shield

Privacy Policy

A safe workplace starts with strong digital defenses, and our commitment to cybersecurity ensures your data is always protected.

1. About this Privacy Policy

1.1 Who we are

ecoPortal is the trading name used by Triplics Limited and its affiliated entities. Unless a collection notice, customer agreement or communication identifies another entity, Triplics Limited is responsible for the ecoPortal website, general enquiries and global marketing activities. The relevant contracting entity is responsible for its own customer, account, billing and relationship-management processing.

Region or activity Responsible ecoPortal entity Address
New Zealand and global website Triplics Limited, NZBN 9429031345217 24 St Benedicts Street, Eden Terrace, Auckland 1010, New Zealand
Australia ecoPortal Australia Pty Ltd, ABN 87 653 664 503 Suite 502 5 140 Bourke Street, Melbourne, VIC 3000, Australia
United Kingdom ecoPortal UK Limited, company number 16721819 Ground Floor, Dearing House, 1 Young Street, Sheffield, S1 4UP, United Kingdom

In this Privacy Policy, “ecoPortal”, “we”, “us” and “our” refer to the relevant ecoPortal entity acting as the privacy agency, APP entity, controller or processor for the processing described. The applicable entity will ordinarily be identified in the relevant customer agreement, order form, collection notice or communication. You may contact any ecoPortal entity through privacy@ecoportal.com and we will route the request to the appropriate entity.

1.2 Scope

This Privacy Policy explains how ecoPortal collects, holds, uses, discloses, transfers, protects and deletes personal information in connection with:

  • the ecoPortal web platform and ecoPortal Connect mobile application;

  • visitor and contractor management services, including kiosk and QR code check-in;

  • our public websites, online forms, demonstrations and trial environments;

  • customer administration, implementation, support, training, billing and relationship management;

  • product analytics, surveys, feedback, marketing and events;

  • recruitment and employment enquiries;

  • and other interactions with ecoPortal where we determine why and how personal information is processed.

This Privacy Policy does not replace a customer’s own employee, contractor, visitor, health and safety or workplace privacy notice. Where a customer controls information in its ecoPortal environment, that customer is responsible for explaining its own processing to affected individuals. ecoPortal may provide supplementary notices at the point of collection where appropriate. Current and former ecoPortal employees and individual contractors are covered by separate internal workforce privacy notices and policies. This Privacy Policy applies to recruitment enquiries and business contact information, but is not intended to be a complete workforce privacy notice.

1.3 Applicable laws

Depending on the person, the relevant ecoPortal entity, the customer and the processing activity, this Privacy Policy is intended to address the New Zealand Privacy Act 2020, the Australian Privacy Act 1988 and Australian Privacy Principles, the EU General Data Protection Regulation, the UK GDPR, the UK Data Protection Act 2018, the UK Data (Use and Access) Act 2025, and applicable electronic communications, direct marketing, cookie and workplace privacy laws. A jurisdiction-specific right applies only where the relevant law applies to the processing.

1.4 Meaning of personal information

“Personal information” includes information or an opinion about an identified or reasonably identifiable individual. Where UK or EU law applies, it includes “personal data”. References to personal information include sensitive information and special category personal data where relevant. Information that has been irreversibly anonymised so that no individual is identifiable is not personal information.

2. Our privacy roles

2.1 Customer as controller or responsible agency

For most information entered into, uploaded to, generated within or integrated with a customer-configured ecoPortal environment, the customer determines the purposes for which the information is processed, the fields and forms used, who may access it, and how long it should be retained. In that context, the customer is generally the controller, responsible privacy agency or organisation responsible for the information.

2.2 ecoPortal as processor, service provider or agent

When we process customer-controlled information solely to provide the contracted services and on the customer’s documented instructions, ecoPortal acts as a processor, service provider or agent. We process that information under the customer agreement, data processing terms and applicable law. We do not use customer-controlled information for unrelated advertising or sell it.

2.3 ecoPortal as independent controller or agency

ecoPortal acts independently when we determine the purposes and means of processing, including for website administration, account and contract administration, billing, service security, fraud prevention, support administration, product and service analytics, our own legal records, marketing and recruitment. Separate workforce notices govern our processing of employee and individual-contractor information. Schedule 1 gives further detail.

2.4 Joint or separate responsibilities

In limited cases, ecoPortal and a customer or other party may each have separate obligations in relation to the same information. Each party remains responsible for its own compliance. Nothing in this Privacy Policy transfers statutory obligations that cannot lawfully be transferred.

