support requests, or when you visit our Website.

  • If you provide feedback through customer surveys, product reviews, or other feedback mechanisms we offer.

    The types of information we collect from you include:

  • Identifiers and Account Information: Names, email addresses, phone numbers, job titles, company details, location information, IP addresses, and/or other device- identifying data provided during account creation or while using our Services.

  • Support Requests: Information you provide when contacting us for support, including communications that may be recorded for quality assurance and training purposes.

  • Commercial Information: Details about the Services you have purchased, used, or expressed interest in, and events or initiatives hosted by ZenContract that you attended or expressed interest in attending.

  • Financial Information: Payment details provided when making purchases through our Website, including billing information.

  • Audio, Electronic, and Visual Information: Signatures, records of our interactions (e.g., phone calls, emails), and preferences such as the frequency at which you wish to receive marketing communications.

Information Collected Automatically

We automatically collect or generate certain Personal Information about you based on your interactions with us, such as when you use our Website and Services. This information may also be associated with your account and includes:

  • Identifiers: Unique user identifiers, unique device identifiers, IP addresses, cookie identifiers, information about product licenses, and usernames.

  • Internet or Other Electronic Network Activity Information: Information about the Website domain visited, which activities and offerings are used, how they are used and for how long, posts and discussions, and engagement with our content, such as online resources or publications.

  • Geolocation Information: Country codes, IP addresses, and language preferences.

  • Electronic Information: Details about operating systems, device types, browser

    information, automatic updates, technical errors, preferred tools and experiences,

    and how you engage with our Website and Services.

  • Commercial Information: Records of interest in our Website and Services or

    completed purchases.

  • Inferences: Insights or assumptions drawn from the personal and usage information

    available to us, including preferences and behavioural patterns.

    Use of Cookies and Related Technologies

    We use cookies (small text files stored by your web browser) and related technologies, such as pixels, local storage, and beacons (collectively referred to as "Cookies"), to collect and store information when you use our Website and Services. Cookies allow us to enhance your experience, understand usage patterns, and deliver targeted advertisements.

    By using our Website and agreeing to this Privacy Policy, you consent to our use of session cookies in accordance with the terms of this Privacy Policy. You can manage your cookie preferences through your browser settings.

    Information from Third-Party Providers

    We may receive information about you from our affiliates, subsidiaries, and third-party sources, such as authentication services or integrations you enable (e.g., Microsoft, Autotask, ConnectWise), where you have authorised such sharing or where this information is publicly available.

    In accordance with applicable law, we may combine this information with data we collect directly from you or automatically through your use of our Website and Services. This helps us ensure that our databases remain current and accurate and allows us to provide you with more relevant content, experiences, and other products or services.

    HOW WE USE YOUR INFORMATION

    We will not process your Personal Information, other than as outlined in this Privacy Policy, without a lawful basis to do so. We may process your Personal Information for the following purposes:

  • Account Creation and Maintenance: To create and manage accounts within the Website and the Services.

  • Security and Fraud Prevention: To identify and investigate activity that is suspicious, potentially fraudulent, or violates this Privacy Policy.

  • Service Delivery: To provide our Website and Services, and otherwise fulfil contracts between you and us.

  • Billing and Payments: To bill you and to collect money owed, including authorising and processing credit card transactions.

  • Identity Verification: To verify your identity and provide secure access to the Website and Services.

  • Communication: To communicate with you, including responding to feedback, inquiries, and requests related to the Website and Services.

  • Third-Party Obligations: To communicate with, and comply with our obligations to, our third-party service providers, suppliers, and other users of our Website and Services.

  • Administrative Notifications: To send administrative messages, reminders, notices, updates, security alerts, and other information relevant to your use of the Website and/or Services.

  • Service Analysis and Improvement: To analyse and report on usage of the Website and Services to identify trends, troubleshoot issues, and improve our offerings.

  • Marketing Communications: To send you marketing and promotional messages and other information that may be of interest to you, where you have provided consent. You can opt out of receiving such materials at any time by using the unsubscribe link provided or contacting us at support@zencontract.com.

  • Legal Rights and Obligations: To protect and/or enforce our legal rights and interests, defend against claims, and comply with legal obligations, including responding to access directions or notification requirements imposed by government agencies, law enforcement, or regulatory authorities.

  • Consent-Based Processing: For other purposes where you have provided explicit consent.

    We may also process your Personal Information for purposes that are compatible with the original purposes described above or that you otherwise authorise.

