Terms of Service for Minimum Viable Protection Ltd
IMPORTANT: These terms are binding on you. It is important that you read them carefully. These terms govern your access to the Site and the Platform and use of the Services (as defined below). If you do not agree to be bound by these Terms you must not use any part of our Site, the Platform or the Services.
1. Definitions and interpretation
1.1 The following words and phrases have specific meanings wherever you see them used in these Terms:
Authorised User means an employee, contractor or agent of the Customer, or an Invited Auditor, who the Customer permits to access the Platform.
Confidential Information means any and all information of a confidential nature which is obtained by one party in relation to the other party in connection with these Terms and a Customer Agreement including without limitation any strategies, concepts, budgets, trading terms, plans, projections, methods, processes, systems, know how, trade secrets, computer software and programs, research data, client lists, intellectual property, business or financial information, employee, customer, financier or supplier information, or any dealings, transactions, affairs or any other information in any form. For the avoidance of doubt, Confidential Information includes all Minimum Viable Protection Intellectual Property and Customer Data.
Customer means the entity (e.g. a company or other organisation) which has entered into a Customer Agreement with Minimum Viable Protection.
Customer Agreement means an agreement under which an entity (e.g. a company or other organisation) engages Minimum Viable Protection to provide Services, including by creating an account on the Platform.
Customer Data includes information, data, and content (including personal information) owned, held, used, or created by the Customer and supplied by the Customer or its Authorised Users to Minimum Viable Protection, including answers, evidence and documents entered into the Platform.
Data Breach means a Security Incident that results in unauthorised or accidental access to, disclosure, alteration, loss or destruction of Customer Data, or an action that prevents the Customer from accessing Customer Data.
Fees means the fees set out in a Customer Agreement or otherwise agreed with a Customer.
Force Majeure Event means an event, or a series of related events, that is outside the reasonable control of the party affected (including failures of the internet or any public telecommunications network, hacker attacks, denial of service attacks, virus or other malicious software attacks or infections, power failures, industrial disputes affecting any third party, changes to the law, disasters, epidemics, pandemics, explosions, fires, floods, riots, terrorist attacks and wars).
GST means goods and services tax payable under the New Zealand Goods and Services Tax Act 1985 or as amended.
Information Privacy Principles means the information privacy principles in the Privacy Act 2020 (NZ).
Intellectual Property Rights means all intellectual property rights wherever in the world, whether registrable or unregistrable, registered or unregistered, including any application or right of application for such rights and these "intellectual property rights" include copyright and related rights, database rights, confidential information, trade secrets, know-how, business names, trade names, trademarks, service marks, passing off rights, unfair competition rights, patents, utility models and rights in designs.
Invited Auditor means an internal or external auditor or assessor whom the Customer invites to access all or part of its Customer Data on the Platform.
New Intellectual Property means all Intellectual Property Rights, including (but not limited to) copyright, in all concepts, designs, drawings, specifications, plans, studies, reports, models, software and documentation collated, prepared, or created in any medium by Minimum Viable Protection (or persons on behalf of Minimum Viable Protection) in carrying out the Services and provided to the Customer as deliverables, but not including Minimum Viable Protection Intellectual Property.
Platform means the online cyber security assessment platform at mvp.kiwi, including all subdomains, applications, reports and related tools we make available.
Security Incident means any actual or suspected event that compromises, or is likely to compromise, the confidentiality, integrity or availability of the Site, the Platform, the Services, or Customer Data.
Services means the Platform, and IT strategy, business strategy, digital transformation and cyber security advisory services and other services provided by Minimum Viable Protection from time to time.
Site means the websites at www.minimumviableprotection.com and mvp.kiwi.
Sub-processor means a third party engaged by Minimum Viable Protection to host, store or process Customer Data in delivering the Services.
Terms means these terms of service.
Minimum Viable Protection means Minimum Viable Protection Limited, a company registered in New Zealand under company number 8174182, and our, us and we used in these Terms refers to Minimum Viable Protection.
Minimum Viable Protection Intellectual Property means all Intellectual Property Rights owned by or licensed to Minimum Viable Protection which are used in the provision of the Services, including (but not limited to) the Site, the Platform, any generic material (e.g. library code, standard text, stock imagery and the like) that has been used in the past by Minimum Viable Protection or which may need to be used in future and which does not specifically identify the Customer, proprietary software, systems, technologies, strategies, manuals, know how, financial approaches, business processes, assessment frameworks, scoring models and methodologies.