3. Personal information we collect

3.1 Account and identity information

  • name, preferred name, username, email address, telephone number and business contact details;

  • employer, organisation, role, team, work location and reporting relationships;

  • account status, permissions, identity-provider identifiers and authentication events; and

  • communications preferences and language or accessibility settings.

3.2 Customer-controlled workplace information

Depending on the modules and fields configured by a customer, customer-controlled information may include:

  • incident, injury, hazard, risk, action, audit, inspection, permit, meeting and safety-observation records;

  • injury details, medical certificates, rehabilitation or return-to-work information, work restrictions, accessibility needs and other health-related information;

  • contractor, supplier, competency, licence, certification, training and induction records;

  • emergency contacts, work location, shift, attendance, check-in and check-out information;

  • documents, notes, comments, signatures, photographs, audio, video and other attachments;

  • government identifiers, police vetting or criminal-history information only where a customer lawfully configures and requests those fields; and

  • workflow history, approvals, tasks, notifications, audit trails and reports generated from the information.

The customer determines which fields are used and is responsible for ensuring that its collection is lawful, necessary and proportionate. ecoPortal does not require customers to collect all of these categories.

3.3 Visitor and contractor information

  • name, contact details, company and host or person being visited;

  • site, purpose of visit, expected and actual arrival and departure times;

  • vehicle or access details, induction completion, acknowledgements and signatures;

  • emergency, safety, accessibility or health information that the site operator lawfully requires;

  • photograph or identification information where configured and lawful; and

  • responses to customer-configured questions and records of site access.

3.4 Website, application, device and usage information

IP address, browser, device, operating system, application version and network information;

session, login, security, diagnostic, crash, error and audit logs;

pages, forms and features viewed or used, timestamps, referring sources and interaction events;

approximate location derived from an IP address, and precise device location only where a feature requires it and permission has been granted;

cookie, local storage, software development kit and similar technology identifiers; and

information necessary to support offline synchronisation, kiosk operation and application performance.

3.5 Customer relationship, support and billing information

  • business contact information, meeting notes, service requests and support communications;

  • call or meeting recordings, transcripts and AI-generated summaries where recording or transcription is used after appropriate notice and, where required, consent;

  • implementation, configuration, training and customer-success records;

  • contract, order, renewal, invoice, payment and transaction information; and

  • records of complaints, disputes, legal requests and regulatory communications.

3.6 Surveys, Feedback Analytics and Product Improvement

We may collect and use account, usage, support, survey, research and feedback information, including Net Promoter Score responses, comments, preferences and opinions, to understand service performance and improve the design, functionality, accessibility, reliability and customer experience of our services.

Surveys may be provided directly by ecoPortal or through approved survey or product-experience providers. Where a survey is displayed to an authenticated user, responses may be associated with the user’s name, email address, account or organisation unless the survey is clearly identified as anonymous. Participation is voluntary unless required for a specific contractual or compliance process, in which case this will be clearly stated.

We limit access to authorised personnel and use aggregated or anonymised information where reasonably practicable. We do not share identifiable survey responses with other customers or unrelated third parties. Responses may be shared with the respondent’s own organisation where this is disclosed and appropriate.

3.7 Marketing, events and enquiries

We may collect contact details, areas of interest, event attendance, campaign interactions, website form submissions, demonstration and trial requests, and records of consent, objection and unsubscribe preferences.

3.8 Recruitment information

We may collect application, curriculum vitae, employment history, qualifications, references, interview notes, work eligibility, background-check information where lawful, and other information a candidate provides or authorises us to obtain.

3.9 Information we do not intentionally request

Unless necessary for a configured customer purpose or required by law, do not provide personal information that is excessive or unrelated to the relevant service. Do not place passwords, payment-card security codes or highly sensitive information in free-text fields or attachments unless the field is specifically designed and approved for that purpose.

4. How we collect personal information

4.1 Directly from you

We collect information directly when you create or use an account, check in to a site, complete a form, upload content, contact support, attend a meeting or event, respond to a survey, apply for a role, use our website or application, or otherwise communicate with us. If a call or meeting will be recorded, transcribed or summarised using an AI-enabled service, we will provide notice before or at the start of the recording and obtain consent where applicable law requires it.

