GOLDNTHREAD PRIVACY POLICY
1. WHO WE ARE AND WHAT THIS POLICY COVERS
Josiah Murray, sole trader, trading as GoldnThread (we, us, our), operates the GoldnThread compliance platform at goldnthread.com. GoldnThread is not a registered company. The agency responsible for your personal information under the Privacy Act 2020 is Josiah Murray.
This policy explains how we collect, use, store, disclose and protect personal information. It applies to:
- visitors to goldnthread.com
- people who enquire about, trial or subscribe to the platform
- individuals whose information is recorded in the platform by our customers, including building owners, facility managers, contractors, inspectors and accredited practitioners
1.1 The laws that apply to us
We comply with:
- the Privacy Act 2020 (New Zealand) and its 13 information privacy principles (IPPs), including IPP 3A, which took effect on 1 May 2026 and governs how individuals are notified when their information is collected indirectly
- the Privacy Act 1988 (Commonwealth of Australia) and the 13 Australian Privacy Principles (APPs), including the Notifiable Data Breaches scheme in Part IIIC
- the Unsolicited Electronic Messages Act 2007 (NZ) and the Spam Act 2003 (Cth) in relation to marketing
Because we operate in both countries, we apply the higher of the two standards where they differ. Where a New Zealand or Australian government agency or local authority is our customer, additional obligations may apply and are dealt with in that customer’s contract.
1.2 Two different roles
When our customers put information into the platform, we hold and process that information on their instructions. Under section 11 of the Privacy Act 2020 (NZ) we hold it as their agent, and we do not use or disclose it for our own purposes. Our customer decides what is collected and why, and our customer is the first point of contact for questions about that information. If you ask us and we are not the right agency to answer, we will tell you who is.
When you deal with us directly, for example by enquiring, subscribing, contacting support or visiting our website, we are the agency responsible for your information and this policy governs it in full.
2. WHAT INFORMATION WE COLLECT
2.1 Information you give us directly
| Category | Examples | Why we collect it |
|---|---|---|
| Identity and contact | Name, work email, phone, job title, employer, work address | To create and administer accounts, provide support, and communicate |
| Account and authentication | Username, hashed password, multi factor authentication settings | To secure your account |
| Billing | Billing contact, billing address, payment method reference, GST number | To charge for the service and issue tax invoices |
| Enquiry and support | The content of your messages, calls and support tickets | To respond to you and improve the service |
| Marketing preferences | Subscription and unsubscribe status | To respect your choices |
We do not collect payment card numbers. Card details are captured and stored by our payment processor.
2.2 Information recorded in the platform by our customers
Our customers record information about people involved in building compliance. This typically includes:
- names, employers, contact details and roles of contractors, inspectors, property managers and accredited practitioners
- licence, accreditation and registration numbers of qualified persons
- attendance records showing who attended a site and when
- electronic signatures, and the time and device context in which a signature was applied
- photographs taken during inspections, which may incidentally include images of people
- comments and notes about work performed
We collect this information indirectly, from our customer, not from the individual concerned.
2.3 Information we collect automatically
- IP address, browser and device type, operating system
- pages visited, features used, time and duration of use
- audit log entries recording actions taken in the platform
- error and diagnostic data
- cookies and similar technologies, described in section 9
2.4 Sensitive information
We do not seek and do not want sensitive information, as that term is defined in the Privacy Act 1988 (Cth), which includes health information, biometric information, and information about racial or ethnic origin, political opinions, religious beliefs, sexual orientation or criminal record. Please do not enter it into the platform. If sensitive information reaches us incidentally, for example in a free text field or a photograph, we will treat it with the higher protections that apply to it and will work with the relevant customer to remove it where appropriate.
2.5 Children
The platform is a business tool and is not directed at children. We do not knowingly collect information about anyone under 16.
3. HOW WE COLLECT INFORMATION, AND WHAT WE TELL YOU (IPP 3 AND IPP 3A)
3.1 Direct collection
Where we collect information directly from you, we tell you at the point of collection why we are collecting it, who will receive it, whether providing it is voluntary or required, and how you can access and correct it. This is required by IPP 3 of the Privacy Act 2020 (NZ) and APP 5 of the Privacy Act 1988 (Cth).
3.2 Indirect collection, and IPP 3A
From 1 May 2026, IPP 3A of the Privacy Act 2020 (NZ) requires an agency that collects personal information about an individual from a source other than that individual to take reasonable steps to make that individual aware of the collection.
