Privacy Policy

Privacy Policy

Mana Tax collects, uses, stores, and protects your personal information in accordance with the requirements of the Privacy Act 2020 of New Zealand. We are committed to handling your information responsibly and transparently.

What is Personal Information?

Personal information is information about an identifiable individual. It includes (but is not limited to):

  • Name, address, and contact details
  • Business name and tax information
  • Xero account and transaction data
  • Payment details
  • Testimonials and feedback
  • Usage data and activity on the platform
  • Communications and support interactions

How We Collect and Use Your Information

When you use the platform, you consent to us using, disclosing, and handling your personal information in accordance with this policy. We never share your personal information with any third party without your approval.
We collect your personal information so we can:

  • Verify your identity
  • Provide the platform’s services and features to you
  • Connect to and interact with your Xero account as authorised by you
  • Process your subscription and billing via Stripe
  • Operate and optimise AI tools and features configured for your business
  • Send transactional notifications about your account, billing, and security
  • Improve the services and features we provide
  • Respond to communications from you, including support requests
  • Meet our legal and regulatory obligations
  • Protect and enforce our legal rights and interests
  • Fulfil any other purpose authorised by you or the Act

 

We do not sell or rent your personal information to third parties. Where you provide third-party credentials or API keys (for example, for Xero or other integrations), these are used exclusively to connect your chosen services and remain under your control.

Third-Party Collection of Information

Where we collect your personal information from someone other than you, we will take reasonable steps to notify you that we have collected your personal information, the purpose of the collection, and the intended recipients of the information.

Storage and Security

We will only retain personal information as long as it is required for the purposes for which the information may lawfully be used. We take all reasonable steps to protect your personal information from any loss, unauthorised access, or other misuse.

  • Cloud storage: all personal information is held on secure cloud infrastructure. We do not keep paper files.
  • Security measures: our systems use secure authentication and multi-factor access controls.
  • Encryption: all data is encrypted in transit and at rest using HTTPS/TLS protocols, and can only be accessed over secure network connections.
  • Backups: all data stored online is backed up and can be retrieved in the event of data loss or corruption.
  • Access controls: data access is limited to authorised personnel only, subject to strict confidentiality obligations.

Data Retention

We retain personal information and platform data for as long as necessary to deliver our services and meet our legal obligations. When your engagement with Mana Tax concludes, we will retain records as required by law and then securely delete or anonymise personal information that is no longer needed.

Disclosure of Your Personal Information

We respect and protect the privacy of your personal information at all times. We may disclose your personal information to:

  • Service providers who assist us in operating the platform (such as hosting providers, billing processors, and analytics services)
  • Xero Limited, as required to facilitate the integration you have authorised
  • Payment processors (such as Stripe) to manage billing
  • Courts, tribunals, and regulatory authorities as required by law
  • The Office of the Privacy Commissioner
  • CERT NZ (to assist with the management of a privacy breach)
  • Government or law enforcement bodies as required by law
  • Anyone else to whom you authorise us to disclose it

 

All third-party providers are subject to strict confidentiality and data security obligations. We conduct due diligence to ensure they meet appropriate privacy and security standards. Your data is never shared with third parties for marketing or commercial purposes unrelated to your engagement with us.

Data Breaches

Our team has processes and systems in place in the event of a data breach. If such an event occurs that poses a risk of harm, we will promptly identify, report, and examine the breach, and notify affected individuals and the Office of the Privacy Commissioner in accordance with our obligations under the Privacy Act 2020.

Accessing and Correcting Your Information

Subject to certain grounds for refusal set out in the Act, you have the right to access your personal information that we hold and to request a correction. You may also request that we restrict how we process your data, or ask for a portable copy of your information. Before you exercise this right, we will need to confirm your identity.
To request access or corrections, please contact us:

insert email, phone, and mailing address before publishing.

We will respond within a reasonable timeframe and no later than 20 working days, in line with our obligations under the Privacy Act.
If you are not satisfied with how we have handled your personal information, you have the right to make a complaint to the Office of the Privacy Commissioner at www.privacy.org.nz.

Internet Use and Cookies

  • Security: while we take reasonable steps to maintain secure connections, providing personal information over the internet is done at your own risk.
  • External links: if you follow a link to another site, that site has its own privacy policy. We suggest you review it before providing personal information.
  • Cookies: we use cookies to monitor use of the platform and support site performance. You may disable cookies in your browser settings, though this may limit some features.
  • Monitoring: we may use third-party services to monitor our systems and prevent unauthorised access.

Changes to This Policy

We may change this policy by uploading a revised version. The change will take effect on the date we upload the revised policy. For significant changes that materially affect how we handle your personal information, we will notify current users directly where appropriate.

New Zealand Jurisdiction

This policy is governed by New Zealand law and is intended only for persons within New Zealand. By using the platform, you agree to submit to the exclusive jurisdiction of the New Zealand courts.
ct.

Contact US

The Privacy Act 2020 gives you the right to request access to your personal information held by Mana Tax. Visit www.privacy.org.nz for more details on the Act.