Privacy policy
intelID privacy policy
How intelID Limited, NZ company number 8630146, handles personal information across the intelid.nz website and the intelID platform. Last updated 31 July 2026.
1. Scope and who we are
This policy, together with our terms and conditions, sets out how we handle personal information collected through the intelid.nz website and through the intelID platform. It applies to visitors to the website, people who apply for access, approved users, and the individuals whose information is returned by a search.
The service is operated by intelID Limited, referred to in this policy as "we" and "us". We handle personal information in accordance with the Privacy Act 2020 and, where credit information is involved, the Credit Reporting Privacy Code 2020.
Two distinct categories of information are covered. Account information is information about you as an applicant or user. Subject information is information about a third party returned by a search that a user runs. Different rules apply to each, and they are dealt with separately below.
2. Information we collect about you
We may collect and process the following information about you:
- Access request information: your name, organisation, role, professional licence or registration details, professional body membership, contact details, the number of users required, and the authorised purposes for which you intend to search. We use this to verify your eligibility for an account.
- Verification evidence: documents you provide to evidence identity, licensing or professional standing, and the results of our checks against public registers and professional bodies.
- Account information: the user records we hold for your organisation, including role and access level.
- Search and audit information: for every query run through the platform, the user who ran it, the time, the search criteria, the sources queried and the authorised purpose declared. This audit record is a compliance requirement and cannot be disabled or deleted by a user.
- Technical information: the IP address used to connect, browser type and version, device and operating system, time zone and the pages or endpoints requested.
- Communications: correspondence with us about access, billing, support and compliance. Account holders receive legal and administrative notices that are necessary to provide the service and cannot be opted out of.
- Billing information: the customer and billing contact details needed to invoice you, and the invoicing and payment records associated with your account, including your subscription and search fees, invoices issued, amounts paid and amounts outstanding. Accounts are invoiced monthly in arrears and we do not collect or store payment card details.
3. How we use that information
We use information about you to:
- verify your eligibility for an account and re-verify it periodically;
- make the service available to you and administer your account;
- authenticate users and apply role-based access control;
- maintain the audit log, monitor for misuse, and investigate suspected breaches of privacy obligations or source terms;
- invoice you and recover amounts owing;
- notify you about changes to the service, these policies or our fees;
- respond to a lawful request from a regulator, a court, or a data provider carrying out its own compliance obligations; and
- maintain and improve the security and reliability of the service.
We do not use your information for advertising, we do not sell it, and we do not trade it. We do not send marketing email to individuals whose details appear in search results.
4. Indirect collection of subject information
The platform provides access to information sourced from third parties. Those sources include public registers, government-authorised databases, licensed credit reporters, licensed directory data and licensed open-source intelligence providers.
In most cases this information is collected indirectly, meaning it is not collected from the individual concerned. We collect, collate and present it in response to searches initiated by our customers.
We do not build a marketing database from subject information, we do not resell it, and it is not exposed to public indexing. Search results are visible only to the account that ran the search.
Digital footprint tracing covers publicly visible information and platform registration signals obtained under the provider's terms. It does not involve private or restricted account content, and it does not involve circumventing a login, an access control or a platform's terms of use.
The platform does not provide health information, criminal justice information or intelligence agency information.
5. Customer obligations under IPP3A
Information Privacy Principle 3A was added by the Privacy Amendment Act 2025 and came into force on 1 May 2026. It applies where an agency collects personal information about an individual from a source other than that individual.
Our customers are responsible for ensuring that their use of the platform complies with the Privacy Act 2020, including principle 3A. That means taking reasonable steps, before collection or as soon as practicable afterwards, to make the individual aware of the fact that the information has been collected, the purpose of collection, who is collecting it, the source or type of source, the intended recipients, any law under which the collection is made, and the individual's rights of access and correction, unless an exception in the Act applies.
