SPRINTIFY
SPRINTIFY PRIVACY POLICY
How Sprintify collects, uses, protects and shares personal information
VERSION 1.0 | 20 JULY 2026
This policy is designed for publication on the Sprintify website and within Sprintify Momentum. Complete all bracketed company, privacy officer, hosting and subprocessor details before publication.
1. Purpose and scope
1.1 Sprintify Limited (Sprintify, we, us or our) respects privacy and is committed to handling personal information transparently, securely and in accordance with applicable privacy law.
1.2 This Privacy Policy applies to personal information we collect through our websites, Sprintify Momentum, Sprintify SEOS, AI features, PRO University, events, communications, sales, support, implementation and other services.
1.3 For organisational customers, Sprintify may process personal information on behalf of the customer controlling the relevant tenant. In that context, the customer is generally responsible for determining why and how the information is used, and its own privacy notice also applies.
1.4 This policy does not apply to third-party services that have their own privacy policies.
2. Who we are and how to contact us
2.1 Sprintify Limited is a New Zealand company. Our registered office is [INSERT].
2.2 Our Privacy Officer can be contacted at [INSERT PRIVACY EMAIL] or [INSERT POSTAL ADDRESS].
2.3 Questions, access or correction requests and privacy complaints may be sent to the Privacy Officer.
3. Information we collect
3.1 Depending on how you interact with us, we may collect:
identity and contact information, such as name, role, organisation, email address, phone number and professional profile;
account and authentication information, including user ID, role, tenant, permissions and login records;
customer and billing information, including subscription, transaction and invoice details;
platform content, including goals, strategies, key results, actions, issues, risks, comments, recognition, learning records, survey responses, files and reports;
communications with us, including support requests, meeting notes, feedback, recordings where notified and event registrations;
technical and usage information, including IP address, device, browser, timestamps, logs, feature interactions, diagnostic data and cookies;
AI interaction data, including prompts, context supplied to AI features, AI outputs, ratings and feedback;
professional qualification information, including enrolment, assessments, certification status, conduct matters and licence history;
recruitment, contractor and supplier information; and
any other information you choose to provide or that we are lawfully authorised to collect.
4. How we collect information
4.1 We collect information directly from you, from your organisation or its administrators, through your use of the Services, from connected Third-Party Services, from public professional sources and from service providers assisting us.
4.2 Where an organisation provides information about its personnel, team members or stakeholders, that organisation is responsible for ensuring it has authority to do so and has provided any required privacy notice.
4.3 You do not have to provide personal information, but some Services may not function or be available without it.
5. Why we use personal information
5.1 We may use personal information to:
provide, configure, administer and support the Services;
create and secure accounts, authenticate users and manage permissions;
deliver onboarding, implementation, training, certification, coaching and professional services;
enable collaboration, strategy execution, goal management, reporting, analytics and AI functionality;
respond to enquiries, support requests and complaints;
process payments, manage subscriptions and maintain business records;
monitor performance, prevent fraud, investigate misuse and protect users, Sprintify and third parties;
improve products, develop new functionality and conduct research using appropriate safeguards;
send service notices and, where permitted, marketing communications;
comply with legal obligations, enforce agreements and establish or defend legal claims; and
carry out corporate transactions, audits, insurance, due diligence and business administration.
6. AI processing
6.1 When you use an AI feature, information in your prompt and relevant authorised platform context may be sent to an approved AI or infrastructure provider to generate a response.
6.2 We configure providers, where commercially and technically available, so identifiable Customer Data is not used to train their public or general-purpose models.
6.3 We may review limited AI interaction data for safety, support, quality assurance and product improvement, using access controls and de-identification where appropriate.
6.4 Do not enter highly sensitive, classified, legally privileged or regulated information into an AI feature unless your organisation and Sprintify have approved that use.
6.5 AI outputs should be reviewed by a person before being used for decisions or external communications.
7. Cookies and analytics technologies
7.1 We may use essential cookies and similar technologies for authentication, security, preferences and core functionality.
