Legal

Privacy Policy

How ViAGO and Black Belt in Thinking handle the personal information in our care.

Last updated: 27 July 2026

1. Who we are

This policy applies to two companies:

  • ViAGO Holdings Limited, NZBN 9429050445585, 11 Pohutukawa Drive, Pukete, Hamilton 3200, New Zealand
  • ViAGO Pty Limited, ABN 95 643 259 705, 75 Carshalton Street, Croydon Park NSW 2133, Australia

ViAGO Holdings Limited is the parent company. In this policy, “ViAGO”, “we”, “us” and “our” mean whichever of those two companies you are dealing with. If you engage us in New Zealand, that is usually ViAGO Holdings Limited. If you engage us in Australia, that is usually ViAGO Pty Limited.

We are a CargoWise Service Partner. We provide consulting services to freight forwarders, customs brokers and other businesses using CargoWise, and we deliver the Black Belt in Thinking (BBIT) training programme.

This policy covers both brands, ViAGO and Black Belt in Thinking, and our websites at viago.com.au and blackbeltinthinking.com.


2. The laws that apply

We handle personal information in accordance with the Privacy Act 2020 (New Zealand) and, where it applies to us, the Privacy Act 1988 (Cth) (Australia) and the Australian Privacy Principles.

“Personal information” means information about an identifiable individual. It includes direct identifiers such as a name or an email address, and also information that identifies a person in combination with other information, such as a staff member's initials against a task in a workflow system.


3. Our role, and our clients' role

Most of the personal information we encounter is not ours. It belongs to our clients. Because our obligations differ in each case, we deal with them separately below.

3.1 Information we collect for our own purposes

This is information we collect and control ourselves: enquiries from our website, contact details for people at client and prospective client organisations, records of the work we carry out, training participant records, and information about our own staff and contractors.

For this information we are the organisation responsible, and the rest of this policy describes how we handle it.

3.2 Information held in our clients' systems

When we are engaged to configure or improve a client's CargoWise environment, the client gives us access to their own system. That system contains information about their staff, their customers, and the parties to their shipments.

For that information:

  • The client remains responsible for it. It is their system and their information.
  • We act on the client's instructions, for the purpose of delivering the services they have engaged us for, and no other purpose.
  • Our obligations are set out in our services agreement with that client.
  • We do not use that information for our own purposes, we do not disclose it to anyone else, and we do not use it to market to anyone.

The limits of our role. We are not a managed service provider. We configure CargoWise. We do not administer our clients' IT environments, we do not provision or manage user accounts or access for their staff, we do not hold or control their credentials, and we do not have custody of their systems between engagements. The client creates a login for us in their own system, decides what it can reach, and can revoke it at any time.

Our relationship with WiseTech Global. Your organisation licenses CargoWise directly from WiseTech Global, and WiseTech handles your data under its own terms with you. We are not a party to that arrangement and we are not a WiseTech subprocessor. We are a separate provider you engage directly, and our handling of your information is governed by our services agreement with you and this policy.

If you are an individual whose information is held in a client's CargoWise system and you wish to access or correct it, you should contact that organisation directly, as it is their record. If you contact us, we will refer you to them where we are able to.


4. What we collect

4.1 Website enquiries

When you complete a form on our website we collect the contact details you provide, such as your name, email address and phone number, together with the details of your enquiry.

4.2 Clients and prospective clients

In the course of an engagement we collect and hold:

  • Contact details and roles for the people we work with at your organisation
  • Correspondence, meeting notes, and records of decisions
  • Organisation charts, where you provide them. These usually contain names and business roles.
  • Configuration exports and screenshots taken from your CargoWise environment. These frequently include staff names, initials, group assignments and task allocations, because CargoWise workflow screens are structured that way. We treat them as containing personal information.
  • Recordings and transcripts of meetings, where these are made (see section 6)

We do not seek out compliance screening results, sanctions matches or denied party screening data. On rare occasions we may see such information incidentally, for example where it is displayed while a client is demonstrating an issue to us. We do not extract, copy or retain it.

4.3 Training participants

For BBIT and other training programmes we collect participant names, work email addresses and the work each participant produces during the programme.

PAVE certification, PCO, PCS and PCP, is delivered through WiseTech Academy. We authored those certifications, but we do not administer enrolments and we do not hold participant or certification records for them. Enquiries about a PAVE certification record should go to WiseTech Academy.

4.4 Staff, contractors and applicants

We collect the information needed to employ or engage people and to run our business. We hold it only for as long as we need it and for as long as employment and tax law requires.

4.5 Website technical information

Our web host keeps server logs, which record technical information such as IP address, browser type and the files requested. These are used to keep the site running and to protect it from abuse. We do not turn them into visitor analytics and we do not use them to work out who you are. See section 9.


5. Why we use personal information

We use personal information to:

  • Respond to enquiries and provide quotes
  • Deliver the services and training you have engaged us for
  • Manage our relationship with you, including invoicing and support
  • Improve how we deliver our services
  • Send you information about our services from time to time, where you have asked for it or where you are an existing client and it is relevant to your engagement. You can ask us to stop at any time.
  • Meet our legal, tax and record keeping obligations

We do not run bulk marketing campaigns. We do not sell personal information, and we do not disclose it to anyone for their own marketing purposes.


6. Meeting recordings and transcripts

We sometimes record or transcribe meetings and calls so we have an accurate record of what was discussed and agreed.

Where we do this:

  • The platform we use displays a notice to all participants when recording starts.
  • If you would prefer a meeting not be recorded, let us know and we will not record it.
  • Recordings and transcripts are stored in our internal systems and are accessible only to the ViAGO personnel working on your engagement.
  • We keep them for 90 days, which is when Microsoft Teams deletes meeting recordings automatically, after which they are deleted unless we are required to retain a specific record for longer.

