Skip to content

Security & privacy

The question everyone asks last, and should ask first

You are about to give a third party access to everything your business knows about its customers and its money. Here is exactly how we handle that.

Encryption in transit and at rest

Data moves over encrypted channels and sits encrypted while we hold it. No unencrypted extracts on laptops, no data sent by email attachment.

Least access, for the shortest time

We ask for the narrowest access that will do the job, and we tell you when to revoke it. Credentials are never shared between engagements.

Data stays in New Zealand where you need it to

If your obligations require onshore processing, we work to that. Where cloud services are involved we agree the region with you before anything moves.

Deleted when the job is done

Working copies are destroyed at the end of the engagement and we confirm it in writing. We do not keep your data as a reference set.

Confidentiality agreements as standard

We sign your NDA, or provide ours. Either way it is in place before we see anything.

A tested way back

Before any cutover we confirm you have a restore point that has actually been restored — not just a backup that has been taken.

The Privacy Act 2020, in plain terms

Moving personal information is a processing activity, and the obligations do not transfer to your supplier — they stay with you. That means the way your migration is run is your compliance position, not ours.

Practically, that comes down to four things: only move what you need, keep it secure while it is in flight, be able to show where it went, and be able to prove the working copies were destroyed. Our engagements are built to produce that evidence as a by-product, so you are not assembling it afterwards.

This is a description of how we work, not legal advice. For advice specific to your obligations, talk to your legal counsel or the Office of the Privacy Commissioner.

Straight answers

Who at Data Moving can see our data?
Only the people working on your engagement, and we will name them. Access is granted per project and removed when it closes.
Do you use offshore subcontractors?
No. The work is done in New Zealand by the people you have met.
What happens to our data if we don't proceed?
Anything we have been given is destroyed and we confirm that to you in writing. Nothing is retained.
Can you work inside our environment instead of taking extracts?
Usually, yes — and where the data is sensitive it is often the better option. We will discuss it during discovery.

Get moving

Still want to dig into it?

Send us your security questionnaire, or just ask. We would rather answer it now than have it surface halfway through a project.

Coverage
Nationwide across New Zealand, remote-first delivery
Response time
We reply to every enquiry within one business day

We use your details only to respond to this enquiry. No lists, no spam.

Book a consultation