Privacy Policy
1. Purpose
1.1 Policy: This privacy policy (Policy) of CIO Studio Limited (we, us, our) applies to all visitors and contacts of www.ciostudio.nz (the Website).
1.2 Purpose: The purpose of this Policy is to let visitors, prospective clients, clients and other contacts (you, your) know when we collect personal information and what we do with it. We do not use, share or transfer personal information except as set out in this Policy. “Personal information” means information about an identifiable individual.
1.3 Who we are: CIO Studio Limited provides fractional CIO, digital strategy, system procurement, IT governance, change management and IT team capability services to businesses in New Zealand. We do not operate a customer membership portal, vendor marketplace, or take payments through the Website.
2. Information we collect
2.1 Browsing: You can browse the Website without disclosing any personal information to us.
2.2 When you contact or engage with us: We collect personal information when you interact with us through any of the following channels:
-
completing the contact/enquiry form on the Website;
-
subscribing to our newsletter or blog updates;
-
downloading a guide, whitepaper or other resource from the Website;
-
registering for an event, webinar or workshop we host or co-host;
-
corresponding with us directly by email, phone or in person (for example, with Ray Delany or another team member).
The personal information collected through these channels typically includes your name, email address, phone number, job title, organisation, and the content of any message, enquiry or correspondence you send us.
2.3 Technical information: When you visit the Website, we and our service providers (see clause 5) may automatically collect technical information about your device and visit, including IP address, browser type and version, operating system, pages viewed, referring pages, search terms used to find the Website, and the date, time and duration of your visit. This information relates to your individual visit and may later be aggregated or anonymised for analysis.
2.4 Sources: We collect personal information directly from you (through the methods listed in clause 2.2), automatically through your use of the Website (see clause 5 on cookies and analytics), and occasionally from third parties you have authorised to share your details with us (for example, a colleague who introduces you to us).
2.5 Services unavailable: If you choose not to provide certain personal information, we may not be able to respond to your enquiry, send you the resource you requested, or register you for an event.
2.6 Updating your details: You can ask us to update or correct the personal information we hold about you at any time by contacting us using the details in clause 9.4.
3. How we use your information
3.1 Purposes: We use the personal information we collect to:
-
respond to your enquiries and correspondence;
-
send you the resource, guide or information you have requested;
-
send you our newsletter, blog updates, or information about our services, where you have subscribed or otherwise agreed to receive these;
-
administer your registration for an event or webinar;
-
understand how the Website is used and improve its content and functionality;
-
maintain records of our dealings with prospective and existing clients; and
-
comply with our legal and regulatory obligations.
3.2 Anonymised data: We may anonymise or aggregate information so that you can no longer be identified from it, and use that data to understand how the Website and our services are used.
4. Disclosure of your information
4.1 General: We do not sell your personal information. We will not disclose personal information we hold about you to any third party except as set out in this clause 4.
4.2 Service providers: We work with third-party service providers who provide website hosting, security, email marketing/CRM, analytics, and related services on our behalf, which may require them to access your information. We use a third-party email marketing/CRM platform to store contact details and send newsletters and other communications you have subscribed to. Our service providers may only use your information to provide services to us, and some may be located outside New Zealand. Where personal information is held or processed overseas, we take reasonable steps to ensure it is subject to safeguards comparable to those required under New Zealand law, including through our contractual arrangements with those providers.
4.3 Legal obligations: We may disclose your information if we believe in good faith that this is reasonably necessary to comply with any law, regulation, legal process or government request; to enforce our agreements and policies; to protect the rights, property or safety of CIO Studio, our clients or the public; or to investigate suspected misuse of the Website.
4.4 Sale of business: If we sell or transfer all or part of our business or assets, your personal information may be disclosed to the prospective buyer (for due diligence purposes) and, if the sale proceeds, to the purchaser so that they can continue operating the business.
