Skip to main content

SECURITY POLICY

Effective date: 19 July 2026

1. Our security commitment

TDA Immigration & Student Services Limited recognises that immigration matters involve confidential and often highly sensitive personal information.

We are committed to taking reasonable administrative, organisational and technical safeguards to protect information from:

  • unauthorised access;
  • loss;
  • misuse;
  • alteration;
  • unauthorised disclosure;
  • copying;
  • destruction; and
  • disruption.

This public Security Policy summarises our approach. It does not disclose confidential technical details that could weaken our security.

2. Scope

This Policy applies to information and systems used by TDA, including:

  • our Website;
  • online forms;
  • customer relationship management systems;
  • authorised artificial intelligence services;
  • email and communication systems;
  • documents and client records;
  • staff accounts and devices; and
  • approved third-party service providers.

3. Shared responsibility

Security is a shared responsibility between TDA, our technology providers, our personnel, our clients and other users.

TDA maintains controls within its reasonable control. Our cloud providers are responsible for the security of the infrastructure and services they operate, according to their contractual terms and published security commitments.

Clients and Website users are responsible for protecting their own:

  • devices;
  • email accounts;
  • passwords;
  • internet connections;
  • downloaded documents; and
  • access to communications sent by TDA.

4. Technology platforms

TDA uses established business technology platforms, including Zoho and OpenAI business services.

Zoho applications

TDA may use:

  • Zoho Sites to operate Website functions;
  • Zoho Forms to collect online information;
  • Zoho CRM to manage enquiries, clients, communications and business records; and
  • other authorised Zoho applications.

Zoho publishes security practices that include secure software development, encrypted network transmission, access controls, monitoring, authentication controls and security review processes.

The availability of particular controls can depend on the relevant Zoho product, subscription and TDA configuration.

OpenAI business services

TDA may use OpenAI business services, including ChatGPT, to assist with authorised administrative, research, document-review and drafting tasks.

OpenAI publishes business-data protections that include:

  • business data not being used to train its models by default;
  • encryption of business data in transit and at rest;
  • authentication and administrative controls;
  • independent security and compliance assessments; and
  • organisational controls for business workspaces.

TDA personnel must use only approved accounts and workspaces for business information.

5. Human responsibility and artificial intelligence

Artificial intelligence is a support tool and does not replace the professional responsibility of a licensed immigration adviser.

Where artificial intelligence assists with professional work:

  • outputs are reviewed by an authorised person;
  • legal and policy information is checked against appropriate sources;
  • factual claims are checked against client records and evidence;
  • artificial intelligence is not permitted to make the final immigration decision;
  • access is restricted to authorised users;
  • staff must not intentionally place client information into unapproved public systems; and
  • the use of artificial intelligence remains subject to privacy, confidentiality and professional obligations.

TDA remains responsible for the immigration advice and services it provides.

6. Access controls

TDA seeks to apply access according to role, responsibility and business need.

Controls may include:

  • individual user accounts;
  • strong password requirements;
  • multi-factor authentication;
  • role-based permissions;
  • restricted administrative privileges;
  • periodic access reviews;
  • prompt removal or adjustment of access when responsibilities change; and
  • secure authentication methods supported by our providers.

Users must not share passwords or permit unauthorised people to access TDA systems.

7. Encryption and transmission security

TDA uses service providers that support encrypted transmission of information over public networks.

Depending on the service and configuration, information may also be encrypted at rest or at field level.

Encryption reduces security risk but does not eliminate every risk. Users should avoid sending unnecessary sensitive information through ordinary email or an unapproved channel.

Where TDA provides a secure submission method, clients should use that method.

8. Data minimisation

TDA seeks to collect and retain only the information reasonably necessary for:

  • assessing an enquiry;
  • providing agreed immigration services;
  • meeting professional and legal obligations;
  • operating our business; and
  • protecting our clients and systems.

Clients should not send unnecessary identity, health, financial or character information through a general Website enquiry.

9. Personnel security

TDA’s personnel are expected to:

  • maintain client confidentiality;
  • access information only for authorised purposes;
  • follow password and authentication requirements;
  • use approved systems;
  • protect devices and documents;
  • report suspected security incidents;
  • verify unusual or sensitive requests;
  • avoid unauthorised disclosure; and
  • comply with applicable professional and privacy obligations.

Access to sensitive information is limited to those who reasonably require it to perform their role.

10. Device and account security

Reasonable security measures may include:

  • current operating systems and software;
  • automatic or timely security updates;
  • anti-malware or endpoint protections;
  • screen locking;
  • device authentication;
  • secure disposal or reconfiguration of devices;
  • restricted administrator access; and
  • controls over locally stored information.

The exact controls may differ according to device type, risk and operational need.

11. Email and communication security

Email can be intercepted, misdirected, accessed through a compromised account or sent to the wrong recipient.

TDA takes reasonable care when sending sensitive information, but clients should also:

  • keep their email account secure;
  • use a strong, unique password;
  • enable multi-factor authentication where available;
  • check recipient details before sending information;
  • tell us promptly if an email account has been compromised;
  • avoid using shared or public devices for confidential communications; and
  • verify unexpected requests for money or sensitive information by contacting TDA through a known method.

TDA will not intentionally ask you to disclose your password.

You should independently verify any unexpected change to TDA’s bank account details before making payment.

