Skip to content
DataHorizon
Book a call

Privacy

What we collect, why, and what we will never do with it.

DataHorizon handles other organisations’ data for a living, so we hold our own site to the standard we design for our clients. This policy covers this website and our commercial dealings, and it is written to be read rather than survived.

Last updated 14 September 2026 · Governed by the Privacy Act 2020 (New Zealand)

The short version

  • We use no tracking cookies and no advertising networks. Our analytics are cookieless and cannot identify you.
  • You can read every page of this site without giving us anything.
  • If you book a call or email us, we keep what you send so we can reply and, if we work together, run the engagement.
  • The reporting health check is scored entirely in your browser. We never see your answers unless you choose to send them.
  • We do not sell, rent or trade personal information. Ever, to anyone.

What we collect on this website

Nothing, if you only read. Browsing the site requires no account, sets no tracking cookie, and puts nothing about you into our hands.

Aggregate analytics. We use Plausible, a cookieless analytics tool, to count page views and see which pages are useful. It sets no cookies, records no device fingerprints and no cross-site identifiers, and cannot single you out. We see totals — pages viewed, referring site, country, broad device type — never individuals.

Booking a call. Our calendar runs on Cal.com. When you book, you give Cal.com your name, email address, chosen time and anything you type into the notes. That reaches us so we can prepare for and attend the meeting.

Emailing us. If you email us we hold that message, your address and our replies for as long as the conversation is live, and afterwards under the retention periods set out below.

The reporting health check

The health check is scored entirely in your browser. Your answers are never transmitted to us, never stored on a server, and disappear when you close the tab.

If you use the “send me the summary” option, your own email client opens with the summary pre-written, so you can see exactly what would be sent before you send it. Nothing leaves your device unless you press send. If you never press send, we never learn that you took it.

Why we hold it, and on what basis

We collect personal information for one purpose: to respond to you, and to deliver work you have asked us to do. We do not collect information speculatively, build marketing profiles, or retain contact details for a future campaign you did not ask for.

We collect it directly from you, we tell you why at the point of collection, and we use it only for that stated purpose — Information Privacy Principles 1 to 4 and 10 of the Privacy Act 2020, applied in practice rather than in the abstract.

Client data during an engagement

This is separate from anything collected through this website, and it is the part that matters most to the organisations we work with.

We work inside your tenant wherever possible. Data engineering, semantic modelling and AI work is performed in your Azure, Fabric or cloud environment, under accounts you issue and can revoke. In that arrangement your data never moves to infrastructure we control.

Where a dedicated environment is necessary, it is provisioned per client, never shared between clients, and hosted in New Zealand or Australian regions unless you direct otherwise in writing.

Personal information in client datasets is masked, tokenised or excluded from development and model-training data wherever the work allows it. Where production personal information must be handled, it is accessed under least-privilege roles and governed by the confidentiality and privacy terms of the engagement agreement, which take precedence over this policy.

At the end of an engagement we return or destroy client data on request and revoke our own access as a standard closing step, retaining only the documentation we need for our own records.

How we protect it

Access to client systems uses named accounts with multi-factor authentication and least-privilege roles — never shared logins. Company devices are encrypted at rest, and data in transit is encrypted with current TLS.

Access is limited to the people doing the work. DataHorizon is small enough that this is a short list, and we can tell you exactly who is on it for your engagement.

If a privacy breach occurs that has caused or is likely to cause serious harm, we will notify you and the Office of the Privacy Commissioner as required by Part 6 of the Privacy Act 2020.

How long we keep it

Booking and enquiry details are kept while the conversation is live. If we do not end up working together, we delete them within 24 months.

Records relating to actual engagements — contracts, invoices, correspondence — are kept for seven years to meet New Zealand tax and company record-keeping requirements, then deleted.

Client data held in any environment we control is governed by the engagement agreement and removed at its conclusion.

Your rights

You can ask us for a copy of the personal information we hold about you, ask us to correct anything inaccurate, and ask us to delete it where we have no legal obligation to keep it. You can also ask us to stop contacting you, and we will.

We do not charge for these requests, and we will not ask you why you are making one.

Changes to this policy

If we change how we handle personal information, we will update this page and the date at the top. Where a change is material and we hold your contact details because of a live engagement, we will tell you directly rather than relying on you to re-read this page.

Who else can see your information

These are the only third parties involved in running this website. Each is bound by its own privacy terms and may process information only on our instructions.

ServicePurposeInformationProcessed in
Cal.comBooking and calendar schedulingName, email address, any notes you add to the booking, meeting timeUnited States / EU
Plausible AnalyticsAggregate website statisticsNo personal information — no cookies, no cross-site tracking, no individual profilesEuropean Union
CloudflareWebsite hosting and deliveryStandard server request logs, including IP addressGlobal edge network
Google FontsTypeface deliveryIP address, as part of the standard request for the font filesGlobal

Asking us about your information

Under the Privacy Act 2020 you can ask what personal information we hold about you, ask us to correct it, and ask us to delete it. Email us and we will respond within 20 working days, which is the statutory maximum — in practice it is usually the same week.

Privacy enquiries: hello@datahorizon.nz

If you are not satisfied with how we have handled a privacy matter, you can complain to the Office of the Privacy Commissioner at privacy.org.nz. We would rather you raised it with us first, but that route is always open to you.