4.2 From customers and other organisations

We may receive information from your employer, a customer, site host, customer administrator, contractor principal, related organisation or another person authorised to provide it. This may include bulk imports, data migrations, invitations, user provisioning and information supplied through customer-configured forms.

4.3 From integrations and identity providers

We may receive information through single sign-on, SCIM, people or page APIs, HR or payroll systems, business intelligence tools and other integrations configured by a customer. Unless separately agreed in writing, the customer is responsible for the integration, mappings, transformations, source-system accuracy and lawful disclosure of the information to ecoPortal.

4.4 Automatically

We collect technical and usage information through the platform, mobile application, logs, cookies, software development kits and similar technologies. Non-essential cookies or storage technologies are used only in accordance with section 10.

4.5 From service providers and public sources

We may receive limited information from analytics, marketing, communications, security, recruitment and professional service providers, and from business directories or other public sources where lawful and relevant.

4.6 Notice when information is collected indirectly

Where required, we or the relevant customer will take reasonable steps to tell the individual that information has been collected from another source, the circumstances of collection, the purposes, intended recipients, the responsible organisations, whether supply is required or voluntary, the consequences of not supplying it, and the individual’s rights. In New Zealand, this includes the notification requirements applying to indirect collection under Information Privacy Principle 3A. A customer may provide the notice on our behalf where this is documented, but each organisation remains responsible for any obligation that applies to it.

5. How and why we use personal information

We use personal information only where the use is connected with a disclosed or lawful purpose, is permitted by the relevant customer’s instructions, or is otherwise required or authorised by law. Our principal purposes are to:

  • provide, configure, secure, maintain and support the services;

  • create accounts, authenticate users and administer permissions;

  • enable health, safety, environmental, quality, contractor and visitor workflows chosen by customers;

  • provide reporting, dashboards, alerts, notifications, audit trails and integrations;

  • respond to enquiries, incidents, support requests and complaints;

  • administer customer relationships, contracts, billing, renewals and service communications;

  • protect people, systems and information, prevent misuse and investigate security events;

  • analyse, maintain and improve the usability, reliability, accessibility and performance of our services;

  • conduct surveys and obtain feedback;

  • market our services where permitted and maintain suppression records;

  • recruit personnel and administer applications;

  • comply with legal, regulatory, audit, insurance and governance requirements; and

  • establish, exercise or defend legal claims and resolve disputes.

Where UK or EU data protection law applies, Schedule 1 identifies the lawful bases on which ecoPortal ordinarily relies for its own processing. When ecoPortal acts as processor, the relevant customer determines the lawful basis for the customer-controlled processing.

6. Sensitive and special category information

Workplace health and safety services may involve health information, injury information, disability or accessibility information, union or representative information, criminal-history information, biometric information or other sensitive information. We process this information only when it is necessary for a legitimate and disclosed purpose, the relevant customer has configured the collection, and an applicable legal condition is satisfied.

Where UK or EU law applies, special category personal data requires both an Article 6 lawful basis and an Article 9 condition. Depending on the process, the relevant condition may relate to employment and social protection law, vital interests, legal claims, substantial public interest, occupational health or another condition established by law. Explicit consent is used only where it is appropriate, freely given and capable of withdrawal. Customers are responsible for determining and documenting the appropriate condition for customer-controlled processing.

Where Australian law applies, sensitive information is collected with consent unless an exception under the Privacy Act applies. Where New Zealand law applies, we apply heightened care to sensitive information and collect only information that is necessary for a lawful purpose.

7. Customer-controlled information

7.1 Customer responsibilities

Customers are responsible for the lawfulness, fairness and transparency of their processing, including deciding what information to collect, giving required notices, obtaining any required consent, establishing permissions, responding to rights requests, setting appropriate retention periods and ensuring that information disclosed to ecoPortal is accurate and authorised.

7.2 ecoPortal access

Authorised ecoPortal personnel and approved subprocessors may access customer-controlled information only where reasonably necessary to provide support, implementation, maintenance, security, incident response, legal compliance or other services authorised by the customer or the customer agreement. Access is subject to role-based controls, confidentiality obligations, logging and internal procedures.

7.3 Public reports and customer sharing

Customers may configure reports, pages or forms to be publicly accessible or may share them with selected recipients. The customer controls that decision and must ensure that public access or sharing is appropriate. ecoPortal provides permission and sharing controls but cannot determine the customer’s lawful purpose or intended audience.