You means the person who accepts these Terms in accordance with clause 2 below, and, if clause 2.2 applies, the Customer on whose behalf you are acting.
2. Application of these Terms
2.1 These Terms are binding and apply to your use of the Site and the Platform and any use of the Services by the Customer. By visiting the Site, creating an account on the Platform, or using the Services, you irrevocably agree to these Terms and our enforcement of the Customer Agreement and these Terms against you.
2.2 Where the Services are used or to be used by a Customer entity (e.g. a company or other organisation), you confirm that you are authorised to agree to these Terms on that Customer entity's behalf and you agree on behalf of that Customer entity that it is bound by these Terms. In that case, references to "you" in these Terms include both the person accepting these Terms and that Customer entity.
2.3 Please also read our Privacy Policy because it will apply to all the information provided to us.
2.4 In respect of all personal information about any identifiable individual which is contained in any Customer Data, you warrant that:
2.4.1 you have the right to collect and use that personal information for the purposes you are using it and to make it available to us and our Sub-processors so that we can together deliver the Services;
2.4.2 you have taken the steps required by the Privacy Act 2020 (NZ), including Information Privacy Principles 3 and 3A, and any other applicable privacy law, to make each individual aware that their personal information is collected and held by you and shared with us, the purpose, and their rights of access and correction, and you will refer those individuals to our Privacy Policy where appropriate; and
2.4.3 our and our Sub-processors' collection, storage, use and disclosure of that personal information to deliver the Services will not breach any privacy, data protection or other similar law in any jurisdiction.
2.5 If you do not agree to be bound by these Terms, you must immediately stop accessing the Site and the Platform and using the Services.
3. Changes
3.1 We may revise these Terms at any time by providing you with at least 30 days' prior notice of the change, whether via the Site, by email or by any other messaging facility we may use. Continued use after that notice constitutes agreement to the changed terms.
3.2 These Terms were last updated on 07/09/2026 [Seventh of September 2026].
4. Our Services
4.1 We will use reasonable efforts to provide the Services:
4.1.1 in accordance with these Terms and New Zealand law;
4.1.2 exercising reasonable care, skill and diligence; and
4.1.3 using suitably skilled, experienced and qualified personnel.
4.2 Our provision of the Services to you is non-exclusive. We can provide the Services to any other person.
4.3 We will maintain the technical and organisational security measures described in our published NZ Privacy Act and Data Protection Statement, including encryption of Customer Data in transit and at rest, logical separation between Customer environments, and role-based access control. We may change those measures from time to time, but will not reduce the overall level of protection they provide during the term of a Customer Agreement.
5. Maintenance and updates
5.1 We will maintain and update the Site and the Platform as and when we consider it appropriate to do so.
5.2 Where practicable, we will give you at least 7 days' notice of any scheduled maintenance that is likely to affect the availability of the Platform. We reserve the right to suspend access at any time, without notice, to all or any part of the Site, the Platform and/or the Services where we consider it necessary for security or other emergency reasons. Neither you nor the Customer has any claim against us in such circumstances.
6. Term and Termination
6.1 A Customer Agreement starts when you accept these Terms and continues until it is terminated under this clause 6 or as otherwise agreed in the Customer Agreement.
6.2 Either party may terminate a Customer Agreement for convenience by giving the other at least 30 days' written notice, unless a Customer Agreement specifies a fixed term or a different notice period.
6.3 Either party may terminate a Customer Agreement immediately by written notice if the other party:
6.3.1 materially breaches these Terms or the Customer Agreement and does not remedy the breach within 14 days of being asked to do so; or
6.3.2 becomes insolvent, enters liquidation or administration, or ceases to carry on business.
6.4 We may suspend your access to the Platform if any Fees remain unpaid 14 days after the due date, and may terminate the Customer Agreement if they remain unpaid 30 days after the due date.
6.5 On termination:
6.5.1 all Fees due up to the date of termination become payable;
6.5.2 for 30 days after the termination date we will maintain read-only access to the Platform for the Customer's nominated administrators so they can export Customer Data, after which all access ends;
6.5.3 we will not withhold or delay access to Customer Data under clause 6.4 or otherwise because of a payment dispute, and we will provide a full export of Customer Data on written request at any time during the 30 day window;
6.5.4 we will delete Customer Data in accordance with clause 9.5; and
6.5.5 each party will return or destroy the other's Confidential Information it no longer needs, subject to clause 15.
