Legal

Privacy policy

Last updated: 19 September 2026

This policy explains how Runasec Limited (“RunaSec”, “we”, “us”) handles personal information. We are based in New Zealand and follow the New Zealand Privacy Act 2020. Where other privacy laws apply to you, such as the GDPR or UK GDPR, we follow those too.

It has two parts, because we play a different role in each:

Then there is a list of the third parties we use, and your rights and how to contact us.

Part 1: Our website and beta signup

What we collect

  • When you join the beta: your name, company, work email and which product you are interested in. The form is run by a form provider, which passes your details to our team by email.
  • When you visit the site: standard analytics data such as pages viewed, approximate location, device and browser type, and your IP address. We only collect this with Google Analytics, which uses cookies, if you allow it.

How we use it

  • To reply to you and run the private beta.
  • To send you occasional RunaSec product news. Every email has an unsubscribe link, and you can also ask us to stop at any time.
  • To understand how the site is used so we can improve it.

We do not sell your information. We only share it with the types of service providers described below.

You don’t have to give us your details, but we can’t reply to a beta request without them.

Cookies and analytics

We only use cookies for Google Analytics, which tells us how people use the site. When you first visit, we ask whether you accept these cookies. Google Analytics does not load unless you choose Accept, and if you decline, no analytics cookies are set.

You can change your choice at any time with Cookie settings, which is also at the bottom of every page. If you withdraw consent, we remove the analytics cookies from your browser. We remember your choice in your browser’s local storage, not in a cookie.

Part 2: RunaCheck and RunaTrain

Who is responsible for what

An MSP or business (“our customer”) connects its Microsoft 365 tenant to our apps. Our customer decides what the apps are used for, and we process the information on its behalf and on its instructions. If you are an employee of one of our customers’ clients and want to see or correct your information, please ask your MSP or employer first. We will help them respond.

The exception is account information for the people who sign in to our apps (name, work email and login details). We are responsible for that information and use it to run and secure your account.

What the apps access and store

When you connect a Microsoft 365 tenant, RunaCheck and RunaTrain generally use read and write access through Microsoft Graph. That lets them assess your configuration and, where you use those features, make changes and run tasks in your tenant on your behalf. The exact permissions are shown on the Microsoft consent screen when you connect, and you can review them at any time in Microsoft Entra.

  • RunaCheck reads and stores your Microsoft 365 security configuration, such as security settings and Conditional Access policies.
  • RunaTrain holds the names and work email addresses of the people being trained, their training results, and their activity in phishing simulations (for example whether they clicked, reported or ignored a simulated email).

App data is stored in the data centres where our servers run. These may be in any country, and we may move them as we grow. Wherever the data is stored, we protect it as this policy describes. Customers can ask us where their data is currently held.

How we use it

Only to provide the apps to our customer, keep them secure and fix problems. We do not sell it or use it for advertising.

AI

We use AI to help deliver your training. However, we do not send personal information or customer tenant data to our AI partners.

How long we keep it, and disconnecting

You can remove our access at any time by removing the RunaSec app from your Microsoft Entra tenant (Enterprise applications). We delete a customer’s data within 30 days after it disconnects or cancels, or sooner if it asks us to.

Security and breaches

We protect data with reasonable technical and organisational safeguards. If we become aware of a breach affecting customer data, we will tell the affected customer without undue delay so it can meet its own obligations, including notifying the Privacy Commissioner where required.

Data processing agreement

Our data processing agreement sets out these commitments in more detail. It applies to customers’ use of RunaCheck and RunaTrain.

Third parties we use

We use trusted service providers to help us run the site and the apps. They operate internationally, so your information may be stored or processed outside New Zealand. We only use providers that protect personal information to a comparable standard or are otherwise bound by suitable safeguards. Customers can ask us for our current list of providers.

Type of providerUsed forPersonal information?
Cloud hostingRunning the apps and storing app dataYes
Content delivery and securityDelivering the website and apps quickly and protecting them from attacksYes (such as IP addresses and requests)
Email and productivityOur email, including beta signups and support messagesYes
Online formsThe beta signup form on our websiteYes
Website analytics (Google Analytics)Understanding how the website is used, only if you accept cookiesYes (website visitors only, not app data)
AI partnersHelping deliver trainingNo. We do not send personal information or tenant data

Your rights and how to contact us

You can ask us to:

  • tell you what personal information we hold about you, and give you a copy;
  • correct it if it is wrong;
  • delete it or stop using it, where the law allows (for example, if you are covered by the GDPR).

Email us at info [at] runasec [dot] com and we will reply within 20 working days. That is the timeframe the New Zealand Privacy Act sets.

If you are not happy with our response, you can complain to the New Zealand Office of the Privacy Commissioner at privacy.org.nz (0800 803 909). If you are in the EU or UK, you can also complain to your local data protection authority. Privacy laws in other places may give you additional rights, so please contact us if you think that applies to you.

Changes to this policy

We will update this page when what we do with personal information changes, for example when we add a new provider or a new feature. The date at the top shows when it was last changed.