Privacy Statement

Purpose of Collection

Axenic only collects information for the purpose of delivering and marketing our services.

Specifically:

  • We collect information about prospective customers for the purpose of marketing our services.
  • We collect information about current customers (including their staff, contractors and suppliers) for the purpose of delivering our services.
  • We collect information about website visitors in order to evaluate the performance of our website.
  • We collect information within our approved tools as part of providing these services to our customers.
  • We may process information using approved AI tools to support the marketing, sales and delivery of our services, such as meeting transcription and drafting deliverables. Our use of AI is described in the section below.

Method of Collection

In general, Axenic will only collect information directly from an individual unless authorised to collect information from another party authorised by that individual (e.g. in the case of references). When collecting personal information, individuals should be made aware of what that information will be used for (e.g. “we will use your email address to send you our newsletters”).

Meetings and workshops may be recorded and transcribed using approved AI tools, only with the knowledge and agreement of participants.

In the course of delivering our services, we may collect personal information about individuals (for example, the staff of our customers) from someone other than the individual concerned, such as through documents, interviews, or meeting transcripts provided to us. Where this occurs, as soon as reasonably practicable we take reasonable steps to make sure those individuals are aware of the collection, its purpose, who may receive the information, that Axenic is the agency collecting and holding it, and their rights of access and correction. In most cases, this notification takes place through our customer rather than directly by us. Where notifying an individual is not reasonably practicable, or another exception under the Privacy Act applies, we may not do so directly.

Personal Information Collected

Customers and prospective customers

We collect information about customers, prospective customers and their stakeholders to deliver and market our services. This includes:

  • Names
  • Contact details (e.g. email address, phone numbers)
  • Employment details (e.g. employer, job title)

Website visitors

We collect information about website visitors to understand how our website is used and to improve it. This includes:

  • IP addresses
  • Operating system
  • Type of web browser
  • Date, time and duration of visit
  • Pages accessed
  • Search terms

We use Google Analytics to collect this information. Google Analytics uses cookies to do this. For more information about Google Analytics click here, and to read Google's privacy policy click here.

Workshop and meeting attendees

When we deliver services such as workshops, interviews, or meetings (including over Microsoft Teams or similar platforms), we may collect information about attendees who are not our direct customer contact, for example other staff, contractors, or stakeholders invited by our customer. This may include:

  • Names
  • Job titles
  • Contact details
  • Anything said or recorded during the session

Where meetings are recorded or transcribed, this is done only with the knowledge of participants, in line with the AI section below. As with other indirect collection, we rely on our customer to make attendees aware that Axenic may be present, may record the session, and may collect and use their information for this purpose. Attendees can contact us directly using the details in this statement if they have questions about how their information is used.

GRC tools

When we deliver services using our approved GRC tools (such as our C&A Portal), we collect the same information about our customer's stakeholders as set out under Customers and prospective customers above. Our GRC tools also allow customer users to record the details of other people within their organisation, such as a system owner assigned to a risk or control. Where a customer does this, we may be able to see:

  • Names
  • Contact details (e.g. email address)
  • Role or job title

Prospective employees and job applicants

For prospective employees, we collect information to facilitate the recruitment process. This is detailed on our careers site - https://careers.axenic.co.nz/privacy-policy

Use of Artificial Intelligence

Axenic uses approved AI tools to support the delivery of our services and our internal operations. Our use of AI is governed by our AI Responsible Use Policy, which is aligned with the requirements of ISO/IEC 42001, and a curated list of approved AI use cases.

When AI tools process personal information:

  • AI services are approved for use only after a third-party security and privacy assessment, consistent with our ISMS requirements and our ISO/IEC 27001:2022 certification.
  • Personal information is never used to train or improve any AI model, whether operated by Axenic or a third-party provider.
  • We configure data retention opt-outs so that information entered into AI tools is not retained by the provider beyond the processing task.
  • AI output that relates to individuals is reviewed by a person. AI does not make decisions about individuals.

