1 APPLICATION
1.1 SonaSafe takes your privacy seriously and is committed to protecting your privacy. SonaSafe is bound by the Privacy Act. This Privacy Policy explains how and SonaSafe collects, uses, holds and discloses your Personal Information. It applies to all interactions you have with SonaSafe including, without limitation, its provision of products and services, including the SonaSafe Products and Services to you and your use of SonaSafe’s website, software, app or other platforms.
1.2 By placing an order with SonaSafe, entering into any written agreement with SonaSafe and/or using the SonaSafe Products and Services (whether the relevant order is completed or the SonaSafe Products andServices are provided), you consent to SonaSafe collecting, holding, using and disclosing your Personal Information in accordance with this Privacy Policy.
1.3 SonaSafe may amend this Privacy Policy from time to time. SonaSafe will update the latest PrivacyPolicy on its website (www.sonasafe.co.nz/privacy-policy)and if material changes are made to this Privacy Policy, SonaSafe will notify you. Please ensure you regularly check the SonaSafe website for updates to this Privacy Policy.
2 DEFINITIONS
2.1 In these Terms, unless the context otherwise requires:
(a) Business Day means a day other than a Saturday, Sunday or public holiday in New Zealand;
(b) IT means information technology;
(c) Non-Identifying Information means information that cannot be used to identify an individual;
(d) Personal Information has the meaning given to it in the Privacy Act;
(e) Privacy Act means the Privacy Act 2020 and includes any amendments to, or replacements of, that Act;
(f) Privacy Policy means this privacy policy as updated from time to time and made available on SonaSafe’s website;
(g) Sensitive Personal Information means Personal Information or an opinion about an individual that has significance to, or is revealing of, the individual, including (without limitation) the individual's racial or ethnic origin, political opinions, religious beliefs, sexual orientation or criminal record;
(h) Services has the meaning given to that term in the SonaSafe Terms;
(i) SonaSafe Dashboard has the meaning given to that term in the SonaSafe Terms;
(j) SonaSafe Products has the meaning given to that term in the SonaSafe Terms;
(k) SonaSafe Terms means the SonaSafe General Terms and Conditions found at (www.sonasafe.co.nz/terms-and-conditions) applicable to the supply of the SonaSafe Products and Services, as may be updated from time to time;
(l) You/Your means the individual who SonaSafe collects the Personal Information from and about.
2.2 Capitalised terms not otherwise defined in this Privacy Policy will have the meanings given to those terms in the SonaSafe Terms.
3 HOW SONASAFE COLLECTS YOUR PERSONAL INFORMATION
3.1 This Privacy Policy relates to your PersonalInformation that is supplied to SonaSafe or collected by SonaSafe, including:
(a) Contact information: your name, position, role, company or organisation, telephone number email, driver's licence number, postal address emergency contact details;
(b) Communications: information provided in communications with SonaSafe including filling out any forms SonaSafe provides you with such as its credit account application form;
(c) Business information: data identifying you in relation to commercial dealings SonaSafe has with you or the business you represent;
(d) Information from public sources: for example, from LinkedIn and similar professional networks, directories or internet publications;
(e) Financial information: bank account details and other payment information (credit card details and billing address) or third-party payer details to process payment for the SonaSafe Products and Services (whether those products and services are supplied or not) and other applicable fees and charges;
(f) Social media: interactions with its social media presence including posts or likes;
(g) Technical information: obtained by accessing its website including IP address, time zone setting, browser plug-in types and versions, operating system you are using, device type, hardware model, MedicalAccess Control (MAC) address, unique identifiers and mobile network information;
(h) Online data: obtained by accessing its website, software, app and its technology services, information about your visit, including URL clickstream to, through and from its website (including date and time),information about your network, such as information about devices, nodes, configurations, connection speeds and network application performance, pages viewed or searched for, page response times, download errors, length of visits and interaction information (such as scrolling, clicks, mouse-overs) and other similar information and whether you click on particular links or open SonaSafe’s emails.
3.2 SonaSafe may receive Personal Information directly from you, the company you represent, or third parties who assist SonaSafe with its legal obligations. This information may be exchanged over the phone, by email, text message, in person, audio-visual conferences or in any other form of written communication or through an online enquiry form on its website.
3.3 If you send SonaSafe an email containingPersonal Information, SonaSafe will use all reasonable endeavours to ensure the confidentiality of that information. SonaSafe’s internet host and its IT support service providers may monitor emails for maintenance and fault detection purposes. SonaSafe may also monitor emails to ensure that it is complying with its legal obligations. SonaSafe may forward emails to related service providers and other third parties to assist with the management of its business or where the email contains feedback or complaints.
3.4 SonaSafe does not collect Personal Information about your online activities across third party websites or online services. If you do not wish to provide Personal Information to SonaSafe, then you do not have to do so, however it may affect your use of its website and its ability to provide you with the SonaSafe Products and Services.
