Privacy
We ask for access to your Microsoft tenant. That deserves a plain answer about what we read, where it goes, how long we keep it, and what we never touch.
Last updated: 4 September 2026
This statement explains how Luna Cyber Limited (NZ company number 9429030669901) handles personal information. It covers two quite different things: information about people who visit this website, and information we encounter inside a client's Microsoft environment while carrying out an audit or remediation work. We treat the second with considerably more care, because it is not ours.
We handle personal information in accordance with the New Zealand Privacy Act 2020 and its Information Privacy Principles.
This site sets no cookies, runs no analytics, and contains no tracking scripts of any kind. We do not build a profile of you, and we cannot tell you apart from any other visitor.
The site is served by Cloudflare, which keeps standard request logs (IP address, timestamp, page requested, browser user-agent) for its own security and abuse-prevention purposes. We use these only to keep the site available and to investigate abuse. We do not use them to identify individual visitors.
Every asset on this site (stylesheet, typefaces, images) is served from our own domain. Loading this page contacts nobody but us. There is no advertising network, no tag manager, no embedded widget, and no font CDN quietly collecting your IP address.
If you email us, we keep that correspondence so we can respond to you and maintain a record of what was agreed. We do not add you to a mailing list, and we do not sell, rent, or share your details with anyone for marketing.
This is the part that matters. To run a Security Posture Audit we ask an administrator in your organisation to approve a dedicated, read-only application identity with the minimum Microsoft Graph, Azure RBAC, and (where relevant) Exchange Online permissions the audit needs. Nothing is enabled until your administrator approves it, and we run a connectivity check against every permission before the audit begins, so you can see exactly what we can and cannot reach.
We read configuration and metadata, not the contents of your business. In practice that includes:
Some of this is personal information about your staff. Account names, email addresses, job attributes, and sign-in records identify real people, and we will not pretend otherwise. We access it only to assess your security posture, we report on it in aggregate and by exception rather than individually wherever the finding allows, and we do not use it for any other purpose.
During Uplift Engagement or Engineering Support work we do make changes, that is the point of it. Those permissions are separate, scoped to the agreed work, approved by you independently of the audit access, and removed when the engagement ends.
Audit evidence is processed by LUNA, our own auditing platform, and stored in encrypted form. Your report and the underlying evidence are retained only for as long as it takes to deliver the engagement and support any agreed re-audits, then deleted. If you would like the specifics of where your data is hosted or exactly how long we hold it for your engagement, ask us and we will tell you directly.
We do not sell client data, and we do not share it with anyone except the small number of service providers we rely on to do the work, each bound to protect it under terms consistent with this statement. We do not disclose who they are as a matter of course, but we will tell you on request.
If we become aware of a privacy breach affecting your information, we will notify you promptly, and we will notify the Office of the Privacy Commissioner where the Privacy Act 2020 requires it.
Under the Privacy Act 2020 you may ask us for a copy of the personal information we hold about you, and ask us to correct it if it is wrong. Email us and we will respond within 20 working days, as the Act requires.
If you are not satisfied with how we have handled your information or your request, you can complain to the Office of the Privacy Commissioner.
If we change how we handle personal information, we will update this page and the date at the top of it. Where the change is significant and affects a current client, we will tell them directly rather than relying on them to re-read this page.
Privacy questions, access requests, and complaints all go to our Privacy Officer: privacy@lunacyber.co.nz.