Legal

Privacy Policy

Last updated: 31 August 2026

Szord Accounting Limited(“Szord”, “we”, “us”, “our”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, disclose and protect personal information in accordance with the Privacy Act 2020(New Zealand) and its Information Privacy Principles (“IPPs”).

By using Szord Accounting (“the Service”), you agree to the practices described in this policy. If you do not agree, please discontinue use of the Service.

1. Who we are

Szord Accounting Limited is a New Zealand company that provides cloud-based accounting software to businesses. Our registered address is New Zealand.

We are an “agency” for the purposes of the Privacy Act 2020 and are responsible for personal information we hold.

2. Personal information we collect

We collect personal information that is necessary to provide the Service. This includes:

Account and identity information

  • Name and email address (used to create and manage your account)
  • Password (stored in hashed form — we never store plaintext passwords)
  • Profile information you choose to provide

Organisation and business information

  • Business name, trading name and address
  • IRD number and GST number
  • New Zealand Business Number (NZBN)
  • Contact phone number and email address
  • Business logo

Financial and transaction data

  • Invoices, bills, quotes and purchase orders you create in the Service
  • Bank transaction data you import (from OFX, QIF or CSV files)
  • Payment records, journal entries and accounting ledger data
  • GST return data and tax period information
  • Customer and supplier contact details you enter

Technical and usage information

  • IP address and browser type
  • Device information
  • Pages visited within the Service and time of access
  • Session tokens used to keep you logged in
  • Error logs and diagnostic information

Communications

  • Messages and attachments you send through the Support Ticket system
  • Email correspondence with our team
  • Feedback you provide on Help Centre articles

3. How we collect personal information

We collect personal information in the following ways:

  • Directly from you when you register for an account, set up your organisation, or contact us
  • From your use of the Service (e.g. transactions you enter, bank statements you import)
  • Automatically through cookies and similar technologies when you use the Service (see Section 9)
  • From third-party services you connect (e.g. Shopify, Vend/Lightspeed) — only the data necessary to operate the integration
  • When you submit a support ticket or contact our team

Where practicable, we collect personal information directly from you (IPP 2). We will always tell you why we are collecting information and how it will be used at the time of collection (IPP 3).

4. Why we collect personal information (IPP 1)

We collect and hold personal information only for lawful purposes connected to our functions and activities. Specifically:

To provide the Service

  • Creating and managing your user account and organisation
  • Processing the accounting transactions and data you enter
  • Generating financial reports and GST return calculations
  • Providing bank reconciliation features

To communicate with you

  • Responding to support tickets and enquiries
  • Sending service-related notifications (e.g. account alerts, product updates)
  • Sending billing and subscription information

To improve the Service

  • Analysing usage patterns to improve features and performance
  • Diagnosing and fixing technical issues

Legal and compliance

  • Meeting our legal obligations under New Zealand law
  • Detecting and preventing fraud, security breaches or misuse of the Service

We do not use your personal information for purposes other than those stated above without your consent, or unless otherwise permitted by law (IPP 10).

5. Storage and security (IPP 5)

We take the security of your personal information seriously and implement appropriate technical and organisational safeguards, including:

  • Encryption of data in transit using TLS (HTTPS)
  • Encryption of data at rest on our database servers
  • Passwords stored using one-way cryptographic hashing
  • Access controls limiting staff access to personal information on a need-to-know basis
  • Regular security monitoring and vulnerability assessments
  • Automated database backups with point-in-time recovery

Our database infrastructure is hosted on Neon (a managed PostgreSQL provider) with servers located in Australia (AWS ap-southeast-2). See Section 8 for information about overseas transfers.

Despite our security measures, no system is completely secure. If you believe your account has been compromised, please contact us immediately at hello@szord.co.nz.

6. Retention of personal information (IPP 9)

We retain personal information only for as long as necessary for the purposes for which it was collected, or as required by law.

  • Account data is retained for the duration of your subscription and for 7 years after account closure, to comply with New Zealand tax and financial record-keeping obligations
  • Financial transaction data (invoices, bills, journal entries, GST returns) is retained for a minimum of 7 years as required by the Tax Administration Act 1994
  • Support ticket communications are retained for 3 years
  • Server logs are retained for 90 days
  • If you request deletion of your account, we will delete or anonymise personal data that is not subject to a legal retention obligation within 30 days

7. Disclosure of personal information (IPP 11)

We do not sell, rent or trade your personal information to third parties. We may disclose personal information in the following circumstances:

Service providers (sub-processors)

We share personal information with trusted third-party service providers who assist us in operating the Service. These providers are bound by confidentiality obligations and may only use your information to perform services on our behalf:

  • Neon — database hosting (Australia)
  • Vercel — application hosting and deployment (global CDN)
  • Email service providers — for transactional emails
  • Payment processors — for subscription billing

Integrations you enable

If you connect a third-party integration (e.g. Shopify, Vend), data will be shared with that provider to the extent necessary to operate the integration. Those providers have their own privacy policies which we encourage you to review.

