Privacy Policy

We respect your privacy and are committed to protecting it through our compliance with the privacy policy below.

1. Introduction

1.1 This Privacy Policy (Policy) governs how Epi-interactive Limited (NZBN 9429031348829) and Epi Australia Pty Ltd (ACN 690 258 345) (we, us, our) will handle the personal information we collect about you, including through our website, Posit or any other service we provide (each a Service and together, the Services). Your privacy is important to us, and we are committed to protecting your personal information in accordance with the Privacy Act 1988 (Cth) (Australian Privacy Act) and Privacy Act 2020 (New Zealand Privacy Act) (together, Privacy Legislation).

1.2 We also uphold your rights to privacy if you are based in the European Union, in accordance with the General Data Protection Regulation (EU) (GDPR). Your rights under the GDPR are listed in clause 13 of this Policy.

1.3 This Policy also describes how you can access and update the personal information you provide to us. If you do not wish to provide personal information to us, then you do not have to do so. However, this may affect your use of our Services offered.

2. What is personal information?

2.1 When used in this Policy, the term “personal information” has the meaning given to it under the Australian Privacy Act, the New Zealand Privacy Act and the GDPR. 

2.2 In general terms, it is any information that can be used to personally identify you. This may include your name, address, telephone number, email address and profession or occupation.  

2.3 If the information we collect personally identifies you, or you are reasonably identifiable from it, the information will be considered personal information.

2.4 We may also collect some information that is not personal information because it does not identify you or anyone else.  For example, we may collect anonymous answers to surveys or aggregated information about how users operate on our website. 

2.5 Your personal information will not be shared, sold, rented or disclosed other than as described in this Policy.  

3. Updates to our Privacy Policy

3.1 We may review this Policy from time to time, including to ensure we are keeping up to date with changing laws, our operations and the changing business environment. We will amend and update the Policy by posting a revised version on our website.

3.2 By continuing to use our website and Services or by providing us with your personal information, you accept the terms of this Policy and any updates to our Policy. If you do not accept the updates to our Policy, you must not use our website, Services or other communication channels.

4. When do we collect personal information about you?

4.1 We collect personal information about you during any interactions you have with us, including when you:

(a) upload information to our website or Services;

(b) open and operate an account;

(c) interact with any of our social media channels;

(d) access, browse, view or use our website and Services; and

(e) provide information to us, including through our website and Services, over email or the phone.

5. What kind of personal information do we collect?

5.1 The personal information we collect may include:

(a) your contact details (including, but not limited to, your full name, email address, physical address and phone number);

(b) financial information;

(c) records of your activity when you use our website, Services and/or social media channels;

(d) recordings of calls and copies of other communications with or from you;

(e) your activity on our website;

(f) information we create in the course of our relationship with you; and

(g) information from your computer or device in relation to your use of our website, Services or social media channels, including but not limited to the IP address, domain name, browser type, activity logs, cookie and browser identifiers and location identifiers (for more information about website analytics see below).

5.2 Where practical, you have the option of interacting with us anonymously or using a pseudonym. However, this option does not apply where we are required by law to deal with identified individuals, or where it is impracticable for us to deal with you without identifying you (including when you register for, access, or use our Services).

6. How do we collect your personal information?

6.1 We collect personal information in different ways, but we collect most of the personal information directly from you.

6.2 At times, we may collect information about you from a third party that you have authorised, or as permitted by law.

6.3 If you have provided us with information about another person, you warrant that you are not prohibited by law in doing so. Your obligations under privacy laws may require you to seek permission from the person and/or may mean that you need to tell that person about the disclosure and let them know that they have a right to access their personal information and that we will handle their personal information in accordance with this Policy.

6.4 If we indirectly collect your personal information and you have not already been notified, we will take reasonable steps to notify you, in accordance with Privacy Legislation and the GDPR.