Most information in the platform reaches us indirectly, because our customer enters it. To meet IPP 3A and APP 5:
(a) Our customers are contractually required to give the required notice to the individuals whose information they enter, and to have the authority to provide that information to us. This obligation is in clause 5.3 of our SaaS Agreement.
(b) We publish this policy at goldnthread.com/privacy as a public statement of what we do with indirectly collected information, and we reference it in platform invitations and notifications sent to inspectors, contractors and practitioners.
(c) We include a notice in the first email or invitation an individual receives from the platform, telling them who entered their details, why, and how to contact us.
(d) Where we rely on an exception under IPP 3A, for example because the individual has already been made aware, or because notification would be impossible or would involve disproportionate effort, or because the information is publicly available, we record the exception relied on and the reasons in our privacy register at the time.
3.3 Lawful and fair collection
We collect information by lawful and fair means, and only where it is necessary for a lawful purpose connected with our functions (IPP 1 and IPP 4, APP 3).
4. WHY WE USE PERSONAL INFORMATION
We use personal information to:
- provide, secure, maintain and support the platform
- create accounts and authenticate users
- generate compliance records, audit trails and electronic signature records
- send service notifications, including expiry reminders and system alerts
- process payments and issue invoices
- respond to enquiries, support requests, access requests and complaints
- detect, investigate and prevent fraud, misuse and security incidents
- comply with our legal obligations, and to establish, exercise or defend legal claims
- produce aggregated and de identified statistics to improve the platform and understand industry trends
- send marketing about our own similar products, where you have not opted out
We use information only for the purpose it was collected for, or a directly related purpose you would reasonably expect, or where an exception in IPP 10 and IPP 11 or APP 6 applies.
4.1 Automated decision making
We do not use automated decision making that produces legal effects for individuals or that significantly affects them. Compliance statuses, expiry alerts and dashboards in the platform are calculated from data our customers enter and from dates set by legislation. They are informational. A human always makes the underlying compliance decision.
5. WHO WE SHARE INFORMATION WITH
We do not sell personal information, and we do not disclose it for another organisation’s marketing.
We disclose personal information to:
| Recipient | Purpose |
|---|---|
| Our customer, being the organisation whose account holds the record | So they can manage their building compliance |
| Other authorised users of that customer’s account | As configured by that customer |
| Councils, regulators and authorities | Only where our customer directs us to, or where required by law |
| Service providers listed in section 6 | To operate the platform |
| Professional advisers, insurers and auditors | Where necessary and under confidentiality obligations |
| A purchaser of our business | On a confidential basis, and only where the purchaser agrees to be bound by this policy |
| Law enforcement, courts and regulators | Where required or authorised by law |
Where we disclose to a service provider, we require them by contract to protect the information, to use it only for the purpose we specify, and not to use or disclose it for their own purposes.
6. WHERE YOUR INFORMATION IS STORED, AND OFFSHORE DISCLOSURE
6.1 Data residency
All production customer data is stored in Australia.
| Component | Provider | Location |
|---|---|---|
| Application and database | Fly.io | Sydney, Australia |
| Backups | Amazon Web Services S3 | ap-southeast-2, Sydney, Australia |
| Photographs and scans uploaded from the field | Amazon Web Services S3 | ap-southeast-2, Sydney, Australia |
| Transactional email: invitations, password resets, notifications | Resend | United States |
Only your name and email address leave Australia, and only to send you email. Everything else in the table above stays in Sydney.
6.2 For New Zealand individuals: offshore storage and IPP 12
Storing information in Sydney means it leaves New Zealand.
Where we send personal information to an overseas provider that stores or processes it on our behalf as our agent, and that provider does not use or disclose it for its own purposes, that is not a “disclosure” for the purposes of the Privacy Act 2020, because under section 11 the information is still treated as held by us. We remain fully accountable for it under the Act.
Where information principle 12 does apply to a disclosure outside New Zealand, we will only make that disclosure where one of the IPP 12 grounds is met, and in practice we do this by requiring the recipient to be bound by contractual safeguards comparable to those in the Privacy Act 2020.
6.3 For Australian individuals: APP 8
Because the platform’s production data is stored in Australia, ordinary use of the platform does not involve disclosing your personal information to an overseas recipient.
Some of our service providers listed in Schedule 2 of our SaaS Agreement may process limited information outside Australia, for example support ticketing or product analytics. Where that occurs, we take reasonable steps under APP 8.1 to ensure the recipient does not breach the Australian Privacy Principles, including through contractual commitments.
