Legal
Privacy Policy
This Privacy Policy explains how Tenarie Limited collects, uses, discloses, stores, and protects personal information. It covers the Tenarie public website, business communications, and Tenarie’s own account and service administration. A customer generally controls personal information that it places in its Tenarie workspaces.
1. Who we are and what this policy covers
Tenarie Limited (“Tenarie”, “we”, “us”, or “our”) is a New Zealand company (company number 9425769). We provide Tenarie, a cybersecurity workspace for assurance, governance, risk, compliance, control testing, evidence, reporting, integrations, frameworks, and related work.
This Privacy Policy applies to personal information we handle in connection with:
- tenarie.com, related Tenarie public pages, and online forms;
- Personal, Team, Business, and Enterprise Accounts, and trial, early-access, preview, pilot, or evaluation services;
- sales, support, service, security, billing, account, and administrative communications;
- events, surveys, product feedback, marketing, and business relationships; and
- the Tenarie platform where we process account information, service metadata, security telemetry, analytics, or other information for Tenarie’s own purposes.
This policy does not govern a third-party website, product, or service that Tenarie does not control, even if it links to or integrates with Tenarie. It also does not replace a signed customer agreement or Data Processing Addendum. If those documents conflict with this policy for customer-controlled personal information, the signed agreement governs to the extent of the conflict.
2. Our privacy roles
Privacy laws use different terms for organizations that decide why and how personal information is handled. Under the New Zealand Privacy Act 2020, Tenarie is an “agency”. Under other laws, Tenarie may be a controller, business, or similar decision-maker for information we use for our own purposes, such as website, account, billing, security, support, service analytics, legal-compliance, and marketing information.
When a customer or workspace administrator uploads, imports, connects, creates, or generates information in the Services, that customer generally decides why that Customer Data is processed. For personal information within that data, the customer is usually the controller or responsible agency and Tenarie is usually its processor, service provider, or contractor.
If you are an Authorized User or your information appears in a customer workspace, contact the relevant customer or workspace administrator first for requests about that Customer Data. We may refer your request to that customer because we may not be authorized to respond directly.
3. Personal information we collect
What we collect depends on how you interact with Tenarie. We aim to collect only information reasonably necessary for a lawful purpose.
3.1 Information you provide
- Account and profile information: name, business email address, telephone number, job title, organization, account preferences, role, permissions, workspace details, and authentication information. Passwords are stored in hashed form, not as readable passwords.
- Commercial and billing information: billing contacts and addresses, tax details, plan, payment status, invoices, and transaction records. A payment provider may collect payment-card or bank details directly rather than Tenarie storing them.
- Support and communications: messages, support requests, feedback, attachments, screenshots, diagnostic details, call notes, and recordings or transcripts where lawfully made and disclosed.
- Website, sales, and event information: Contact Us and Product Inquiry submissions, demo or event registrations, survey responses, preferences, and engagement information.
- Customer Data: records, evidence, documents, files, configurations, audit and workflow records, organizational metadata, and connector-imported information you choose to place in the Services.
3.2 Information collected automatically
- Device and network information: IP address, browser and operating-system details, device type or identifiers, language, referring URL, pages viewed, timestamps, and approximate location derived from IP address.
- Account, log, and security information: authentication events, session information, access and API logs, administrative actions, security events, errors, diagnostics, and fraud or abuse signals.
- Usage and telemetry: features used, workspace activity, entitlement use, connector and workflow status, report activity, performance data, and product interaction data.
- Cookie and tracking information: cookie identifiers, preferences, website events, and related data described in section 8.
3.3 Sensitive information we ask you not to provide
Unless Tenarie expressly approves it in writing, do not upload or connect special-category or sensitive personal information; patient or protected-health records; payment-card data; bank-account details; government-issued identifiers; biometric or criminal-record information; information about children; production passwords, private keys, or unrestricted API tokens; or other highly regulated information that is not appropriate for a cybersecurity compliance workspace.
