Skip to content

Legal

Privacy Policy

How we handle personal information under the New Zealand Privacy Act 2020 and, where it applies, Australian privacy law.

Effective 10 October 2026 · ResponseRise Ltd

1. Who we are

AssessDesk is provided by ResponseRise Ltd, a New Zealand company. This policy explains how we handle personal information under the New Zealand Privacy Act 2020 and, where it applies, the Australian Privacy Act 1988 and the Australian Privacy Principles.

You can reach our privacy officer at support@assessdesk.co.nz.

2. Two kinds of information

Information about our customers and users. Details of the consultancies that subscribe, their team members, and people who use the client portal, so we can run accounts, billing and support. We are responsible for this information.

Information our customers put into AssessDesk. Consultancies store information about their clients, such as staff names, contact details, facilities, training records, assessment answers, reports, findings, photos and documents. We hold this on behalf of the consultancy, which is responsible for it. If you are a client of a consultancy and have a question about your information, please contact that consultancy first; we'll help them respond.

3. What we collect

Account details: name, email address, phone, position, profile photo, and (if you add one) a signature image for reports.

Sign-in security: your password (stored only in a one-way scrambled form, never readable), two-step sign-in settings, and the public part of any passkey (Face ID or Touch ID). Your fingerprint or face never leaves your device.

Business and billing details: your firm's name, address, branding and subscription. Card payments are handled by Stripe; we don't see or store full card numbers.

Activity records: sign-ins, changes, downloads and exports, with the time and IP address, kept for security and to give you an audit trail.

Devices: if you use the phone app and allow notifications, a device token so we can send them.

Messages: emails you send us for support.

Course sign-in: when someone signs in to a course with a QR code, their name, the course and the time (and, if they add themselves, their email and workplace).

We collect this from you directly, from your organisation (for example when a consultancy invites you), or automatically as you use the Service.

4. How we use it

to provide the Service, including sign-in, notifications and emails about activity on your account;

to keep the Service and your data secure, back it up, and investigate misuse;

to bill subscriptions and provide support;

to tell account owners about important changes to the Service, prices or these policies;

to meet our legal obligations.

We don't sell personal information, use it for advertising, or use information our customers put into AssessDesk to train artificial intelligence models. We don't use analytics or tracking tools.

5. Who we share it with

We share information only with the suppliers who help us run the Service, under agreements that require them to protect it, and where the law requires it.

SupplierWhat forWhere
VercelRuns the website and appSydney, Australia (company in the USA; some logs may be processed there)
Neon (on Amazon Web Services)Database and its backupsSydney, Australia
Cloudflare R2Documents, photos, files and their backupsOceania region
PostmarkSending emailsUnited States
StripeSubscription paymentsUnited States and elsewhere
ApplePhone app notificationsUnited States

Within a consultancy, information is visible to the people that consultancy gives access to. Clients see only their own organisation's information, and only what the consultancy shares with them.

6. Where it's stored

AssessDesk's database, files and backups are stored in Australia. Australia's privacy laws give protections comparable to New Zealand's. Where suppliers process information in the United States (for example the content of emails we send, and payment details), we choose suppliers that protect it in a way comparable to New Zealand law, as the Privacy Act requires.

7. How we protect it

encryption in transit (HTTPS) and at rest;

each consultancy's information is kept separate, checked on every request;

two-step sign-in for team accounts (optional for client users), and on every account we use to run the Service;

passwords stored only in a one-way scrambled form;

private file storage, with files only handed out after a permission check;

continuous database backups and daily file backups;

monitoring and alerts for errors and suspicious sign-in activity;

records of sign-ins and changes, and limited, recorded access for our own people.

8. How long we keep it

While a subscription is active: for as long as the consultancy keeps it in AssessDesk.

After a subscription ends: for 30 days the consultancy's team can still sign in, read-only, to export; then it is permanently and automatically deleted from the Service; backup copies expire within a further 30 days.

Billing records: as long as tax law requires (in New Zealand, generally 7 years).

Activity records: 2 years, then deleted automatically (and all of them when the account is deleted).

9. Your rights

You can ask to see the personal information we hold about you and ask us to correct it. Most details can be changed directly in your Profile. For information a consultancy holds about you in AssessDesk, contact that consultancy; we'll pass on requests that reach us. We'll respond within 20 working days.

If you're not happy with how we've handled your information, please contact us first. You can also complain to the Office of the Privacy Commissioner (privacy.org.nz) in New Zealand, or the Office of the Australian Information Commissioner (oaic.gov.au) in Australia.

10. Cookies

AssessDesk only uses cookies it needs to work: keeping you signed in, completing two-step and passkey sign-in, and remembering a few display choices (such as how a list is shown). We don't use advertising or analytics cookies.

11. If something goes wrong

We have a written plan for responding to privacy breaches. If a breach is likely to cause serious harm, we'll notify the people affected and the Privacy Commissioner as the Privacy Act requires (and the Office of the Australian Information Commissioner where the Australian scheme applies). Where the breach involves information a consultancy holds in AssessDesk, we'll tell that consultancy straight away and help them notify.

12. Changes and contact

We may update this policy and will publish the current version on our website, with the date it took effect. We'll email account owners about significant changes.

Questions or requests: support@assessdesk.co.nz.

Privacy Policy · AssessDesk