    Lawful Basis for Processing

    We process your Personal Information based on the following lawful bases:

  1. Consent: Where you have given your explicit consent for specific processing activities, such as receiving marketing communications. You may withdraw your consent at any time by contacting us or using the opt-out mechanisms provided.

  2. Contractual Necessity: Where processing is necessary for the performance of a contract with you.

  3. Legal Obligations: To comply with applicable laws and regulations, including notification and reporting obligations.

  4. Legitimate Interests: Where processing is necessary for the purposes of our legitimate interests, such as improving our Services, provided these interests are not overridden by your interests or fundamental rights and freedoms.

If we rely on our legitimate interests, we balance your rights against ours to ensure your information is not processed unfairly. You have the right to object to such processing based on circumstances specific to you.

Anonymised and Aggregated Data

We may anonymise and aggregate Personal Information such that no individual can be identified from the data. This anonymised and aggregated information is not considered Personal Information under this Privacy Policy and may be used for any purpose, including research, analysis, and improving our Website and Services. We will ensure that such actions are carried out responsibly and in compliance with applicable laws.

HOW WE SHARE YOUR INFORMATION

We do not sell your Personal Information. However, we may share your Personal Information with trusted third parties, as outlined below, only where we have a lawful basis to do so and in compliance with New Zealand’s Privacy Act 2020.

Service Providers

We may share your Personal Information with trusted third-party service providers who assist us in delivering our Website and Services. This may include:

  • Hosting providers.

  • Payment processors (e.g., for credit card transactions).

  • Customer support platforms.

  • IT infrastructure providers.

    These service providers are required to adhere to strict privacy and data protection standards to ensure your Personal Information is handled securely and in accordance with applicable privacy laws. They may only use your Personal Information to perform the specific tasks we have engaged them for and cannot use it for any other purposes.

    Affiliates and Subsidiaries

    ZenContract’s affiliates and subsidiaries may receive Personal Information to support the purposes described in this Privacy Policy, such as providing you with the Website and Services or administering purchases, billing, and other transactions. These entities are contractually bound to adhere to the same privacy standards outlined in this Privacy Policy.

    Business Transfers

    If ZenContract undergoes a merger, acquisition, reorganisation, or sale of some or all of its assets, your Personal Information may be transferred as part of the business transaction. In such cases we will ensure the acquiring organisation agrees to protect your Personal Information in accordance with this Privacy Policy, and you will be notified of any significant changes to how your Personal Information is handled.

    Legal Obligations

    We may disclose your Personal Information to comply with:

  • Applicable laws, regulations, or legal processes.

  • Requests from government agencies, law enforcement, or regulatory authorities. This may include responding to lawful access directions or reporting obligations.

Your Authorised Parties

We may share your Personal Information with third parties at your direction or with your explicit consent. Examples include:

  • Sharing information with a nominated representative.

  • Authorised data sharing with other organisations you work with.

    Protecting Legal Rights and Interests

    We may share your Personal Information where necessary to:

  • Protect or enforce our legal rights, such as defending against claims.

  • Prevent, detect, or investigate potential fraud, unauthorised activities, or violations of

    this Privacy Policy.

    Aggregated and Anonymised Information

    We may anonymise and aggregate your Personal Information in a manner that ensures no individual can be identified. Such anonymised data is not considered Personal Information under this Privacy Policy and may be shared for purposes such as:

  • Research and analysis.

  • Improving our Website and Services.

  • Creating reports or insights into usage trends.

    Disclosures for Operational Support

    We may share Personal Information with other businesses that support us, such as those hosting or maintaining underlying IT systems, processing payments, or marketing our Services. These entities are contractually bound to comply with applicable privacy laws and cannot use the information for their own purposes.

    Safeguards for Data Sharing

    Whenever we share your Personal Information, we ensure appropriate safeguards are in place, such as:

  • Contractual agreements requiring third parties to adhere to privacy standards comparable to those under New Zealand law.

  • Taking reasonable steps to ensure the security and confidentiality of your Personal Information.

    Your Choices

    You may withdraw your consent for sharing Personal Information at any time by contacting us using the details provided in this Privacy Policy. Please note:

  • Withdrawal of consent will not affect any processing already undertaken based on your prior consent.

  • Certain types of sharing may be necessary to provide the Services, and opting out could limit your use of our platform.

INTERNATIONAL DATA TRANSFERS

Your information may be stored and processed in New Zealand or other countries where our service providers operate. We ensure that any international data transfers comply with Information Privacy Principle 12 (IPP 12) under the Privacy Act 2020, with appropriate safeguards in place.

