Privacy Policy

Effective date: January 22nd 2025Last updated: February 12th 2026

This Privacy Policy explains how Maximus Limited ("Maximus", "we", "us", or "our") collects, uses, stores, and discloses personal information.

Maximus helps B2B companies build and run go-to-market, outbound, lead generation, and revenue operations systems. In doing so, we may collect and process personal information relating to website visitors, prospective clients, client personnel, and business contacts. This reflects the GTM and outbound services described on our website.

We are committed to handling personal information in accordance with the New Zealand Privacy Act 2020. The Act requires organisations to have a privacy officer, apply reasonable safeguards to personal information, and comply with rules governing overseas disclosures.

1. Who we are

  • Legal entity: Maximus Limited
  • Website: www.maximusgtm.com
  • Email: ian@maximusgtm.com
  • Privacy Officer: Ian Bishop
  • Privacy contact email: privacy@maximusgtm.com
  • Registered address: 26 Tutaritari Road, Whitianga, 3591, New Zealand

2. What personal information we collect

Information you provide directly

  • name
  • work email address
  • phone number
  • company name
  • job title
  • enquiry details
  • meeting notes or correspondence
  • any other information you choose to provide

Information we collect through our website

  • IP address
  • browser type
  • device information
  • pages visited
  • referral source
  • approximate location data
  • cookie and analytics data
  • form submissions

Information we collect in the course of providing services

  • contact lists and prospect data
  • business contact details
  • CRM records
  • campaign activity data
  • sales engagement data
  • call notes, meeting notes, and account research
  • client team member details
  • other business information provided by a client for the purpose of delivering services

Information from third parties

We may also receive personal information from public sources, social networks, data providers, enrichment tools, client systems, referral partners, and software platforms used in connection with our services.

3. Why we collect personal information

We may collect, use, and process personal information to:

  • respond to enquiries and requests
  • provide services to clients
  • build, operate, and improve GTM, outbound, lead generation, and revenue workflows
  • create prospect lists and account intelligence
  • manage relationships with prospective and current clients
  • communicate with you about our services
  • send marketing communications where lawful
  • run analytics, reporting, and performance measurement
  • maintain security and prevent misuse
  • comply with legal and regulatory obligations
  • protect our legal rights and interests

4. How we use personal information on behalf of clients

In many cases, Maximus acts as a service provider to clients. That means we may handle personal information that a client provides to us, or asks us to collect or enrich, for the limited purpose of delivering agreed services such as:

  • outbound campaign setup and management
  • CRM and data workflow configuration
  • lead generation and list building
  • account research and targeting
  • reporting and analysis
  • sales process support

Where we process personal information on behalf of a client, we do so in accordance with our agreement with that client and subject to applicable law.

5. What we do not intend to collect unless specifically agreed

Our services are generally designed around business contact and GTM data, not highly sensitive personal information. Unless expressly agreed in writing, we do not intend to collect, hold, or process:

  • customer financial account data
  • health information
  • government identity documents
  • special category or highly sensitive personal information
  • regulated client file data beyond what is reasonably necessary for the services

For clients in regulated industries, including financial services, any handling of more sensitive categories of data should be separately documented in the applicable statement of work or data schedule.

6. Cookies, analytics, and tracking

We may use cookies, analytics tools, and similar technologies to understand website usage, improve website performance, and support marketing and remarketing activities. These technologies may collect information such as:

  • pages visited
  • time on site
  • referral source
  • browser and device information
  • interactions with website forms or content

You can usually control cookies through your browser settings. Some site features may not function properly if cookies are disabled.

7. Who we may share personal information with

We may disclose personal information to:

  • our employees, contractors, and advisers who need it to perform their work
  • software and infrastructure providers that support our business and service delivery
  • analytics, CRM, sales engagement, communications, and workflow providers
  • professional advisers such as lawyers, accountants, and insurers
  • regulators, law enforcement, or government agencies where required by law
  • a purchaser or successor in connection with a business sale, merger, or restructure

8. Overseas storage and disclosure

Maximus may use software tools and service providers that store or process information outside New Zealand. New Zealand privacy law places rules around disclosures of personal information outside New Zealand, including under Information Privacy Principle 12.

Where personal information is disclosed or made available to service providers outside New Zealand, we take reasonable steps to ensure that appropriate protections are in place. These steps may include:

  • using reputable providers with published privacy and security commitments
  • putting contractual protections in place where appropriate
  • limiting the information shared to what is reasonably necessary
  • assessing the role of the overseas provider in relation to the information

9. How we protect personal information

We use reasonable technical and organisational safeguards to protect personal information from loss, misuse, unauthorised access, modification, or disclosure. These safeguards may include:

  • role-based access controls
  • password management and multi-factor authentication where supported
  • secure cloud platforms
  • restricted access to client workspaces and documents
  • staff and contractor confidentiality obligations
  • data minimisation practices
  • secure disposal or deletion practices where appropriate

No method of transmission or storage is completely secure. We therefore cannot guarantee absolute security.

10. How long we keep personal information

We retain personal information only for as long as reasonably necessary for:

  • the purposes for which it was collected
  • delivering services
  • maintaining business records
  • resolving disputes
  • complying with legal, tax, insurance, or regulatory obligations

Retention periods may differ depending on the type of information and the services involved. Where appropriate and reasonably practicable, we will delete or de-identify personal information when it is no longer required.

11. Access and correction

You may request access to personal information we hold about you, and request correction if you believe it is inaccurate.

To make a request, contact us at privacy@maximusgtm.com.

We may need to verify your identity before responding. We will handle requests in accordance with applicable law.

12. Marketing communications

We may send marketing or service-related communications to business contacts where lawful. You can unsubscribe from marketing emails at any time using the unsubscribe link or by contacting us directly.

13. Privacy breaches

If we become aware of a privacy breach affecting personal information we hold, we will assess it promptly and take steps required by law. New Zealand guidance states that serious privacy breaches must be notified to the Privacy Commissioner as soon as possible.

Where appropriate, we will also notify affected clients or individuals.

14. Third-party links and platforms

Our website or communications may contain links to third-party websites or integrate with third-party platforms. We are not responsible for the privacy practices of those third parties.

15. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. The latest version will be posted on our website with the revised effective date.

16. Contact us

If you have any questions, concerns, or privacy requests, please contact:

Privacy Officer

Maximus Limited / Maximus GTM

privacy@maximusgtm.com

26 Tutaritari Road, Whitianga, 3591, New Zealand

If you are not satisfied with our response, you may contact the Office of the Privacy Commissioner in New Zealand. The Privacy Commissioner provides guidance on privacy rights and obligations under the Privacy Act 2020.