Company policies

Practical safeguards for information, service and trust.

This framework explains how ClearDesk approaches personal information, confidential records, system access, responsible technology and service continuity across New Zealand, the UAE and Sri Lanka.

How to read this page: it is a public summary of our operating approach. The signed engagement, client instructions and applicable law control where they are more specific. Requirements can differ by service, sector, data location and jurisdiction.

Core controls

Our policy commitments

Simple enough to understand. Specific enough to guide the work.

01

Data protection & privacy

  • Collect only information relevant to the agreed work
  • Use it for stated business purposes
  • Support access, correction and other applicable rights
  • Do not sell client or applicant information
02

Security & access

  • Need-to-know, role-based access
  • MFA where the system supports it
  • Approved devices and transfer methods
  • Access reviewed and removed when no longer required
03

Confidentiality

  • Confidentiality obligations for people handling client data
  • Client information separated by engagement
  • Information shared only for agreed delivery or legal duties
  • Queries escalated before uncertain disclosure
04

Records & disposal

  • Retention follows the engagement and applicable law
  • NZ tax records generally kept for at least seven tax years
  • UAE Corporate Tax records generally kept for at least seven years
  • Secure return or deletion when retention is no longer required
05

Cross-border handling

  • Data locations and access considered during onboarding
  • Client instructions recorded
  • Supplier and transfer safeguards reviewed where applicable
  • Sector and free-zone requirements checked when relevant
06

Incident response

  • Contain, preserve facts and assess impact
  • Escalate internally without avoidable delay
  • Notify clients, regulators or affected people when required
  • Record actions and improve controls after review
07

Responsible technology & AI

  • No confidential client data in unapproved public AI tools
  • Human review for material outputs
  • No automated professional advice or final filing decisions
  • Technology selected for a defined business purpose
08

Third parties

  • Use providers appropriate to the task and data risk
  • Clarify who performs each responsibility
  • Limit access to what delivery requires
  • Review changes that materially affect the engagement
09

Continuity & quality

  • Document calendars, workpapers and decisions
  • Back up records according to the agreed system
  • Review work against scope and supporting evidence
  • Maintain handover and escalation routes
Requests and concerns

A clear route to raise something

Contact info@cleardesk.co.nz for a privacy request, information-security concern, service complaint or policy question. Please avoid including sensitive records in the first message; we will confirm a suitable transfer method if documents are needed.

  • We acknowledge the issue and identify the responsible contact.
  • We verify the relevant facts, engagement terms and legal requirements.
  • We explain the outcome or next step in plain language.
  • We record corrective actions where a process needs improvement.

Related documents

Engagement controlsConfirmed in the client proposal and engagement terms

Policy framework updated 5 September 2026. ClearDesk reviews this framework when services, systems or relevant requirements materially change.

Need a policy or security detail for onboarding?

Tell us what your organisation needs to review. We can explain the relevant operating control and agree engagement-specific responsibilities in writing.