We require any third-party service providers handling your Personal Information outside New Zealand to comply with comparable data protection standards under the Privacy Act 2020, including by entering into appropriate contractual arrangements. These providers are prohibited from using Personal Information for their own purposes and must process the data strictly in accordance with our instructions, this Privacy Policy, and comparable privacy standards under New Zealand law.

If you would like more information about the safeguards we apply to international data transfers, please contact us using the details provided in this Privacy Policy.

DATA RETENTION

We retain your Personal Information for as long as necessary to provide the Services, comply with legal obligations, resolve disputes, and enforce our agreements. Retention periods vary depending on the type of data and the purposes for which it is processed. Specifically:

  • We will retain your Personal Information until we no longer have a valid reason for keeping it.

  • If you request us to stop using your Personal Information, we will delete or anonymise it unless we are required to retain it to comply with legal obligations.

  • Certain information may need to be retained for specific periods to meet regulatory or legal requirements, such as keeping invoice records for seven years to fulfil tax obligations.

    You should also be aware that we maintain backups and system logs for up to 12 months to ensure data integrity, resolve technical issues, and comply with legal or contractual obligations. These backups and logs are automatically deleted once their retention period expires.

    When your Personal Information is no longer required, we securely delete or anonymise it to ensure it is no longer identifiable.

    PROTECTING PERSONAL INFORMATION

    We take the protection of your Personal Information seriously and are committed to safeguarding it from loss, unauthorised access, or misuse. For detailed information about our encryption practices, access controls, incident response protocols, and other security measures, please refer to our Security Posture Document.

To achieve this, we implement reasonable physical, electronic, and procedural safeguards, including:

  • Secure access controls to limit who can access Personal Information.

  • Encryption of data where appropriate.

  • Regular monitoring and auditing of our systems for vulnerabilities.

  • Incident response procedures for addressing data breaches or security incidents.

  • Staff training to ensure employees understand their responsibilities for protecting

    Personal Information and how to handle it appropriately.

    In the event of a privacy breach that poses a risk of serious harm, we will notify affected individuals and the New Zealand Office of the Privacy Commissioner as soon as practicable after becoming aware of a notifiable privacy breach, and in accordance with the Privacy Act 2020. For further details, refer to our Security Posture Document.

    YOUR RIGHTS

    Under the New Zealand Privacy Act 2020, you have the right to:

  • Access the Personal Information we hold about you.

  • Request correction of any inaccurate or incomplete information.

  • Withdraw consent for certain data processing activities.

  • File a complaint with the New Zealand Privacy Commissioner if you believe your

    rights have been violated.
    To exercise these rights, please contact us using the details provided below.

    INTERNET USE

    While we strive to use commercially reasonable means to maintain secure internet connections and protect your Personal Information, no method of transmission over the internet is completely secure. We encourage you to use secure channels when sharing Personal Information and contact us if you have concerns. We cannot guarantee the security of information transmitted to or from our Website or Services. If you have any concerns about the security of your Personal Information, please contact us using the details provided in this Privacy Policy.

    LINKS TO OTHER WEBSITES

    Our Website may contain links to external Websites. If you follow a link to another Website, please be aware that the owner of that Website will have its own privacy policy, which will apply to the use of your Personal Information on that Website. We encourage you to review the privacy policy of any external Website before providing Personal Information. ZenContract is not responsible for the privacy practices or content of external Websites.

INFORMATION ABOUT CHILDREN

We do not knowingly collect Personal Information from or about children under the age of 16. Our Website and Services are not intended for use by children. If you believe we have inadvertently collected Personal Information from or about a child, please contact us at support@zencontract.com, and we will take steps to delete the information.

CHANGES TO THIS PRIVACY POLICY

We may update this Privacy Policy from time to time to reflect changes in our practices, services, or legal obligations. When we make changes, we will update the "Last Updated" date at the top of this Privacy Policy.

Where changes are significant, we will notify you in a manner appropriate to the circumstances, such as by posting a notice on our Website, within our Services, or by sending an email. We encourage you to periodically review this Privacy Policy to stay informed about how we are protecting your Personal Information.

CONTACT US

If you wish to exercise your rights under this Privacy Policy or any applicable privacy laws, you may do so by contacting us at support@zencontract.com. Please include the following details in your request:

  • Evidence of your identity (e.g., a valid form of identification).

  • A clear description of your request (e.g., the Personal Information you are requesting

    access to or the correction you are seeking).

    We will respond to access or correction requests as soon as practicable and no later than 20 working days after receiving your request, in accordance with the Privacy Act 2020.