7. Fees and Payment
7.1 You agree to pay all applicable Fees.
7.2 Unless otherwise agreed in a Customer Agreement, Minimum Viable Protection will invoice you monthly for Services undertaken in the previous month.
7.3 All Fees exclude GST, which you must pay on taxable supplies under these Terms.
7.4 You agree to pay Minimum Viable Protection's invoice by the 20th of the month following the date of invoice in cleared funds without set-off or deduction.
8. Your Obligations
8.1 You must comply with all applicable laws, regulations and rules when using the Site, the Platform and the Services, and with respect to any Customer Data you provide to us.
8.2 You must provide to us, or procure for us, such information and documentation as is reasonably necessary to enable us to perform our obligations under these Terms.
8.3 You must not use the Services:
8.3.1 in any way that is unlawful, illegal, fraudulent, or harmful; or
8.3.2 in connection with any unlawful, illegal, fraudulent, or harmful purpose or activity.
8.4 You are responsible for everything done on the Platform through your account and by your Authorised Users, and for ensuring your Authorised Users comply with these Terms.
8.5 You and your Authorised Users must keep login credentials secure, must not share them, and must tell us immediately if you believe they have been compromised.
8.6 You must not attempt to access another Customer's data or account, interfere with the operation or security of the Platform, or copy, scrape or extract the Platform's assessment content, frameworks or scoring logic other than through the export features we provide.
8.7 You must ensure the information you and your Authorised Users enter into the Platform is accurate and current. Our outputs depend on it.
9. Customer Data
9.1 You own Customer Data. We hold and process Customer Data as your agent for the sole purpose of providing the Services, and do not use it for any other purpose except as set out in this clause 9 or as required by law.
9.2 We may use Customer Data in aggregated and de-identified form, which does not identify you or any individual, to improve the Platform, produce benchmarks and develop new services.
9.3 We use Sub-processors to host and support the Platform. Our current Sub-processors are Vercel and Supabase, each of which holds SOC 2 Type 2 and ISO/IEC 27001 certification, and Customer Data is stored in the Au region. We will give you at least 30 days' notice via the Site or by email before adding or replacing a Sub-processor that will process Customer Data, and will require every Sub-processor to protect Customer Data under a written agreement to a standard no less than that required by these Terms and the Privacy Act 2020 (NZ).
9.4 You may export your Customer Data from the Platform at any time during the term of a Customer Agreement using the features we provide.
9.5 Deletion after termination:
9.5.1 you may export Customer Data in a machine-readable format, comprising assessment responses and metadata, generated reports, and uploaded evidence artefacts in the format in which they were uploaded;
9.5.2 we will permanently delete all Customer Data from the Platform and instruct each Sub-processor to do the same within 60 days after the end of the 30 day export window in clause 6.5.2;
9.5.3 Customer Data held in routine encrypted backups will be deleted as those backups expire, and in any case within 90 days of the deletion date in clause 9.5.2. Until deleted it remains protected by clause 15 and is not accessed or restored except to recover the Platform;
9.5.4 we will give you written confirmation of deletion on request;
9.5.5 we may retain Customer Data beyond these periods only where a law, regulator or court requires it, or where it is needed for a live legal claim between us. We will tell you if that applies, what we are retaining and why, and delete it once the reason ends; and
9.5.6 aggregated and de-identified data created under clause 9.2, which does not identify you or any individual, is not Customer Data and is not deleted.
9.6 Some features of the Platform use artificial intelligence to help interpret answers, summarise evidence and draft recommendations. Where we do so, we will identify the feature as AI-assisted, we will not permit any third-party AI provider to use Customer Data to train its models, and you remain responsible for reviewing and acting on the output.
9.7 We do not sell, rent or trade Customer Data. We do not use Customer Data, evidence files or identifiable assessment responses to train any public artificial intelligence model, and we do not permit any Sub-processor or AI provider to do so. AI-assisted output is guidance to support your decisions. It is not legal, audit or professional advice.