6.4 Foreign legal process
Fly.io and Amazon Web Services are United States headquartered companies. Although your data is stored in Australia, their parent companies may be subject to United States legal process, including under the CLOUD Act. If we receive a binding order to disclose customer data, we will, unless we are legally prohibited, notify the affected customer before disclosing, disclose only the minimum required, and challenge overbroad or unlawful requests.
7. HOW WE PROTECT INFORMATION (IPP 5 AND APP 11)
We take reasonable steps to protect personal information from loss, misuse, unauthorised access, modification and disclosure. Our current measures include:
- encryption of all data in transit using TLS 1.2 or higher
- encryption of all data at rest, including databases and backups
- multi factor authentication enforced on all administrative and cloud infrastructure accounts
- role based access control, with production access limited to personnel with an operational need
- quarterly access reviews, and revocation within one business day of a person leaving or changing role
- confidentiality obligations in all employment and contractor agreements
- privacy and security awareness training on induction and at least annually
- automated encrypted backups
- logging and immutable audit trails of material actions
- a documented incident response and breach notification process
- code review before production deployment, and separation of production and non production environments
No system is perfectly secure. We do not guarantee absolute security, but we do commit to the measures above and to improving them.
We are not currently ISO 27001 certified or SOC 2 attested. If that changes, this policy will be updated.
Note for Jos. Do not let this list drift ahead of reality. Every line here is a representation. Under section 9 of the Fair Trading Act 1986 and section 18 of the Australian Consumer Law, overstating your security posture is misleading conduct, and it is one of the most commonly enforced privacy failures in both countries. If a control is not operating today, take it out and add it when it is.
8. RETENTION AND DELETION (IPP 9 AND APP 11.2)
We keep personal information only as long as we need it for the purpose we collected it, or as long as we are required to keep it by law.
| Information | Retention |
|---|---|
| Customer data in an active account | For the life of the account, as directed by the customer |
| Customer data after account termination | Exportable for 60 days, deleted from active systems within a further 30 days, deleted from backups within a further 90 days |
| Billing and tax records | 7 years, as required by the Tax Administration Act 1994 (NZ) and Australian tax law |
| Support and enquiry records | 2 years after the last interaction |
| Marketing contact records | Until you unsubscribe, then a suppression record only |
| Security and audit logs | 12 months, or longer where needed for an active investigation |
| Website analytics | 26 months |
Customers may have their own statutory obligations to retain building compliance records, including under the Building Act 2004 (NZ), the Public Records Act 2005 (NZ) for public offices and local authorities, and Australian state building and records legislation. Those obligations sit with the customer.
9. COOKIES AND ANALYTICS
We use:
- Strictly necessary cookies, for login, session management and security. These cannot be turned off.
- Functional cookies, to remember your preferences.
- Analytics cookies, to understand how the platform and website are used.
You can control cookies through your browser settings. Turning off strictly necessary cookies will prevent the platform from working.
We do not use third party advertising cookies and we do not permit third parties to track you across other websites through our platform.
10. YOUR RIGHTS
10.1 Access and correction
You have the right to ask for confirmation of whether we hold personal information about you, to access it, and to ask us to correct it if it is wrong. These rights come from IPP 6 and IPP 7 of the Privacy Act 2020 (NZ) and APP 12 and APP 13 of the Privacy Act 1988 (Cth).
How to make a request: email privacy@goldnthread.com with enough detail for us to find the information, and proof of identity.
Timeframes: in New Zealand we must decide on your request as soon as reasonably practicable and no later than 20 working days after we receive it. In Australia we will respond within 30 days.
Cost: we do not charge for access or correction requests from individuals in New Zealand except in the limited circumstances the Privacy Act 2020 allows. In Australia we do not charge to make a request, and any charge for giving access will not be excessive.
If we refuse: we will tell you why in writing and how to complain.
If information is in a customer’s account: we will usually redirect your request to that customer, because they are the agency responsible for it, and we will tell you who they are. We will assist them to respond.
If we correct information: where we have disclosed it to someone else, we will take reasonable steps to tell them about the correction. If we do not agree to correct it, you may ask us to attach a statement of the correction you sought, and we will do so.
10.2 Complaints and unsubscribing
You may ask us at any time to stop sending you marketing. Every marketing email has an unsubscribe link, and we action unsubscribes within 5 working days.
Complaints are dealt with in section 12.
11. DATA BREACH NOTIFICATION
We maintain a documented incident response and breach notification procedure. See our Data Privacy and Security Concerns Policy for the full internal process.
