Privacy and information care

Privacy policy

How we collect, use, protect and manage personal information when you visit our website or work with YJ Consulting.

Last updated 28 July 2026

At a glance

Necessary information. Clear purposes. Human accountability.

01

Purpose-led collection

We collect personal information only where it is reasonably necessary for a lawful business purpose.

02

No website form storage

Our enquiry form prepares an email in your own email application. It does not submit the draft to our website.

03

Cookie-free website analytics

We use Ahrefs Web Analytics to understand aggregated website use. It does not use analytics or advertising cookies by default, and we do not use it for cross-site tracking.

04

Your information, your rights

You may ask for access to or correction of personal information we hold about you.

01

Scope and who we are

Crescellere Limited, trading as YJ Consulting (YJ Consulting, we, us or our), is an Auckland-based management consultancy and a New Zealand agency for the purposes of the Privacy Act 2020.

This policy applies to personal information we handle about website visitors, people who enquire or book a meeting, current and former clients, client personnel and stakeholders, suppliers, contractors, professional advisers and other business contacts. It applies whether the information is provided through this website, by email, in a meeting, through a client engagement or by another lawful means.

A collection notice, engagement agreement or project-specific notice may provide more detail for a particular service. Those documents supplement this policy. Nothing in this policy limits your rights under New Zealand law.

02

Information we collect

The information we collect depends on how you interact with us and what is reasonably necessary for the relevant purpose. It may include:

  • Contact and enquiry information: your name, email address, organisation, role, area of interest, message, meeting preferences and correspondence.
  • Client and service information: instructions, business context, objectives, stakeholder details, source documents, working notes, decisions, approvals, delivery records and engagement history.
  • Administrative and commercial information: engagement terms, invoicing details, payment and transaction records, tax records, supplier details and consent or communication preferences.
  • Identity or verification information: information reasonably needed to confirm identity, authority or a person's right to make a request. We do not collect copies of identity documents unless they are necessary.
  • Technical and security information: IP address, device and browser type, requested page, time of request, security events and similar operational log data processed when the website is delivered.

An engagement may involve sensitive information, including employment, financial, immigration, health, dispute or allegation-related information. We ask for this only where it is necessary and appropriate to the agreed scope, and we apply care proportionate to its sensitivity.

If you give us personal information about another person, you should be authorised to do so and, where appropriate, make sure they understand how their information will be handled. We may also need to notify that person directly.

03

How we collect information

We collect information directly from you where that is practicable. Direct collection may occur through email, meetings, documents, calls, bookings, invoices or agreed project tools. At or before collection, we take reasonable steps to explain who is collecting the information, why it is needed, the intended recipients, whether supply is voluntary or required, the consequences of not supplying it, and your access and correction rights, unless the Privacy Act permits an exception.

We may also receive information from an organisation you represent, a client or client representative, an authorised adviser, referee, contractor, public source, government agency or another person where collection is lawful and relevant to our work.

Indirect collection and IPP3A

If we collect personal information about you from someone else and Information Privacy Principle 3A applies, we will take reasonable steps to notify you of the required matters before collection or as soon as practicable afterwards. We will only rely on a statutory exception where it applies to the circumstances; an exception is not treated as the default.

We use fair and lawful collection methods and do not collect in a way that is unreasonably intrusive, particularly where children or young people are involved.

04

Why we use personal information

We may use personal information to:

  • respond to enquiries and arrange conversations;
  • assess fit, define scope, prepare proposals and manage engagements;
  • deliver agreed advisory, operational, documentation and coordination work;
  • communicate with clients, authorised stakeholders, suppliers and professional advisers;
  • manage instructions, approvals, versions, records, invoices and payments;
  • maintain service quality, business continuity, security, auditability and fraud prevention;
  • respond to privacy requests, complaints, disputes, insurance matters and legal obligations; and
  • send relevant business communications where permitted by the Unsolicited Electronic Messages Act 2007.

We use information for the purpose for which it was obtained, a directly related purpose, or another purpose permitted by law. Before using or disclosing personal information, we take reasonable steps to ensure it is accurate, up to date, complete, relevant and not misleading for that purpose.

We do not sell or rent personal information, provide it to data brokers, or use it for unrelated advertising profiles.

