Privacy Policy
Gorilla Technology Ltd · Applies to gorillatechnology.com and our services
Last updated: 16 September 2026
Gorilla Technology Ltd (“Gorilla”, “we”, “us” or “our”) provides IT services, IT projects, software development, cybersecurity and technology advisory services to organisations across New Zealand and internationally. We take the privacy of personal information seriously and this policy explains how we collect, use, store, disclose and protect it, in line with the Privacy Act 2020 and the 13 Information Privacy Principles (IPPs) it sets out.
This policy applies to personal information we hold about clients, prospective clients, website visitors, job applicants, suppliers and other individuals we deal with in the course of our business. It does not apply to information we process purely on behalf of a client as that client’s IT service provider, where the client remains responsible as the agency collecting that information under the Act; in those cases the client’s own privacy policy governs.
CONTENTS
Information we collect
How we collect it
How we use your information
Who we share it with
Overseas storage and disclosure
Cookies and website analytics
Marketing communications
How we keep it secure
How long we keep it
Access, correction and your rights
Privacy breaches
Children’s privacy
Links to other websites
Changes to this policy
How to contact us
INFORMATION WE COLLECT
The personal information we collect depends on how you interact with us. It typically includes:
- Contact details – name, job title, organisation, email address, phone number and postal address.
- Enquiry and engagement information – details you provide when you contact us, request a quote, book an audit, or engage us for services, including any Statement of Work correspondence.
- Technical and account information collected when delivering managed IT, cybersecurity or software development services, such as system logs, device details, network configuration data and, where relevant to a support ticket, information contained in the systems we are asked to work on.
- Website usage information – pages viewed, referral source, approximate location, device and browser type, and other information gathered through cookies and analytics tools (see “Cookies and website analytics” below).
- Recruitment information – CVs, cover letters, references and interview notes, if you apply for a role with us.
- Communications – records of calls, emails, meeting notes and correspondence with our team.
We do not seek to collect sensitive information beyond what is reasonably necessary for the services above, and we do not knowingly collect more personal information than we need.
HOW WE COLLECT IT
Wherever practicable, we collect personal information directly from you – for example, through our website contact and enquiry forms, by phone, by email, or in person or via video call. We may also collect information:
- From your organisation, where a colleague provides your contact details for a project or support engagement.
- Automatically through our website, via cookies and analytics tools.
- From publicly available sources, such as company registers or LinkedIn, for business development purposes.
- From third parties such as referees or recruitment platforms, in a hiring context.
HOW WE USE YOUR INFORMATION
We collect and use personal information for the following purposes, consistent with IPP 10:
- To respond to enquiries and provide quotes.
- To deliver, manage and invoice for IT services, projects, software development, cybersecurity and advisory work.
- To provide support, troubleshoot issues and maintain the security and reliability of systems we manage.
- To communicate with you about your account, service changes, or matters relevant to an engagement.
- To send marketing communications about our services, where you have agreed to receive these or as otherwise permitted by law.
- To improve our website and services, including through website analytics.
- To assess job applications.
- To meet our legal, regulatory, tax and accounting obligations, and to establish, exercise or defend legal claims.
We do not sell personal information. We may disclose it to:
- Service providers we engage to help run our business, such as hosting providers, cloud platform providers (including Microsoft 365), accounting and payroll providers, email and communications tools, and website analytics providers – each bound by contract or their own privacy terms to protect the information.
- Subcontractors and specialist partners, where needed to deliver a particular project or Managed Detect and Respond service, as described in our Standard Terms.
- Professional advisers, such as our lawyers, accountants or insurers, where reasonably necessary.
- Regulators or authorities, where required by law, such as the New Zealand Police, Inland Revenue, or in response to a lawful request.
- A purchaser or prospective purchaser of all or part of our business, subject to appropriate confidentiality protections.
We only disclose the information reasonably necessary for these purposes.
OVERSEAS STORAGE AND DISCLOSURE
Some of the tools we use to run our business and deliver services – including cloud hosting, Microsoft 365 and other software-as-a-service platforms – store or process data on servers located outside New Zealand, including in Australia, the United States or elsewhere. Under IPP 12, before we disclose personal information to an overseas person, we consider whether that overseas recipient is subject to privacy laws providing comparable safeguards to the Privacy Act 2020, or otherwise ensure appropriate contractual protections are in place. Where practicable, we prefer providers offering New Zealand or Australian data hosting regions.
Our website uses cookies and similar technologies to help it function properly and to understand how visitors use the site. This may include tools such as website analytics services that record page views, session duration, general location (derived from IP address) and referral information. This data is generally aggregated and does not identify you personally, though IP addresses can in some circumstances be personal information.
Most browsers let you refuse or delete cookies through their settings. Doing so may affect how some parts of our website work.
MARKETING COMMUNICATIONS
We may send you information about our services, insights or events by email, in line with the Unsolicited Electronic Messages Act 2007. Every marketing email includes a way to unsubscribe, and we will action any unsubscribe request promptly. Unsubscribing from marketing communications will not affect service-related communications about an active engagement.
HOW WE KEEP IT SECURE
As a cybersecurity-focused technology partner, we apply the security practices we recommend to our own clients. This includes access controls, encryption of data in transit and at rest where appropriate, staff training, and regular review of our own systems. No system is completely secure, but we take reasonable steps under IPP 5 to protect personal information against loss, misuse and unauthorised access, use, modification or disclosure.
HOW LONG WE KEEP IT
We keep personal information only for as long as it is needed for the purposes described in this policy, or as required by law – for example, tax and accounting records are generally retained for at least seven years under New Zealand law. Once information is no longer required, we take reasonable steps to delete or de-identify it, in line with IPP 9.
ACCESS, CORRECTION AND YOUR RIGHTS
Under IPPs 6 and 7, you have the right to ask us:
- Whether we hold personal information about you, and to access that information.
- To correct personal information we hold about you if it is wrong, or to attach a statement of correction if we disagree with the requested correction.
To make a request, contact us using the details below. We will respond within the timeframes required by the Privacy Act 2020 (normally within 20 working days) and may ask you to verify your identity first. There is generally no charge for a straightforward access or correction request.
PRIVACY BREACHES
If we become aware of a privacy breach that has caused, or is likely to cause, serious harm, we will notify the affected individuals and the Office of the Privacy Commissioner as soon as practicable, in accordance with our obligations under the Privacy Act 2020.
CHILDREN’S PRIVACY
Our services are directed at businesses and organisations rather than children. We do not knowingly collect personal information from children, and if we become aware that we have done so without appropriate consent, we will take steps to delete it.
LINKS TO OTHER WEBSITES
Our website may contain links to third-party websites, including social media platforms. We are not responsible for the privacy practices of those sites, and we encourage you to review their own privacy policies.
CHANGES TO THIS POLICY
We may update this policy from time to time to reflect changes in our practices or the law. The “last updated” date at the top of this page shows when it was last revised. We encourage you to review this policy periodically.
HOW TO CONTACT US
If you have a question, request or concern about how we handle personal information, please contact us:
Gorilla Technology Ltd
Phone: +64 9 377 8977
Contact form: gorillatechnology.com/contact-us
If you are not satisfied with our response, you can contact the Office of the Privacy Commissioner:
Office of the Privacy Commissioner
Website: privacy.org.nz
Phone: 0800 803 909
© 2026 Gorilla Technology Ltd. All rights reserved. This privacy policy is provided for general information and does not constitute legal advice.