Virtus Group Limited

Privacy Policy — Operational Summary

How we collect, use, share, protect, and retain personal information in ICT Professional & Managed Services
Document control
OwnerPrivacy Lead (CEO)
Approved byCEO
Version / datev1.2 / 25 Sep 2025 — review by 01 Oct 2027
Applies toAll staff, contractors, and client work
DistributionPublic
Privacy Act 2020 OPC Guidance DSR Workflow Cross‑border & Processors

Document hierarchy (how this fits)

  1. Tier 1 — Privacy Policy (this summary): Operational commitments, contacts, and how we handle personal information.
  2. Tier 2 — Policies & Methods: Information Security Statement, Incident Response Plan (privacy breach section), DPIA approach, Records & Retention schedule.
  3. Tier 3 — Procedures & Templates: DSR intake form & log, Processor due‑diligence checklist, Cross‑border assessment, Breach log.
  4. Tier 4 — Registers & Evidence: Processing register (mini‑ROPA), training, audits, decisions and notifications.

Change control: This controlled summary links to detailed procedures/templates; superseded versions are archived.

1. Scope & definitions

This summary applies to personal information we handle when providing ICT Professional Services and Managed Services, our public websites, and work undertaken for clients.

Personal informationProcessingData Subject Request (DSR) Terms are used in plain English consistent with New Zealand law.

2. Principles & lawful basis (NZ)

3. Roles & contacts

Privacy Leadprivacy@virtusgroup.co.nz • After‑hours: 0800 847 887 (VIRTUS)
Alternatecompliance@virtusgroup.biz
Submit a DSREmail privacy@virtusgroup.co.nz with “DSR” in the subject

4. Information we process (mini‑ROPA)

Examples below are indicative; specific client SoWs may add or constrain processing.
PurposeCategoriesSystems / processorsLawful basisRetentionRecipients
Client engagement & delivery Contact details; project communications; work artefacts Microsoft 365 (Exchange, SharePoint/OneDrive); PSA/ticketing Contract 7 years (tax/audit); project artefacts per SoW Client; approved processors
Security monitoring Telemetry/logs tied to work assets (may be pseudonymous) M365 Defender; SIEM/XDR; firewall/flow logs Legitimate interests / contract 12–24 months (per system) N/A
Billing & compliance Identity/contact details; billing records Finance system; bank/payment providers Legal obligation / contract 7 years (tax) Auditors; tax authorities as required
Supplier & subcontractor management Contact details; due‑diligence records Vendor management register Legitimate interests While active + 7 years N/A

5. Collection & use

6. Storage, security & retention

7. Sharing, processors & cross‑border transfers

8. Data Subject Requests (DSR)

  1. Intake: submit via privacy@virtusgroup.co.nz; we log type (access/correction/deletion/objection/complaint).
  2. Verify identity: reasonable steps appropriate to the request.
  3. Locate data: search relevant systems/processors using the register above.
  4. Respond: as soon as practicable; if complex, send a holding note with next steps.
  5. Refusals: if declined on lawful grounds, explain why and how to complain to the OPC.
  6. Recordkeeping: request, decision, approver, closure date retained per policy.

9. Privacy incidents & breaches

10. Cookies & telemetry

Our public websites may use limited analytics and session cookies for performance and security. Where required, we provide notices and choices.

11. Review, audit & training

Related policies & templates

Legislative references (NZ)