Data Handling & Security Notice
This notice summarises how Maximus Limited handles client data and business contact data in connection with our GTM, outbound, lead generation, and revenue operations services. It should be read together with our Privacy Policy.
1. Purpose of this notice
Our clients often ask:
- what data Maximus will hold
- where that data sits
- how it is protected
- who can access it
- how long it is retained
This notice provides a practical summary of our current approach.
2. Types of data we typically handle
The exact data we handle depends on the scope of work, but typically includes:
Business contact data
- names
- work email addresses
- work phone numbers
- company names
- job titles
- LinkedIn URLs
- business location details
Client commercial and campaign data
- target account lists
- prospecting criteria
- CRM records
- campaign activity and engagement data
- notes, tags, and account status information
- call task data
- meeting and outreach outcomes
- reporting dashboards and performance data
Client team data
- names and work contact details of client team members
- meeting notes
- project communications
- access permissions and system user information
3. Data we generally do not require
Unless specifically agreed in writing, Maximus does not typically require:
- end-customer financial account details
- payment card information
- detailed health information
- government-issued identity records
- highly sensitive regulated records unrelated to GTM execution
For regulated clients, we aim to minimise data exposure and keep the scope of data handling proportionate to the services being delivered.
4. How we receive data
We may receive data through:
- website forms
- email and calendar communications
- client-provided spreadsheets or exports
- CRM and sales tools
- public and licensed business data sources
- enrichment and workflow tools
- meeting notes and project collaboration tools
5. How we use data
We use data only for legitimate business and service delivery purposes, including:
- building and enriching target lists
- running outbound and account-based campaigns
- setting up or managing workflows in CRM and sales systems
- analysing performance
- coordinating with client teams
- delivering reports and recommendations
We do not use client data for unrelated purposes.
6. Where data may be stored
Depending on the engagement, data may be stored in systems used by Maximus or the client, including:
- email and document platforms
- CRM platforms
- sales engagement platforms
- enrichment or workflow tools
- project and note-taking systems
- reporting tools
These systems may store or process data in New Zealand or overseas, depending on the provider.
If requested by a client, Maximus can provide an engagement-specific list of the key systems used for that client.
7. Access controls
Access to data is limited to personnel and contractors who need access to perform their role. Our approach may include:
- role-based permissions
- restricted workspace access
- account-level authentication controls
- revocation of access when no longer required
- confidentiality obligations in contractor and service arrangements
8. Security measures
We take reasonable steps to safeguard data, including steps aligned with the Privacy Act 2020 requirement to use safeguards that are reasonable in the circumstances. These measures may include:
- reputable cloud infrastructure
- secure account access practices
- MFA where supported and appropriate
- document and folder access restrictions
- controlled sharing settings
- device and password hygiene
- limiting unnecessary duplication of client data
- deletion or archival practices where appropriate
9. Overseas providers
Some of the software tools used in modern GTM execution may involve offshore storage or processing.
Where personal information is disclosed or made available to service providers outside New Zealand, Maximus takes reasonable steps to assess and manage privacy risk, consistent with New Zealand requirements relating to overseas disclosures.
10. Retention and deletion
We aim to retain data only for as long as reasonably necessary for:
- delivering services
- maintaining business and project records
- complying with legal, insurance, tax, or contractual requirements
- handling disputes or follow-up work
At the end of an engagement, we may return, delete, archive, or de-identify client data depending on:
- the contractual position
- the type of data
- legal or operational requirements
- backup and system limitations
Clients may request engagement-specific retention or deletion terms in their agreement.
11. Incident response
If we identify a material security issue or privacy incident affecting client data, we will investigate and take appropriate steps. Where required, we will notify the relevant client and comply with applicable legal obligations relating to privacy breach assessment and notification.
12. Client-specific arrangements
For some engagements, particularly in regulated industries such as financial services, we may agree additional data handling terms in:
- a statement of work
- a data schedule
- a confidentiality agreement
- a vendor due diligence response
If a client requires a more detailed data map or supplier questionnaire response, we can provide one specific to that engagement.
13. Contact
For security, privacy, or data handling queries, contact:
