Privacy Policy
Last updated: 14 September 2026
This policy explains how personal information is handled in AVUT. It is written to meet the information privacy principles (IPPs) in the Privacy Act 2020.
1. Who we are
AVUT is operated by Alex Westphal, Christchurch, New Zealand. For anything in this policy, including access and correction requests and privacy complaints, contact support@avut.nz. Alex Westphal is also the privacy officer for the purposes of section 201 of the Privacy Act 2020.
2. Two different roles — please read this first
AVUT handles two kinds of personal information, and our responsibilities differ between them.
Your account. If you sign up for AVUT, we are the agency that collects and holds your account information, and this policy governs it.
Your organisation’s records. Most of the personal information in AVUT — personnel, team memberships, skill checks, issued equipment, notes — is entered by an organisation about its own people. We hold that information solely on that organisation’s behalf. Under section 11 of the Privacy Act 2020 it is treated as held by the organisation, not by us. The organisation is responsible for telling its people what it collects and why, and for answering their access and correction requests.
If you are a member of an organisation that uses AVUT and you want to see or correct what is recorded about you, contact that organisation. If you contact us instead, we will pass the request on and assist the organisation in responding, but we cannot change an organisation’s records on our own initiative.
3. What information we collect
Account information — your name, email address, and an optional profile image, collected when you register or are invited. We also hold authentication records and, for each active session, the IP address and browser user-agent it was created from, so you can stay signed in and so we can tell you which devices are signed in to your account.
Signing in with GitHub or Google — if you choose to sign in that way instead of with a password, that provider gives us your name, email address and profile image so we can create or match your account. We never receive your password, and we get no other access to that account. Using a social provider is optional; an email address and password works just as well.
Organisation records — information an organisation enters or uploads about its personnel. This is usually names, email addresses, team memberships, skill and assessment results, and equipment issued. We do not collect this from the individuals concerned; it comes from the organisation. This is permitted by IPP 2(2), which allows collection from another source where collecting directly would not be reasonably practicable for the purpose.
D4H data — if an organisation connects a D4H account, we retrieve personnel and team information from the D4H platform using an access token that organisation supplies. D4H integration is entirely optional and off unless an organisation turns it on.
Activity records — AVUT keeps an audit log of actions taken on records, recording who did what and when. This exists so organisations can see the history of their own data.
4. How we use your information
We use personal information to operate AVUT, to authenticate you, to send service emails such as invitations and password resets, to maintain the audit log, and to diagnose faults. We do not sell personal information, and we do not use it for advertising or profiling.
5. Who we share it with
We use the following providers to run the service. Each holds or processes information on our behalf, under section 11 of the Privacy Act 2020, and is not permitted to use it for its own purposes.
- Vercel — application hosting and file storage.
- Neon — the PostgreSQL database.
- Resend — sending service email.
- D4H — only where an organisation has connected its own D4H account. Information exchanged with D4H is governed by that organisation’s own arrangement with D4H.
Sign-in providers are different. If you sign in with GitHub or Google, that provider is not acting on our behalf. It passes us the account details described in section 3, and it learns that you have signed in to AVUT. What it does with that is governed by its own privacy policy, not by this one. This only happens if you choose to use it.
We may also disclose information where the law requires it, or where it is necessary to prevent or lessen a serious threat to someone’s life or health.
6. Where your data is held
AVUT’s application and database run on Amazon Web Services infrastructure in the Sydney region (ap-southeast-2), in Australia. Service email is sent through Resend, which may process message content outside Australia and New Zealand.
One qualification, because it is true of every site served this way: your connection reaches us through a globally distributed network, so it is received at whichever of that network’s locations is nearest you. The application code that reads and writes your information, and the database it talks to, run in Sydney.
Because these providers hold information on our behalf rather than for their own purposes, this is not a cross-border disclosure under IPP 12. We remain responsible under IPP 5 for the safeguards protecting it, and we have satisfied ourselves those safeguards are appropriate.