10. Intellectual Property Rights and Software
10.1 Minimum Viable Protection Intellectual Property Rights:
10.1.1 we own, or have a license to, all rights, title and interest, including all Intellectual Property Rights, in and to Minimum Viable Protection Intellectual Property and any suggestions, enhancements, requests, recommendations, corrections or other feedback provided by Customers relating to Minimum Viable Protection Intellectual Property;
10.1.2 subject to these Terms, we grant you a worldwide, non-exclusive, non-transferable, non-sublicensable license to use and copy Minimum Viable Protection Intellectual Property to the extent reasonably required to enable you to make use of the Services;
10.1.3 we own all rights, title and interest, including all Intellectual Property Rights in New Intellectual Property;
10.1.4 subject to you having paid all amounts due and payable to us in accordance with a Customer Agreement, we grant you a non-revocable, royalty free, non-exclusive licence to use the New Intellectual Property to the extent reasonably required to enable you to make use of the Services;
10.1.5 we retain all right, title and interest in any source or HTML code, mark-up files and Minimum Viable Protection proprietary software used by Minimum Viable Protection or its contractors and agents in providing the Services, the Platform and the Site; and
10.1.6 your rights in relation to any licence in respect of Minimum Viable Protection Intellectual Property and New Intellectual Property are conditional upon, on each occasion, you having paid all amounts due and payable to Minimum Viable Protection in accordance with a Customer Agreement concerning the Services which produced the New Intellectual Property or made use of Minimum Viable Protection Intellectual Property.
10.2 Your Intellectual Property Rights:
10.2.1 you own all right, title and interest, including Intellectual Property Rights, in and to Customer Data; and
10.2.2 you grant us a royalty free, worldwide, non-exclusive licence to use Customer Data during the term of a Customer Agreement and the retention period in clause 9.5, to the extent reasonably necessary to enable Minimum Viable Protection to provide the Services and exercise its rights under clause 9.
10.3 Nothing in these Terms will operate to assign or transfer any Intellectual Property Rights from us to you or the Customer, or from you or the Customer to us.
10.4 If we reasonably determine, or any third party alleges, that the use of the Services by you in accordance with these Terms, including, but not limited to your use of the New Intellectual Property, infringes any person's Intellectual Property Rights, we may at our own cost and expense:
10.4.1 modify or revoke the Services and/or the New Intellectual Property in such a way that they no longer infringe the relevant Intellectual Property Rights; or
10.4.2 procure for you the right to use the Services and/or New Intellectual Property in accordance with these Terms.
10.5 Where we provide any software to you to enable you to use the Services:
10.5.1 we retain all Intellectual Property Rights in that software (including both the human readable and machine-readable parts);
10.5.2 you have no right to access the source or object code of the software other than in running the software to use the Services and you agree not to reverse engineer, reproduce, duplicate, copy, sell, assign, sublicence, resell or exploit any portion of the software other than as strictly necessary for you (and not anyone else) to use the Services;
10.5.3 you will only use the software for the purposes it was provided;
10.5.4 all proprietary notices on or in the software are to be retained and not altered or removed; and
10.5.5 you will keep your copy of the software secure and not let anyone else access or use it and you will not use the software to provide services that are the same or equivalent to the Services, to anyone else.
11. Viruses
11.1 While we maintain the security measures described in clause 4.3, we do not guarantee that the Site or the Platform will be free from bugs, defects or viruses, or that they will be uninterrupted. You are responsible for configuring your own information technology and computer programmes to access the Site and the Platform, and should use your own virus protection software.
11.2 We will not be liable for any loss or damage caused by a virus, distributed denial-of-service attack, or other technologically harmful material that may infect your computer equipment, computer programs, data, or other proprietary material due to your use of the Site or the Platform or to your downloading of any material from the Site or the Platform.
11.3 You must not misuse the Site or the Platform by knowingly introducing viruses, trojans, worms, logic bombs or other material which is malicious or technologically harmful. You must not attempt to gain unauthorised access to the Site, the Platform, the server on which they are stored, or any server, computer or database connected to them. You must not attack the Site or the Platform via a denial-of-service attack or a distributed denial-of-service attack.
12. Warranties and exclusions
12.1 We warrant to you that:
12.1.1 we have the legal right and authority to enter into and to perform our obligations under these Terms;
12.1.2 we will comply with all applicable legal requirements applying to the exercise of our rights and the fulfilment of our obligations under these Terms;
12.1.3 the use of the Services in accordance with these Terms will not breach any legal requirements applicable under New Zealand law; and
12.1.4 we have or have access to all necessary know-how, expertise and experience to perform our obligations under these Terms.