Securing Personal Information

Axenic’s employees follow our privacy policy, information security policy and associated requirements from our Information Security Management System (ISMS) that provide guidance on how to secure all of our information including personal information. This includes how and where to store that information.

Approved AI tools are subject to the same ISMS requirements as all other systems, including access control, logging and incident management. Incidents involving AI tools are managed under our incident management process.

Retention of Personal Information

Axenic will keep personal information only as long as is required to fulfil the purposes for which it has been collected. Specifically:

  • Customer and prospective customer contact information is retained indefinitely as we periodically get in touch with customers and prospective customers to market and deliver our services.
  • Approved GRC tool data is retained for the lifetime of the customer's subscription.
  • Website visitor data is retained for 26 months, to allow us to understand website trends.
  • Workshop and meeting attendee information, including recordings and transcripts, is retained only for the duration of the engagement and deleted once the engagement ends.
  • Personal information entered into approved AI tools is not retained by the provider beyond the processing task, in line with our configured retention settings and enterprise agreements.

If you contact us and ask for your personal information to be removed before the end of the retention period, we will consider all reasonable requests. Where removing that information does not prevent us from providing a service to our customer, or meeting a legal or policy obligation, we will remove it.

Requests for Personal Information

All individuals may request copies of information held about them by Axenic. They should do this by contacting the Chief Privacy Officer directly or emailing privacy@axenic.co.nz.

If we receive a request for personal information, we will:

  • Verify the identity of the sender
  • Acknowledge the request within seven working days
  • Respond within 20 working days (unless an extension is required)
  • Advise the requestor if information needs to be withheld

Correction of Personal Information

Any individual may request that personal information held about them be corrected. Such requests should be directed to the Chief Privacy Officer.

Axenic will endeavour to correct the information or note that a correction was requested if Axenic disagrees that a correction is required (i.e. Axenic believes the information is correct).

If information is corrected, we will consider whether inaccurate information has been disclosed to other parties.

Disclosure of Information

Personal information will not be disclosed to other parties or organisations unless this has been authorised by the individual concerned, is necessary to comply with a legitimate legal request, or is necessary for the purpose the information was obtained.

Some of the approved AI and cloud services we use are operated by providers hosted outside New Zealand, including in Australia and the United States. Where personal information is processed by these providers, we only use providers under enterprise agreements that contractually require the information to be protected in a way that, overall, provides comparable safeguards to those in the New Zealand Privacy Act 2020. For customers with jurisdiction requirements, we offer AI services hosted and processed in Australia.

Complaints

Complaints should be directed to the Chief Privacy Officer, who will investigate and action privacy complaints within a reasonable timeframe. If an investigation identifies a privacy incident, the process described under Incidents below will be followed.

If you are not satisfied with our response, you have the right to complain to the Office of the Privacy Commissioner. You can find out how to make a complaint on the Privacy Commissioner's website: privacy.org.nz.

Incidents

If an event causes one of the Information Privacy Principles to be breached, or breaches one of the commitments in this statement, our privacy incident management process will be invoked. If the incident involves a security breach (i.e. a breach of IPP 5), the security incident management process will be used, with the Chief Privacy Officer added as a stakeholder.

For a privacy incident with no security implications, the security incident process will still be used, but the Chief Privacy Officer will replace the CISO as the accountable party.

Where a privacy breach has caused, or is likely to cause, serious harm, we will notify the Office of the Privacy Commissioner and the affected individuals, as required under Part 6 of the Privacy Act 2020.

Your rights

You have the right to ask for a copy of any personal information we hold about you, and to ask for it to be corrected if you think it is wrong.

If you’d like to ask for a copy of your information, or to have it corrected, please contact us using one of the following methods:

Email: privacy@axenic.co.nz

Telephone: +64 4 499 8012

Post:

Chief Privacy Officer

Axenic Ltd.

PO Box 25494

Wellington 6146

New Zealand

 

Last updated: August 2026