6.5 We will only collect sensitive information about you with your consent and if the information is reasonably necessary for, or directly related to, one or more of our functions or activities. We will only use or disclose your sensitive information for the primary purpose for which it was collected, or for a directly related secondary purpose that you would reasonably expect, unless you have consented otherwise or the use or disclosure is required or authorised by law.

7. Why do we collect personal information and what do we use it for?

7.1 We collect personal information to:

(a) provide you Services;

(b) provide you with support in relation to our Services;

(c) offer you products or services that may be of interest to you;

(d) provide you with products and Services you request;

(e) provide you with support;

(f) manage our relationship with you;

(g) provide general administrative and business purposes; and

(h) comply with New Zealand laws, Australian laws, and any applicable overseas laws.

8. Direct marketing materials

8.1 We may send you direct marketing communications and information about our Services that we consider may be of interest to you. These communications may be sent in various forms, including mail, SMS and email, in accordance with applicable marketing laws, such as the Australian Spam Act 2003 (Cth).  

8.2 If you indicate a preference for a method of communication, we will endeavour to use that method whenever practical to do so.

8.3 In addition, at any time you may opt-out of receiving marketing communications from us by contacting us at info@epi.group or by using opt-out facilities provided in the marketing communications and we will then ensure that your name is removed from our subscription/mailing list.

8.4 We do not provide your personal information to other organisations for the purposes of direct marketing.

9. What happens if we cannot collect your personal information? 

9.1 If you do not provide us with the personal information described above, some or all of the following may happen:

(a) we may not be able to provide our Services to you, either to the same standard or at all;

(b) we may not be able to provide you with information about the Services that you may want, including information about special promotions; or

(c) we may be unable to tailor the content of our website to your preferences and your experience of our website may not be as enjoyable or useful.

10. Who do we disclose your information to? 

10.1 We may disclose your personal information to: 

(a) Our directors, employees, agents, contractors or service providers, including, without limitation, consultants, web hosting providers, IT systems administrators, mailing houses, couriers, payment processors, data entry service providers, electronic network administrators, debt collectors, and professional advisors such as accountants, solicitors, business advisors, for the purposes of operating our website or our business, fulfilling requests by you, and to otherwise provide Services to you;

(b) suppliers and other third parties with whom we have commercial relationships, for business, marketing, and related purposes, which may include overseas parties;

(c) credit reporting agencies and courts, tribunals, regulatory authorities where customers fail to pay for goods or services provided by us to them, and other law enforcement officers as required by Law; 

(d) any other organisation for any authorised purpose with your express consent; and 

(e) to any person or organisation that we are permitted or required to disclose your personal information by law.

10.2 We may disclose your personal information:

(a) for the purpose for which it was collected (or a purpose that is directly related to that purpose); and

(b) to the third parties we can disclose your information to achieve the purposes set out in clause 7.1.

10.3 We may share your personal information in an anonymised aggregate form with others.

10.4 We only disclose this information if the third party has agreed to comply with the standards in this Policy.

10.5 If there is any change or potential change to the control of our business pursuant to the sale, assignment or transfer of the business, or business assets, its assets and/or liabilities, we reserve the right to sell, assign and/or transfer our user databases, together with any personal information and non-personal information contained in those databases to the extent permitted by law. In that event, your personal information may be disclosed to a potential purchaser, assignee or transferee, however any disclosures will only be made in good faith and where confidentiality is maintained.

11. Storage and security of your personal information

11.1 We will store your personal information in accordance with our obligations under Privacy Legislation and GDPR and will take reasonable steps to ensure the security of your personal information.

11.2 We will only keep your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.

11.3 To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements.

11.4 Under Australian Law, we must keep basic information about our customers (including contact, identity, financial and transaction data) for five years for Australian tax law purposes.

11.5 In some circumstances, you can ask us to delete your data. See your legal rights below for further information.

11.6 In some circumstances we may anonymise your personal data (so that it can no longer be associated with you) for research or statistical purposes in which case we may use this information indefinitely without further notice to you.

