Home / Privacy policy
Privacy policy
What we collect, why we collect it, where it lives, and how to get it back or have it deleted.
1. Our commitment
We handle personal information in accordance with the Privacy Act 2020 (New Zealand) and the thirteen information privacy principles in it. Where we handle the personal information of people in Australia, or act for Australian clients, we also handle it in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
Where the two regimes differ, we apply whichever gives you the stronger protection. "Personal information" means information about an identifiable individual — the same thing Australian law calls personal information and other jurisdictions call personal data.
2. Information we collect
Information you give us
- Your name, email address, phone number and organisation when you submit an enquiry form, email us or call us.
- What you tell us about your project, business processes and systems during enquiries, workshops and discovery.
- Billing details and purchase order information if you become a client.
- Anything else you choose to send us, including attachments and documents.
Information we collect automatically
- Standard web server logs: IP address, browser and device type, the pages requested, referring page, and the date and time of the request.
- The IP address and browser string attached to a form submission, which we keep as a record of the enquiry and to limit automated abuse of the form.
Information we handle for clients
When we build, host or support a platform for a client, that platform may hold personal information about the client's own customers, staff or members. We handle that information only on the client's instructions and only to deliver the agreed services. The client remains the agency responsible for it, and their own privacy policy governs how it is used. If you are a customer of one of our clients, please contact that organisation directly.
3. Cookies and analytics
This website does not set advertising or tracking cookies. If we add analytics, we will use it in a privacy-respecting configuration, and this policy will be updated before it goes live. Most browsers let you block or delete cookies through their settings; blocking them will not stop this website working.
4. Why we collect it, and what we do with it
We collect personal information so that we can:
- answer your enquiry and keep a record of the conversation;
- prepare proposals, quotes and estimates;
- deliver, host, support and improve the services you have engaged us for;
- invoice you and keep the accounting records the law requires;
- keep our website and systems secure, and investigate misuse;
- meet our legal obligations.
Providing the information is voluntary, but if you do not give us your name and a way of contacting you, we cannot respond to an enquiry or provide services.
5. Marketing and electronic messages
We do not sell or rent contact details to anyone, and we do not add enquirers to a marketing list without asking. If we send commercial electronic messages, they will identify us clearly and carry a working unsubscribe option, as required by the Unsolicited Electronic Messages Act 2007 (NZ) and the Spam Act 2003 (Cth). Unsubscribing takes effect promptly and does not affect service messages about work we are doing for you.
6. Who we share it with
We do not sell personal information. We disclose it only where it is necessary for the purpose it was collected, including to:
- service providers who host our website, email, ticketing and accounting systems, under contracts that require them to protect it;
- subcontractors and specialists working on your project, bound by confidentiality obligations;
- a client's own systems, where we are integrating or migrating data on their instructions;
- our professional advisers, insurers or auditors where reasonably required;
- anyone else with your authorisation, or where the law requires or permits disclosure.
7. Storage and overseas transfer
Our systems and the platforms we build are normally hosted in New Zealand or Australia. Some service providers we rely on — including cloud, email and productivity platforms — store or process information in other countries, such as the United States and the European Union.
Before sending personal information overseas we take reasonable steps to satisfy ourselves that the recipient is subject to privacy safeguards comparable to those in the Privacy Act 2020 (NZ), and, for Australian Privacy Principle 8 purposes, that the overseas recipient will handle the information consistently with the Australian Privacy Principles.
8. How we protect it
We apply reasonable technical and organisational safeguards: encryption in transit, access control and least-privilege permissions, multi-factor authentication on administrative systems, patching, monitoring, logging and backups. Staff and contractors may access personal information only where they need it to do their job.
No system is perfectly secure, and we cannot guarantee the security of information while it is in transit to us over the internet. If we suffer a privacy breach that is likely to cause serious harm, we will notify the affected people and the Office of the Privacy Commissioner (NZ), and, where the Notifiable Data Breaches scheme applies, the Office of the Australian Information Commissioner.
9. How long we keep it
- Enquiries that do not become projects: deleted within 24 months of the last contact.
- Client project records: kept for the life of the engagement and then for seven years, which is the retention period business and tax records are subject to in New Zealand. Australian tax records are generally kept for at least five years.
- Server and security logs: kept for a short rolling period, normally no more than 12 months.
We delete or de-identify personal information once we no longer need it for a lawful purpose.
10. Access, correction and deletion
You have the right to ask us for confirmation of whether we hold personal information about you, to ask for a copy of it, and to ask us to correct it if it is wrong. Email hello@3rdrockdigital.com with enough detail to identify yourself and what you are asking for.
We will respond as soon as reasonably practicable and within 20 working days. There is normally no charge. If we decline a request, we will tell you why and how to complain. If we cannot correct information, you may ask us to attach a statement of the correction you sought, and we will do so.
You can also ask us to delete information we no longer need. Where we are required to keep records — tax and accounting records, for example — we will tell you which records those are and delete the rest.
11. Complaints
If you think we have mishandled your personal information, contact us first at hello@3rdrockdigital.com. We will acknowledge your complaint within five working days and give you a substantive response within 20 working days.
If you are not satisfied with our response, you can complain to:
- New Zealand: Office of the Privacy Commissioner — 0800 803 909, privacy.org.nz.
- Australia: Office of the Australian Information Commissioner — 1300 363 992, oaic.gov.au.
12. Children
This website and our services are aimed at businesses and are not directed at children. We do not knowingly collect personal information from children. If you believe a child has given us personal information, contact us and we will delete it.
13. Changes to this policy
We may update this policy as our services or the law change. The current version is always on this page with its "last updated" date. If a change materially affects how we handle information we already hold about you, we will tell you directly.
Privacy enquiries
3rd Rock Digital Limited
Level 3, 120 Featherston Street, Wellington 6011, New Zealand