7.4 Requests from individuals

If a request relates to customer-controlled information, the individual should generally contact the relevant customer. If the request is sent to ecoPortal, we will verify the context, forward or refer it to the customer where appropriate, and assist the customer as required by law and contract. We will not disclose customer-controlled information directly where doing so would conflict with the customer’s lawful instructions or the rights of another person.

8. Sharing and disclosure

We disclose personal information only where reasonably necessary for a stated purpose, on customer instructions, with the individual’s authorisation where required, or as otherwise permitted or required by law. Recipients may include:

  • the customer that controls the relevant portal, its authorised administrators, users, site hosts and recipients selected by the customer;

  • cloud hosting, data storage, communications, support, analytics, survey, security, identity, payment and other service providers that process information for us;

  • our employees, long-term contractors and affiliated entities who need access for their role and are bound by confidentiality and privacy obligations;

  • professional advisers, auditors, insurers, banks, debt-recovery providers and regulators;

  • a purchaser, investor or successor in connection with an actual or proposed corporate transaction, subject to appropriate confidentiality and due diligence controls;

  • courts, tribunals, law-enforcement agencies and public authorities where disclosure is lawfully required or permitted; and

  • other recipients identified at the time of collection or authorised by the individual or customer.

We maintain a current list of material subprocessors. The list should identify the provider, service, processing location and relevant safeguards where appropriate. We require processors and service providers to protect personal information, use it only for authorised purposes and notify us of relevant incidents.

Subprocessor list: ecoPortal Subprocessor List

We do not sell personal information. We do not disclose customer-controlled information to third parties for those third parties’ independent advertising purposes.

9. International transfers and overseas access

9.1 Where information may be processed

Customer production data is ordinarily hosted in Australia, subject to the customer agreement and service configuration. ecoPortal personnel in New Zealand and approved personnel or subprocessors in other countries may access information where necessary to provide the services. Website, communications, survey, support and business-system providers may process information in the countries stated in the current subprocessor list.

9.2 New Zealand transfers

Where New Zealand Information Privacy Principle 12 applies to an overseas disclosure, we disclose only where an applicable statutory basis exists. This may include comparable foreign-law safeguards, an approved binding scheme or prescribed country, contractual safeguards requiring comparable protection, application of the New Zealand Privacy Act, or informed authorisation in the limited circumstances permitted by law. We distinguish a disclosure to an overseas recipient from storage or processing by an agent on our behalf, while applying appropriate contractual and security protections in either case.

9.3 Australian transfers

Where Australian Privacy Principle 8 applies, we take reasonable steps before disclosing personal information overseas to ensure that the recipient handles it consistently with the Australian Privacy Principles, unless an exception applies. We may remain accountable under Australian law for the recipient’s conduct. Our privacy notices and subprocessor information identify likely recipient countries where practicable.

9.4 EU and EEA transfers

Where EU GDPR transfer restrictions apply, we use an adequacy decision, the European Commission Standard Contractual Clauses, binding corporate rules or another lawful transfer mechanism. Where required, we assess the laws and practices of the destination and implement supplementary safeguards. New Zealand currently benefits from an EU adequacy decision; transfers to countries without adequacy, including relevant processing in Australia or other locations, require an appropriate transfer mechanism.

9.5 UK transfers

Where UK GDPR transfer restrictions apply, we use UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses or another lawful mechanism. Where required, we apply the UK international-transfer data protection test, acting reasonably and proportionately to assess whether the destination provides protection that is not materially lower than the UK standard, and we implement supplementary safeguards.

9.6 Further information

You may contact us for further information about the transfer mechanism relevant to your information and, where legally required, a copy or summary of the safeguards. We may redact confidential or security-sensitive terms.

10. Cookies and similar technologies

Our websites and applications may use cookies, local storage, pixels, software development kits and similar technologies. These technologies may be used for:

  • strictly necessary functions, including security, authentication, load balancing and preference management;

  • functional features and remembering choices;

  • performance, diagnostics and analytics;

  • customer-support and in-product guidance; and

  • advertising or campaign measurement where permitted.

Where consent is required, we do not activate non-essential technologies until the user has made a clear and informed choice. The user may reject non-essential technologies as easily as accepting them and may withdraw consent through the cookie preference tool. Withdrawing consent does not affect processing that occurred lawfully before withdrawal. Strictly necessary technologies cannot always be disabled because the service may not function without them.