12. Online form security

TDA uses approved online form services to collect information.

Our controls may include:

  • encrypted connections;
  • access restrictions;
  • form validation;
  • anti-spam or CAPTCHA controls;
  • verification controls where appropriate;
  • secure account authentication; and
  • field-level protections where supported and configured.

Do not submit malicious files, unlawful material or information that is not required for the stated purpose.

13. Third-party service providers

TDA assesses service providers with regard to factors such as:

  • the nature and sensitivity of the information;
  • provider security and privacy information;
  • contractual protections;
  • access controls;
  • encryption capabilities;
  • data location and overseas processing;
  • reliability and business continuity; and
  • the ability to meet TDA’s legal and professional obligations.

No third-party platform can be guaranteed to be free from all risk. TDA uses providers and configurations that it considers reasonable for its operations and reviews them where appropriate.

14. Backups, availability and continuity

TDA uses cloud services and operational measures intended to support reasonable availability and recovery.

Depending on the system, these may include:

  • provider-level redundancy;
  • backups;
  • version history;
  • recovery processes;
  • secure copies of essential records;
  • alternative communication arrangements; and
  • procedures for responding to service interruption.

TDA does not guarantee uninterrupted access to any Website or third-party platform.

15. Monitoring and logging

TDA and its service providers may maintain system, access, security and audit logs for purposes including:

  • detecting suspicious activity;
  • troubleshooting;
  • investigating incidents;
  • protecting accounts and systems;
  • verifying administrative activity; and
  • complying with legal obligations.

Monitoring is undertaken for legitimate security and operational purposes and is subject to applicable privacy requirements.

16. Security incident management

A security incident may include:

  • unauthorised account access;
  • malware;
  • phishing;
  • loss of a device or document;
  • accidental disclosure;
  • compromised credentials;
  • unauthorised alteration;
  • service disruption; or
  • a privacy breach.

When TDA becomes aware of a suspected incident, we will take steps appropriate to the circumstances, which may include:

  1. containing the incident;
  2. protecting affected accounts or systems;
  3. preserving relevant evidence;
  4. investigating what occurred;
  5. assessing affected information and individuals;
  6. reducing the likelihood of further harm;
  7. restoring systems or information;
  8. notifying service providers, insurers or professional advisers;
  9. notifying affected individuals and regulators where required; and
  10. reviewing controls and implementing appropriate improvements.

17. Privacy-breach notification

Where an incident involves personal information, TDA will assess it under the Privacy Act 2020.

If the breach has caused or is likely to cause serious harm, TDA will notify the Office of the Privacy Commissioner and affected individuals unless a lawful exception applies.

18. Security limitations

Despite reasonable safeguards, no method of internet transmission, cloud storage, email communication or electronic processing is completely secure.

Security can also be affected by factors outside TDA’s control, including:

  • compromised client email accounts;
  • weak or reused passwords;
  • infected personal devices;
  • unauthorised access by people with physical access to a device;
  • telecommunications failures;
  • sophisticated cyberattacks;
  • vulnerabilities in third-party systems; and
  • incorrect information supplied by a user.

TDA does not claim that security risk can be eliminated. Our objective is to identify, reduce, manage and respond to risk appropriately.

19. Client security guidance

Clients can help protect their information by:

  • using strong and unique passwords;
  • enabling multi-factor authentication;
  • keeping devices and software updated;
  • checking that they are using TDA’s correct Website and email address;
  • not sending passwords by email;
  • not sending unnecessary sensitive information;
  • using secure document-submission methods provided by TDA;
  • checking email recipients carefully;
  • contacting TDA independently about unusual payment instructions;
  • telling us immediately if information was sent to the wrong person; and
  • notifying us if their email account, device or identity documents may have been compromised.

20. Reporting a security concern

If you believe that:

  • TDA’s Website or system has a security weakness;
  • your information may have been accessed without authority;
  • a message claiming to be from TDA is fraudulent;
  • you have sent information to the wrong recipient; or
  • your account or device has been compromised,

please contact us promptly:

Security Contact
TDA Immigration & Student Services Limited
Email: info@tdavisa.nz
Telephone: +64 9 337 0380

For urgent concerns, include “URGENT SECURITY CONCERN” in the email subject line.

Do not include unnecessary sensitive information in the initial report.

21. Responsible disclosure

We welcome responsible reports of genuine security vulnerabilities affecting our Website or systems.

When reporting a suspected vulnerability:

  • provide enough detail for us to investigate;
  • do not access, copy, alter or delete another person’s information;
  • do not disrupt our systems or services;
  • do not use social engineering;
  • do not demand payment or threaten disclosure;
  • do not publicly disclose the issue before TDA has had a reasonable opportunity to investigate and respond; and
  • comply with applicable law.

This Policy does not authorise access to any account, system or information.

TDA does not operate a formal bug-bounty programme and does not promise payment for reports.

22. Review and changes

TDA may update this Security Policy to reflect:

  • changes to technology;
  • changes to providers or configurations;
  • identified risks;
  • security incidents;
  • changes to law or professional obligations; and
  • improvements to our security practices.

The current version will be published on our Website with its effective date.

23. Contact

Questions about this Security Policy may be directed to:

TDA Immigration & Student Services Limited
300 Richmond Road
Grey Lynn
Auckland
New Zealand

Email: info@tdavisa.nz
Telephone: +64 9 337 0380