Skip to content
NZC AI

Data governance and security

Stated plainly, including what is not yet in place

Energy, carbon and ESG work involves commercially sensitive material. This page sets out how NZC Portal Ltd handles it, and is written to be accurate rather than reassuring.

Commitments

How we handle client data

Your data remains yours

Client documents and datasets are provided to us for the purpose of delivering the product. Ownership does not transfer to NZC Portal Ltd.

Purpose limitation

Client material is used to produce outputs for that client. We do not sell client data or share it with other clients.

Access control

Access to client environments is limited to personnel who need it to operate or support the product.

Human review before reliance

Outputs are drafts for review. A qualified person is responsible for what is relied upon, published or submitted.

Deletion on request

Clients can request deletion of material they have provided, subject to any legal retention requirement.

Third-party model providers

We use third-party AI model providers under their commercial terms. Where a provider is used, this is disclosed during onboarding.

Current position

Certification and formal assurance

NZC Portal Ltd does not currently hold ISO 27001, SOC 2 or Cyber Essentials certification, and we do not claim compliance with standards we have not been assessed against. Where a partner requires formal certification before deployment, we will say so at the first conversation rather than later.

Security controls, hosting arrangements, sub-processors and retention periods are documented per engagement and confirmed in writing as part of the commercial agreement. We are happy to complete a security questionnaire on that basis.

Our published privacy and cookie policies are being finalised. Until they are published, data-protection questions can be raised through the contact form and will be answered directly.

Responsible AI

Where our software stops

NZC Portal Ltd products provide software-assisted analysis and draft outputs. They do not replace professional, regulatory, legal, financial or technical advice, and they do not constitute an assessment, audit or assurance opinion.

Statutory assessment, certification and formal sign-off must be completed by an appropriately qualified or accredited person. Where clients need that, we point them to the relevant qualified organisation rather than implying our software covers it.