Privacy Policy

Effective Date: 10/08/2026

Last Updated: 10/08/2026

1. About this Privacy Policy

Capture The Bug Limited (“Capture The Bug”, “CTB”, “we”, “us” or “our”) is a New Zealand company providing managed Penetration Testing as a Service (“PTaaS”), cybersecurity assessment services and related software and platform functionality.

This Privacy Policy explains how we collect, use, store, disclose and protect personal information when you:

  • visit capturethebug.xyz or related CTB websites;
  • create or use a CTB account;
  • use the Capture The Bug platform;
  • procure or receive penetration testing or cybersecurity services;
  • communicate with us;
  • attend our events or webinars;
  • receive marketing communications from us; or
  • otherwise interact with CTB.

This Privacy Policy does not replace contractual data-processing provisions agreed separately with enterprise customers.

2. Privacy laws

CTB is based in New Zealand and handles personal information in accordance with the New Zealand Privacy Act 2020.

Where applicable to particular processing activities, we also take account of privacy and data-protection requirements including:

  • the EU General Data Protection Regulation (“GDPR”);
  • the UK GDPR;
  • the Australian Privacy Act 1988 and Australian Privacy Principles; and
  • other applicable privacy laws.

Nothing in this Policy is intended to provide rights that do not otherwise apply under applicable law.

3. Information we collect

We may collect the following categories of information.

3.1 Account information

This may include:

  • name;
  • business email address;
  • telephone number;
  • job title;
  • employer;
  • account credentials;
  • authentication information;
  • account preferences; and
  • organisation membership.

3.2 Customer and business information

We may collect:

  • company name;
  • billing details;
  • commercial contact information;
  • contract information;
  • purchase order information;
  • service requirements;
  • support requests; and
  • communications between CTB and the Customer.

3.3 Penetration-testing information

In connection with authorised testing, CTB may process information relating to:

  • IP addresses;
  • domains and subdomains;
  • URLs;
  • applications;
  • APIs;
  • cloud environments;
  • systems and network architecture;
  • security configurations;
  • test accounts and credentials;
  • vulnerability information;
  • screenshots and evidence;
  • logs;
  • HTTP requests and responses;
  • test results;
  • remediation information;
  • penetration-testing reports; and
  • other information reasonably necessary to perform the Services.

Customers should provide only the information reasonably required for testing.

3.4 Technical information

When you use the Platform or Website, we may automatically collect:

  • IP address;
  • browser type;
  • operating system;
  • device information;
  • login activity;
  • session data;
  • timestamps;
  • audit logs;
  • security events;
  • referring URLs; and
  • usage information.

3.5 Communications

We may retain communications with CTB, including emails, support tickets, meeting notes and other business communications.

3.6 Marketing information

Where permitted by law, we may collect information about:

  • marketing preferences;
  • campaign engagement;
  • event participation;
  • website interactions; and
  • business interests.

4. How we obtain information

We may obtain information:

  • directly from you;
  • from your employer or organisation;
  • from authorised users within your organisation;
  • through our Platform;
  • during an authorised penetration test;
  • from service providers;
  • from publicly available business sources; or
  • from another lawful source.

Where applicable law requires notification when personal information is obtained indirectly, CTB will take reasonable steps to provide the required notice unless an applicable exception applies.

5. Why we use personal information

We may process personal information to:

  • provide the Platform and Services;
  • perform authorised penetration tests;
  • create and administer accounts;
  • authenticate users;
  • scope and coordinate engagements;
  • communicate findings;
  • produce reports;
  • support vulnerability remediation;
  • perform retesting;
  • maintain audit records;
  • provide customer support;
  • secure our systems;
  • detect misuse or fraud;
  • improve the Platform and Services;
  • administer contracts and invoices;
  • meet legal and regulatory obligations;
  • establish or defend legal claims;
  • send marketing communications where permitted; and
  • operate and improve our business.

6. Legal bases for processing

Where the GDPR or equivalent laws apply, our legal basis may include:

  • performance of a contract;
  • legitimate interests;
  • compliance with legal obligations;
  • consent; or
  • another lawful basis available under applicable law.

