Privacy Policy

How we handle your data

How Policybase collects, uses, and protects your information under the New Zealand Privacy Act 2020.

Last updated: March 2026

This policy explains how Policybase collects, uses, stores, and discloses personal information in accordance with the New Zealand Privacy Act 2020 and its Information Privacy Principles (IPPs).

Who we are

Policybase is operated from New Zealand. We are the “agency” responsible for personal information collected through policybase.co and the Policybase platform.

Contact details:

What personal information we collect (IPP 1-4)

We only collect personal information that is necessary to provide our service. We collect it directly from you, and we tell you why we need it at the time of collection.

When you use policybase.co or the Policybase platform, we may collect:

  • Name and email address (when you contact us or create an account)
  • School name and your role
  • Policy content you create or upload to the platform
  • Usage data (pages visited, features used)
  • Device and browser information via standard web analytics

We do not collect personal information by unlawful means, and we do not collect more information than is reasonably necessary.

Why we collect it and how we use it (IPP 10)

We use your information for the purpose it was collected:

  • Providing and improving the Policybase service
  • Responding to your enquiries
  • Sending service-related communications (we do not send marketing emails unless you opt in)
  • Monitoring and improving site performance and security

We do not use personal information for purposes other than those for which it was collected, unless you consent or an exception under the Privacy Act 2020 applies.

Disclosure to third parties (IPP 11)

We do not sell your data. We do not share your personal information with third parties for marketing purposes.

We may share information with service providers who help us operate the platform (such as hosting and email providers), but only to the extent necessary and under appropriate agreements. These providers may be located in Australia or New Zealand.

We may disclose personal information if required by law, or to prevent a serious threat to health or safety.

AI and your data

If you use Policybase’s AI features, your policy content is processed by AI models to generate drafts, suggestions, and analysis. Your content is not used to train AI models. AI processing is an optional add-on that you choose to enable.

Data storage and security (IPP 5)

Your data is stored on servers in Australia and New Zealand. We take reasonable steps to protect personal information from loss, unauthorised access, use, modification, or disclosure. This includes:

  • Encryption in transit (TLS) and at rest
  • Access to production systems restricted to authorised personnel
  • Regular review of security practices

Cross-border disclosure (IPP 12)

If we disclose personal information to an overseas service provider (for example, a cloud hosting provider with servers in Australia), we take reasonable steps to ensure the information is protected in a way that is comparable to the protections under the Privacy Act 2020.

Your rights (IPP 6-7)

Under the Privacy Act 2020, you have the right to:

  • Request access to the personal information we hold about you (IPP 6)
  • Request correction of any information that is inaccurate, incomplete, or misleading (IPP 7)
  • Request deletion of your personal information where we no longer need it

We will respond to access and correction requests without undue delay. If we refuse a request, we will give you the reason and advise you of your right to complain to the Office of the Privacy Commissioner.

To exercise these rights, email hello@policybase.co.

Data portability

You can export all your policies and data from Policybase at any time. Your data is yours.

Retention (IPP 9)

We do not keep personal information for longer than is necessary for the purpose it was collected. If you close your account, we will delete your data within a reasonable timeframe, unless we are required to retain it by law.

Cookies

We use essential cookies to keep the site working. We use analytics cookies to understand how people use the site. We do not use advertising or tracking cookies.

Unique identifiers (IPP 12-13)

We do not assign unique identifiers to individuals unless it is necessary for the efficient operation of the service. We do not require you to provide a unique identifier as a condition of access to a service, unless it is for a purpose connected to the original assignment.

Children’s information

Policybase is used by schools, so some policies on the platform may relate to students. We do not collect personal information directly from children. Schools are responsible for their own data practices in relation to students, consistent with their obligations under the Privacy Act 2020 and the Education and Training Act 2020.

Changes to this policy

We may update this policy from time to time. Changes will be posted on this page with an updated date. If changes are significant, we will notify account holders by email.

Complaints

If you are not satisfied with how we have handled your personal information, you can complain to the Office of the Privacy Commissioner at privacy.org.nz.

Contact

If you have questions about this policy, email hello@policybase.co.

Have questions?

Our team is here to help. Get in touch and we'll get back to you within one business day.