Trust Centre
How we protect your data
Transparency on the third parties we work with, how we handle your information, and the changes we make to keep it secure.
Subprocessors
A subprocessor is a third party that HybrIT NZ engages to help deliver its services, such as hosting infrastructure, identity, or productivity tools. A subprocessor may store or process data outside New Zealand, so the primary data location listed for each is not always New Zealand. We keep this register current and post changes in the Updates tab.
Last reviewed: 23 July 2026
| Subprocessor | Purpose | Primary data location | More information |
|---|---|---|---|
| Microsoft 365 backup | Australia (Sydney) | Visit | |
| Managed AI (Claude) services | United States | Visit | |
| Password management and credential storage | United States | Visit | |
| Microsoft 365 security assessment and remediation | European Union | Visit | |
| Backup and business continuity (BCDR) | Australia | Visit | |
| Service management and support ticketing | United Kingdom | Visit | |
| Managed detection and response (MDR) | Global (US, UK, Australia) | Visit | |
| IT documentation and asset management | Australia (AWS, Sydney) | Visit | |
| Microsoft 365 productivity, Entra ID identity, GitHub, and Azure cloud hosting | Australia / New Zealand (service-dependent) | Visit | |
| Remote monitoring and management (RMM) and endpoint management | European Union | Visit | |
| Password and documentation management for MSPs | United Kingdom | Visit | |
| Website and infrastructure monitoring | European Union | Visit | |
| Accounting, invoicing, and billing | United States | Visit |
Frequently asked questions
Common questions about how we handle your data, where it lives, and how we keep it secure.
How does HybrIT protect my data?
We apply a zero-trust model with least-privilege access across every environment, apply policies aligned to ISO 27001 and CIS Controls, encrypt data in transit and at rest, and enforce MFA on all accounts. Security is built into every plan rather than sold as an add-on.
See our security approachWhere is my data stored?
Customer data is primarily hosted in Microsoft Azure data centres in the Australia and New Zealand regions. Some subprocessors process limited data overseas, and each is bound by contractual data protection obligations. The Subprocessors tab lists each one with its primary data location.
Is HybrIT NZ certified to a compliance framework?
Not yet. We apply policies aligned to ISO 27001 and CIS Controls, and certification to ISO 27001 and ISO 42001 (AI management) is planned. The platforms we deliver on, including Microsoft Azure and Microsoft 365, hold their own independent certifications.
What happens if there is a data breach?
Our managed detection and response team investigates and contains threats around the clock. Where a breach affects your personal data, we notify you without undue delay in line with the Privacy Act 2020 and your agreement with us.
How is my data handled when you use AI tools like Claude?
Our Managed AI service runs on Anthropic's Claude under commercial terms. Anthropic does not train its models on your business inputs or outputs under those terms, and data is handled under enterprise privacy controls.
Anthropic Trust CenterHow do I request a copy of my data or exercise my privacy rights?
You can ask for a copy of the personal information we hold, or ask us to correct it, at any time. Contact us at [email protected] or +64 6 241 8300.
Read our privacy policyWhich subprocessors does HybrIT use?
We engage a small set of trusted third parties to deliver our services, each bound by data protection obligations. The current list is published in the Subprocessors tab and updated as it changes.
What happens to my data if I leave HybrIT?
Your data stays yours. At offboarding we hand over admin control, credentials, and documentation, and remove our access. Unless your agreement includes a specific exit plan, any data we still hold is securely deleted 30 days after offboarding.
How do you vet and manage access for HybrIT staff?
Staff are vetted at hire, including police checks for New Zealand staff. Access to client environments is least privilege, protected by MFA, logged, and reviewed regularly. Access is removed the day someone leaves.
What's your backup and disaster recovery approach?
We protect our own company data and infrastructure with independent SaaS backup platforms, separate from the systems they protect. Backup arrangements for your environment are defined in your service agreement, as these vary by service.
Can I request my data stays only in New Zealand?
Partially. We can host Azure workloads in Microsoft's New Zealand North region on request. Microsoft 365 and identity data resides in the Australian geography, and some subprocessors process data overseas, so a fully NZ-only footprint isn't achievable with a modern cloud stack. We're transparent about where each system holds data.
Is there a data processing agreement (DPA) available?
Data processing and privacy obligations are built into our master services agreement rather than a separate DPA. You can read the privacy provisions in our MSA.
Read the MSA privacy provisionsHow are responsibilities split between HybrIT and me?
Security is shared. We manage the platforms, patching, monitoring, backups, and access controls in scope of your agreement. You remain responsible for how your team uses the systems, approving access, and the accuracy of your own data. Your service agreement sets out the exact split.
Updates
A record of changes to our security posture, subprocessors, and data handling.
Trust Centre published
We launched the HybrIT Trust Centre, including our subprocessor register and a security and privacy FAQ.