Privacy

Privacy and Data Handling

This notice explains what information @I Design collects, why, where it is held and how you can access or correct it, in line with the New Zealand Privacy Act 2020.

Engineering programs involve sensitive design data, so we collect only what each purpose needs and restrict access by role.

  • Data minimisation by default.
  • Use limited to the purpose of collection.
  • Access and correction on request.

Collection Scope

What We Collect

We collect only what we need to respond to enquiries, deliver engagements and keep our services secure.

Information is collected directly from you, through the contact form, by email or during an engagement. This website does not use analytics or advertising cookies.

  • Contact details you provide: name, email address, organisation and message.
  • Project information you choose to share: requirements, constraints and engineering files.
  • Service records: correspondence, engagement documents and, where a hosted workspace is used, access and security logs.

Use

How Information Is Used

Information is used for the purpose it was collected for, or a directly related purpose.

  • Responding to enquiries and assessing program fit.
  • Delivering engagements within an agreed scope.
  • Maintaining security and meeting legal obligations.

How project data may be used beyond delivering your engagement, including for model improvement, is agreed in writing for each engagement before any project data is shared.

Storage and Disclosure

Where Information Is Held

We do not sell personal information. We share it only with service providers that help us operate, or where the law requires it.

Enquiries sent through this website are processed by a third-party form service (Web3Forms) and delivered by email, so they may be stored on servers outside New Zealand. Where information is sent overseas, we take reasonable steps to make sure it is protected in a way comparable to the Privacy Act 2020.

Security Model

Security and Access Controls

Access to information is restricted by role, purpose and environment.

  • Role-based access controls.
  • Environment isolation matched to the deployment pathway.
  • A documented incident response process, including notification of notifiable privacy breaches.

Retention and Rights

Retention, Access and Correction

Personal information is kept only as long as it is needed for its purpose or required by law. You can ask to access or correct the personal information we hold about you.

Send requests to web@rockbrain.co.nz. We may need to verify your identity before acting on a request. If you are not satisfied with our response, you can complain to the Office of the Privacy Commissioner at privacy.org.nz.