5. Cookies and analytics
5.1 Cookies: We use cookies and similar technologies to recognise your device and understand how the Website is used.
5.2 Google Analytics: We use Google Analytics to understand traffic patterns on the Website, including the number of visitors, pages viewed, and time spent on the Website. This information is aggregated and does not personally identify you. You can view Google’s privacy policy here.
5.3 Managing cookies: Most browsers accept cookies by default. You can change your browser settings to block or delete cookies; instructions are usually in your browser's “Help” menu. Blocking cookies may affect some Website functionality, though all core content remains accessible without them.
5.4 Targeted advertising: We use third-party advertising platforms — including Google Ads, Meta (Facebook and Instagram), and LinkedIn — to show advertisements about our services to people who have previously visited the Website (retargeting) and to people who match interest or demographic profiles relevant to our services. To enable this, these platforms may place cookies or tracking pixels on your device when you visit the Website. This allows those platforms to recognise your device when you visit other websites or use their platforms, and to serve you relevant advertisements. We do not share your name or contact details with these advertising platforms for this purpose; the targeting is based on device/cookie identifiers and platform-defined audience categories. You can opt out of this type of advertising through the following mechanisms:
-
Google: Google Ads Settings or the NAI opt-out tool
-
Meta: Ad preferences within your Facebook or Instagram account settings
-
LinkedIn: Ad preferences within your LinkedIn account settings
You can also limit tracking at a device level by adjusting your browser's cookie settings (see clause 5.3), though this may not fully prevent all ad personalisation across platforms.
6. Linked sites
6.1 Third-party links: The Website may contain links to third-party websites or articles. These are provided for your convenience. We do not endorse and are not responsible for the privacy practices of any linked websites. We recommend you review the privacy policy of any third-party site before providing your personal information to it.
7. Security
7.1 Safeguards: We take reasonable steps to protect personal information from loss, misuse, unauthorised access, disclosure, alteration or destruction. However, no method of transmission over the internet is completely secure, and we cannot guarantee the security of information transmitted to or from the Website.
8. Your communication preferences
8.1 Opting out: You may unsubscribe from our newsletter or marketing communications at any time using the unsubscribe link included in those communications, or by contacting us directly using the details in clause 9.4.
8.2 Transactional messages: Even if you unsubscribe from marketing communications, we may still need to contact you about matters directly relating to an enquiry, event registration, or engagement you have with us.
8.3 Retention: We keep your contact details for as long as is reasonably necessary for the purpose they were collected, or until you ask us to remove them, whichever is earlier. If you have not engaged with us for an extended period, we may periodically review and delete inactive contact records.
9. Accessing and correcting your information
9.1 Privacy Act 2020: Under the New Zealand Privacy Act 2020, you have rights to access and request correction of personal information we hold about you. More information about the Act is available here.
9.2 Access: You may request a copy of the personal information we hold about you.
9.3 Correction: You may request that we correct or update any personal information we hold about you that is incomplete or inaccurate.
9.4 Contact us: To make a request, or if you have any concerns about this Policy, please contact:
-
Ray Delany
-
Email: ray@ciostudio.nz
-
Phone: 021 337 434
9.5 Cost: We do not normally charge a fee to provide access to or correct your personal information. We may charge a reasonable fee, where permitted by law, if a request is manifestly unfounded, repetitive or excessive.
9.6 Verifying identity: We may ask you for information to verify your identity before actioning a request, to ensure your information is not disclosed to the wrong person.
9.7 Office of the Privacy Commissioner: If you are not satisfied with our response to a privacy concern, you may contact the Office of the Privacy Commissioner:
-
PO Box 10-094, Wellington 6143, New Zealand
-
Phone: +64 4 474 7590 | Enquiries line: 0800 803 909
-
Email: enquiries@privacy.org.nz
10. Changes to this Policy
10.1 Updates: We may update this Policy from time to time. Any changes will be posted on this page and the “last updated” date above will be revised accordingly. We encourage you to review this Policy periodically.
