Privacy Policy
Last updated: 25 July 2026
Introduction and Data Controller
PCI Assessments Center ("the platform") is a free self-assessment and training service operated by Haumaru Whānau ("we", "our", or "us"). We are committed to protecting your personal data in accordance with applicable data protection laws, including the EU General Data Protection Regulation (GDPR), the Kingdom of Saudi Arabia's Personal Data Protection Law (PDPL), the New Zealand Privacy Act 2020, and other regional data protection regulations. This Privacy Policy explains how we collect, use, share, and protect your personal information when you use PCI Assessments Center.
Key Definitions:
- Personal Data: Any information relating to an identified or identifiable natural person.
- Processing: Any operation performed on personal data, including collection, storage, use, or disclosure.
- Data Subject: The individual to whom personal data relates.
- Tenant: The organisation account under which your assessments and reports are stored.
1. Personal Data We Collect
Data collected directly from you:
- Account details — full name, work email, and organisation name.
- Self-assessment responses, evidence notes, and eligibility attestations you record against PCI DSS SAQs.
- Generated Self-Assessment Questionnaires (SAQs) and Attestations of Compliance (AoCs) produced from your inputs.
- Training progress, quiz answers, and readiness-checklist state.
- Any correspondence you send us.
Data collected automatically:
- IP address, browser type, and device information.
- Session and authentication tokens required to keep you signed in.
- Basic usage telemetry to detect abuse and improve reliability.
Sensitive personal data: PCI Assessments Center is a compliance readiness tool. Do not upload cardholder data, authentication data, or other sensitive personal data into free-text fields. We do not require or intentionally collect such data.
2. Legal Basis for Processing
- Consent — where you have opted in to specific processing.
- Contractual necessity — to provide the account, assessments, reports and training you request.
- Legal obligations — where required by applicable law.
- Legitimate interests — to operate, secure, and improve the platform, provided such interests do not override your fundamental rights.
3. How We Use Your Personal Data
- To create and maintain your PCI Assessments Center account and tenant workspace.
- To store your assessment answers, eligibility attestations, and generated PDF reports.
- To deliver training modules and track your learning progress.
- To send transactional messages (sign-in, password reset, service notices).
- To detect misuse, secure the platform, and comply with legal obligations.
- To improve the platform's content, usability and reliability.
4. Your Data Protection Rights
- Right to be informed about how your personal data is processed.
- Right of access to your personal data and a copy of it.
- Right to rectification of inaccurate or incomplete data.
- Right to erasure of your account and associated assessments.
- Right to restrict processing in certain circumstances.
- Right to data portability — you can export your generated SAQ and AoC PDFs at any time from your dashboard.
- Right to object to processing based on legitimate interests.
- Right to withdraw consent where processing is based on consent.
- Right to lodge a complaint with a supervisory authority in your jurisdiction.
To exercise any of these rights, contact us using the details at the bottom of this policy.
5. Data Sharing and Disclosure
We do not sell, trade, or rent your personal data. We share information only where necessary:
- Sub-processors — cloud hosting, authentication, and database services that run the platform, under contractual data-processing terms.
- Within Haumaru Whānau — among our affiliated entities for legitimate operation of PCI Assessments Center.
- Legal requirements — where required to comply with applicable law or valid legal process.
- Protection of rights — to protect the safety of our users or the public.
- Business transactions — in connection with a merger, acquisition, or asset sale, subject to confidentiality obligations.
6. Tenant Isolation and Security
Every organisation using PCI Assessments Center is a separate tenant. Row-level security ensures that only members of your tenant can view your assessments, evidence, eligibility attestations, and generated reports.
Technical measures:
- Encryption of data in transit (TLS) and at rest.
- Row-level security on every tenant-scoped table.
- Secure authentication and least-privilege access controls.
- Regular patching and dependency updates.
Organisational measures:
- Access on a need-to-know basis, with contractual confidentiality obligations.
- Documented incident response and breach notification procedures.
If a personal data breach poses a risk to your rights and freedoms, we will notify affected users and relevant supervisory authorities within the timeframes required by applicable law (including within 72 hours under GDPR and PDPL).
7. Cross-Border Data Transfers
Your personal data may be transferred to and processed in countries outside your jurisdiction, including where our hosting sub-processors and Haumaru Whānau entities operate. Transfers are protected by Standard Contractual Clauses, adequacy decisions, or other approved mechanisms under applicable law.
8. Data Retention
- Active accounts: assessment data and generated reports are retained while your account is active.
- Account deletion: on request, we delete your account and associated tenant data, except where retention is required by law.
- Server logs and telemetry: retained for a limited period for security and reliability.
9. Cookies and Tracking Technologies
PCI Assessments Center uses only essential cookies and browser storage required for sign-in, session management, and security. We do not use advertising cookies. You can control cookies through your browser settings; disabling essential cookies will prevent sign-in.
10. Children's Privacy
PCI Assessments Center is intended for business and professional use and is not directed at individuals under 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
11. Updates to This Privacy Policy
We may update this policy to reflect changes in our practices or legal requirements. When we make material changes we will update the "Last updated" date and, where appropriate, notify account holders.
12. Contact Information
For questions about this Privacy Policy or to exercise your rights, contact Haumaru Whānau via the Haumaru contact page or visit haumaru.org.