Client Portal

Security Notice

This page is maintained by Smallbiz IT Solutions to answer common security and privacy questions about the client portal. It describes controls that are in place today and how the portal should be used. It is not an independent certification.

Authorised Access Only

The Smallbiz IT Solutions client portal is provided for authorised customers, our staff, and approved representatives acting on behalf of a customer. Access is granted on a need-to-use basis and may be removed at any time.

Attempted or actual unauthorised access, including sharing credentials or accessing accounts you do not own, is prohibited and may be reported to the appropriate authorities.

Security & Monitoring

Activity in the portal — including sign-ins, MFA events, ticket updates, and administrative actions — may be monitored, audited, and logged for security, operational, and compliance purposes.

Logs are used to detect misuse, investigate incidents, and improve the reliability of the service.

Privacy

Information you submit through the portal — including tickets, comments, attachments, and contact details — is stored and processed so we can provide support services to you or your organisation.

See our Privacy Policy for more detail on how personal information is collected, used, and shared.

Sensitive Information

Do not submit the following through tickets, comments, or attachments:

  • Passwords or passphrases
  • Multi-factor authentication (MFA) codes or backup codes
  • Payment card numbers, CVVs, or full banking details
  • Encryption keys, API secrets, or private certificates
  • Other credentials that would grant access to your systems

If a support task requires a credential, our team will arrange a secure method separately. Approved vendors (for example Microsoft, telco or ISP partners, hardware suppliers) may be given the minimum information required to help resolve your issue.

Multi-Factor Authentication

Multi-factor authentication (MFA) is required for all portal accounts. After verifying MFA, you can choose to trust the browser you signed in from for up to 30 days so you are not prompted for a code on every sign-in.

You will be re-prompted for MFA when you sign in from a new browser or device, from a new country, or when we detect a high-risk sign-in. You can review and revoke trusted devices at any time from your profile.

Data Retention

Tickets, comments, attachments, service records, and related logs may be retained for operational, security, legal, and compliance purposes. Retention periods are set to what we consider reasonable for delivering ongoing support and meeting our record-keeping obligations.

If you need a specific record removed, contact us using the details below and we will assess the request against our retention and legal obligations.

Contact Information

To report a security concern, suspected unauthorised access, or a question about this notice, contact:

support@smallbizitsolutions.co.nz

Last updated: 5 July 2026