VeridianVERIDIANANALYTICS LIMITED
Legal · Privacy

Data Privacy & Protection Policy

Trust is the foundation of everything we do — particularly given the sensitive financial and compliance data our work involves. This policy explains how we collect, use, store, protect, and dispose of personal information, and the rights you hold over it.

Last updated: June 2026

01Our commitment

Veridian Analytics Limited (“Veridian,” “we,” “us,” or “our”) provides data analytics, business intelligence, and AML/CFT consulting, risk assessment, training, and compliance support services to small and medium businesses in New Zealand. Trust is the foundation of everything we do, particularly given the sensitive financial and compliance data our work involves. This policy explains how we collect, use, store, protect, and dispose of personal information and client data, and the rights you hold over your information.

This policy is designed to comply with the New Zealand Privacy Act 2020 and reflects internationally recognised privacy and data protection principles where applicable.

02Information we collect

Depending on the nature of our engagement, we may collect:

  • Identity information — full name, date of birth, contact details, and government-issued identification, where required for customer due diligence (CDD) or beneficial ownership verification.
  • Business information — company registration details, financial statements, organisational structure, and beneficial ownership records.
  • Transactional and financial data — banking records, transaction histories, and payment data submitted for analytics or AML/CFT risk assessment purposes.
  • Technical data — IP addresses, device information, and website usage analytics collected through our website and client portals.
  • Communications — emails, meeting notes, and other correspondence arising from our engagement with you.

We collect personal information directly from individuals wherever practicable. Where we collect information indirectly — for example, from a third-party data provider, public register, or referral — we will, in line with Information Privacy Principle 3A (IPP 3A), take reasonable steps to notify the individual concerned, consistent with our obligations under the Privacy Act and applicable New Zealand privacy legislation.

03Why do we collect it?

We only collect and use personal information for purposes that are lawful, necessary, and directly connected to our services, including:

  1. 1.Delivering data analytics, reporting, and business intelligence services under client engagement agreements.
  2. 2.Conducting AML/CFT risk assessments, customer due diligence, and compliance support work.
  3. 3.Meeting our own regulatory obligations as a service provider, including under applicable AML/CFT legislation.
  4. 4.Improving our services, including the limited use of de-identified or aggregated data for service development.
  5. 5.Communicating with clients, prospective clients, and website visitors who make enquiries.

We do not use personal information for any purpose unrelated to these activities without first seeking explicit consent.

04Our legal basis for processing

ActivityLegal basis
Client analytics & reporting engagementsPerformance of a contract; consent
AML/CFT support & risk assessmentLegal obligation under the AML/CFT Act 2009; legitimate interest in supporting client compliance
Marketing communicationsConsent (opt-in); legitimate interest, where permitted
Website analyticsConsent via cookie preferences; legitimate interest
Regulatory and law enforcement requestsLegal obligation

Where we process special categories of data — such as information that may reveal suspected criminal activity in the course of AML/CFT support work — we do so strictly under the legal obligation and crime-prevention bases recognised under both NZ and international data protection frameworks, and limit access to authorised personnel only.

05How we protect your information

We apply administrative, technical, and physical safeguards proportionate to the sensitivity of the data we hold, including:

  • Encryption of data in transit and at rest.
  • Role-based access controls that limit data access to personnel who require it to perform their duties.
  • Secure New Zealand and internationally-hosted cloud infrastructure with audited security certifications.
  • Regular review of our data handling practices and third-party processor agreements.
  • Confidentiality obligations that apply to all staff and contractors who handle client data.

06Data retention

We retain personal information only for as long as necessary to fulfil the purposes outlined in this policy, including any legal, regulatory, or reporting requirements. In particular:

  • AML/CFT-related records — including customer due diligence documentation, risk assessments, and records of transactions reviewed in the course of our support work — are retained for a minimum of five years, consistent with the record-keeping obligations under the AML/CFT Act 2009.
  • General client and business records are retained for the duration of the client relationship and a reasonable period thereafter to meet legal, accounting, and dispute resolution requirements.
  • Website and marketing data is retained only as long as necessary for the purpose collected, or until consent is withdrawn. Our website may use cookies and analytics tools to improve user experience and understand website performance. Users may manage cookie preferences through their browser settings.

Once information is no longer required, we securely delete or irreversibly de-identify it.

07Sharing and cross-border transfer of information

We do not sell personal information. We may share information with:

  • Subcontractors or service providers (e.g. secure cloud hosting providers) under written confidentiality and data protection agreements.
  • Regulators, the New Zealand Police Financial Intelligence Unit (FIU), or other authorities, where required or authorised by law.
  • Professional advisors, where necessary to deliver our services.

Where personal information is transferred outside New Zealand — including to cloud infrastructure providers located overseas — we ensure the transfer complies with Information Privacy Principle 12 of the Privacy Act 2020. This means we only transfer data overseas where:

  • The receiving jurisdiction has comparable privacy safeguards (New Zealand currently holds EU adequacy status, meaning data flows between the EU/EEA and NZ are recognised as meeting equivalent protections in both directions); or
  • The recipient is itself subject to the NZ Privacy Act; or
  • We have your authorisation, having informed you of the risks; or
  • The transfer is otherwise permitted under a prescribed binding scheme.

08Your rights

Under the Privacy Act 2020, and consistent with international frameworks such as the GDPR, you have the right to:

  • Access the personal information we hold about you.
  • Correct information you believe is inaccurate, incomplete, or misleading.
  • Request an explanation of how a decision affecting you was made, where automated processing is involved.
  • Make a complaint about how we have handled your information.

We will respond to access and correction requests within 20 working days, as required under the Act. Please note that in certain circumstances — particularly relating to active AML/CFT investigations or suspicious activity reporting — we may be legally restricted from disclosing certain information, including the existence of a report made to the FIU (“tipping-off” prohibitions under the AML/CFT Act).

To exercise your rights, contact us at privacy@veridiananalytics.co.nz.

09Data breach notification

In the event of a privacy breach that has caused, or is likely to cause, serious harm, we will notify the Office of the Privacy Commissioner and affected individuals as soon as practicable, in accordance with the mandatory breach notification requirements of the Privacy Act 2020.

10Complaints

If you are unsatisfied with how we have handled your personal information, you may contact us directly at privacy@veridiananalytics.co.nz. If you remain unsatisfied, you have the right to lodge a complaint with the Office of the Privacy Commissioner (www.privacy.org.nz), which has authority to investigate complaints and, where unresolved, refer matters to the Human Rights Review Tribunal.

11Changes to this policy

We may update this policy from time to time to reflect changes in law, regulation, or our business practices. The “last updated” date at the top of this page will always reflect the most current version.

12Professional services disclaimer

Veridian Analytics Limited provides data analytics, business intelligence, and compliance support services. We do not provide legal advice, financial advice, or regulatory determinations. Clients should obtain independent professional advice where required.

Contact us

Veridian Analytics Limited, Auckland, New Zealand

NZBN: 9429053740748

Email: privacy@veridiananalytics.co.nz

This policy does not constitute legal advice. Clients with specific compliance obligations should seek independent legal counsel regarding their own data protection responsibilities.