Effective Date: 10/08/2026
Last Updated: 10/08/2026
1. About this Privacy Policy
Capture The Bug Limited (“Capture The Bug”, “CTB”, “we”, “us” or “our”) is a New Zealand company providing managed Penetration Testing as a Service (“PTaaS”), cybersecurity assessment services and related software and platform functionality.
This Privacy Policy explains how we collect, use, store, disclose and protect personal information when you:
This Privacy Policy does not replace contractual data-processing provisions agreed separately with enterprise customers.
2. Privacy laws
CTB is based in New Zealand and handles personal information in accordance with the New Zealand Privacy Act 2020.
Where applicable to particular processing activities, we also take account of privacy and data-protection requirements including:
Nothing in this Policy is intended to provide rights that do not otherwise apply under applicable law.
3. Information we collect
We may collect the following categories of information.
3.1 Account information
This may include:
3.2 Customer and business information
We may collect:
3.3 Penetration-testing information
In connection with authorised testing, CTB may process information relating to:
Customers should provide only the information reasonably required for testing.
3.4 Technical information
When you use the Platform or Website, we may automatically collect:
3.5 Communications
We may retain communications with CTB, including emails, support tickets, meeting notes and other business communications.
3.6 Marketing information
Where permitted by law, we may collect information about:
4. How we obtain information
We may obtain information:
Where applicable law requires notification when personal information is obtained indirectly, CTB will take reasonable steps to provide the required notice unless an applicable exception applies.
5. Why we use personal information
We may process personal information to:
6. Legal bases for processing
Where the GDPR or equivalent laws apply, our legal basis may include:
Our legitimate interests may include providing and securing our services, preventing misuse, improving our products, administering customer relationships and developing our business.
7. Customer Data and our role
For certain information submitted by enterprise customers or processed during penetration-testing engagements, the Customer may act as controller and CTB may act as processor.
Where CTB processes personal data on behalf of a Customer, the applicable Customer agreement and Data Processing Agreement will govern that processing.
8. Security testing data
Penetration testing can expose technical information that is commercially sensitive.
CTB treats vulnerability findings, test evidence, credentials, architecture information, customer configurations and penetration-testing reports as confidential information.
Access is restricted to personnel and service providers who require access for legitimate purposes.
9. Security
CTB maintains reasonable technical and organisational safeguards appropriate to the nature and sensitivity of the information we process.
Measures may include:
No internet-based system can be guaranteed to be completely secure.
10. Disclosure of information
We may disclose information to:
Service providers may process information only for legitimate purposes consistent with our contractual arrangements.
11. International transfers
CTB operates internationally and may use service providers located outside New Zealand.
Where required by applicable law, we use appropriate contractual, legal or organisational safeguards for international transfers.
12. Data retention
We retain personal information only for as long as reasonably necessary for:
Penetration-testing information may be subject to specific retention periods agreed with Customers.
Information may remain temporarily in secure backups after deletion from production systems.
13. Cookies and analytics
Our Website and Platform may use cookies and similar technologies for:
More information is provided in our Cookie Policy.
14. Marketing
Where permitted by law, CTB may send communications about products, events and cybersecurity content.
You may unsubscribe from marketing communications at any time using the unsubscribe mechanism provided or by contacting us.
Operational and security communications may still be sent where necessary.
15. Automated decision-making and AI
CTB may use automation to support internal operations, analytics, workflow management or service delivery.
CTB will not intentionally submit Customer Confidential Information or penetration-testing findings to publicly available generative AI services for model training unless authorised by the Customer or otherwise expressly agreed.
If CTB introduces material automated decision-making affecting individual legal rights, this Policy will be updated as appropriate.
16. Your privacy rights
Depending on applicable law, you may have rights to:
These rights may be subject to legal limitations.
17. Privacy breaches
Where CTB becomes aware of a privacy or security incident involving personal information, CTB will investigate and take appropriate response measures.
Where notification is legally required, CTB will notify affected parties and/or regulators as required by applicable law.
18. Children
CTB's services are intended for business users and are not directed to children.
We do not knowingly solicit personal information from children through the Platform.
19. Third-party websites
Our Website may link to third-party services.
CTB is not responsible for the privacy practices of third parties.
20. Changes to this Policy
We may update this Privacy Policy periodically.
Material changes will be communicated through appropriate channels, which may include our Website, Platform or email.
21. Contact
Privacy enquiries may be sent to:
Privacy Officer
Capture The Bug Limited
Email: [email protected]
Address: 526 Victoria Street, Hamilton Central, Waikato
Flexible, scalable PTaaS for modern product teams.