12.2 You acknowledge that:
12.2.1 complex software is never wholly free from defects, errors and bugs, and Minimum Viable Protection gives no warranty or representation that the Site or the Platform will be wholly free from such defects, errors and bugs;
12.2.2 we do not warrant or represent that the Site or the Platform will be compatible with any device not approved by us; and
12.2.3 we do not give any representation, warranty or other assurance whatsoever as to the fitness for purpose, functionality, operation, continuation or use of any device that you may use to access the Site or the Platform.
12.3 You acknowledge that assessment results, scores, reports and recommendations produced through the Platform or the Services:
12.3.1 are based on the information you and your Authorised Users supply;
12.3.2 are guidance to help you improve your security posture and are not an audit, certification, or assurance of compliance with any law or standard; and
12.3.3 do not guarantee that you will not suffer a security incident, breach or loss.
12.4 All of the parties' warranties and representations in respect of the subject matter of these Terms are expressly set out in these Terms. No further terms are implied.
12.5 You agree that you are using the Services for the purpose of a business and that, to the extent permitted by law, the Consumer Guarantees Act 1993 (NZ) and any other similar consumer protection legislation in any jurisdiction does not apply to the Services, the Site or the Platform.
13. Indemnities
13.1 We will indemnify and will keep indemnified you against any and all liabilities, damages, losses, costs and expenses (including legal expenses and amounts reasonably paid in settlement of legal claims) suffered or incurred by you and arising out of any claim brought against the Customer by a third party to the extent that the claim alleges that your use of the Services infringes the third party's Intellectual Property Rights (a Minimum Viable Protection Indemnity Event).
13.2 You must:
13.2.1 upon becoming aware of an actual or potential Minimum Viable Protection Indemnity Event, notify us;
13.2.2 provide to us all such assistance as may be reasonably requested by us in relation to the Minimum Viable Protection Indemnity Event;
13.2.3 allow us the exclusive conduct of all disputes, proceedings, negotiations and settlements with third parties relating to the Minimum Viable Protection Indemnity Event; and
13.2.4 not admit liability to any third party in connection with the Minimum Viable Protection Indemnity Event or settle any disputes or proceedings involving a third party and relating to the Minimum Viable Protection Indemnity Event without our prior written consent,
and our obligation to indemnify you under clause 13.1 will not apply unless you comply with the requirements of this clause 13.2.
13.3 We will not be liable to you under a Minimum Viable Protection Indemnity Event to the extent that the third party's claim arises from the Customer's breach of the Customer Agreement or these Terms, use of the Services in a manner not reasonably contemplated by the Customer Agreement or these Terms, or any Customer Data or third party's data.
13.4 You agree to indemnify, and hold us and our respective officers, directors, employees and agents, harmless from and against any claims, liabilities, damages, losses, and expenses, including, without limitation, any tax, legal and/or accounting fees, arising out of or in connection with your access to or use of the Site, the Platform or the Services, any breach of the warranties in clause 2.4, or your violation of these Terms.
14. Liability and insurance
14.1 The limitations and exclusions of liability set out in this clause 14 and elsewhere in a Customer Agreement and these Terms govern all liabilities arising under a Customer Agreement and these Terms or relating to the subject matter of a Customer Agreement and these Terms, including liabilities arising in contract, in tort (including negligence) and for breach of statutory duty, except to the extent expressly provided otherwise in a Customer Agreement and these Terms.
14.2 Neither party is liable to the other under or in connection with these Terms or a Customer Agreement for:
14.2.1 loss of profit, opportunity, revenue, savings, business, use, data (including Customer Data), or goodwill;
14.2.2 consequential, indirect, incidental, or special damage or loss of any kind, including damage to the Customer's systems; or
14.2.3 any losses arising out of a Force Majeure Event,
except that clause 14.2.1 does not exclude our liability for loss of Customer Data caused by our breach of clause 15 (Confidentiality) or clause 16 (Security Incidents and Data Breach Notification), which remains subject to clause 14.6.
14.3 This clause 14 does not apply to limit your liability to pay the Fees for the Services.
14.4 Neither party will be responsible, liable, or held to be in breach of these Terms or a Customer Agreement for any failure to perform its obligations under these Terms or a Customer Agreement or otherwise, to the extent that the failure is caused by the other party failing to comply with its obligations under these Terms or a Customer Agreement, or by the negligence or misconduct of the other party or its personnel.