12. Security and data quality

12.1 Protecting the personal information of yours that we hold and process is important to us. We take reasonable steps to ensure your personal information is protected from misuse and loss and from unauthorised access, modification or disclosure.

12.2 Although we take reasonable steps to ensure personal information held by us (or on our behalf) is protected and held securely, unfortunately no data transmission over the internet can be guaranteed to be totally secure. Therefore, we do not make any warranties in relation to the security of any information you disclose or transmit to us, and we are not responsible for the theft, destruction, or inadvertent disclosure of your personal information where our security measures have been breached. Any transmission of personal information is conducted at your own risk.

12.3 We may hold your information in either electronic or hard copy form. Personal information is destroyed or de-identified when no longer needed or when we are no longer required by Law to retain it (whichever is the latter).

12.4 Should a data breach involving personal information occur:

(a) We will take positive steps to address the breach in a timely manner and take remedial action such that the data breach does not result in serious harm.

(b) We will undertake reasonable and expeditious assessment to determine if it is an ‘eligible data breach’, that is a breach likely to result in serious harm to any individual affected.

12.5 In compliance with the Australian Privacy Amendment (Notifiable Data Breaches) Act 2017 (Cth), we agree that if we become aware of reasonable grounds to believe an eligible data breach has occurred, we will promptly notify the Office of the Australian Information Commissioner (Commissioner), the Association of Market and Social Research Organisations (AMSRO), and the affected individuals at likely risk of serious harm.

13. If I am based in the EU, what are my legal rights under the GDPR? 

13.1 If the General Data Protection Regulation applies to you because you are in the European Union, you have rights under data protection laws in relation to your personal data:

(a) The right to be informed – that’s an obligation on us to inform you how we use your personal data;

(b) The right of access – that’s a right to make what’s known as a ‘data subject access request’ for copy of the personal data we hold about you;

(c) The right to rectification – that’s a right to make us correct personal data about you that may be incomplete or inaccurate;

(d) The right to erasure – that’s also known as the ‘right to be forgotten’ where in certain circumstances you can ask us to delete the personal data we have about you (unless there’s an overriding legal reason we need to keep it);

(e) The right to restrict processing – that’s a right for you in certain circumstances to ask us to suspend processing personal data;

(f) The right to data portability – that’s a right for you to ask us for a copy of your personal data in a common format (for example, a .csv file);

(g) The right to object – that’s a right for you to object to us processing your personal data (for example, if you object to us processing your data for direct marketing); and

(h) Rights in relation to automated decision making and profiling – that’s a right you have for us to be transparent about any profiling we do, or any automated decision making.

13.2 These rights are subject to certain rules around when you can exercise them.

13.3 If you wish to exercise any of the rights set out above, please contact us at info@epi.group.

14. Access and retention of your own personal information

14.1 You agree that any information you give to us will be accurate, correct and up to date.

14.2 You must inform us if any of your personal information changes, to ensure that the details we hold about you are up to date and correct. If we are not willing to correct errors that you have identified in your personal information, you may request that we take reasonable steps to attach a statement to the personal information noting the correction sought.

14.3 Subject to any exceptions in Privacy Legislation, you have a right to know what information we hold about you. If you’d like to receive a copy of the personal information we hold about you, or request correction of that information, please contact us at info@epi.group. 

14.4 Please note that we may ask you to verify your identity before responding to such requests.

14.5 We may charge you a reasonable fee to cover our administrative and other reasonable costs in providing the information to you. We will not charge for simply making the request and will not charge for making any corrections to your personal information.

14.6 There may be instances where we cannot grant you access to the personal information we hold. For example, we may need to refuse access if granting access would interfere with the privacy of others or if it would result in a breach of confidentiality. If that happens, we will give you written reasons for any refusal.

15. How can you withdraw your consent to this Policy? 

15.1 You may withdraw your consent to this Policy at any point.  If you wish to withdraw your consent to our collection and retention of your data, please contact info@epi.group and we can arrange for your data to be deleted, destroyed or returned to the extent we are permitted by law.  However, this may affect your use of our website or any products and services offered on it.