4. How we collect personal information
We collect personal information:
- directly from you when you register, use the Services, submit a form, contact us, attend an event, or otherwise interact with Tenarie;
- automatically through the Website, Services, logs, cookies, security controls, and similar technologies;
- from your employer, customer, account owner, or workspace administrator when they invite you, configure your access, assign permissions, or provide information about you;
- from Third-Party Services that a customer authorizes Tenarie to connect to, including identity providers and source-system connectors;
- from business partners, event organizers, referral sources, professional networks, public sources, and business contact providers; and
- from service providers that help us prevent abuse, secure, operate, measure, or improve the Services.
When we collect information indirectly, we will take reasonable steps to notify the person where New Zealand Information Privacy Principle 3A or another applicable law requires it, unless an exception applies. A customer, administrator, partner, or source may provide that notice where lawful and appropriate.
Providing information is generally voluntary, but we may be unable to create an Account, provide a requested feature, process an Order, respond to an inquiry, or meet a legal requirement without necessary information. Where collection is required or authorized by a particular law, we will identify that law when required.
5. Why we use personal information
| Purpose | Examples |
|---|---|
| Provide and operate Tenarie | Create Accounts, authenticate users, administer organizations and workspaces, enable plans and features, process Customer Data as authorized, and provide integrations. |
| Support and customer success | Respond to requests, troubleshoot, provide service communications, assist with onboarding, and manage customer relationships. |
| Billing and commercial administration | Process payments, issue invoices, administer plans and renewals, assess entitlements or usage, and maintain financial records. |
| Security, integrity, and reliability | Protect Accounts and Services, detect and prevent fraud or misuse, maintain logs, monitor availability, investigate incidents, and enforce agreements. |
| Analytics and improvement | Understand website and product use, fix defects, improve usability and performance, develop features, and produce aggregated or de-identified insights. |
| Communications and marketing | Respond to inquiries and send product, event, research, survey, or business-to-business marketing communications, subject to consent and opt-out rights. |
| Legal and corporate purposes | Comply with law, respond to lawful requests, protect rights and safety, support audits, keep records, defend claims, and complete corporate transactions. |
We may aggregate or de-identify information so it no longer identifies a customer, user, or individual and use that information for lawful business purposes. We will not try to re-identify it except to test whether de-identification is effective or where law permits.
6. Legal bases where applicable
The New Zealand Privacy Act is organized around the Information Privacy Principles rather than the GDPR concept of a single “lawful basis” for every processing activity. We collect personal information only where necessary for a lawful purpose connected with our functions and handle it consistently with the applicable principles.
Where another applicable law requires a legal basis, we may rely on:
- contract: to provide Services, administer Accounts and subscriptions, deliver support, and communicate about the service;
- legitimate interests: to operate, secure, improve, and market Tenarie; prevent abuse; manage business relationships; and protect Tenarie, customers, users, and others;
- consent: for optional tracking, direct marketing, recordings, testimonials, or other activities where consent is required;
- legal obligation: to comply with tax, accounting, corporate, privacy, regulatory, law-enforcement, and other legal duties; and
- vital interests or public interest: in rare cases involving safety, security, emergencies, or lawful public functions.
7. Customer-controlled data
Customers choose what Customer Data to submit, import, connect, configure, or generate. They are responsible for the rights, permissions, notices, consents, lawful bases, and instructions needed to process it.
Where Tenarie processes personal information for a customer, we process it to provide, secure, support, maintain, and improve the Services; follow the customer’s configurations and lawful documented instructions; perform agreed services; and comply with law. Customer Data may include Authorized User information, organizational metadata, evidence and attachments, audit and workflow records, and connector-imported data.
A signed customer agreement or Data Processing Addendum may include more specific processing instructions, confidentiality and security terms, subprocessor requirements, assistance obligations, international-transfer safeguards, and deletion commitments. That document takes precedence for the covered Customer Data.