Cookie policy

Browser settings may also block or delete technologies, but browser controls do not replace any consent mechanism we are legally required to provide.

11. Direct marketing and service communications

We send direct marketing only where permitted by applicable law. Depending on the jurisdiction and relationship, we may rely on consent, a permitted existing-customer exception or a legitimate interest that does not override the individual’s rights. Electronic marketing will identify the sender and provide a simple unsubscribe method. We maintain suppression records so that an unsubscribe request is respected.

A person may object to direct marketing or withdraw marketing consent at any time. This does not prevent us from sending essential security alerts, service notices, support communications, account administration, billing or contractual communications that are not direct marketing.

We comply, where applicable, with the New Zealand Unsolicited Electronic Messages Act 2007, the Australian Spam Act 2003, UK Privacy and Electronic Communications Regulations and data protection rules governing direct marketing.

12. Artificial intelligence and automated decision making

12.1 AI-assisted features

Some ecoPortal features may use artificial intelligence to assist users with functions such as finding a form, suggesting field content, or generating a summary. AI output is intended to assist, not replace, the judgement of the customer or user. Users should review output for accuracy and appropriateness before relying on it, particularly where health, safety, employment, or legal consequences may follow.

12.2 Use of personal information in AI features

We process personal information through AI features only for the underlying service purpose and on an applicable lawful basis. AI features may be disabled at the organisation level. We apply appropriate data minimisation, access, security, supplier, and retention controls. Customer-controlled information is not used by ecoPortal or its AI service providers to train AI models, and prompts are not logged, shared, or redistributed to third parties by our AI service providers (AWS Bedrock and Google Vertex) when processing customer data.

12.3 Significant automated decisions

ecoPortal does not intend its standard services to make decisions based solely on automated processing that produce legal or similarly significant effects on individuals. Customers may configure workflows, rules, alerts, and reports, but remain responsible for appropriate human review and for determining whether their use constitutes automated decision-making under applicable law.

If ecoPortal introduces significant automated decision-making for its own purposes in the future, appropriate disclosures, safeguards, human review, and challenge rights will be implemented as required by applicable law.

13. Data quality

We take reasonable steps to ensure that personal information we use or disclose for our own purposes is accurate, up to date, complete, relevant and not misleading. Customers and users are responsible for maintaining customer-controlled information and should promptly correct inaccurate or outdated records. We may preserve an audit trail or a record of a correction where required for security, accountability, legal or operational reasons.

14. Security

We maintain technical and organisational safeguards appropriate to the nature, context and risk of the processing. These safeguards may include:

  • encryption in transit and at rest where appropriate;

  • identity, authentication, role-based access and least-privilege controls;

  • logging, monitoring, intrusion detection and abuse protection;

  • secure software development, dependency and vulnerability management;

  • malicious-file scanning and security testing;

  • backup, resilience, recovery and continuity controls;

  • supplier due diligence and contractual security obligations;

  • confidentiality obligations, workforce screening where appropriate and privacy and security training; and

  • incident detection, response, investigation and remediation procedures.

Customers are responsible for their own devices, networks, identity systems, integrations, administrator decisions, user permissions and secure use of the service. ecoPortal remains responsible for the security controls it provides and for protecting personal information in its custody or control. No system or transmission method is completely secure, and we do not guarantee absolute security.

15. Privacy and security incidents

If you become aware of a suspected privacy or security incident affecting ecoPortal, contact privacy@ecoportal.com promptly and provide the available details. We will assess, contain, investigate and remediate incidents in accordance with our response procedures.

Where ecoPortal acts as processor or service provider, we will notify the relevant customer without undue delay and provide reasonably available information and assistance required by law and contract. Where ecoPortal is the controller or responsible agency, we will notify affected individuals and regulators when the applicable notification threshold is met and within the required timeframe. This may include notification to the New Zealand Privacy Commissioner as soon as practicable for a notifiable privacy breach, and notification under EU or UK law within 72 hours of awareness where the statutory risk threshold is met.

Incident information may change as an investigation progresses. We may provide updates, mitigation guidance and post-incident information as appropriate, subject to security, privilege, confidentiality and law-enforcement constraints.

16. Retention and deletion

We retain personal information only for as long as reasonably necessary for the purpose for which it was collected, to comply with customer instructions and contractual commitments, to meet legal, tax, audit, insurance, security and governance requirements, or to establish, exercise or defend legal claims. We then delete, deidentify or anonymise it unless continued retention is required or permitted by law.