Exceptions include where notification would prejudice the purpose of the collection or the maintenance of the law, where the individual has already been made aware, where compliance is not reasonably practicable in the circumstances, or where the information will not be used in a form in which the individual is identifiable. The customer is responsible for assessing whether an exception applies to their file and for recording that assessment.
We do not have a direct relationship with the individuals whose information is accessed through the platform, and we do not give principle 3A notification to those individuals on a customer's behalf.
We may suspend or terminate access where we reasonably believe a customer is using the platform in breach of its privacy obligations.
6. How subject data is handled in the platform
Every search requires the user to declare an authorised purpose. The declaration, the user identity and the query are recorded in an audit log that the customer cannot alter.
Access is role-based. A user can only reach the sources their role permits, and only after we have verified them individually.
Data is encrypted in transit and at rest. Access by our own personnel is limited to what is required for support, billing, security and compliance, and is logged.
Where a source imposes its own restrictions on the use or retention of information, those restrictions apply in addition to this policy.
8. Where your information is stored
The platform is hosted on Google Cloud Platform. Data is held in a hosting region selected for the service, and some processing or support may occur outside New Zealand.
Where information is transferred outside New Zealand, we take reasonable steps to ensure the recipient is subject to safeguards comparable to those in the Privacy Act 2020, in accordance with Information Privacy Principle 12.
Our vendor security programme is benchmarked to SOC 2 Type II providers. Further information about our hosting provider's privacy and security obligations is available at cloud.google.com/security.
9. Security
Information is stored on secure servers. Controls include encryption in transit and at rest, role-based access control, individual user accounts with no shared credentials, audit logging of every query, and monitoring for anomalous use.
Where you hold credentials for the platform, you are responsible for keeping them confidential and for notifying us immediately of any suspected unauthorised use.
Transmission of information over the internet is never completely secure. We take reasonable steps to protect your information, but we cannot guarantee the security of information transmitted to the service.
If a privacy breach occurs that has caused, or is likely to cause, serious harm, we will notify the affected individuals and the Office of the Privacy Commissioner as required by the Privacy Act 2020, and we will notify the affected customer.
10. Disclosure of your information
We may disclose personal information in the following circumstances:
- to service providers who host, support, secure or process payments for the service, and only to the extent needed to perform those functions on our behalf;
- to a data provider carrying out an audit or compliance review of access to its data, where our licence with that provider requires it;
- where we are under a legal duty to disclose, or where disclosure is necessary to enforce our terms or to protect the rights, property or safety of any person;
- to a regulator, including the Office of the Privacy Commissioner, in connection with an enquiry or complaint; and
- in the event that we sell or buy a business or assets, to the prospective party, and if we are acquired, as one of the transferred assets. Any acquirer remains bound by this policy in respect of information transferred.
We do not disclose personal information to advertisers or data brokers, and we do not permit a third party to contact you with marketing on the basis of information you have given us.
11. Retention
Verification material is retained while the account exists and afterwards for as long as our source licences, our compliance obligations and applicable law require.
Audit records of searches are retained after an account closes so that the lawful basis for a past search can be evidenced if it is later questioned.
Declined access requests are retained only as long as needed to record the decision and to handle any review of it.
We do not retain personal information for longer than the purpose for which it may lawfully be used requires.
12. Access, correction and complaints
Under Information Privacy Principles 6 and 7 of the Privacy Act 2020 you have the right to request access to, and correction of, personal information we hold about you. Our Privacy Officer is Mike Gillam, Director. Address access, correction and complaint requests to the Privacy Officer by email at privacy@intelid.nz or by phone on 027 299 7603. We may need to verify your identity before responding, and we will respond within the statutory timeframe. If we decline a request we will give the reason and tell you how to complain.
If you believe your personal information has been accessed through the platform and you have questions about how it was obtained or used, contact us and we will assist where appropriate. Where the information was returned to a customer in response to their search, that customer is the agency responsible for its subsequent use, and we may direct part of your enquiry to them.
If you are not satisfied with our response, you may complain to the Office of the Privacy Commissioner at privacy.org.nz.
