Privacy Policy
Last updated 28 September 2026
heliosIT ("we", "us", "our") is committed to protecting your privacy. This policy explains how we collect, use, store, and disclose personal information, and your rights under the Privacy Act 2020.
It covers information we collect about our own clients, website visitors, and enquirers. Where we handle personal information on behalf of a client as part of providing IT services, we do so as their agent (see section 9).
1. Who we are
- Entity: Jason Webb trading as heliosIT
- NZBN: 9429051667795
- Address: Christchurch, New Zealand
- Privacy contact: Jason Webb, [email protected]
2. What information we collect
Information you give us
- Name, email address, phone number, business name, and postal address
- Billing and payment details
- The content of your enquiries and communications with us
- Information you provide when we deliver services to you, including system credentials and configuration details
Information we collect automatically from our website
- IP address, browser type, device type, operating system
- Pages visited, time on site, referring URL
- Cookie and analytics data
Information from third parties
- Publicly available business information
- Referral information from other clients or partners
- Payment confirmation from payment processors
Sensitive information
We do not collect sensitive information such as health, ethnicity, or political opinions, and we ask that you do not send it to us.
3. Why we collect it and how we use it
We collect personal information to:
- Respond to enquiries and provide quotes
- Provide, manage, and support our services
- Manage accounts, invoicing, and payment collection
- Communicate with you about your projects and services
- Meet our legal, tax, and record keeping obligations
- Improve our website and services
- Send you occasional service updates or marketing, where you have opted in
You do not have to give us your personal information, but if you do not we may be unable to provide services to you.
4. Cookies and analytics
Our website uses cookies and similar technologies. Strictly necessary cookies are required for the site to function. We also use Umami, a privacy-focused analytics service that does not use cookies, to understand how the site is used.
You can disable cookies in your browser settings. Some site features may not work if you do.
5. Who we share information with
We may share your personal information with:
- Service providers who help us operate, including hosting providers, email providers, accounting software, and payment processors
- Subcontractors engaged to deliver services to you, under equivalent confidentiality obligations
- Professional advisers such as accountants and lawyers
- Government agencies or courts where required by law
- A purchaser of our business, if we sell it
We do not sell your data. We do not sell your personal information to anyone, for any purpose.
6. Overseas storage
Some of our service providers store data outside New Zealand, including in Australia, the United Kingdom, the European Union, India, and the United States. Current providers are:
| Provider | Purpose | Location |
|---|---|---|
| Fastmail | Email and documents | United States, United Kingdom, Australia, India, Austria |
| Cloudflare | Website hosting, DNS and application hosting, spam protection on our contact form (Turnstile) | Global network, United States |
| Hnry | Invoicing, accounts and payment processing | New Zealand; overseas locations not listed |
| Web3Forms | Delivering contact form submissions to us | Not listed |
| Cal.com | Call booking | Not listed |
| Umami | Website analytics (no personal information) | Not listed |
Before disclosing personal information overseas we take reasonable steps to ensure the recipient is subject to comparable safeguards, as required by information privacy principle 12.
7. How we store and protect information
We store information electronically using access-controlled systems with multi-factor authentication, encryption in transit, and encryption at rest where available. We limit access to those who need it.
No method of transmission or storage is completely secure. While we take reasonable steps, we cannot guarantee absolute security.
We keep personal information only as long as needed for the purposes it was collected, and to meet legal obligations. Financial records are kept for at least 7 years as required by the Tax Administration Act 1994.
8. Privacy breaches
If we experience a privacy breach that has caused or is likely to cause serious harm, we will notify the Office of the Privacy Commissioner and affected individuals as soon as practicable, as required by the Privacy Act 2020.
Where the breach affects personal information we hold on behalf of a client, we will notify that client without undue delay and support them in meeting their own notification obligations.
9. Information we handle for our clients
When providing IT services we may access personal information that belongs to our clients and relates to their customers, staff, or contacts. In that situation the client is the agency responsible for that information under the Privacy Act 2020, and we handle it only:
- as instructed by that client
- for the purpose of providing the agreed services
- under the confidentiality and security terms of our contract with them
If you are an individual whose information is held by one of our clients, please contact that organisation directly. We will refer any such request to them.
10. Your rights
Under the Privacy Act 2020 you have the right to:
- Ask us to confirm whether we hold personal information about you
- Request access to that information
- Request correction of information that is wrong
To make a request, email [email protected]. We may need to verify your identity. We will respond within 20 working days.
There is no charge for a request, although we may charge a reasonable fee for large or repeated requests, and will tell you before doing so.
11. Marketing and unsubscribing
If we send you marketing emails you can unsubscribe at any time using the link in the email or by emailing us. We comply with the Unsolicited Electronic Messages Act 2007. We will still send you emails necessary to deliver services you have engaged us for.
12. Third party links
Our website may link to other sites. We are not responsible for their privacy practices. Read their policies before providing information.
13. Changes to this policy
We may update this policy. The current version is always available at heliosit.co.nz/privacy with the last updated date at the top.
14. Complaints
If you have a privacy concern, contact us first at [email protected] and we will respond within 20 working days.
If you are not satisfied with our response you can complain to the Office of the Privacy Commissioner:
- Post: PO Box 10094, Wellington 6143
- Phone: 0800 803 909
- Web: privacy.org.nz