Privacy Policy
Last updated: 2 September 2026
1. Who we are and what this policy covers
Opside Technology ("Opside", "we", "our" or "us") is a website design and development business based in New Zealand. We are the agency responsible for the personal information described in this policy.
This policy applies to:
- Our own website at opside.tech, including our contact and enquiry forms; and
- Websites we build, host and maintain for our clients, where we install analytics and contact forms as part of our service. If you have arrived here from a link in the footer of a small business website, this is the policy that explains the analytics and form handling on that site.
Where this policy covers a client website, we and the business that owns that website are each responsible for the personal information collected through it. The client uses your enquiry to respond to you and run their business; we operate the website, its forms and its analytics on their behalf. You can exercise any of the rights in this policy against either of us, and we will coordinate so you only have to ask once.
This policy does not cover what a client does with your information after we pass an enquiry to them, or any third-party website we link to. It also does not cover our own internal employment or supplier records.
2. The short version
- We collect what you type into a contact or enquiry form, so a human can reply to you.
- We use Google Analytics 4 to understand how people find and use our website and the websites we build. This uses cookies and similar technologies.
- Where the law requires it, we ask for your consent before any non-essential analytics cookies are set, and you can change your mind at any time.
- We do not sell your personal information.
- You can ask us for a copy of your information, ask us to correct or delete it, or complain, by emailing [email protected].
3. Information we collect
3.1 Information you give us
When you complete an enquiry form on our website, we ask for and collect:
- Your name
- Your business name and the type of business you run
- The city or area you operate in
- Your email address
- Your phone number
- What you want your website to achieve
Forms on client websites collect similar contact details, and whatever else that business needs in order to respond — for example a preferred appointment time, a service you are interested in, or a description of the job you need done. Please do not send us sensitive information, such as health information or government identifiers, through a website form.
If you email, call or text us, we also keep a record of that correspondence. If you become a client, we collect the information we need to deliver and invoice for the work.
3.2 Information collected automatically
When you visit our website or a website we host, the following is collected automatically:
- Analytics information via Google Analytics 4: the pages you view, how long you spend on them, the links and buttons you click, whether you started or completed a form, the website or search that referred you, your approximate location (usually city level, derived from your IP address), your device type, screen size, browser, operating system and language.
- Server and security logs, kept by our hosting provider: your IP address, the time of your request, the page requested, and your browser user agent. These are used to keep the site running, prevent abuse and investigate faults.
We do not use analytics to build advertising profiles about you, and we do not combine analytics data with your enquiry to identify you personally.
4. Cookies and analytics technologies
Cookies are small files stored on your device. Similar technologies include local storage and pixels. We group them as follows.
| Type | What it does | Consent needed? |
|---|---|---|
| Strictly necessary | Keeps the site secure and working, remembers your cookie choice, and protects forms against spam and abuse. | No — the site cannot work without these. |
| Analytics (Google Analytics 4) | Cookies in the _ga family, typically set for up to 2 years, which distinguish one visitor from another so we can count visits and see which pages work. | Yes, where the law requires it. |
Google Analytics 4 specifically. GA4 is provided by Google LLC. Google acts as our data processor for analytics and processes the data on our instructions. GA4 truncates and discards IP addresses rather than logging or storing them, and we have not enabled Google Signals, advertising personalisation, or the sharing of analytics data with Google's advertising products. Our GA4 properties are configured to retain user-level and event-level data for 14 months, after which it is deleted automatically. You can read Google's explanation at How Google uses information from sites that use our services.
Your choice. Where you are in a jurisdiction that requires consent for non-essential cookies, analytics cookies are not set until you accept them, and declining does not stop you using the site. You can change or withdraw your choice at any time using the cookie settings link on the site, by clearing cookies in your browser, or by using the browser controls and opt-outs described in section 12.
5. Websites we build and host for clients
Most of the websites we work on belong to small local businesses — tradespeople, salons, clinics and similar. Our involvement in your information on those sites is limited and specific.
5.1 Analytics on client websites
Where a client has taken our analytics and reporting service, we install Google Analytics 4 on their website and configure it the same way we configure our own: no advertising features, no Google Signals, IP addresses discarded, and a 14 month retention period. We use the resulting reports to advise that business on how their website is performing. Each client can see the analytics for their own website only. We never combine analytics across different clients to profile individual people.
