Privacy policy.
You trust us with your bank transactions. This policy explains, in plain English, what we collect, why, where it's kept and your rights under the New Zealand Privacy Act 2020.
Last updated 26 September 2026
Who we are
MyCEO ("we", "us") designs, builds and looks after websites and apps, makes brand films, and prepares monthly management reports for New Zealand businesses. We follow the information privacy principles in the Privacy Act 2020. Our privacy officer is responsible for how we handle personal information and can be reached at hello@myceo.co.nz.
We handle personal information in two ways. For our own records about clients and enquirers, we are the agency responsible under the Act. For information we hold on a client's behalf, such as its bank exports and the data collected through its website or app, the client's business is responsible and we act as its agent. Data we hold for your business explains the difference.
What we collect
- What you tell us: your name, email address, business name and details, and anything you write in a brief, email or Ask-an-Accountant question.
- Business bank exports you send us for your Monthly CEO Briefing (by email until our member area opens). These show transactions, amounts and the names of people and businesses you pay or are paid by.
- Billing details: invoices and payment records. Card and bank account details are handled by our payment provider, Stripe, and aren't stored by us.
- Member area, once it opens: the email address you sign in with, when you sign in, and what you send us there, such as questions, change requests, messages, files you attach and bank exports.
- Project material you give us for a website, app or film, such as text, photos, logos and staff names.
- Likeness and voice: if a person signs a Likeness and Voice Release for a film or website, their photos, video or voice recordings, and any digital version or voice model we make from them for that project.
- Data from your website or app: the enquiries, bookings, orders and customer accounts collected through a website or app we host or look after for you. We hold these for your business, as its agent.
- Details of other people you name to us, such as your accountant's name and firm in a Membership Order.
- Technical data: our hosting provider keeps standard server logs (such as IP address, browser and the pages requested) to keep the site running and secure. We don't use advertising trackers or tracking cookies. Once it opens, the member area will use two essential cookies: one keeps you signed in for up to 30 days, and one simply tells the site you're signed in so the menu can say "My account". If you hide the founding offer notice, your own browser remembers that choice; it isn't sent to us.
We collect information directly from you wherever we can. You don't have to give us anything, but without it we may not be able to reply or provide a service.
Why we use it
Only for the purposes we collected it for: to reply to you and send proposals, to prepare your briefing and reports, to build and look after your website, app or film, to invoice you and keep business records, and to meet our legal and professional obligations. We don't sell personal information and we don't use it for anyone else's marketing.
We publish a case study or review only with your written agreement, and only the words and details you approve.
Data we hold for your business
Some information belongs to our clients' businesses, not to us. We hold it on your behalf, as your agent under section 11 of the Privacy Act, and your business stays the agency responsible for it. That covers:
- the bank exports you send us for your briefing, and the payee names in them;
- the personal information of the end users of your website or app, such as the people who make enquiries, bookings, orders or accounts through a site or app we host or look after for you;
- the content and staff details you give us for a project.
We use this information only to provide the services you've ordered, to meet our legal and professional obligations, and as you instruct in writing. We never sell it, use it for marketing or contact the people named in it. We use payee names only to sort transactions into categories, and our reports show totals rather than individual people wherever possible.
Your business is responsible for telling those people how their information is used where the Act requires it, for example under information privacy principles 3 and 3A, and in the privacy policy on your own website. If your website or app collects health information, the Health Information Privacy Code 2020 also applies, so please tell us before launch.
If you're a customer of a business whose website or app we look after, please contact that business first about your information. If you contact us, we'll pass your request to the business within two working days and help it respond.
Information about other people
Sometimes we collect personal information about someone from another person rather than from them directly. For our own records, the main example is a client's accountant, whose name and firm a client may give us so we can work alongside them. Information privacy principle 3A requires us to take reasonable steps to tell that person we have their information, unless an exception applies, for example because they already know. When we first contact a client's accountant or another adviser, we tell them who we are, why we have their details, who we may share them with, and how to see or correct them, and we point them to this policy.
If we collected your information this way and you'd like to know more, email hello@myceo.co.nz.
Who we share it with
We don't share your information except:
- with service providers that help us run MyCEO, such as website hosting, email, secure file storage, AI writing assistance, accounting and payment processing. They may use it only to provide their service to us;
- with your accountant, or anyone else you've asked us in writing to share it with;
- where the law requires or allows it, for example to a government agency with legal authority to ask for it, or to our professional body for a confidential quality review.