8. Cookies and website technologies
We use cookies and similar browser technologies for the following purposes:
| Category | Purpose |
|---|---|
| Strictly necessary | Authentication, security, session management, load balancing, fraud prevention, and core service operation. |
| Functional | Remember preferences, form state, language, or interface choices. |
| Analytics and performance | Understand visits and product use, measure performance, improve content and usability, and diagnose errors. |
| Marketing and attribution | Measure campaigns, attribute form submissions, manage business leads, and understand interest in Tenarie, where permitted. |
The public Website uses HubSpot tracking and HubSpot-hosted Contact Us and Product Inquiry forms. The tracking service may receive page URL, referring page, IP address, browser and device details, timestamps, cookie identifiers, and interaction information. A form is loaded only when you open it, but the approved HubSpot website tracking script is currently requested when a Website page loads.
The Website also requests font files from Google Fonts and displays a linked BetaList badge from BetaList. Those providers may receive ordinary web-request information such as your IP address, browser details, requested resource, referring page, and timestamp.
You can block or delete cookies through your browser settings. Blocking technologies may affect Website or Service functionality. Where applicable law requires consent for non-essential technologies or requires recognition of an opt-out preference signal, Tenarie will apply the required choice or control. Browser “Do Not Track” signals are not otherwise interpreted consistently across services.
9. How we share personal information
We do not sell personal information for money. We may disclose personal information to:
- customers and administrators: Account owners, workspace administrators, and authorized personnel who can access user details, roles, activity, audit information, support context, and Customer Data within their permissions;
- service providers and subprocessors: providers of cloud infrastructure, storage, email, forms, customer relationship management, identity, billing, support, analytics, error monitoring, security, logging, backup, and communications;
- integration providers: systems a customer or user authorizes Tenarie to connect to, subject to the integration’s permissions;
- professional advisers: lawyers, accountants, auditors, insurers, consultants, and other advisers subject to appropriate duties;
- business and event partners: resellers, implementation partners, co-hosts, sponsors, or channel partners where lawful and with notice or consent where required;
- corporate transaction parties: prospective or actual buyers, investors, lenders, and advisers involved in a financing, restructure, merger, acquisition, or sale, subject to appropriate safeguards;
- authorities and other parties: courts, regulators, law enforcement, or others where required by law or reasonably necessary to protect rights, safety, security, or the integrity of the Services; and
- recipients you direct: any other person where you or the relevant customer instructs or authorizes disclosure.
Current providers used in parts of the Tenarie environment include HubSpot for Website analytics, forms, and optional contact synchronization; SendGrid for service email; Google for signup anti-automation verification and public Website fonts; and DigitalOcean for hosted infrastructure or object storage where enabled. Provider use and locations may change as our Services evolve.
Some cookie-based analytics or advertising disclosures may be treated as a “sale”, “sharing”, or targeted advertising under certain regional laws even where no money changes hands. Where such a law applies, we will provide required rights and controls.
10. Integrations and connected services
A customer may choose to connect Tenarie to cloud services, identity providers, productivity tools, repositories, security products, storage systems, ticketing services, or other data sources. Enabling an integration instructs Tenarie to access, import, export, disclose, and process information as necessary to provide it.
Third-Party Services have their own privacy, security, retention, availability, and support practices. Customers are responsible for reviewing those terms, configuring least privilege, protecting third-party credentials, and ensuring integrations are lawful and appropriate.
11. International processing and disclosure
Tenarie is based in New Zealand, but we and our service providers may store, access, support, or process personal information in other countries, including Australia and the United States. Those countries may have privacy laws that differ from those where you live.
When Information Privacy Principle 12 applies to a disclosure outside New Zealand, we will take reasonable steps to use a permitted basis for the disclosure. Depending on the circumstances, this may include confirming comparable safeguards, using contractual protections, disclosing to a provider that processes information only on our behalf without independent use, obtaining authorization after informing the individual of the relevant risk, or relying on another lawful ground.
Where EU, UK, Swiss, or similar international-transfer requirements apply, we may use adequacy decisions, standard contractual clauses, the UK international data transfer addendum, transfer assessments, or other lawful safeguards. A signed Data Processing Addendum may provide more specific terms for Customer Data.