5.2 Forms on client websites
When you submit an enquiry, booking request or quote request on a website we built, the details are delivered by email to that business so they can respond to you. The message passes through our email delivery provider, and a copy may sit in our systems briefly as part of that delivery and for troubleshooting. We do not use enquiries sent to a client to market our own services to you, and we do not sell or rent them to anyone.
5.3 Hosting and maintenance
Under our monthly plans we host client websites, apply software updates, monitor security and take daily backups. This means content submitted to a client website, including form submissions held on that site, may be included in encrypted backups we hold. Our staff access this data only to run, secure, back up and fix the website, or where a client asks us to.
5.4 Payments and other add-ons
Some client websites include online payments or bookings. Card payments are handled directly by a specialist third-party payment provider on that business's account. Neither we nor the client website stores your full card number. If a client website uses booking or e-commerce tools, the privacy terms of those tools also apply.
5.5 When our involvement ends
If a client leaves us or takes over their own hosting, we hand the website and its data to them and delete our copies in line with section 9. From that point the business is solely responsible for the site, and this policy no longer applies to it.
6. How and why we use your information
We use personal information only for the purposes it was collected for, or a directly related purpose you would reasonably expect. Under the GDPR and UK GDPR we must also have a lawful basis, set out below.
| What we do | Lawful basis |
|---|---|
| Reply to your enquiry, quote for work, and deliver a website we have agreed to build | Performance of a contract, or steps taken at your request before entering one |
| Pass an enquiry made on a client website to that business | Legitimate interests — you submitted the form in order to be contacted by that business |
| Measure and improve how our websites and client websites perform, using analytics | Consent where required for cookies; otherwise our legitimate interest in understanding and improving our services |
| Host, secure, back up and troubleshoot websites | Legitimate interests in keeping our services available and secure |
| Send marketing emails about our services, and publish testimonials | Consent, which you can withdraw at any time |
| Keep invoicing, tax and business records, and handle disputes | Legal obligation, and our legitimate interest in establishing or defending legal claims |
We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects.
7. Who we share information with
We do not sell your personal information, and we do not share it for cross-context behavioural advertising. In the last 12 months we have not sold or shared personal information as those terms are defined under California law. We disclose information only as follows.
- The client whose website you contacted. Your enquiry is delivered to that business so they can respond.
- Service providers who work for us, under contracts that require them to protect your information and use it only for the service they provide to us. These currently include:
- Resend (United States) — delivers form submissions and transactional email.
- Google LLC (United States and elsewhere) — provides Google Analytics 4.
- Our website hosting and infrastructure provider — serves the websites and holds server logs and backups.
- Business tools we use to run the company, such as email, file storage and accounting software.
- Professional advisers, such as our accountant or lawyer, where needed.
- Authorities and others, where the law requires or authorises it, or where disclosure is necessary to prevent a serious threat to someone's life, health or safety, or to protect our legal rights.
- A buyer, if our business is sold or restructured, subject to the same protections set out in this policy.
8. Sending information overseas
Some of our providers, including Resend and Google, store and process information outside New Zealand, principally in the United States and the European Union.
As required by information privacy principle 12 of the Privacy Act 2020, we only send personal information overseas where we are satisfied the recipient is required to protect it with safeguards comparable to those under the Privacy Act, which we do through our contracts with those providers.
For transfers of information out of the European Economic Area or the United Kingdom, we rely on the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, together with additional technical measures such as encryption in transit and at rest.
9. How long we keep information
- Enquiries that do not become work: up to 24 months from your last contact with us, then deleted.
- Client project and correspondence records: for the life of the engagement and 7 years afterwards, to meet New Zealand tax and business record-keeping requirements.
- Google Analytics data: user-level and event-level data is deleted automatically after 14 months. Aggregated reports that cannot identify you may be kept longer.
- Server logs: typically 30 days.
- Website backups: rolling daily backups, retained for up to 90 days, then overwritten.
- Marketing subscribers: until you unsubscribe, plus a minimal record of your unsubscribe so we do not contact you again.
Where we no longer need information for the purpose we collected it, we delete it or irreversibly de-identify it.