4 HOW SONASAFE USES YOUR PERSONAL INFORMATION
4.1 SonaSafe uses your Personal Information for various reasons, including the following purposes:
(a) to enable SonaSafe to provide you with the SonaSafe Products and Services;
(b) to communicate with you including sending you quotes or order confirmations, emailing you an invoice or arranging for the delivery of the SonaSafe Products and Services;
(c) to contact you to send you information about SonaSafe Products and Services (including important notices relating to changes or improvements to SonaSafe Products andServices);
(d) to assist you with information and providing support where you have queries or issues in respect of the SonaSafe Products and Services or website;
(e) to monitor and enforce any Security Interest SonaSafe may in accordance with the SonaSafe Terms;
(f) to monitor its website, the SonaSafe Dashboard and any other technology services, to ensure they are used appropriately and working as intended, including tracking outages, unauthorised use, or troubleshooting issues that you report to SonaSafe;
(g) to protect its information and technology platforms from hacks, or identifying and addressing malware and other security threats; and
(h) to comply with the law, including auditing and reporting requirements. SonaSafe reserves the right to obtain further information from you to comply with the law if required.
4.2 Non-Identifying Information may be collected to assist SonaSafe to understand how its customers use its products, services and website. Non-Identifying Information may be collected, used, stored and disclosed at SonaSafe’s discretion.
4.3 You consent to SonaSafe contacting you in respect of the purposes set out above. This consent includes contact by electronic message pursuant to the Unsolicited Electronic Messages Act 2007(New Zealand) or any equivalent legislation in any other relevant jurisdiction.
4.4 Where you receive electronic marketing communications from SonaSafe, you may opt out of receiving further marketing communications by following the opt-out instructions provided in the communication.
4.5 If there is a change of control in SonaSafe’s business or a sale or transfer of business assets, you consent to SonaSafe transferring (to the extent permissible at law) its user databases, together with any of your Personal Information and Non-Identifying Information contained in those databases to the new purchaser.
5 WHY SONASAFE USES YOUR PERSONAL INFORMATION
5.1 SonaSafe collects, holds, uses and discloses your Personal Information for several reasons including:
(a) to provide the SonaSafe Products and Services, and manage its relationship with you;
(b) to contact you to respond to your queries, or if SonaSafe needs to tell you something important;
(c) to comply with its legal obligations and assist government and law enforcement agencies or regulators;
(d) to further its legitimate business interests or those of a third party provided those do not override any interest or rights you have as an individual; or
(e) to identify and tell you about other products or services that SonaSafe thinks are of interest to you.
5.2 Its legitimate business interests include monitoring how users access its website, understanding and responding to feedback and enquiries, and providing the appropriate facilities to enable it to provide the SonaSafe Products and Services.
6 WHY SONASAFE USES SENSITIVE PERSONAL INFORMATION
6.1 SonaSafe will only use Sensitive PersonalInformation if:
(a) it is not otherwise permitted under this Privacy Policy, but SonaSafe has your express and informed consent;
(b) SonaSafe needs to protect your vital interests or those of another person for example, in medical emergencies;
(c) you have manifestly made the data public; for example, where you have published it on social media;
(d) this is necessary to deal with legal claims;
(e) this is necessary for substantial public interest for example, to prevent or detect unlawful acts; or
(f) as permitted by applicable law.
7 WHO SONASAFE SHARES YOUR PERSONAL INFORMATION WITH
7.1 There are instances where SonaSafe may disclose your PersonalInformation where it is permitted or required by law. SonaSafe may share yourinformation with others as follows:
(a) Related entities: who assist SonaSafe in providing the SonaSafe Products and Services and/or undertaking research and development;
(b) Suppliers: who provide its business with goods and services;
(c) Shared service centres: that SonaSafe or third parties operate including for IT services, marketing, risk management and office support services;
(d) Financial institutions: for payment processing;
(e) Credit agencies: to obtain information such as a credit report to assess any application of credit you make with SonaSafe;
(f) Law enforcement bodies and its regulators: or authorities in accordance with law or good practice;
(g) Appropriate parties in the event of emergencies: to protect the health and safety of you and others;
(h) Family or representative: any person, family member, representatives or other organisations that you have consented, or where SonaSafe is required, permitted, authorised or otherwise directed toby law;
(i) Advertising networks and analytics service providers: to support and display ads on its website, apps and other social media tools;
(j) Third parties: in the context of the acquisition or transfer of any part of its business or in connection with the business reorganisation; and
(k) Independent contractors: including website designers, mailing and courier services, printers and distributors of direct marketing material and external advisors such as auditors, lawyers and debt collectors.
8 DISCLOSURE OF YOUR PERSONAL INFORMATION TO OVERSEAS RECIPIENTS
8.1 As SonaSafe is an international company, your Personal Information may be collected, used and stored in overseas jurisdictions where SonaSafe, or its service providers or partners, have a presence. These jurisdictions may be subject to different data protection requirements. SonaSafe will use reasonable endeavours to protect your Personal Information in accordance with this Privacy Policy and any locally applicable data protection requirements.