Customer-controlled information is retained according to the customer’s instructions, the customer agreement, the configured retention settings and applicable law. Following expiry or termination, information is returned, made available for export, placed into any agreed read-only arrangement, or deleted in accordance with the agreement. Residual copies in encrypted backups are isolated from routine use and overwritten through the normal backup cycle, unless preservation is required by law or for an active incident or dispute.

Schedule 2 describes our retention framework. Exact periods may vary by record type and jurisdiction, and shorter or longer periods may apply where required by a customer instruction or law.

17. Your privacy rights

17.1 How to make a request

You may contact privacy@ecoportal.com to exercise a right that applies to you. Please describe the information and the right you wish to exercise. We may ask for information reasonably necessary to verify your identity, authority and relationship to the relevant customer. We will not request more verification information than necessary.

17.2 Customer-controlled information

Where a customer controls the information, the request should normally be directed to that customer. We will assist the customer and will tell you where to direct the request where reasonably possible. This does not limit any right you have to contact ecoPortal or a regulator.

17.3 New Zealand rights

Where the New Zealand Privacy Act applies, you may request access to personal information held about you and request correction. If a correction is not made, you may ask for a statement of correction to be attached to the information. Other rights and remedies may arise under the Privacy Act and applicable codes.

17.4 Australian rights

Where the Australian Privacy Act applies, you may request access to and correction of personal information. Where lawful and practicable, you may interact anonymously or using a pseudonym, although this is generally not practicable for an authenticated account, site check-in or workplace record. You may opt out of direct marketing and ask us to identify the source of information used for direct marketing where the law requires.

17.5 EU and EEA rights

Where the EU GDPR applies, and subject to its conditions and exemptions, you may have rights to information, access, rectification, erasure, restriction, data portability, objection, withdrawal of consent, and not to be subject to certain solely automated decisions. You may object at any time to processing for direct marketing. Where we rely on legitimate interests, you may object on grounds relating to your particular situation.

17.6 UK rights

Where UK data protection law applies, and subject to its conditions and exemptions, you may have rights to information, access, rectification, erasure, restriction, data portability, objection, withdrawal of consent, and safeguards concerning significant automated decisions. You may object at any time to processing for direct marketing. We will conduct a reasonable and proportionate search when responding to an access request, as permitted by UK law.

17.7 Consent

Where processing is based on consent, you may withdraw consent at any time using the method provided or by contacting us. Withdrawal does not affect processing that was lawful before withdrawal. If the information is necessary for a service or legal obligation, withdrawal may mean that the relevant feature or service cannot be provided.

17.8 Fees, timing and refusals

We ordinarily handle privacy requests without charge. We may charge a reasonable fee or refuse to act only where the applicable law permits, such as where a request is manifestly unfounded, excessive or repetitive, and we will explain the basis. We will respond within the timeframe required by the applicable law. We may extend the response period where permitted and will notify you of the extension. Rights are not absolute, and we may withhold information where an exemption applies, including to protect another person’s privacy, security, legal privilege or confidential commercial information.

18. Complaints

You may make a privacy complaint by emailing privacy@ecoportal.com. Please provide enough information to identify the issue, relevant customer or account, dates and the outcome sought. We will acknowledge the complaint, investigate it fairly, keep appropriate records and respond in writing. For a complaint governed by UK data protection law, we will acknowledge it within 30 days and take appropriate steps to investigate and respond without undue delay.

If you are not satisfied, you may complain to the regulator that applies to you:

New Zealand: Office of the Privacy Commissioner

Australia: Office of the Australian Information Commissioner

United Kingdom: Information Commissioner’s Office

European Union or EEA: the supervisory authority in the country of your habitual residence, place of work or the alleged infringement

You may contact a regulator without first contacting us, although we welcome the opportunity to resolve the issue directly.

19. Government and law-enforcement requests

 We disclose personal information to a public authority only where required or lawfully permitted. Where a request concerns customer-controlled information, we will ordinarily direct the authority to the customer where appropriate. If we are legally compelled to disclose, we will review the request, disclose only information within its lawful scope, and notify the customer or affected person unless prohibited or inappropriate. We may challenge an unlawful, disproportionate or defective request where reasonably practicable.
 