05

Your choices at collection

Providing information through our website or by email is generally voluntary. If you do not provide information needed to understand an enquiry, verify authority, meet a legal requirement or deliver an agreed service, we may be unable to respond, accept the engagement or complete the relevant work.

If a particular collection is required by law or contract, we will identify that requirement where it is not already clear. You can ask why information is needed before providing it.

06

Who we share information with

We disclose personal information only where it is connected with the purpose for which it was collected, you have authorised the disclosure, or another basis under the Privacy Act or other law applies. Depending on the context, recipients may include:

  • YJ Consulting personnel and contractors who need the information for authorised work and are subject to confidentiality and handling requirements;
  • service providers supporting website hosting, security, email, scheduling, document collaboration, accounting, storage, backup and business administration;
  • a client's authorised personnel, stakeholders or other professional advisers where this is part of the agreed scope;
  • our legal, accounting, insurance, security or other professional advisers where reasonably necessary; and
  • a court, tribunal, regulator, government agency, law enforcement body or other person where disclosure is required or authorised by law, or is necessary to prevent or lessen a serious threat as permitted by law.

We use proportionate due diligence, contractual controls, access limits and data minimisation when a provider processes personal information for us. We do not authorise a provider to use information for its own unrelated marketing.

07

Overseas processing and disclosure

Some providers may store or process information outside New Zealand. Where an overseas provider acts solely as our agent, we remain responsible for taking reasonable steps to protect the information and for managing the provider appropriately.

If we disclose personal information to an overseas person for that person's own purposes, we comply with Information Privacy Principle 12. This may involve confirming that the recipient is subject to the New Zealand Privacy Act, is covered by comparable safeguards, is contractually required to provide comparable safeguards, or obtaining your express and informed authorisation where the Act permits it.

We assess the purpose, sensitivity, destination, provider controls and contractual protections before making a material overseas disclosure.

08

Website, email, bookings and cookies

Enquiry form and email

The enquiry form on this website prepares a message in your own email application. The draft is not submitted to or stored by this website. Your email provider controls the draft and sending. If you send it, the message and email metadata are received and retained in YJ Consulting's Titan email service in accordance with our business needs, this policy and the provider's controls.

If you use the copy option, the prepared text is placed on your device's clipboard. We do not receive it unless you send it to us.

Website hosting and essential security cookie

This website is hosted through ChatGPT Sites by OpenAI and delivered using Cloudflare infrastructure. Those providers may process technical request, device, usage, log and security information to host, maintain, protect and deliver the site.

Cloudflare currently uses the strictly necessary __cf_bm cookie for bot detection and website security. Cloudflare states that it expires after 30 minutes of continuous inactivity and does not track users from site to site. Blocking necessary cookies may affect security or site availability.

Ahrefs Web Analytics

We use Ahrefs Web Analytics to understand aggregated website traffic and improve this site. The Ahrefs script may record the page URL, referrer, browser and device information, language, approximate country or city, page views and outbound link clicks. It does not receive the contents of an enquiry draft prepared on this website.

Ahrefs states that Web Analytics does not use cookies or persistent identifiers by default and does not track individuals across websites or devices. Ahrefs processes a visitor's IP address with user-agent information and a salt that changes every 24 hours to calculate a daily visitor count. Ahrefs states that it discards the raw IP address, deletes the old salt after 24 hours, and stores aggregated analytics information for reporting and service improvement.

Bookings and external links

Our booking link opens Google Calendar. Information you enter there is provided to Google and YJ Consulting and is governed by Google's privacy terms as well as this policy once we receive it. Links to LinkedIn, Facebook, Instagram and other external websites take you away from this site. Those services control their own collection practices.

09

AI-assisted tools and automated decisions

This website does not use AI profiling or automated decision-making about visitors. We do not make a legal, immigration, employment, financial or similarly significant determination about a person solely from an automated output.

If an engagement proposes using an AI-assisted tool with personal information, we will first assess necessity, data minimisation, confidentiality, provider terms, security, retention and overseas-processing implications. We will use an appropriate human review gate and provide further notice or seek authority where required. An engagement's agreed controls take precedence if they are stricter.