14.5 Each party must take reasonable steps to mitigate any loss or damage, cost or expense it may suffer or incur arising out of anything done or not done by the other party under or in connection with these Terms or a Customer Agreement.
14.6 To the extent permitted by law, our aggregate liability to you under a Customer Agreement and these Terms will not exceed the total amount received by us under such Customer Agreement in the 12-month period preceding the commencement of the event giving rise to the liability.
14.7 We will maintain and keep in force during the term of a Customer Agreement insurance of such types and in such amounts as may be notified to you from time to time. Certificates of insurance will be provided to the Customer upon request.
15. Confidentiality
15.1 In this clause 15, Disclosing Party means the party disclosing Confidential Information and Receiving Party means the party receiving the Confidential Information.
15.2 The Receiving Party must:
15.2.1 keep the Confidential Information strictly confidential;
15.2.2 not disclose the Confidential Information to any person without the Disclosing Party's prior written consent, and then only under conditions of confidentiality no less onerous than those contained in a Customer Agreement and these Terms;
15.2.3 use the same degree of care to protect the confidentiality of the Confidential Information as the Receiving Party uses to protect the Receiving Party's own confidential information of a similar nature, being at least a reasonable degree of care;
15.2.4 act in good faith at all times in relation to the Confidential Information; and
15.2.5 not use any of the Confidential Information for any purpose other than providing or receiving the Services.
15.3 Notwithstanding clause 15.2, the Receiving Party may disclose the Confidential Information to its officers, employees, professional advisers, insurers, agents, Sub-processors and contractors who have a need to access the Confidential Information for the performance of their work with respect to the permitted purpose and who are bound by a written agreement or professional obligation to protect the confidentiality of the Confidential Information.
15.4 This clause 15 imposes no obligations upon a Receiving Party with respect to Confidential Information that:
15.4.1 is known to the Receiving Party before disclosure under the Customer Agreement and these Terms and is not subject to any other obligation of confidentiality;
15.4.2 is or becomes publicly known through no act or default of the Receiving Party; or
15.4.3 is obtained by the Receiving Party from a third party in circumstances where the Receiving Party has no reason to believe that there has been a breach of an obligation of confidentiality.
15.5 The restrictions in this clause 15 do not apply to the extent that any Confidential Information is required to be disclosed by any law or regulation, by any judicial or governmental order or request, or pursuant to disclosure requirements relating to the listing of the securities of a party on any recognised stock exchange.
15.6 The provisions of this clause 15 will continue in force indefinitely following the termination of a Customer Agreement.
16. Security Incidents and Data Breach Notification
16.1 What we will do. If we become aware of a Security Incident affecting Customer Data, we will:
16.1.1 take immediate steps to contain the incident and limit any harm;
16.1.2 assess what happened, what Customer Data is affected, and the likely impact on the Customer and any affected individuals; and
16.1.3 notify you as set out in this clause 16.
16.2 When we will tell you. We will notify you without undue delay, and in any case within 72 hours of confirming a Data Breach affecting your Customer Data. If we have not completed our assessment within that time, we will tell you what we know and follow up as further information becomes available.
16.3 What we will tell you. Our notification will be in writing, sent to the email address you have provided to us, and will include, as far as we know at the time:
16.3.1 what happened and when;
16.3.2 the Customer Data and individuals affected;
16.3.3 the steps we have taken or intend to take in response;
16.3.4 what we recommend you do; and
16.3.5 a contact for further information.
16.4 Regulators and affected individuals. Responsibility for notifying regulators and affected individuals depends on whose personal information is involved.
16.4.1 Where we hold personal information as the agency responsible for it, including account and contact details of users who register with us directly, we will assess the Data Breach and, where it has caused or is likely to cause serious harm, notify the Office of the Privacy Commissioner and the affected individuals as soon as practicable and in any case within 72 hours of becoming aware of it.
16.4.2 Where we hold personal information contained in Customer Data as your agent under section 11 of the Privacy Act 2020 (NZ), you are the responsible agency. You are responsible for deciding whether the Data Breach is notifiable and for notifying the Office of the Privacy Commissioner, the Office of the Australian Information Commissioner where you are an Australian Customer, any other regulator, and affected individuals. We will give you the information and reasonable assistance you need to meet those obligations within the required timeframes.
