Live compliance platform · built around HSWA 2015 Aotearoa New Zealand
Legal — Erasure requests

How to request deletion of your data.

Last updated: 2 Jun 2026 · Privacy Policy

Your right

1. Your Right to Request Erasure

Under the New Zealand Privacy Act 2020, you have the right to ask us to delete or correct personal information we hold about you. This page explains how we handle erasure requests specifically: how to make one, how we assess it, what the possible outcomes are, and what you can expect from us in terms of timing.

Not all personal information can be erased on request. TrustPoint holds certain records for health and safety compliance purposes under the Health and Safety at Work Act 2015 (HSWA). Where retaining records is necessary to fulfil those obligations, we will explain this clearly in our response and tell you what we can do instead.

Short version: Account and profile data can typically be deleted. Compliance and audit records linked to a site, contractor relationship, or WorkSafe obligation are retained for up to seven years but can be pseudonymised so they are no longer associated with you by name.

2. How to Make a Request

Email us at operations@trustpoint.nz with the subject line “Personal Information Erasure Request”. Please include:

We may ask you to verify your identity before processing your request. This is to protect you. We will not delete or modify another person’s data based on an unverified request.

3. How We Assess Your Request

When we receive an erasure request, we follow this process:

  1. Acknowledge within 5 working days. We will confirm receipt and let you know what information we hold about you that is in scope of the request.
  2. Assess against HSWA obligations. We check whether any of the information in scope is part of a compliance or audit record that we are required to retain under the Health and Safety at Work Act 2015 or that may be needed for a WorkSafe NZ investigation. Gate induction records, document approval records, and override audit trail events fall into this category.
  3. Determine outcome for each data type (see Section 4 below).
  4. Act on the request and notify you within 20 working days of receiving your original request, as required by the Privacy Act 2020.

If your request is complex or involves a large volume of records, we may notify you within 20 working days that we need additional time, and provide a revised estimate.

4. Outcomes by Data Type

The table below describes what happens to each category of personal information following an erasure request we are able to fulfil.

Data typeOutcomeReason
Account name and email addressDeletedNo continuing compliance purpose once the account is closed.
Company name and NZBNDeletedNo continuing compliance purpose once the account is closed and all relationships are terminated.
Worker name and phone number (persons record)PseudonymisedThe gate induction record must be retained for HSWA. The worker’s name is replaced with an anonymised token and their phone number is removed, so the record no longer identifies them personally.
Gate induction records (site, timestamp, readiness state)Retained (7 years)Required for WorkSafe NZ audit trail. Retained in pseudonymised form after the worker’s personal details are removed.
Uploaded compliance documents (certificates, insurance, H&S plans)Retained (7 years)Form part of the compliance evidence record for the Builder and Contractor relationship. Required for potential WorkSafe investigations. Company identifying information remains but document files may be deleted on request if no active regulatory proceedings are known.
Audit trail events (approvals, overrides, relationship changes)Retained (7 years)Tamper-evident audit chain required under HSWA. Cannot be altered without breaking the hash chain. Retained as an aggregate record; no personal-name field in most event types.
Email address used for login attempts and rate-limitingDeletedNo continuing purpose once account is closed.
Notification preferences and in-app notificationsDeletedNo continuing purpose once account is closed.
Stripe billing recordsRetained per Stripe policyStripe is a separate data controller for payment records. Erasure requests for payment data should be directed to Stripe’s privacy team.

5. Pseudonymisation

Where we pseudonymise your data rather than delete it, this means:

Pseudonymisation is a recognised technique under the Privacy Act 2020 and aligns with the principle of using the least privacy-invasive means to achieve a lawful purpose.

6. Where Erasure Is Refused

We may decline to erase personal information if:

If we refuse your request, we will tell you in writing within 20 working days, explain why, and advise you of your right to complain to the Office of the Privacy Commissioner.

7. Timeframes

We will respond to your request within 20 working days of receiving it, as required by the Privacy Act 2020 (section 46). If we need more time, we will notify you and give a revised date.

Where we are carrying out pseudonymisation, the technical work is performed directly on the live database by a TrustPoint operator and is typically completed within the same timeframe.

8. Complaints

If you are not satisfied with how we have handled your erasure request, you may complain to the Office of the Privacy Commissioner:

privacy.org.nz · Phone: 0800 803 909

We encourage you to contact us first at operations@trustpoint.nz so we have the opportunity to resolve the issue directly.