7. How we protect it
Access to organisation data requires an authenticated account with a role granting the relevant permission, enforced on the server rather than only in the interface. Data is encrypted in transit. D4H access tokens are encrypted at rest using AES-256-GCM with a unique initialisation vector and an authentication tag for each value. Actions on records are written to an audit log attributing them to the account that performed them.
No system is perfectly secure, and we do not claim otherwise. AVUT is actively developed software offered free of charge, and you should weigh that when deciding what to put in it.
8. Administrator access to your data
System administrators can sign in as another user in order to diagnose faults and provide support. While doing so they can see what that user sees, including that organisation’s records. Every such session is recorded in the audit log, identifying both the administrator and the account being accessed. We use this only where it is necessary to operate or support the service.
9. Health and other sensitive information
AVUT must not be used to record health information. This includes medical conditions, injuries, treatment, fitness-for-duty assessments, and any similar information about an identifiable person. It must also not be used for information about criminal history or any other category attracting heightened protection. AVUT is not built to handle information governed by the Health Information Privacy Code 2020, and free-text fields such as notes, tags, and custom properties are not an exception to this.
Organisations are responsible for ensuring their people do not enter such information. If you believe health information has been entered, contact us and we will work with the organisation to remove it.
10. How long we keep it
We do not keep personal information for longer than is required for the purposes for which it may lawfully be used.
Organisation records are deleted within 30 days after an organisation stops using AVUT, unless that organisation asks us to delete them sooner. During those 30 days the organisation may request a copy of its data. AVUT is pre-release and neither of these is automated yet — both are done by hand, on request, by the person named in section 1. Email that address and we will action it.
Account information is deleted when you ask us to close your account. There is no self-service account closure yet — email us at the address in section 1 and we will action it.
Audit log entries are retained after the account or record they describe has been deleted, and they still identify the person. An audit log that disappears along with its subject cannot serve its purpose, which is to let an organisation establish what happened to its records.
When an account is deleted, the entries recording what that account did remain, and so do the name and email address as they stood when each entry was written. The link to the account itself is removed, but we do not describe what is left as anonymous, because it is not: the person is still identifiable from it, that information is still personal information, and this policy still applies to it. Entries recording things done to the account, as opposed to by it, are deleted along with the account.
11. Your rights
Under IPP 6 and IPP 7 of the Privacy Act 2020 you have the right to ask for confirmation of whether we hold personal information about you, to access it, and to ask us to correct it if it is wrong.
If we decline to correct information, you may ask us to attach a statement of the correction you sought. We will take reasonable steps to ensure that statement accompanies the information whenever it is later used or disclosed.
We will respond to a request as soon as reasonably practicable, and no later than 20 working days after receiving it, as the Act requires. There is no charge.
For information held on an organisation’s behalf, direct your request to that organisation — see section 2. New Zealand law does not give a general right to erasure or a general right to object to processing, and we would rather say so plainly than imply rights you do not have. Deletion of organisation records is a matter for the organisation that entered them.
12. Privacy breaches
If a privacy breach occurs that it is reasonable to believe has caused, or is likely to cause, serious harm, we will notify the Office of the Privacy Commissioner and the affected people as soon as practicable, as Part 6 of the Privacy Act 2020 requires. Where the information affected is held on an organisation’s behalf, we will notify that organisation without undue delay so it can meet its own obligations.
13. Cookies
AVUT sets cookies that are strictly necessary to keep you signed in and to remember interface preferences such as your theme. We do not use advertising or third-party tracking cookies, which is why you are not asked to consent to any.
14. Complaints
If you think we have mishandled your personal information, please contact us first so we can try to put it right. If you are not satisfied, you may complain to the Office of the Privacy Commissioner at privacy.org.nz.
15. Changes to this policy
We may update this policy. If a change materially affects how we handle your personal information, we will tell account holders by email before it takes effect. The date at the top shows when this version was published.
See also our Terms of Service.