15.2 You may choose to restrict the collection or use of your personal information. If you have previously agreed to us using your personal information for direct marketing purposes, you may change your mind at any time by contacting us at the email address listed in this Policy.

15.3 To unsubscribe from our e-mail database, or opt out of any communications, please contact us at info@epi.group, with “Unsubscribe” in the subject line of the e-mail or use our opt-out facilities provided in the marketing communications and we will then ensure that your name is removed from our subscription/mailing list. 

16. Third party sites and services

16.1 Our website and Services may use third party software and services for us to provide our Services to you. These third parties may have their own terms and conditions, and privacy policies. Before disclosing your personal information on any other website or to any third party, we encourage you to examine the terms and conditions of using that website and its privacy policy. Third party websites are responsible for informing you about their own privacy practices. 

16.2 We may provide links or reference to websites outside of our website. These linked sites are not under our control, and we cannot accept responsibility for the conduct of ay companies, businesses, affiliates, advertisers and sponsors linked to our website. This Policy does not apply to any other websites and we take no responsibility for the privacy practices of other websites.

17. Website analytics

17.1 Generally, this information is not personally identifiable data, but to the extent that it is considered personal information for the purposes of any applicable law or regulation, we will comply with our obligations under any such law or regulation when processing that information.

18. Cookies

18.1 When you access our website, we may send a “cookie” (which is a small summary file containing a unique ID number) to your computer. This enables us to recognise your computer. It also enables us to keep track of Services you view so that, if you consent, we can send you news about those Services.  

18.2 We also use cookies to measure traffic patterns, to determine which areas of our website have been visited and to measure transaction patterns in the aggregate.  

18.3 By using our website with cookies enabled you consent to cookies being used. Some of the ways we use cookies include, but are not limited to, customising our website with your preferences, identifying you for security reasons, analysing trends on our website, facilitating market research and promotional activities, and measuring the effectiveness of our marketing initiatives.

18.4 If you do not wish to receive cookies, you can set your browser so that your computer does not accept them. 

19. Google analytics

19.1 We also use Google Analytics to collect data about the use of our website. We may use Google’s analysis to help us gain a better understanding of our audience demographics and how people interact with our website. We may disclose the information collected by Google Analytics, in an aggregate, anonymised (not personal) form only, to third parties. When we use Google Analytics, Google’s privacy policy will also apply and the data that is collected and stored on the Google server is governed by Google’s privacy policy. 

20. Contacting us

20.1  If you have any questions about this Policy, any concerns or a complaint regarding the treatment of your privacy or a possible breach of your privacy, please contact us at:

info@epi.group  



By Post (New Zealand)

Epi-interactive Ltd.

PO Box 15327

Miramar, Wellington 6243

 

By Post (Australia)

Epi Australia Pty Ltd.

GPO Box 724

Sydney, NSW 2001

21. What is the process for complaining about a breach of privacy? 

21.1 If you believe that your privacy has been breached, please contact us using the contact information in clause 20 above and provide details of the incident so that we can investigate it.  

21.2 We will treat your requests or complaints confidentially.  

21.3 We will treat your complaint confidentially, investigate your complaint and aim to ensure that we contact you and your complaint is resolved within a reasonable time (and in any event within the time required by the Privacy Legislation and/or the GDPR, if applicable).

21.4 If you are not satisfied with our response or the way we have handled your complaint, you may escalate your complaint to:

The Office of the Australian Information Commissioner (OAIC) if the complaint is made in Australia. The OAIC’s contact details are:

GPO Box 5288
Sydney NSW 2001
Australia

1300 363 992

www.oaic.gov.au    

The New Zealand Privacy Commissioner if the complaint is made in New Zealand. The New Zealand Privacy Commissioner’s contact details are:

Office of the Privacy Commissioner
PO Box 10094
The Terrace
Wellington 6143
New Zealand

0800 803 909

www.privacy.org.nz