New Zealand Privacy Policy

Last Updated: September 1, 2026

1. About This Privacy Policy

For individuals in New Zealand, we handle personal information in accordance with the information privacy principles under the Privacy Act 2020 (Privacy Act). In this policy:

  • ‘personal information’ means information about an identifiable individual; and
  • ‘biometric information’ has the meaning given to that term in the Biometric Processing Privacy Code 2025 (Biometrics Code), and includes information about a person’s face, fingerprints or voice that is collected for the purpose of biometric processing.

This Privacy Policy applies in relation to the personal information we collect from anyone who visits our websites and/or uses our Services in New Zealand, and exists to supplement, and applies in addition to, our general Privacy Policy (General Policy). To the extent of any inconsistency with the General Policy, this Privacy Policy will prevail.

Specifically, this Privacy Policy describes:

  • the types of personal information we obtain;
  • how we use that personal information;
  • with whom we share it;
  • your rights in respect of your personal information; and
  • how you can contact us about our privacy practices, including to make a complaint.

Capitalised terms not defined in this Privacy Policy have the meanings given to those terms in the General Policy.

Please read this Privacy Policy carefully to understand our policies and practices regarding the personal information we collect and how we use it.

This policy is available free of charge on our website. On request, we will take reasonable steps to provide a copy in a different format.

2. Personal Information We Collect

We collect your personal information for the lawful purposes of providing our Services and operating our business, as outlined in the General Policy, and only where the information is necessary for those purposes.

We collect personal information directly from you where practicable, by lawful means and by means that are fair and not unreasonably intrusive in the circumstances, particularly where we collect personal information from children or young persons.

At or before the time we collect personal information from you (or, if not practicable at that time, as soon as practicable afterwards), we will take reasonable steps to make you aware of:

  • the fact that we are collecting the information, and the purpose for which we are collecting it;
  • the intended recipients of the information;
  • our name and address, and the name and address of any other agency that will hold the information;
  • if the collection is authorised or required by or under law, the particular law and whether the supply of the information is voluntary or mandatory;
  • the consequences (if any) for you if you do not provide the information; and
  • your rights of access to, and correction of, the information.

Personal information we collect from other sources

We may also collect personal information about you from a source other than you. For example, a school or other organisation that uses our Services may provide us with personal information about students, parents, caregivers or staff. Where we do so, we will take reasonable steps to make you aware of the matters described above as soon as reasonably practicable after collection, unless you have already been made aware of those matters (including by the school or other organisation that provided the information to us) or another exception under the Privacy Act applies.

3. Sensitive Information

Collection and handling

The Privacy Act does not define separate categories of ‘sensitive’ personal information. We recognise, however, that some personal information is more sensitive than other personal information, and that the steps that are reasonable to protect it are correspondingly greater.

We will only collect such information where it is necessary for one or more of our functions or activities, and we will only use or disclose it:

  • in accordance with applicable laws, this Privacy Policy and the General Policy; and
  • for the purposes for which it was collected, or purposes directly related to those purposes that you would reasonably expect.

Biometric information

Where we offer features that involve biometric processing, we will comply with the Biometrics Code, including by:

  • assessing, before we begin collecting biometric information, whether the biometric processing is necessary and proportionate, and whether the purpose could reasonably be achieved as effectively by a means that has less privacy risk;
  • providing a clear and conspicuous notice, before or at the time of collection, that sets out the purposes of the processing, whether an alternative that does not involve biometric processing is available, how long we retain biometric information, and where our proportionality assessment (or a summary of it) can be viewed; and
  • not using biometric information to categorise individuals, except as permitted by the Biometrics Code.

We will not use biometric information to train, develop or improve artificial intelligence (AI) or machine learning (ML) models, or for the purposes of direct marketing.

AI use

Where we use AI or ML tools in connection with our Services, we will do so in accordance with applicable laws, this Privacy Policy and the General Policy.

Except as permitted by applicable law or with your authorisation, we do not use AI to make decisions about you that have legal or similarly significant effects, without meaningful human oversight. If we propose to use AI in a way that is likely to have a significant effect on you, we will provide additional notice and explain your available options, including how to request human review.

4. How We Use Personal Information

We use and disclose personal information for the purposes for which it was collected (as outlined in the General Policy) and for directly related purposes that you would reasonably expect, or otherwise with your authorisation, or as required or authorised by law.

Unique identifiers

We assign unique identifiers (such as account or user identifiers) to individuals only where doing so is necessary to enable us to carry out one or more of our functions efficiently.

We do not assign to you a unique identifier that, to our knowledge, has already been assigned to you by another agency. Where our Services record a unique identifier assigned to you by another agency — for example, a National Student Number assigned by the Ministry of Education — we do so for the sole purpose of communicating with that agency about you, and not as an identifier of our own.

We take reasonable steps to ensure that unique identifiers are assigned only to individuals whose identity is clearly established, and to minimise the risk of misuse of unique identifiers. We will not require you to disclose a unique identifier except for a purpose in connection with which that identifier was assigned, or a purpose directly related to such a purpose.