7.2 With consent where required, we may use analytics and marketing technologies to understand website and product use and improve communications.
7.3 You may control non-essential cookies through our cookie banner, browser settings or other controls we provide. Blocking essential cookies may prevent parts of the Services from working.
7.4 A lawyer should confirm whether a separate Cookie Notice and consent management platform are required for the markets in which Sprintify operates.
8. When we share information
8.1 We may share personal information with:
the organisation that controls your Sprintify tenant and its authorised administrators;
our personnel, contractors, professional advisers and authorised Sprintify PRO professionals who need access to deliver services;
cloud hosting, authentication, communications, payment, analytics, support, security, integration and AI service providers;
connected third-party services at your or your organisation’s direction;
regulators, courts, law enforcement or other persons where required or permitted by law;
a buyer, investor, lender or adviser in connection with a genuine corporate transaction, subject to confidentiality safeguards; and
other parties where you have authorised disclosure.
8.2 We do not sell personal information as that term is ordinarily understood.
8.3 We may disclose aggregated or de-identified information that does not reasonably identify an individual or customer.
9. Overseas processing
9.1 Our service providers may process information in New Zealand, Australia, the United States, Europe and other locations identified in our current subprocessor list [INSERT LINK].
9.2 Where New Zealand Information Privacy Principle 12 or another cross-border rule applies, we will take reasonable steps to ensure the recipient is subject to comparable safeguards, an approved contractual mechanism, or another lawful basis for disclosure.
9.3 Internet communications and cloud services may involve routing through multiple countries.
10. Security
10.1 We use reasonable administrative, technical and organisational safeguards appropriate to the information and risks, which may include access controls, encryption in transit, logging, backup, secure development practices, supplier assessment and incident response.
10.2 Customers and users are responsible for protecting credentials, using available multi-factor authentication, configuring permissions appropriately and notifying us of suspected compromise.
10.3 No method of transmission or storage is completely secure. If a privacy breach causes or is likely to cause serious harm, we will notify affected parties and the New Zealand Privacy Commissioner as required by law.
11. Retention and deletion
11.1 We retain personal information only for as long as reasonably necessary for the purposes described in this policy, contractual commitments, dispute resolution and legal, tax, audit and security requirements.
11.2 Tenant content is generally retained for the subscription period and a limited post-termination export and recovery period, after which it may be deleted or de-identified in accordance with our retention schedule and backup cycles.
11.3 Certification and licence records may be retained for longer to verify qualifications, protect brand integrity and maintain professional history.
11.4 Aggregated or de-identified data may be retained indefinitely where it no longer identifies an individual or customer.
12. Your rights and choices
12.1 Subject to applicable law, you may request access to or correction of personal information we hold about you.
12.2 You may unsubscribe from marketing emails using the link in the message. We may still send necessary service, security, billing or legal communications.
12.3 Where Sprintify processes information on behalf of your organisation, we may refer your request to that organisation or assist it to respond.
12.4 We may need to verify your identity and may refuse or limit a request where permitted by law. We will explain the reason where required.
12.5 For requests under other applicable privacy regimes, including deletion, restriction, objection or portability rights, contact our Privacy Officer. The availability of those rights depends on the law that applies.
13. Children and young people
13.1 The Services are designed primarily for organisations and adults and are not directed to children under 16 unless Sprintify has expressly agreed to an approved programme with appropriate organisational and parental or guardian safeguards.
13.2 Customers must not create accounts for children or submit children’s personal information without lawful authority and Sprintify’s prior approval where required.
14. Complaints
14.1 Please contact our Privacy Officer first so we can investigate and respond.
14.2 You may also complain to the Office of the Privacy Commissioner in New Zealand or another applicable supervisory authority.
15. Changes to this policy
15.1 We may update this policy to reflect changes in law, technology or our Services. We will publish the updated version and state its effective date.
15.2 We will provide additional notice of material changes where reasonably appropriate.
16. Contact
16.1 Privacy Officer, Sprintify Limited: [INSERT EMAIL], [INSERT POSTAL ADDRESS], https://sprintifymomentum.com.