New Zealand Privacy Act 2020
ReadyPrivacy Policy with NZ Schedule, collection notices, breach process, and IPP 3A support for indirect collection. Built for customers operating under the Privacy Act 2020.
Security & trust
Comprehendly is a StepCare product. This page summarises our privacy and security posture for New Zealand and Australian customers — what is ready today, and what is actively underway.
NZ/AU privacy readiness, GDPR-ready controls, SOC 2–ready posture with attestation in progress, and an independent penetration test underway.
Privacy Policy with NZ Schedule, collection notices, breach process, and IPP 3A support for indirect collection. Built for customers operating under the Privacy Act 2020.
Privacy Policy with AU Schedule covering sensitive information, APP 8 overseas disclosure, APP 11 security, and the Notifiable Data Breaches scheme.
GDPR-ready controls: lawful-basis thinking, data minimisation, retention discipline, DPA, and EU database residency in Frankfurt. AI language processing may still occur in the United States, as disclosed in the sub-processor list.
SOC 2–ready controls are in place (access control, change management, monitoring, least-privilege production access). Formal attestation is in progress; we will publish the report when issued.
An independent penetration test is underway. Findings will be remediated and a summary made available to enterprise customers under NDA.
A customer DPA is published at /legal/dpa and accepted with the Terms. Enterprise countersignatures available on request.
Where your data lives, and what actually gets kept.
Primary databases are hosted on Supabase in Sydney (Australia) and/or Frankfurt (EU). AI language processing (OpenAI) and some hosting/CDN services still process data in the United States — disclosed in the Privacy Policy and sub-processor list.
Voice and phone audio is processed in real time and is not persisted as audio files. Twilio call recording is disabled. Answers are linked to transcript quotes for provenance — a record of what was said, not a recording archive.
Phone-based form completion and demo OTP run through Twilio. For population outreach campaigns, customers remain responsible for consent, identification, and unsubscribe / Do Not Call obligations; product controls for that workflow are described in our Forms roadmap.
The database is backed up automatically through Supabase, and every deployment runs through version-controlled CI/CD rather than manual server changes.
How we keep the number of people who can touch customer data small.
Third parties that process personal information for Comprehendly. Full detail, including regions, is in the published sub-processor list.
We keep a documented incident response process and an up-to-date register of every sub-processor above, so if something goes wrong anywhere in our stack, there is a clear path to find out, contain it, and tell you.
Found a security issue, or think you have? Report it to hello@stepcare.app — we read every message ourselves.
Production access is tightly restricted. Standing access to customer data is limited to the smallest practical set of accounts, with multi-factor authentication and audit logging on sensitive access.
Talk to us directly — no ticket queue, no account manager relay.