Security & Data Protection Policy

How Margineer protects customer data — retention, breach response, logging, incident handling and disaster recovery.

Guidance, not legal advice. This policy sets Margineer's operational security standards and states the privacy obligations that apply in New Zealand and Australia. It is not legal advice. Specific notification thresholds and record-keeping periods should be confirmed with a privacy lawyer and the company's accountant before launch.
Document ownerSecurity Lead, Margineer
Version1.0 (draft for review)
StatusPre-launch — for partner review and internal implementation
Applies toMargineer web application and all systems that process customer data
JurisdictionsNew Zealand and Australia
Review cycleEvery 12 months, or after any material change or significant incident

1. Purpose and scope

Margineer is an AI-powered web application, built by accountants, that turns a manufacturer's financial and operating data into plain-English insight. Customers across New Zealand and Australia entrust Margineer with sensitive business information. This policy defines how that information is classified, retained, protected, monitored and recovered, and how Margineer responds when something goes wrong.

It covers five areas: data retention, data-breach security and response, audit logging, incident logging and response, and disaster recovery and business continuity.

2. What Margineer holds — data classification

Every control in this policy is sized against the sensitivity of the data it protects. Margineer classifies data into four tiers.

TierExamplesHandling standard
Confidential — business financialsRevenue, margins, product costs, pricing, inventory, payroll totals, cash-flow figures, uploaded CSV/Excel, Xero extractsEncrypted at rest and in transit; access strictly least-privilege; tenant-isolated; access logged
Personal information (PII)User and customer account details — name, email, business, contactGoverned by NZ Privacy Act 2020 and AU Privacy Act 1988 (APPs); minimised and access-controlled
Secrets & credentialsOAuth tokens (Xero), API keys, password hashesNever stored in plaintext; held in a secrets manager; never written to logs
Operational / systemAudit logs, application logs, metricsIntegrity-protected; access-restricted; retained per the schedule in Section 3

Business financial data is treated as the highest-value asset: a breach here is commercially damaging to the customer, even where little personal information is involved.

3. Data retention

Margineer follows the principle of data minimisation: it collects only what the product needs and keeps it only as long as there is a clear purpose. The schedule below sets default retention periods. Periods marked (confirm) should be validated with the company's accountant and privacy counsel before launch.

Data classRetentionThen
Uploaded financial data & Xero extractsLife of subscriptionSecure deletion 90 days after cancellation (export window)
Derived insights & monthly reportsLife of subscriptionDeleted with the source data
Account & PIILife of accountDeleted or anonymised 90 days after closure
Billing & tax records7 years (confirm)Retained to meet NZ/AU record-keeping rules, then deleted
Audit logs12 months minimumArchived or securely deleted
Application / system logs90 daysRotated and deleted
Database backups35-day rolling windowOldest backups rotated out automatically
Secrets / OAuth tokensWhile connection is activeRevoked and deleted on disconnect
Support communicationsLife of account + 24 monthsDeleted

Deletion and offboarding

4. Data-breach security and response

Preventive controls

Response process

When a breach is suspected, Margineer follows a defined sequence, with a single accountable owner:

StepWhat happens
1. Detect & recordLog the event; open an incident record (Section 6)
2. Triage & assess severityConfirm scope; classify severity; determine data and individuals affected
3. ContainStop the exposure — revoke access, isolate systems, rotate credentials
4. Eradicate & recoverRemove the cause; restore clean service (Section 7)
5. NotifyAssess notification obligations (below) and notify regulators/customers as required
6. ReviewPost-incident review and tracked remediation

Notification obligations

New Zealand — Privacy Act 2020. If a privacy breach is likely to cause serious harm (a 'notifiable privacy breach'), Margineer must notify the Office of the Privacy Commissioner as soon as practicable after becoming aware of it, and notify affected individuals (or give public notice if individual notice is not reasonably practicable). Reporting is done via the Commissioner's NotifyUs tool. Failing to notify a serious breach is an offence carrying a fine of up to NZ$10,000.

Australia — Notifiable Data Breaches (NDB) scheme. Where an 'eligible data breach' is likely to result in serious harm, an entity covered by the scheme must notify the OAIC and affected individuals. An organisation generally has up to 30 days to assess whether a breach is likely to result in serious harm. The NDB scheme applies to APP entities (generally those with annual turnover above A$3M, and others in specific categories); Margineer adopts these obligations as a baseline standard and will confirm applicability as it grows.

Margineer keeps a record of every breach and its assessment, whether or not the threshold to notify is met. As an AI-powered product, Margineer also notes the 2024 Australian reforms introducing transparency obligations around automated decision-making, and will keep its privacy disclosures current.

5. Audit logs

Audit logs record who did what, to what, when and from where, so security-relevant activity can be investigated and demonstrated.

What is logged

How logs are protected

6. Incident logging and response

Audit logs are the routine record of security events. An incident log is the record of a specific incident being worked. Every incident — outage, suspected breach, data-integrity issue — gets its own record.

Every incident record captures

Severity levels

LevelDefinitionTarget response
SEV1 — CriticalConfirmed data breach or full service outageImmediate; contain within 1 hour; owner + leadership engaged
SEV2 — HighSuspected breach, auth failure, or partial outageWithin 2 hours
SEV3 — MediumDegraded service or single-customer impactWithin 1 business day
SEV4 — LowMinor issue, no data riskNext business day

Every incident feeds a post-incident review and a tracked remediation list. Incident records support the breach-notification decisions in Section 4.

7. Disaster recovery and business continuity

Margineer sets recovery targets per system, backs data up securely, and — critically — tests that it can actually restore. An untested backup is not a backup.

Recovery targets

SystemRPO (max data loss)RTO (max downtime)
Production database (customer data)≤ 1 hour (point-in-time recovery)≤ 4 hours
File storage (uploads, exports)≤ 24 hours≤ 8 hours
Application servicen/a (stateless — redeploy)≤ 4 hours

Backups and testing

Scenarios covered

Cloud region outage, data corruption, ransomware, accidental deletion, provider failure, and encryption-key loss.

Communications

A defined plan for keeping customers informed during an outage — status updates, expected restoration, and follow-up.

8. Roles, responsibilities and review