11.1 New Zealand: notifiable privacy breaches
Under sections 112 to 118 of the Privacy Act 2020 (NZ), if a privacy breach has caused, or is likely to cause, serious harm to an affected individual, we must:
- notify the Office of the Privacy Commissioner as soon as practicable after becoming aware of the breach. The Commissioner expects notification within 72 hours, even if we are still investigating.
- notify the affected individuals as soon as practicable, unless an exception in the Act applies, for example where notification would prejudice the security of an individual, or would reveal a trade secret. Where individual notification is not reasonably practicable we may give public notice instead.
In assessing serious harm we consider the factors in section 113, including the sensitivity of the information, the nature of the harm that may result, who obtained or may obtain the information, whether the information is protected by a security measure, and any relevant cultural considerations.
Failing to notify the Commissioner without reasonable excuse is an offence under section 118, with a fine of up to NZ$10,000.
11.2 Australia: the Notifiable Data Breaches scheme
Under Part IIIC of the Privacy Act 1988 (Cth):
- if we have reasonable grounds to suspect an eligible data breach, we must take all reasonable steps to complete an assessment within 30 calendar days of becoming aware, under section 26WH(2). We treat 30 days as an outer limit and aim to complete assessments far faster.
- an eligible data breach occurs where there is unauthorised access to, unauthorised disclosure of, or loss of personal information, that is likely to result in serious harm to one or more individuals, and we have not been able to prevent that harm through remedial action.
- if we have reasonable grounds to believe an eligible data breach has occurred, we must prepare a statement and give it to the Office of the Australian Information Commissioner as soon as practicable, under section 26WK. The statement must set out our identity and contact details, a description of the breach, the kinds of information concerned, and recommendations about the steps individuals should take.
- we must also notify affected individuals as soon as practicable, under section 26WL, by notifying everyone whose information was involved, or only those at risk of serious harm, or by publishing the statement on our website and taking reasonable steps to publicise it where individual notification is not practicable.
11.3 What we will tell you
Where we notify you of a breach affecting your information, we will tell you what happened, what information was involved, what we have done about it, what we recommend you do, and how to contact us and the relevant regulator.
11.4 If the breach involves a customer’s data
Where the breach affects personal information held in a customer’s account, that customer is the agency or entity responsible for deciding whether to notify and for making the notification. We will notify the customer within 48 hours of becoming aware and will give them the information and assistance they need to meet their obligations.
12. COMPLAINTS
12.1 Complain to us first
Email privacy@goldnthread.com with the details of your complaint. We will acknowledge within 5 working days and aim to give you a substantive response within 20 working days. If we need longer, we will tell you why and when to expect an answer.
12.2 New Zealand
If you are not satisfied, you can complain to:
Office of the Privacy Commissioner PO Box 10094, Wellington 6143, New Zealand Phone: 0800 803 909 Email: enquiries@privacy.org.nz Web: privacy.org.nz
12.3 Australia
If you are not satisfied, you can complain to:
Office of the Australian Information Commissioner GPO Box 5218, Sydney NSW 2001, Australia Phone: 1300 363 992 Web: oaic.gov.au
The OAIC generally requires you to complain to us first and to give us 30 days to respond.
13. CHANGES TO THIS POLICY
We may update this policy. The current version is always at goldnthread.com/privacy, with the effective date at the top. If we make a change that materially affects how we handle your personal information, we will notify account holders by email at least 30 days before it takes effect.
Scheduled reviews already identified:
- before 10 December 2026: review section 4.1 against the automated decision making transparency requirement commencing in the Privacy Act 1988 (Cth) on that date
- before 10 December 2026: assess whether the Children’s Online Privacy Code, required to be registered by that date, has any application to us
- annually: full review as part of the internal compliance audit procedure
14. CONTACT US
Privacy Officer Josiah Murray, Director Josiah Murray, trading as GoldnThread Email: privacy@goldnthread.com Post: 1/18 Killarney Street, Takapuna, Auckland 0622, New Zealand
We are required by section 201 of the Privacy Act 2020 (NZ) to have a privacy officer.
Reviewed by qualified legal counsel. Statutory references and commencement dates verified as at 23 August 2026 against the Privacy Act 2020 (NZ), the Privacy Amendment Act 2025 (NZ), the Privacy Act 1988 (Cth), OAIC guidance on the Notifiable Data Breaches scheme, and Office of the Privacy Commissioner guidance.