10

Security and information integrity

We take reasonable steps to protect personal information against loss, unauthorised access, use, modification, disclosure and other misuse. Controls are selected according to the information, system and risk and may include:

  • access limited by role and business need, with strong authentication where supported;
  • secure transmission, provider security controls, backups and device protections;
  • confidentiality requirements, careful sharing and review points for sensitive work;
  • provider assessment, incident response and recovery procedures; and
  • secure deletion or de-identification when information is no longer required.

No internet transmission or storage system can be guaranteed completely secure. Please tell our Privacy Officer promptly if you believe information has been sent to us incorrectly or accessed without authority.

Unique identifiers

We assign or use client, project or record identifiers only where necessary for an operational function. We do not adopt a government-assigned identifier as our own identifier unless that use is lawful and necessary.

11

Retention and secure disposal

We keep personal information only for as long as there is a lawful business purpose or retention requirement. The period depends on the type of record, the engagement, sensitivity, contractual commitments, tax and accounting obligations, insurance requirements, limitation periods, complaints, disputes and any legal hold.

  • An unsent website enquiry draft is not retained by this website.
  • Sent enquiries are retained for as long as reasonably needed to respond, assess the request and maintain appropriate business records.
  • Client and engagement records are retained for the engagement and an appropriate period afterwards, including at least seven years where New Zealand tax record-keeping law requires it.
  • A limited suppression record may be kept after an unsubscribe so that we can continue to honour it.

When information is no longer required, we securely delete, destroy or de-identify it, subject to normal backup lifecycles and lawful retention requirements.

12

Your access and correction rights

You may ask whether we hold personal information about you, request access to it and ask us to correct it. Send your request to the Privacy Officer using the details below. Please describe the information clearly enough for us to locate it.

We may ask for reasonable evidence of identity and, if you act for someone else, your authority. We will usually respond as soon as reasonably practicable and no later than 20 working days, subject to any lawful extension, transfer, withholding ground or other provision in the Privacy Act.

If we do not make a requested correction, you may ask us to attach a statement of correction to the information. If we refuse or limit a request, we will explain the applicable reason and your right to complain where the law requires.

You may also ask us to delete information, limit optional communications or withdraw an authorisation for future handling. The Privacy Act does not provide an unrestricted right to erasure, but we will consider the request and delete information where there is no lawful reason to retain it.

13

Electronic marketing

We send commercial electronic messages only where we have consent or another permission recognised by the Unsolicited Electronic Messages Act 2007. Messages identify YJ Consulting, include accurate contact information and provide a functional, easy way to unsubscribe.

You can opt out at any time. We will action a valid unsubscribe request within five working days and may retain a minimal suppression record to prevent further marketing messages. An unsubscribe does not prevent service, transaction, safety or legally required communications.

14

Privacy breaches

If a privacy breach occurs, we will take steps to contain it, protect affected information, preserve necessary records, assess cause and harm, and reduce the risk of recurrence.

Where a breach has caused or is likely to cause serious harm, we will notify the Office of the Privacy Commissioner and affected people as soon as practicable, subject to the notification provisions and permitted exceptions in the Privacy Act 2020.

15

Questions, requests and complaints

Our Privacy Officer is responsible for supporting compliance, handling requests and investigating privacy concerns.

Privacy OfficerSteffanie Zhang

YJ Consulting, operated through Crescellere Limited

Auckland, Aotearoa New Zealand

steff@yjconsulting.org

Please contact us first and explain what happened and the outcome you are seeking. We will acknowledge and investigate the concern fairly. If you are not satisfied, you may complain to the Office of the Privacy Commissioner.

How to make a privacy complaint ↗

16

Changes to this policy

We review this policy when our practices, providers or legal obligations change. The current version is published at this address with its last-updated date. If a material change affects information already collected, we will provide further notice or seek authority before a new use where required by law.

17

Legal framework and further information

This policy is designed around YJ Consulting's current activities and the Privacy Act 2020, including the 13 Information Privacy Principles and IPP3A. Relevant record-keeping and electronic-message obligations are also addressed. Other laws or an approved privacy code may apply to a particular engagement, information type or recipient. Where that occurs, we will apply the specific requirement and provide further notice where appropriate.

If this policy and a mandatory legal requirement differ, the legal requirement applies.