Data Security Statement

1. Our Commitment

Awareness Academy recognises the importance of protecting personal and organisational information.

We aim to apply appropriate safeguards to the information we collect, use and manage through our services.

Our security approach is designed to support confidentiality, integrity and appropriate access to information.

2. Information Protection

Depending on the information and systems involved, our security practices may include:

  • Access controls.
  • Secure account management.
  • Appropriate handling of confidential information.
  • Use of reputable technology service providers.
  • Regular review of information handling practices.
  • Measures to reduce the risk of unauthorised access.

Specific security measures depend on the systems and service providers used.

3. Access Management

Access to information should be limited to authorised individuals who require it for legitimate business or service delivery purposes.

Where client or participant information is involved, access arrangements should reflect the agreed scope of the engagement.

4. Assessment and Organisational Data

Our organisational assessment services may involve information relating to employee wellbeing, resilience and workplace experiences.

We aim to support responsible data handling through:

  • Clear assessment purposes.
  • Appropriate reporting arrangements.
  • Consideration of confidentiality.
  • Appropriate access restrictions.
  • Use of aggregated reporting where suitable.

The specific data management arrangements will depend on the assessment design and client agreement.

5. Third Party Technology Providers

Awareness Academy may use external platforms for:

  • Website hosting.
  • Online learning.
  • Booking and scheduling.
  • Communications.
  • Data collection.
  • Assessment delivery.

These providers may process information on our behalf or independently under their own terms.

We consider the security and privacy implications of the services we use.

6. Data Breach Response

If we become aware of a suspected or confirmed security incident involving personal information, we will assess the incident and take appropriate steps to contain, investigate and respond to it.

Where legally required, we will notify affected parties and relevant authorities.

7. Client Responsibilities

Organisations engaging Awareness Academy should ensure that:

  • They have appropriate authority to provide information.
  • Participants receive relevant privacy information.
  • Data access arrangements are clearly established.
  • Any additional security requirements are communicated before engagement.

Specific responsibilities may be established through a written client agreement.

8. Questions About Data Security

If you have questions about our data security practices, please contact:

Awareness Academy
Email: zac@awarenessacademy.co.nz
Phone: +64 (0) 21 724 974