13. External links
The website and the platform may contain links to third-party websites. Those websites have their own privacy policies and we do not accept responsibility for them. Please review them before submitting personal information.
14. Changes to this policy
Any changes to this policy will be posted on this page. Where the changes are material, we will notify account holders by email. This privacy policy was last updated on 31 July 2026.
15. Contact
Privacy enquiries, access requests, correction requests and privacy complaints should be directed to our Privacy Officer, Mike Gillam, Director, by email at privacy@intelid.nz or by phone on 027 299 7603. General and access enquiries about the platform go to info@intelid.nz.
intelID LimitedSuite 1259917b Farnham StreetParnellAuckland 1052New Zealand16. How this policy maps to the information privacy principles
The Privacy Act 2020 sets out thirteen information privacy principles, and the Privacy Amendment Act 2025 added principle 3A, which came into force on 1 May 2026. This section summarises how each principle applies to us. Where credit information is involved, the Credit Reporting Privacy Code 2020 applies in addition, and in some cases in place of, the principles below.
- IPP1 to IPP4 (collection): we collect account information only where it is necessary to verify eligibility, issue and administer an account, and meet our obligations to our data providers. We collect it lawfully, fairly and without unreasonable intrusion, and we tell applicants why it is being collected at the point we ask for it.
- IPP3A (indirect collection): where an agency collects personal information about an individual from a source other than that individual, it must take reasonable steps to make the individual aware of the matters listed in principle 3A, unless an exception in the Act applies. Subject information returned by the platform is collected indirectly. Because we have no direct relationship with the individual concerned, the customer who runs the search is the agency responsible for meeting principle 3A in relation to their own collection and use of that information, and for assessing whether an exception, such as prejudice to the maintenance of the law or to the purpose of the collection, applies. Clause 5 above sets out that obligation in full. We do not give principle 3A notification on a customer's behalf.
- IPP5 (storage and security): covered in clauses 8 and 9. Encryption in transit and at rest, role-based access control, individual accounts, audit logging and monitoring for anomalous use.
- IPP6 (access): you may ask whether we hold personal information about you and ask for access to it. Requests go to the Privacy Officer at privacy@intelid.nz. We will confirm your identity, respond within the statutory timeframe, and if we refuse access we will tell you the ground for the refusal and your right to complain to the Office of the Privacy Commissioner. Access may be withheld where the Act allows, for example where release would prejudice the maintenance of the law, breach another person's privacy, or reveal material subject to legal professional privilege. A request for information held by a credit reporter is dealt with by that credit reporter under the Credit Reporting Privacy Code 2020, and we will tell you where to direct it.
- IPP7 (correction): you may ask us to correct personal information we hold about you. If we correct it, we will take reasonable steps to notify anyone we have disclosed it to. If we decline to correct it, you may ask us to attach a statement of the correction sought but not made, and we will attach that statement to the record. Where the underlying information came from a public register or a credit reporter, the correction has to be made at that source, and we will tell you who holds it.
- IPP8 (accuracy): before we use or disclose personal information we take reasonable steps to check it is accurate, up to date, complete, relevant and not misleading. Search results are presented with their source and the date they were returned so that a user can assess currency before relying on them.
- IPP9 (retention): covered in clause 11. We do not keep personal information for longer than is required for the purposes for which it may lawfully be used.
- IPP10 and IPP11 (use and disclosure): covered in clauses 3 and 10. Information is used and disclosed only for the purpose it was obtained for, or for a directly related purpose, or where the Act otherwise permits. Every search requires the user to declare an authorised purpose, and that declaration is recorded.
- IPP12 (offshore disclosure): covered in clause 8. Where information is transferred outside New Zealand we take reasonable steps to ensure the recipient is subject to comparable safeguards.
- IPP13 (unique identifiers): we do not assign unique identifiers to individuals beyond an internal account reference, and we do not require you to disclose a unique identifier assigned by another agency except where that agency's own rules permit it.