20. Children and young people

 ecoPortal’s public website and standard business services are not directed to children. A customer may use the services in a workplace, training, visitor or incident context involving a young person. In that case, the customer must ensure that the collection and use is lawful, fair, proportionate and accompanied by age-appropriate information or consent where required. We apply heightened care to information about children and young people. 

21. Third-party links and services

Our websites and services may link to third-party websites or enable customer-configured integrations. The third party’s privacy policy applies to processing it independently controls. We are not responsible for a third party’s privacy practices, but we assess and contract with subprocessors where required. 

22. Changes to this Privacy Policy

 We may update this Privacy Policy to reflect changes in law, technology, our services or our processing. The current version and effective date will be published on our website. Where a change is material, we will take reasonable steps to bring it to the attention of affected individuals or customer administrators. We will obtain fresh consent where a new use requires consent and existing consent does not cover it. 

23. Contact details

Privacy enquiries, requests, complaints and incident notifications may be sent to:

Contact item Details
Privacy email privacy@ecoportal.com
Telephone +64 9 630 6951
New Zealand entity Triplics Limited, NZBN 9429031345217
New Zealand address 24 St Benedicts Street, Eden Terrace, Auckland 1010, New Zealand
Australian entity ecoPortal Australia Pty Ltd, ABN 87 653 664 503
United Kingdom entity DecoPortal UK Limited, company number 16721819
United Kingdom address Ground Floor, Dearing House, 1 Young Street, Sheffield, S1 4UP, United Kingdom
Data Protection Officer Daniel Alexander daniel@ecoportal.com

Schedule 1: Processing purposes and lawful bases

This schedule applies when ecoPortal determines the purposes and means of processing. When ecoPortal acts solely as a processor, the customer determines the relevant lawful basis and any special category condition. The basis used for a particular activity depends on the facts and applicable law.

Activity Information ecoPortal role UK or EU lawful basis Sensitive or special category position
Provide customer-controlled platform services Account, workplace, visitor, contractor, incident, injury, document and workflow information Processor, service provider or agent The customer determines the lawful basis. ecoPortal processes under the customer contract and documented instructions. Customer determines any Article 9 condition or Australian sensitive-information basis.
Create and administer accounts Identity, contact, role, permissions, authentication and preferences Independent controller or agency for account administration Contract; legitimate interests in providing and administering secure business services; legal obligation where applicable Normally not required. If accessibility or health information is used, an applicable condition is required.
Customer support, implementation, training and recorded meetings Contact details, communications, portal configuration, support content, audit records and any notified recording, transcript or AI summary Independent controller for relationship administration; processor where accessing customer data Contract; legitimate interests in supporting customers and maintaining service quality; consent where recording or transcription law requires it Underlying customer basis applies when support content includes sensitive information. Avoid recording sensitive discussions unless necessary, disclosed and lawfully authorised.
Service security, fraud and incident response Authentication, IP, device, logs, audit trails, content needed to investigate an event Independent controller or agency Legitimate interests and recognised legitimate interests where applicable; legal obligation; vital interests in an emergency Legal claims, substantial public interest, vital interests or another condition where sensitive information is necessary.
Billing, contracts and records Business contacts, contracts, invoices, payments and correspondence Independent controller or agency Contract; legal obligation; legitimate interests in financial administration and legal Not ordinarily applicable.
Product analytics and service improvement Usage events, diagnostics, feature interactions, account context and feedback Independent controller or agency Legitimate interests in improving and securing services; consent where required for non-essential tracking Avoid sensitive content where possible. Use aggregated or anonymised data where practicable.
Surveys and Net Promoter Score Name, email, organisation, score, response and account context unless anonymous Independent controller or agency, or processor if conducted solely for a customer Legitimate interests in customer experience and service improvement; consent where required Do not solicit special category information unless necessary and an applicable condition exists.
Direct marketing and events Business contact details, interests, engagement, event records and consent or opt-out status Independent controller or agency Consent; legitimate interests where lawful; permitted existing-customer marketing Not ordinarily applicable. Do not use customer-controlled health and safety information for marketing.
Recruitment Application, employment history, qualifications, references, work eligibility and interview records Independent controller or agency Steps before entering a contract; legitimate interests; legal obligation; consent for optional talent-pool retention Employment, social protection, explicit consent or another lawful condition where sensitive information is processed.
Legal, regulatory, audit and disputes Relevant account, customer, transaction, communication, incident and evidence records Independent controller or agency Legal obligation; legitimate interests in governance and legal claims; public task only where applicable Legal claims, substantial public interest or another applicable condition.
Cookies and similar technologies Device, browser, cookie identifiers, usage and campaign information Independent controller or agency, with providers acting as processors or separate controllers as disclosed Consent for non-essential technologies where required; legitimate interests or necessity for essential technologies Not ordinarily applicable.
AI-assisted features Inputs, selected source content, output, usage and diagnostic information Processor for customer-controlled use; independent controller for security and limited service administration Same lawful basis as the underlying service purpose; consent only where specifically required Same Article 9 or sensitive-information condition as the underlying processing. Human review and additional safeguards apply.