Our providers, and storage overseas
Some of our providers store data outside New Zealand. Before we send personal information overseas, we make sure it will be protected in a way comparable to the Privacy Act, as information privacy principle 12 requires, usually through the provider's contract terms. Our main providers are:
| Provider and role | Where data may be stored |
|---|---|
| Cloudflare: hosting, member area, secure file storage, email delivery | Worldwide, including the United States |
| Anthropic (Claude): AI assistance in preparing and translating reports and messages | United States |
| Stripe: membership payments | United States and other countries |
| Xero: invoicing | Australia and the United States |
| Google (Gmail): business email, including bank exports and files you email to us | United States and other countries |
AI tools. Where we use AI software to help prepare a report, it runs under Anthropic's commercial terms, which prohibit training AI models on your data. We don't let any provider use client information to train its models. The AI doesn't decide anything about your reports, and an accountant reviews every report before it reaches you. When we translate your reports or messages, for example between English and Korean, we use only the providers listed here. We never put client information into free translation tools or messaging apps.
The full, current list of providers, and where each stores data, is available from our privacy officer at hello@myceo.co.nz. We tell clients in writing at least 14 days before adding a provider that will hold data we hold for them.
How we keep it safe
- We never ask for passwords. When our member area opens, it will have no passwords to steal: you'll sign in with a link we email you, which works once and expires after 15 minutes.
- Bank exports sent by email. Until our member area opens, members email their monthly bank export to hello@myceo.co.nz, which arrives in our business email account. We use it only to prepare your briefing. We don't forward it or put it into any other app or service, apart from our email provider and the AI assistance listed above, which may not train on it. We permanently delete the email, the attachment and any working copy within 30 days after we deliver the briefing it was used for, keeping only the summaries and categories in our working papers. Please send only the export file, and never send passwords, online banking logins, PINs or card numbers. When the member area opens, it will replace email for bank exports. This follows information privacy principles 5 (storage and security) and 9 (keeping information no longer than needed).
- Bank exports and reports are kept only in our business email account and on encrypted, password-protected devices, and only the person preparing your briefing can open them.
- Every account that can reach client files uses two-factor sign-in.
- We never ask for your online banking login, and we can't make payments from your accounts, other than collecting the membership fees you authorise through Stripe. If anyone claiming to be MyCEO asks for your banking login or asks you to pay a new account, don't act on it and tell us straight away.
- We keep only what we need, and delete it on schedule (see below).
How long we keep it
| Information | Kept for |
|---|---|
| Bank exports you send us, including the email they arrive in and any working copies | Permanently deleted within 30 days after we deliver the briefing they were used for |
| Briefings and Ask-an-Accountant reports | While you're a client and seven years afterwards, to meet professional record-keeping obligations. Each one is emailed to you when it's delivered, and for 30 days after you leave we'll resend any copy you ask for |
| Our working papers | While you're a client and seven years afterwards. They keep summaries and categories, not full bank exports |
| Invoices and payment records | Seven years, as the Tax Administration Act 1994 requires for business records |
| Member area sign-in records, once it opens | Sign-in links are deleted within a day; sessions end after 30 days or when you sign out |
| Enquiries that don't go ahead | 12 months, then deleted |
| Requests, messages and files you send us by email or, once it opens, in the member area (other than bank exports, which follow the schedule above) | While you're a client and seven years afterwards, as the written record of what was asked and agreed |
| Website and app project files | Handed over to you, then deleted within 90 days after the Order ends |
| Film project files | 90 days after delivery, then deleted, unless you ask us in writing for a copy first |
| Digital versions and voice models made under a Likeness and Voice Release | Deleted within 90 days after delivery, keeping only the finished material. Never used to train AI models |
| Data collected through your website or app | Held for your business while we host or look after it. When all your Orders end, returned to you on request, then deleted unless the law requires us to keep it |
Your rights
You can ask for a copy of the personal information we hold about you, and ask us to correct it (information privacy principles 6 and 7). Email hello@myceo.co.nz. We'll respond as soon as we can, and within 20 working days. If we don't make a correction you asked for, you can ask us to attach a statement of the correction you wanted. If the information is held for one of our clients, we'll pass your request to that business, as explained above.
If you're unhappy with how we've handled your information, please tell us first so we can put it right. You can also complain to the Office of the Privacy Commissioner at privacy.org.nz.
If something goes wrong
Who notifies a privacy breach depends on whose information it is.
- Information we hold for your business, such as bank exports and the data collected through your website or app. We tell your business in writing without undue delay and within 24 hours of becoming aware of the breach, with what we know, what we're doing to contain it and what we need from you. Because we hold this information as your agent under section 11, your business decides whether the breach is notifiable and notifies the Privacy Commissioner and the people affected under Part 6 of the Privacy Act. We give you the information and help you need, at no charge where we caused the breach.
- Our own records, such as contact details, enquiries, invoices, and our reports and working papers. If a breach has caused, or is likely to cause, serious harm, we notify the Privacy Commissioner and the people affected as soon as practicable, as Part 6 of the Privacy Act requires.
Emails from us
Emails about your service, such as briefings, reports, invoices and replies, are part of working with us. We send marketing emails only with your consent, always identify ourselves, and include a working unsubscribe link, as the Unsolicited Electronic Messages Act 2007 requires.
Changes to this policy
If we change this policy, we'll update this page and the date above. For significant changes, we'll tell current clients by email before they take effect.