Last updated: 23 August 2026
Why this page opens the way it does
In 2008 the religious historian Karen Armstrong was awarded the TED Prize, and used it to
ask for something unusual: a shared charter, written by people of many faiths and none, built
on the one rule almost every tradition arrives at independently — that we should treat others
as we would wish to be treated. The Charter for Compassion was launched on 12 November 2009 and has since been
signed by people in more than a hundred countries.
We are not a signatory and we claim no association. We simply think the Golden Rule is the
right test for a privacy policy, because a privacy policy is exactly the document where a
company decides how much of your life it is comfortable helping itself to.
So the whole of what follows is one question asked repeatedly: would we be content
if someone did this with ours? Where the answer was no, we stopped doing it. That is
why this page is shorter than most, and why there is no section explaining our advertising
partners.
1. Who we are
Primesoft NZ Ltd is a New Zealand company providing software development and IT services to
clients in the Auckland region and throughout New Zealand.
We are the agency responsible for the personal information described here, under the
Privacy Act 2020.
Privacy Officer: Greg Stevenson
Email: greg@primesoft.co.nz
Or: use the form on our contact page
2. What we collect
If you just visit this website
Our web server records the ordinary things a web server records: the IP address making the
request, the page asked for, the time, and the browser’s self-description. These logs exist so
we can keep the site running and secure.
This site runs no analytics, no advertising trackers, and no third-party cookies.
We do not use Google Analytics, Tag Manager, advertising pixels, or session-recording tools.
No third party receives a record of your visit. Cookies are set only for administrators who log
in to manage the site.
If you contact us
The contact form collects the name, email address, subject and message you type into it. We
use them to answer you, and we keep the correspondence so that we have a record of what was
asked and what we said.
If you are a client
Delivering software development, support and IT services means we hold business contact
details, records of the work, correspondence, and — depending on the engagement — access to
systems that contain your own organisation’s data. We treat anything we can see inside a client
system as confidential and use it only to do the work we were engaged to do.
Our LinkedIn application
Primesoft operates a small private application that publishes posts to our own
LinkedIn profile through LinkedIn’s API. Section 8 sets out exactly what it touches.
3. Why we collect it, and what we use it for
We collect personal information only where we need it for a lawful purpose connected to
running our business: answering enquiries, delivering and supporting the services we have been
engaged to provide, invoicing, meeting our legal and tax obligations, and keeping our systems
secure.
We do not use your information for any other purpose without asking you first, and
we do not sell personal information to anyone, ever. We do not build marketing
profiles and we do not run behavioural advertising.
4. Where it is held
This website and its data sit on servers owned and operated by Primesoft in New Zealand.
Our email is hosted on Microsoft 365, and our LinkedIn application necessarily talks to
LinkedIn. Both are overseas providers, so information in our email or sent through that
application is stored outside New Zealand — see section 6.
5. Who we share it with
We disclose personal information only:
- to service providers who need it to do something for us — hosting, email, accounting —
and only as much as that task requires; - where you have asked us to, or would obviously expect us to;
- where the law requires it, or to establish or defend a legal claim; or
- where disclosure is necessary to prevent a serious threat to someone’s life, health or
safety.
We do not share client data between clients.
6. Information that goes overseas
Under information privacy principle 12 we must tell you when personal information leaves New
Zealand. Ours does, in two places:
- Microsoft 365 — our email. Microsoft operates under privacy obligations
comparable to New Zealand’s. - LinkedIn (United States) — only the content we ourselves publish, and the
credentials for our own account. See section 8.
7. How long we keep it
We keep personal information only as long as we have a reason to. Enquiries that go nowhere
are deleted once the conversation is finished. Client records are kept for the life of the
engagement and then for as long as tax, contractual and professional-record obligations require
— generally seven years. Server logs are kept for a short operational period and then rotated
away.
8. Our LinkedIn application, in detail
We run a private, internal application registered with LinkedIn that lets us prepare and
publish posts to our own LinkedIn profile rather than composing them by hand in a browser. It
exists for our convenience. It is not offered to anyone else and it has no users but us.
What it requests: permission to post as the signed-in member
(w_member_social), and basic sign-in (openid, profile) so
it knows which profile it is posting to.
What it stores: an access token for our own LinkedIn account, and our own
LinkedIn member identifier. Both are held on Primesoft-controlled machines with file permissions
restricting them to the operating account.
How it publishes: only when one of us explicitly tells it to, one post at a
time. Nothing is published automatically or on a schedule.
What it does not do: it does not read your LinkedIn profile, your connections,
your messages, or your activity. It does not collect, store or process the personal information
of any other LinkedIn member. It does not scrape LinkedIn. It does not import LinkedIn data into
any other system, and nothing it touches is sold, shared or used for advertising.
If you have interacted with a Primesoft post on LinkedIn, that interaction is held by LinkedIn
under LinkedIn’s own
privacy policy, not by us.
9. Keeping it safe
We protect personal information with the safeguards you would expect of a company that does
this for a living: encrypted connections, access limited to the people who need it, credentials
held in encrypted stores rather than in documents or code, patched systems, and backups.
No system is perfect. If we ever suffer a privacy breach that has caused, or is likely to
cause, serious harm, the Privacy Act 2020 requires us to notify the Office of the Privacy
Commissioner and the people affected as soon as practicable — and we will.
10. Your rights
You have the right to ask us whether we hold personal information about you, to see it, and
to ask us to correct it if it is wrong. Write to the Privacy Officer at the address in section 1.
We will respond as soon as we can and within 20 working days, as the Act requires. There is no
charge. If we cannot give you something — because it would reveal another person’s information,
for example — we will tell you why, and we will attach a note of your requested correction to the
record even where we do not agree with it.
11. If you are unhappy with how we have handled this
Tell us first, at the address in section 1. We would rather hear it than not.
If we do not resolve it to your satisfaction, you can complain to the Office of the Privacy
Commissioner:
- privacy.org.nz
- 0800 803 909
- PO Box 10 094, Wellington 6140
12. Changes
If we change this policy we will change the date at the top of this page. If a change is
significant, we will say what changed rather than quietly replacing the text.