12. Security
We use technical and organizational measures designed to protect personal information and Customer Data against accidental or unlawful loss, destruction, alteration, unauthorized access, or unauthorized disclosure. Depending on the system and risk, these measures may include encryption in transit and at rest, access controls and least privilege, multifactor authentication, tenant separation, logging and monitoring, vulnerability management, change control, backup and recovery procedures, personnel training, vendor diligence, and incident response.
No internet transmission or storage system is completely secure, and we cannot guarantee absolute security. Customers and users are responsible for strong credentials, safe devices and networks, appropriate roles and permissions, protection of tokens and connector credentials, and exports or backups appropriate to their needs.
13. Retention
We keep personal information only as long as reasonably necessary for the purposes described in this policy, including providing Services, maintaining Accounts, complying with legal, tax, accounting, and audit duties, resolving disputes, enforcing agreements, maintaining security, preventing fraud, and preserving legitimate business records.
Retention of Customer Data depends on the applicable plan, Terms, signed agreement, account and deletion settings, support process, retrieval period, backup lifecycle, and legal requirements. Paid self-service customers generally have up to 30 days after termination or expiry to use available export methods, subject to the exceptions in our Terms and Conditions. Personal, trial, early-access, preview, pilot, and evaluation access may have a shorter or no post-termination retrieval period.
When information is no longer needed and no lawful retention requirement applies, we will delete, anonymize, aggregate, or securely isolate it until deletion is possible. Protected backups may remain for a limited period until overwritten or deleted through the ordinary backup lifecycle.
14. Your privacy rights
New Zealand law gives individuals rights to request access to personal information we hold about them and to ask us to correct it. If we do not make a requested correction, you may ask us to attach a statement of correction. We will respond within the time required by law, ordinarily no later than 20 working days for a New Zealand Privacy Act request, subject to permitted extensions and withholding grounds.
Depending on your location and context, you may also have rights to request deletion, restriction, objection, portability, or information about processing; withdraw consent; opt out of direct marketing or certain sale, sharing, targeted-advertising, or profiling activities; or complain to a regulator. These rights are not absolute and may be limited by lawful exceptions.
To make a request, use our Contact Us form. We may need to verify your identity and authority, clarify the request, and determine whether Tenarie or a customer controls the information. We may limit, decline, or redirect a request where law permits, including where disclosure would affect another person, reveal confidential security information, conflict with a legal duty, or concern Customer Data controlled by a customer.
15. Marketing communications
We may send business-to-business communications about Tenarie products, services, events, research, surveys, and updates where lawful. You can opt out of marketing emails using the unsubscribe link in the message or by contacting us.
Opting out of marketing does not prevent necessary service, security, legal, billing, support, account, or administrative communications.
16. Children
Tenarie is a business and professional cybersecurity service and is not directed to children. Authorized Users must be at least 18 or the age of legal majority in their jurisdiction, whichever is higher. We do not knowingly collect personal information directly from children through the Services. Customers must not upload or connect children’s information unless Tenarie expressly approves it in writing and appropriate legal, privacy, security, and commercial terms are in place.
17. Privacy breaches
If we become aware of a privacy breach involving information for which Tenarie is responsible, we will assess it and notify affected people, customers, the New Zealand Privacy Commissioner, or other regulators where required by law.
If a confirmed incident affects personal information Tenarie processes for a customer, we will notify that customer in accordance with the applicable Terms, Data Processing Addendum, or signed agreement. The customer may be responsible for assessing and making notifications concerning the Customer Data it controls.
18. Changes to this policy
We may update this Privacy Policy to reflect changes in our Services, business, law, technology, or privacy practices. We will post the revised policy with an updated date. If a change materially affects your privacy rights or how we use personal information, we will provide additional notice where required by law or where reasonably appropriate.
19. Contact and complaints
Contact our privacy officer with a question, request, or complaint using our Contact Us form.
- Company: Tenarie Limited
- New Zealand company number: 9425769
- Website: tenarie.com
If you are not satisfied with our response, you may complain to the Office of the Privacy Commissioner of New Zealand or another regulator with jurisdiction. We encourage you to contact us first so we can try to resolve the matter.