9 HOW SONASAFE HOLDS YOUR PERSONAL INFORMATION
9.1 SonaSafe may keep your Personal Information in physical and electronic form (or a combination). SonaSafe will store and process this information securely using good practice and physical, technical and administrative security measures. These measures include:
(a) the use of identity and access management technologies to control access to systems on which information is processed and stored;
(b) requiring all employees to comply with internal information security policies and keep information secure;
(c) requiring all employees to complete training about information security; and
(d) monitoring and regularly reviewing its practice against its own policies and against industry best practice.
9.2 Although SonaSafe will take reasonable measures to protect your Personal Information from misuse, interference or loss, unauthorised access, modification or disclosure, it cannot guarantee the security of information you transmit. Any transmission is at your own risk.
10 HOW LONG SONASAFE HOLDS YOUR PERSONAL INFORMATION FOR
10.1 SonaSafe retains the data it collects for different periods of time depending on what it is and how it uses the data. SonaSafe generally keeps your information, including yourPersonal Information, as needed to provide the SonaSafe Products and Services to you, comply with legal, accounting or regulatory requirements or to deal with claims. Once SonaSafe no longer needs to hold your Personal Information, SonaSafe will destroy it (either by shredding physical documents or permanently deleting electronic information from its server, subject to any back-up records).
11 HOW YOU CAN CORRECT YOUR PERSONAL INFORMATION
11.1 If you believe any ofyour Personal Information that SonaSafe holds is inaccurate, out of date,incomplete, irrelevant or misleading, please contact SonaSafe in writing. It is your responsibility to advise SonaSafe of any changes to your Personal Information (for example change of residential address, email address or phonenumber). Any written request by you cannot be unreasonably withheld by SonaSafeand SonaSafe will respond within a reasonable period (but being no more than 30days after your request). In some limited circumstances SonaSafe may not makerequested corrections to Personal Information, in which case SonaSafe willprovide you with written reasons for this decision.
11.2 You can withdraw your consent relating to Personal Information which you have given to SonaSafe atany time. However, this will not affect any actions which SonaSafe has taken in respect of your Personal Informationprior to your consent being withdrawn. In some cases, SonaSafe may be required by law to continue to holdand/or use your Personal Information to meet legal requirements, in which case SonaSafewill do so, to the extent required by law.
12 HOW YOU CAN ACCESS YOUR PERSONAL INFORMATION
12.1 All individuals have a right to request accessto their Personal Information and to requestits correction. Please contact SonaSafe if you would like to access the Personal Information it holds about you. SonaSafe will generally provide youwith access to your Personal Information within a reasonable period (but being no more than 30 days after your request). There are some circumstances in which SonaSafe is not required to give you access to your Personal Information, such as where the information relates to anticipated legal proceedings or the request is frivolous or vexatious. If SonaSafe denies or restricts your access, SonaSafe will explain why in writing.
12.2 There is no charge forrequesting access to your Personal Information, but SonaSafe may require you tomeet its reasonable costs in providing you with access (such as photocopyingcosts or costs for time spent on collating large amounts of material). SonaSafe will respond to your requests to access Personal Information in a reasonable time (but being no more than 30 days after your request). If you are forwhatever reason not satisfied with the response or resolution of your concerns or complaint, you can contact the Office of the Privacy Commissioner on 0800803 909 or by emailing enquiries@privacy.org.nz.
13 GOOGLE ANALYTICS
13.1 SonaSafe use Google Analytics on its website. Google Analytics collects and processes data by usingthe website's cookies to analyse the use of the website including, how longusers spend on each webpage and collect other online data described above. Thisinformation is used mainly for the optimisation of the website to enhance theuser experience. The data collected by Google is transmitted to a server in theUnited States (or other countries outside of New Zealand) You can review howGoogle uses data by clicking on the following link: https://policies.google.com/technologies/partner-sites.
14 COOKIES AND SIMILAR TECHNOLOGIES
14.1 SonaSafe may use and collect data through cookies (including persistent cookies) and other similar technology (such as web beacons) on its website. You can opt out of its use of cookies.
14.2 Its website, email updates and other communications may, from time to time, contain links to andfrom the websites of others. The Personal Information you provide through these websites is not subject to this Privacy Policy and the treatment of your Personal Information by such websites is not its responsibility. If you follow a link to any other websites, please note that these websites have their own privacy policies which will set out how your information is collected and processed when visiting those sites.
15 CONTACT SONASAFE
15.1 If you have any questions about how SonaSafe uses, stores, discloses or otherwise manages your Personal Information or have any concerns about its compliance with the Privacy Act, please contact:
SonaSafe 20/20 Limited
Level 2, Unit 448 Enterprise Street
Birkenhead, Auckland
sales@sonasafe.co.nz
15.2 SonaSafe will respond toyour concerns as soon as reasonably practicable (and no more than 30 days afteryour request). If you are for whatever reason not satisfied with the response or resolution of your concerns or complaint, please contact the Office of the Privacy Commissioner.