Your accountant or advisors

If you invite your accountant or other users to your organisation, they will have access to your financial data within the Service according to the role you assign them. You control who you invite.

Legal requirements

We may disclose personal information if required to do so by law, court order, or to protect the rights, property or safety of Szord, our customers, or the public.

Business transfers

In the event of a merger, acquisition or sale of assets, your personal information may be transferred to the acquiring entity, subject to the same privacy protections.

8. Overseas transfers of personal information (IPP 13)

Some personal information is transferred to, and stored in, countries outside New Zealand:

  • Database servers in Australia (AWS ap-southeast-2, operated by Neon)
  • Application hosting infrastructure on Vercel (global CDN nodes)

Before transferring personal information overseas, we take reasonable steps to ensure that the recipient is subject to privacy protections comparable to those under the Privacy Act 2020, or that one of the permitted grounds in IPP 13 applies.

Australia has privacy legislation (the Privacy Act 1988 (Cth)) that provides comparable protections to New Zealand law.

9. Cookies and tracking technologies

We use cookies and similar technologies to operate and improve the Service:

  • Session cookies — to keep you logged in during your session (essential)
  • Authentication tokens — to remember your login across sessions if you select 'Remember me' (essential)
  • Analytics cookies — to understand how the Service is used and improve it (analytics)

Essential cookies are necessary for the Service to function and cannot be disabled. You may disable analytics cookies through your browser settings. Note that disabling cookies may affect the functionality of the Service.

We do not use cookies for advertising or cross-site tracking.

10. Your rights — access and correction (IPPs 6 & 7)

Under the Privacy Act 2020, you have the right to:

Access your personal information (IPP 6)

You may request a copy of the personal information we hold about you. We will respond within 20 working days. We may charge a reasonable fee for large or complex requests.

Correct your personal information (IPP 7)

If you believe personal information we hold about you is incorrect, incomplete or misleading, you may request that we correct it. We will correct the information if we agree it is inaccurate, or attach a statement of correction if we do not agree.

Request deletion

You may request deletion of your account and associated personal information. We will comply unless we are required to retain it by law (e.g. tax record-keeping obligations).

How to exercise your rights

To make an access, correction or deletion request, contact our Privacy Officer:

Privacy Officer

Szord Accounting Limited

New Zealand

Email: privacy@szord.co.nz

We may require you to verify your identity before processing your request.

11. Privacy breach notification

Under Part 6 of the Privacy Act 2020, we are required to notify the Office of the Privacy Commissioner and affected individuals if a privacy breach occurs that is likely to cause serious harm.

We maintain a privacy breach response procedure. If we become aware of a notifiable breach, we will:

  • Notify the Office of the Privacy Commissioner as soon as reasonably practicable
  • Notify affected individuals without undue delay
  • Take steps to contain and remediate the breach

If you become aware of or suspect a privacy breach, please notify us immediately at privacy@szord.co.nz.

12. Children's privacy

The Service is not directed at children under the age of 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information without parental consent, please contact us and we will delete it promptly.

13. How to make a complaint

If you have a concern about how we have handled your personal information, we encourage you to contact our Privacy Officer in the first instance:

Privacy Officer, Szord Accounting Limited

Email: privacy@szord.co.nz

We will acknowledge your complaint within 5 working days and endeavour to resolve it within 20 working days.

If you are not satisfied with our response, you may complain to the Office of the Privacy Commissioner:

Office of the Privacy Commissioner

PO Box 10094, The Terrace, Wellington 6143

Phone: 0800 803 909

Website: www.privacy.org.nz

14. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will update the “Last updated” date at the top of this page. If changes are material, we will notify you by email or by a prominent notice within the Service.

Your continued use of the Service after any changes constitutes your acceptance of the updated policy.

15. Contact us

For any privacy-related questions, requests or concerns, please contact:

Privacy Officer

Szord Accounting Limited

New Zealand

Email: privacy@szord.co.nz

General enquiries: hello@szord.co.nz