Schedule 2: Retention framework

The following framework uses retention criteria rather than inflexible periods because customer configurations and legal requirements differ. ecoPortal must maintain an operational retention schedule containing approved periods, owners, systems and deletion methods.

Record category Retention approach Criteria
Customer platform and visitor data For the customer-selected period, the agreement term and any agreed export, read-only or deletion period. Deleted or returned after termination unless law, dispute, backup or explicit customer instruction requires temporary retention. Customer instruction, contract, configured retention and applicable workplace or health and safety laws.
Account and user-profile data While the account is active and for a limited period after deactivation needed for security, reactivation, audit or contractual records. Account status, customer instruction, security and limitation periods.
Authentication, audit and security logs For a period proportionate to security, investigation and audit needs. Longer retention may apply for an incident, legal hold or regulatory requirement. Security risk, incident history, standards, customer commitments and legal claims.
Support, implementation and training records For the customer relationship and a reasonable period afterwards. Records forming part of a contract, dispute or service decision may be retained for the applicable limitation period. Contract administration, support history, audit and legal claims.
Contracts, invoices, payments and tax records For the period required by tax, companies, accounting and limitation laws in the relevant jurisdiction. Statutory record-keeping and legal claims.
Website analytics and diagnostic data For the shortest period that supports the stated analytics, security or diagnostic purpose, then aggregated, anonymised or deleted. Cookie configuration, analytics need and privacy settings.
Marketing contacts and event records Until objection, withdrawal or the information becomes stale. Minimal suppression information may be retained to honour an opt-out. Marketing relationship, consent records and suppression requirements.
Survey and feedback records For the period needed to analyse and act on the response, then deleted, deidentified or aggregated. Identifiable retention should be shorter than aggregate reporting retention. Survey purpose, follow-up need and customer commitments.
Recruitment records For the recruitment process and a limited post-process period for legal and administrative purposes. Longer talent-pool retention requires clear notice and, where appropriate, consent. Employment law, limitation periods and candidate choice.
Incident, complaint and legal-hold records Retained and overwritten according to the documented backup cycle. Deleted information is not restored to active use except for disaster recovery, and will be deleted again through the normal cycle. Recovery objectives, security, technical feasibility and legal holds.
Backups Retained and overwritten according to the documented backup cycle. Deleted information is not restored to active use except for disaster recovery, and will be deleted again through the normal cycle. Recovery objectives, security, technical feasibility and legal holds.

 

Schedule 2: Jurisdiction-specific rights and regulators

Jurisdiction Key rights Regulator Important qualification
New Zealand Access; correction; statement of correction; complaint and remedies under the Privacy Act and applicable codes. Indirect collection notices under IPP 3A where applicable. Office of the Privacy Commissioner Requests are generally handled without charge. Statutory response periods and exemptions apply.
Australia Access; correction; anonymity or pseudonymity where lawful and practicable; direct-marketing opt-out and source information where required; privacy complaint. Office of the Australian Information Commissioner APP 1 requires an accessible privacy policy and complaint process. APP 8 addresses overseas disclosures. From 10 December 2026, certain significant automated-decision uses must be described in the privacy policy.
European Union and EEA Information; access; rectification; erasure; restriction; portability; objection; withdrawal of consent; rights regarding certain automated decisions; complaint. Relevant national supervisory authority Rights are subject to conditions and exemptions. Direct-marketing objection is absolute. International transfers require Chapter V safeguards.
United Kingdom Information; access; rectification; erasure; restriction; portability; objection; withdrawal of consent; safeguards regarding significant automated decisions; complaint. Information Commissioner’s Office The Data (Use and Access) Act 2025 modifies aspects of UK data protection law, including complaints, access searches, automated decisions, cookies and international transfers.