Our legitimate interests may include providing and securing our services, preventing misuse, improving our products, administering customer relationships and developing our business.

7. Customer Data and our role

For certain information submitted by enterprise customers or processed during penetration-testing engagements, the Customer may act as controller and CTB may act as processor.

Where CTB processes personal data on behalf of a Customer, the applicable Customer agreement and Data Processing Agreement will govern that processing.

8. Security testing data

Penetration testing can expose technical information that is commercially sensitive.

CTB treats vulnerability findings, test evidence, credentials, architecture information, customer configurations and penetration-testing reports as confidential information.

Access is restricted to personnel and service providers who require access for legitimate purposes.

9. Security

CTB maintains reasonable technical and organisational safeguards appropriate to the nature and sensitivity of the information we process.

Measures may include:

  • encryption in transit;
  • encryption at rest where appropriate;
  • role-based access controls;
  • multi-factor authentication;
  • access logging;
  • secure development practices;
  • monitoring;
  • vulnerability management;
  • backups;
  • personnel access controls; and
  • incident-response procedures.

No internet-based system can be guaranteed to be completely secure.

10. Disclosure of information

We may disclose information to:

  • hosting providers;
  • cloud infrastructure providers;
  • communications providers;
  • authentication providers;
  • analytics providers;
  • professional advisers;
  • payment and accounting providers;
  • approved contractors assisting with service delivery;
  • regulators or law-enforcement authorities where legally required;
  • prospective purchasers or investors in connection with a legitimate corporate transaction; and
  • other parties with your authorisation.

Service providers may process information only for legitimate purposes consistent with our contractual arrangements.

11. International transfers

CTB operates internationally and may use service providers located outside New Zealand.

Where required by applicable law, we use appropriate contractual, legal or organisational safeguards for international transfers.

12. Data retention

We retain personal information only for as long as reasonably necessary for:

  • the purposes for which it was collected;
  • providing the Services;
  • contractual requirements;
  • security and audit requirements;
  • legal compliance;
  • dispute resolution; or
  • legitimate business purposes.

Penetration-testing information may be subject to specific retention periods agreed with Customers.

Information may remain temporarily in secure backups after deletion from production systems.

13. Cookies and analytics

Our Website and Platform may use cookies and similar technologies for:

  • authentication;
  • security;
  • session management;
  • preferences;
  • performance;
  • analytics; and
  • permitted marketing activities.

More information is provided in our Cookie Policy.

14. Marketing

Where permitted by law, CTB may send communications about products, events and cybersecurity content.

You may unsubscribe from marketing communications at any time using the unsubscribe mechanism provided or by contacting us.

Operational and security communications may still be sent where necessary.

15. Automated decision-making and AI

CTB may use automation to support internal operations, analytics, workflow management or service delivery.

CTB will not intentionally submit Customer Confidential Information or penetration-testing findings to publicly available generative AI services for model training unless authorised by the Customer or otherwise expressly agreed.

If CTB introduces material automated decision-making affecting individual legal rights, this Policy will be updated as appropriate.

16. Your privacy rights

Depending on applicable law, you may have rights to:

  • request access to personal information;
  • request correction;
  • request deletion;
  • object to certain processing;
  • restrict certain processing;
  • withdraw consent;
  • request portability; and
  • complain to a privacy regulator.

These rights may be subject to legal limitations.

17. Privacy breaches

Where CTB becomes aware of a privacy or security incident involving personal information, CTB will investigate and take appropriate response measures.

Where notification is legally required, CTB will notify affected parties and/or regulators as required by applicable law.

18. Children

CTB's services are intended for business users and are not directed to children.

We do not knowingly solicit personal information from children through the Platform.

19. Third-party websites

Our Website may link to third-party services.

CTB is not responsible for the privacy practices of third parties.

20. Changes to this Policy

We may update this Privacy Policy periodically.

Material changes will be communicated through appropriate channels, which may include our Website, Platform or email.

21. Contact

Privacy enquiries may be sent to:

Privacy Officer

Capture The Bug Limited

Email: [email protected]

Address: 526 Victoria Street, Hamilton Central, Waikato

Security that works like you do.

Flexible, scalable PTaaS for modern product teams.