16.4.3 Neither party will make a notification that names the other without first telling the other, unless the law or a regulator requires it.
16.5 Your obligations. You must:
16.5.1 tell us without undue delay, and in any case within 24 hours, if you become aware of a Security Incident involving the Site, the Platform, the Services, or your access credentials, by emailing [security email address];
16.5.2 keep your login credentials secure and tell us immediately if you believe they have been compromised; and
16.5.3 cooperate with us in good faith to investigate, contain and resolve any Security Incident.
16.6 Working together. Both parties will cooperate in responding to a Security Incident, including sharing relevant information and preserving evidence. Neither party will publicly attribute a Security Incident to the other without first consulting the other, except where required by law or a regulator.
16.7 After the incident. Once a Data Breach affecting your Customer Data has been resolved, we will give you a written summary on request covering the cause, the impact, and the steps we have taken to prevent a recurrence.
16.8 No admission. A notification under this clause 16 is not an admission of fault or liability. Nothing in this clause 16 changes the limits and exclusions of liability in clause 14.
17. Force Majeure Event
17.1 If a Force Majeure Event gives rise to a failure or delay in either party performing any obligation under these Terms (other than any obligation to make a payment), that obligation will be suspended for the duration of the Force Majeure Event.
17.2 A party that becomes aware of a Force Majeure Event which gives rise to, or which is likely to give rise to, any failure or delay in that party performing any obligation under these Terms, must:
17.2.1 promptly notify the other; and
17.2.2 inform the other of the period for which it is estimated that such failure or delay will continue.
17.3 A party whose performance of its obligations under these Terms is affected by a Force Majeure Event must take reasonable steps to mitigate the effects of the Force Majeure Event.
18. Disputes
18.1 Any and all disputes arising out of these Terms, a Customer Agreement, or any termination, will be determined by binding arbitration in English under the Arbitration Act 1996 in Auckland, New Zealand, by one arbitrator who will be a lawyer knowledgeable in relevant technology matters appointed by the President for the time being of the Arbitrators and Mediators Institute of New Zealand Incorporated (AMINZ) on a request by either you or us.
18.2 The Arbitrator shall permit the parties and any witnesses to appear by videoconference that we will organise and pay for if reasonably necessary. The costs of arbitration shall be shared equally unless the arbitrator otherwise specifies (e.g. where the arbitrator determines that the dispute is frivolous or vexatious).
19. General
19.1 Assignment: We may assign or transfer our rights under these Terms or a Customer Agreement, at our sole discretion, without restriction. You may not assign or transfer your rights under these Terms or a Customer Agreement without our prior written consent, which may be withheld in our absolute discretion.
19.2 Notices: Any notices or other communications permitted or required under these Terms, including those regarding modifications to these Terms, will be in writing and given by us:
19.2.1 via email (in each case to the address that you provide); or
19.2.2 via the Site or the Platform.
For notices made by email, the date of receipt will be deemed the date on which such notice is sent.
19.3 No waiver: No failure or delay by us to exercise any right or remedy provided under a Customer Agreement or these Terms or by law will constitute a waiver of that or any other right or remedy, nor will it prevent or restrict the further exercise of that or any other right or remedy. No single or partial exercise of such right or remedy by us will prevent or restrict the further exercise of that or any other right or remedy.
19.4 Survival: The obligations of the parties under clauses 6.5 (consequences of termination), 9 (Customer Data), 10 (Intellectual Property Rights and Software), 13 (Indemnities), 14 (Liability and insurance), 15 (Confidentiality), 16 (Security Incidents and Data Breach Notification), 18 (Disputes) and this clause 19 shall survive the expiry or the termination of a Customer Agreement.
19.5 Severability: If any provision or part-provision of these Terms is or becomes void, illegal or unenforceable, it will be deemed modified to the minimum extent necessary to make it valid, legal and enforceable. If such modification is not possible, the relevant provision or part-provision will be severable and deemed to be deleted, and will not affect the validity, legality, or enforceability of the remaining provisions.
19.6 Governing Law: These Terms will be governed by and construed in accordance with New Zealand law. You agree to submit to the exclusive jurisdiction of the courts of New Zealand with respect to any claim or matter arising out of or in connection with these Terms or their termination.
If you have any questions or concerns in relation to the these Terms, please contact us.