10. How we protect information
We take reasonable safeguards against loss, misuse and unauthorised access, including HTTPS and TLS encryption on every site we host, encrypted storage and backups, multi-factor authentication on our administrative accounts, access limited to the people who need it, and regular software and security updates as part of our monthly plans.
No method of transmission or storage is completely secure, so we cannot guarantee absolute security. Please do not send us sensitive personal information by email or through a website form.
11. Your privacy rights
11.1 Everyone
Under the Privacy Act 2020 you have the right to ask us for confirmation that we hold personal information about you and for access to it (principle 6), and the right to ask us to correct it (principle 7). If we decline a correction, you can ask us to attach a statement of the correction you sought, and we will.
We will respond to a request as soon as reasonably practicable and within 20 working days. There is normally no charge. We may need to verify your identity first, and in limited cases the Privacy Act allows us to refuse a request — if so, we will tell you why and how to complain.
11.2 If you are in the EEA or the UK
In addition, you have the right to:
- access, correct, or erase your personal information;
- restrict or object to our processing, including profiling;
- object at any time to processing based on our legitimate interests, and to direct marketing, which we will always stop on request;
- receive your information in a portable, machine-readable format and have it transmitted to another provider;
- withdraw consent at any time, without affecting processing carried out before you withdrew it; and
- lodge a complaint with your local supervisory authority.
11.3 If you are a California resident
Under the CCPA as amended by the CPRA you have the right to know the categories and specific pieces of personal information we have collected, the sources, our purposes and the categories of recipients; to delete personal information; to correct inaccurate personal information; to opt out of the sale or sharing of personal information; and to limit the use of sensitive personal information. We will not discriminate against you for exercising these rights.
In the last 12 months we have collected the following categories of personal information: identifiers such as your name, email address, phone number and IP address; commercial information about the services you enquired about or purchased; and internet or network activity such as your browsing and interaction with our websites. We collect these from you directly and automatically through analytics and server logs, for the business purposes in section 6. We do not sell or share personal information, and we do not collect sensitive personal information for the purpose of inferring characteristics, so no limitation right applies.
You may use an authorised agent to make a request on your behalf, with proof of their authority.
11.4 How to make a request
Email [email protected] with what you want and, if your request relates to a client website, which website it was. If your request concerns information a client holds, we will pass it to them and help them respond.
12. Your tracking choices and opt-outs
- Cookie settings: where a consent banner is shown, use the cookie settings link on the site to change or withdraw your choice at any time. On this site you can right here.
- Google Analytics opt-out: install the Google Analytics Opt-out Browser Add-on to stop GA4 measurement across every site you visit.
- Your browser: you can block or delete cookies in your browser settings, or browse in a private window. Blocking strictly necessary cookies may stop parts of a site working.
- Global Privacy Control: we honour the GPC signal as a valid opt-out of the sale or sharing of personal information where the law recognises it. There is no agreed standard for older "Do Not Track" browser signals, so we do not respond to those.
- Marketing email: use the unsubscribe link in any marketing message, or email us.
13. Children
Our services are aimed at businesses and are not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child has given us their information, contact us and we will delete it.
14. Privacy breaches
If a privacy breach occurs and it is reasonable to believe it has caused, or is likely to cause, serious harm, we will notify the Office of the Privacy Commissioner and the affected people as soon as practicable, as required by Part 6 of the Privacy Act 2020. Where a breach affects a client website, we will notify that client without undue delay so they can meet their own obligations, and we will support them in doing so. Where the GDPR applies, we will notify the relevant supervisory authority within 72 hours where required.
15. Changes to this policy
We may update this policy as our services or the law change. The date at the top shows when it was last revised. If a change materially affects how we use your information, we will take reasonable steps to tell you — for example by a notice on our website or an email — before it takes effect, and where the change requires your consent, we will ask for it.
16. Contact us and how to complain
For any privacy question or request, or to complain about how we have handled your personal information, contact our privacy contact:
- Email: [email protected]
- Phone: (+64) 27-419-6973
- Opside Technology, New Zealand
We take complaints seriously and will acknowledge yours within 5 working days and aim to resolve it within 20 working days.
If you are not satisfied with our response, you can complain to the Office of the Privacy Commissioner in New Zealand. If you are in the EEA or the UK, you may complain to your local data protection authority or, in the UK, to the Information Commissioner's Office.