7. Who we share personal information with

We disclose personal information to:

  • Service providers who host our systems and support our business, including cloud storage, email, our customer relationship management system, accounting software, electronic signature services, collaboration and whiteboarding tools, and AI assistance tools. They may only use the information to provide their service to us.
  • Google, when you submit our contact form, because the form uses Google reCAPTCHA to check the submission is not automated. See section 9.
  • Professional advisers, such as our accountants and lawyers, where needed.
  • Anyone else, where you have agreed, or where we are required or authorised by law.

We do not disclose personal information to WiseTech Global unless you ask us to, or it is necessary to resolve a support issue and you have agreed to it.

Our client work is carried out by our own people, whether employed by us or engaged directly as individual contractors, all of whom are subject to the same confidentiality obligations. We do not subcontract client work to other firms.


8. Sending information overseas

Some of the service providers we use store or access information outside Australia and New Zealand. The countries involved are Australia, New Zealand and the United States. Where a provider's support or security teams are located in another country, they may access information from there.

Before we disclose personal information to an overseas service provider we take reasonable steps to satisfy ourselves that they protect it to a standard comparable to the Privacy Act 2020 (New Zealand), as required by Information Privacy Principle 12.

We maintain an internal register of the service providers we use, what information each holds and where it is held. If you are a client and require that detail for your own due diligence, contact us and we will provide it.


9. Our website and cookies

We do not track visitors to our website. We do not run web analytics, advertising pixels, remarketing tags or behavioural tracking of any kind. We do not know which pages you viewed before contacting us, and we cannot connect your enquiry to your browsing.

The following set cookies:

  • Cloudflare, which serves our website, sets a cookie that distinguishes real visitors from automated traffic. This is what keeps the site available and protects it from attack.
  • Our contact form, which is provided by HubSpot, loads Google reCAPTCHA to prevent spam submissions. reCAPTCHA sets a cookie on Google's domain and assesses whether a submission is likely to be automated. This occurs only on our contact page.

These exist to make the site work and to keep it free of abuse. They are not used for marketing or to build a profile of you.

You can block or delete cookies through your browser settings. If you block them the contact form may not work, in which case please email us instead.


10. AI and automated tools

We use AI assistance tools in our work, for example to help draft documents, analyse configuration and prepare materials.

  • We use these tools under commercial terms which prohibit the provider from using our content to train their models.
  • Microsoft 365 Copilot runs within our Microsoft tenancy, with data at rest in Australia.
  • Our other AI provider is located in the United States.
  • We do not put client data into AI tools where doing so would breach our confidentiality obligations to that client.
  • We do not use AI to make decisions about individuals. No automated system of ours makes any decision affecting a person's rights, entitlements or employment.

11. How we protect personal information

We take reasonable steps to protect personal information from misuse, loss, and unauthorised access, modification or disclosure. It is held in access controlled systems, and access is limited to the people who need it for the work they are doing. We do not describe our specific security controls here, because publishing them would weaken them.

Everyone who works on your engagement, whether employed by us or engaged directly as an individual contractor, is subject to confidentiality obligations.

Where we access a client's CargoWise environment we use a login the client creates for us in their own system, with the access they choose to grant. We do not create, hold or manage credentials for anyone else, and the client can revoke our access at any time without reference to us.

Our own email, documents and meeting recordings are held in Microsoft 365 with data at rest located in Australia.

Training participant material is held on individually secured boards, accessible only to that participant and their instructor.

No system is completely secure. Section 13 sets out what we do if a breach occurs.


12. How long we keep personal information

We keep personal information for as long as we need it for the purposes described in this policy, and for as long as the law requires us to keep it, including tax and record keeping obligations in Australia and New Zealand. When we no longer need it, we delete it or de-identify it.

Some of this happens automatically. Meeting recordings are deleted by Microsoft Teams after 90 days.

If you would like us to delete personal information we hold about you, contact our Privacy Officer and we will do so unless we are required to keep it.


13. Privacy breaches

If we become aware of a privacy breach we assess it promptly. If it is likely to cause serious harm we will notify the affected individuals and the relevant regulator: the Office of the Privacy Commissioner in New Zealand, as soon as practicable, and the Office of the Australian Information Commissioner where the Australian scheme applies. Where a breach involves information in a client's system we will inform that client immediately so they can meet their own obligations.


14. Accessing and correcting your information

You can ask us for a copy of the personal information we hold about you, and ask us to correct it if it is wrong.

Contact our Privacy Officer using the details in section 16. We may need to verify your identity first. We will respond within 20 working days in New Zealand, and within a reasonable period, usually 30 days, in Australia. There is no charge for making a request.

If we are unable to provide what you have asked for, we will explain why in writing.


15. Complaints

If you believe we have mishandled your personal information, please raise it with us first. Write to our Privacy Officer at the address in section 16 and we will investigate and respond, normally within 30 days.

If you are not satisfied with our response:

  • New Zealand: Office of the Privacy Commissioner, privacy.org.nz, 0800 803 909
  • Australia: Office of the Australian Information Commissioner, oaic.gov.au, 1300 363 992

16. Contact us

Privacy Officer
Peter Cronin, Managing Director
Email: privacy@viago.com.au
Phone: +61 414 965 929

ViAGO Holdings Limited, 11 Pohutukawa Drive, Pukete, Hamilton 3200, New Zealand
ViAGO Pty Limited, 75 Carshalton Street, Croydon Park NSW 2133, Australia


17. Changes to this policy

We may update this policy from time to time. The current version is always available on our website, with the date it was last updated shown at the top. If we make a significant change we will note it on our website.