How we handle your data, and why we will not overclaim it

2026-09-29 · Articles for website owners

There is a sentence that almost wrote itself this week: all your data stays in New Zealand. It is short, it sells, and plenty of providers say something like it. We are not going to use it, because it is not quite true, and the true version is better.

We have just finished a significant piece of work on how client data is stored across our infrastructure. Here is the honest account of where things sit.

Client data is held in New Zealand

The systems we run for clients, including websites, databases and the Aiva platform, are hosted in New Zealand. Client records and the data their customers give them are stored here, under New Zealand law. They are not shipped offshore for processing, and they are not pooled with another client's.

It is encrypted where it sits

Storage holding client data is now encrypted at the volume level, with the keys held separately from the data itself. If hardware left the building, the disks would be unreadable.

This is a recent improvement rather than something we have always had. We would rather say that plainly than imply it was always the case. It was worth doing properly, and it is done.

Now the part most providers skip

We keep off-site backups. Any provider that does not is one failure away from losing your business along with their own, so this is not optional.

Off-site means exactly that: a copy leaves the building. Our backup storage provider has no New Zealand region, so that copy sits outside the country.

So here is the honest shape of it. Live data is in New Zealand. Backup copies are not. What makes that acceptable is what happens before they leave.

The backups are encrypted so that we cannot read them either

Backups are encrypted before they go anywhere, using public-key encryption. The practical consequence is worth spelling out, because it is the strongest thing on this page:

The server that creates the backups cannot decrypt them. It holds only the key needed to lock them, not the one that opens them. Neither can the storage provider. Neither can anyone who compromises our infrastructure, including ransomware, which is exactly the scenario where most backup arrangements quietly fail.

The key that opens those backups is held offline, by a named person, in New Zealand. So a backup copy does sit on overseas storage, as ciphertext that only comes back to life here.

We think that is a stronger position than "all your data stays in New Zealand". It is also one we can put in front of a security reviewer without flinching.

Why we are being this specific

Because vague security claims are the ones that fall over.

At some point a client's customer, or a compliance team, asks where the data goes. When that happens, "it all stays onshore" is the kind of answer that turns into an awkward correction six months later. We would rather give you something accurate now that you can pass straight on.

What we do not do

  • We do not sell client data, or their customers' data.
  • We do not mix one client's data with another's.
  • We do not send marketing to your customers without a lawful basis, and an opt-out is honoured immediately.

What we are deliberately not publishing

You will notice this article does not name our encryption tooling, our hosting layout, or how keys are managed beyond the fact that they are held offline and off-site. That is on purpose. A detailed public description of a security design is mostly useful to someone probing it.

If your organisation runs a vendor security assessment, send it to us and we will answer it properly, in writing, to a named person. Get in touch and we will take it from there.

Tell us what you're trying to build

First consultation free. We'll give you an honest read on scope, a fixed price, and a realistic timeline - usually measured in weeks.

Get in touch