5. How We Disclose Personal Information

Where we hold personal information on behalf of a school or other organisation that uses our Services, we hold that information as that organisation’s agent and we use and disclose it only as authorised by that organisation. Please see the Notice to Our Organization Customer End Users section of the General Policy.

We are likely to disclose personal information to recipients outside New Zealand (including our service providers, delivery networks, support teams and related companies) for the purposes described in this Privacy Policy and the General Policy. Due to the dynamic nature of our service providers and the way that modern cloud and support services operate, it is not practicable for us to list all the countries in which such recipients may be located at a particular point in time.

We typically disclose personal information to the following categories of recipients outside New Zealand:

  • cloud hosting and data storage providers;
  • software (including software-as-a-service) vendors;
  • IT support and cybersecurity service providers;
  • payment and billing processors;
  • professional advisers; and
  • customer support providers.

In the ordinary course of operations, those recipients are commonly located overseas, including in Australia, the United Kingdom, the United States of America, and certain member states of the European Union. However, the specific providers that we use, and the countries in which they are located, may change as our service arrangements evolve.

Before we disclose personal information to a recipient outside New Zealand, we take reasonable steps to satisfy ourselves that one or more of the following applies:

  • the recipient is carrying on business in New Zealand and, in relation to the information, we believe on reasonable grounds that the recipient is subject to the Privacy Act;
  • the recipient is subject to privacy laws that, overall, provide comparable safeguards to those in the Privacy Act;
  • the recipient is required to protect the information in a way that, overall, provides comparable safeguards to those in the Privacy Act, including under contractual terms such as model contractual clauses; or
  • the recipient is a participant in a prescribed binding scheme, or is subject to privacy laws of a prescribed country.

Where none of the above applies, we will only disclose your personal information to a recipient outside New Zealand with your authorisation, having expressly informed you that the recipient may not be required to protect the information in a way that, overall, provides comparable safeguards to those in the Privacy Act.

You may contact us at any time to request further information about whether your personal information is likely to be disclosed to recipients outside New Zealand and, if so, the countries in which those recipients are likely to be located at that time (see How to Contact Us in the General Policy).

6. Your Rights and Choices

You may request access to your personal information by contacting us (see How to Contact Us in the General Policy). We will decide whether to grant your request and advise you of that decision as soon as reasonably practicable, and in any event no later than 20 working days after we receive your request. We may charge a reasonable fee only in the limited circumstances permitted by the Privacy Act. If we refuse access, we will provide our reasons and explain how you can make a complaint.

You may request that we correct your personal information by contacting us (see How to Contact Us in the General Policy) if you consider it is inaccurate, out-of-date, incomplete, irrelevant or misleading. We will respond as soon as reasonably practicable, and in any event no later than 20 working days after we receive your request. If we do not correct the information as you have requested, we will, if you ask us to, take reasonable steps to attach to the information a statement of the correction sought but not made, and we will provide our reasons and explain how you can make a complaint. If we correct personal information and you ask us to notify third parties to whom we have disclosed that information, we will take reasonable steps to do so, where practicable and lawful.

Where a request relates to the personal information of a child or young person, we will consider whether the person making the request is entitled to make it on that individual’s behalf, having regard to the individual’s age and circumstances and to their best interests. We may decline a request where the individual concerned is under the age of 16 and disclosure would be contrary to their interests. Where we hold the information on behalf of a school or other organisation, we will refer the request to that organisation.

We have appointed a privacy officer whose responsibilities include encouraging our compliance with the information privacy principles, dealing with requests made to us under the Privacy Act, and working with the Office of the Privacy Commissioner. You can contact our privacy officer at [email protected].

If you have a question or complaint about how we handle your personal information, please contact us in the first instance (see How to Contact Us in the General Policy). We will acknowledge your complaint and respond within a reasonable timeframe. If you are not satisfied with our response, you may complain to the Office of the Privacy Commissioner (OPC). See www.privacy.org.nz for contact details, or telephone 0800 803 909. You may not bring proceedings before the Human Rights Review Tribunal in relation to a privacy complaint before complaining to OPC.

7. Advertising and Marketing

We may use your personal information for direct marketing in accordance with the Privacy Act and the Unsolicited Electronic Messages Act 2007. You may opt out of direct marketing at any time by using the unsubscribe facility in our communications or by contacting us.

8. How We Protect Personal Information

We will take reasonable steps to protect your personal information against loss, and against access, use, modification or disclosure that is not authorised, and against other misuse.

We take reasonable steps to ensure that the personal information we collect is accurate, up-to-date, complete, relevant and not misleading before we use or disclose it. However, you acknowledge that we rely on you to provide information to us that is, to your knowledge, accurate, up-to-date and complete.

Where a privacy breach has caused, or is likely to cause, serious harm to an affected individual, we will notify OPC and affected individuals as soon as practicable, as required by the Privacy Act. Where we hold the affected personal information on behalf of a school or other organisation, we will also notify that organisation.

9. Retention of Personal Information

We will not keep personal information for longer than it is required for the purposes for which it may lawfully be used. Where we no longer need personal information for any purpose permitted under this Privacy Policy, the General Policy and the Privacy Act, and we are not required by law to retain it, we will take reasonable steps to destroy it or to de-identify it.