Jitbug - Privacy and Data Policy

Last updated: 14 July 2026

Social Recruitment Technology Limited trading as Jitbug (“Jitbug”, “we”, “us” and “our”) is committed to protecting Personal Information in accordance with the New Zealand Privacy Act 2020, including the Information Privacy Principles. Where applicable, we also take account of other privacy and data protection requirements, including the European Union General Data Protection Regulation (“GDPR”).

This Privacy and Data Policy explains how we collect, use, disclose, store and transfer Personal Information supplied by Users or collected by us, how we comply with these legal requirements, and the ways in which Users can protect their privacy.

Our Privacy and Data Policy also specifies other requirements, such as how Users may access, correct and delete information held about them.

By using our services (including our Scissors™ app), or accessing our website, Users agree to comply with the terms and conditions of this Privacy and Data Policy and agree that Jitbug may process (i.e. collect, use, store, transfer, disclose or otherwise process) User’s Personal Information in accordance with this Privacy and Data Policy (as well as for any other use authorised by the User).

Our Privacy and Data Policy explains:

1. USER CONSENT

Jitbug provides a mobile application (Scissors™) to assist the recruitment of teachers by early childhood centres, which includes services supplied by third party providers (together, “our services”). We collect Personal Information in order to be able to provide and improve our services, and for the other uses described below.

By using our services, accessing our website or providing Personal Information to us, Users consent to our collection, storage, use and disclosure of Personal Information (including any sensitive information provided) in accordance with this Privacy and Data Policy.

2. INFORMATION WE COLLECT

There are three ways we collect information:

(A) Information Users Give Us

In order to purchase or use our services, a User must provide us with certain contact, billing and Personal Information including name, address, phone number, email address, industry specific information and company information. Users may also at times provide financial information.

Users may also provide us with information when they:

Users can always choose not to provide us with Personal Information, however this may mean that we are unable to supply our services effectively, or at all.

(B) Information We Collect from Use of Our Services

We may automatically collect information (which may include Personal Information) when Users interact with or use our services by visiting our website or communicating with us. This information may include:

(C) Information We Collect from Third Parties

We work closely with third parties (for example, our service providers) in order to be able to develop and supply our services, and provide them to Users.

We may receive the same kinds of information described in (a) and (b) above from third parties.

Indirect Collection and Notice (Information Privacy Principle 3A)

We may collect Personal Information about an individual from early childhood centres, employers, referees, service providers, government agencies, verification providers, or other Users of our services.

When we collect Personal Information about an individual from someone other than that individual, we will take reasonable steps to make the individual aware of the collection as soon as reasonably practicable after we collect it, unless we have already done so.

Our notice will explain:

We may not provide a separate notice where an exception under the Privacy Act 2020 applies.

Personal Information Received from Users about Others

When using our services, Users may disclose, and we may collect, Personal Information about someone else. For example, data supplied by Users may contain Personal Information relating to the customers, or employees of Users.

Before disclosing Personal Information to us about someone else, Users must ensure that they are authorised to disclose it and that the disclosure complies with applicable privacy and data protection laws. This does not limit our responsibility to meet our own obligations under the Privacy Act 2020, including Information Privacy Principle 3A where it applies.

Users shall remain responsible for all Personal Information collected and processed by the User, and for compliance with applicable privacy and data protection laws.

3. HOW WE USE PERSONAL INFORMATION

We collect and use Personal Information in order to be able to provide and improve our services.

We also use Personal Information to:

For these purposes we may receive, use, store, share, send, combine, transform, reformat, encrypt, mask, organise, geomap, update and delete Personal Information (and undertake any further processing activities expressed or implied in this Policy). The Personal Information that we collect will not be further processed in ways that are incompatible with the initial purposes for which the data was collected.

4. WHO WE SHARE INFORMATION WITH

We share information, including Personal Information, as necessary to provide Users the service requested or authorised. For example, we may share information with:

From time to time we may use third-party data processors to provide elements of services for us. We will have contracts in place with all of our data processors, to prevent them from doing anything with Users’ Personal Information unless we or the User has instructed them to do so. Unless the User agrees otherwise, our data processors will:

We require that our service providers and suppliers (data processors) agree to keep all User information we share with them confidential. While we provide these third parties with no more information than is necessary to perform the function for which we engaged them, Users should be aware that any information provided by the User to these third parties independently/directly is subject to the third parties' respective privacy policies and practices.

We may also share or use non-Personal Information (i.e. information that is related to a Person but does not personally identify that individual, such as aggregated, anonymised or de-identified data) publically or with third parties, such as our third party suppliers. For example, we may share or use information publically to show trends about the general use of our services. This data or information will in no way identify Users or any other individual.

5. STEPS TAKEN TO PROTECT PERSONAL INFORMATION

Protecting the security of User Personal Information is of the utmost importance to Jitbug. We maintain a variety of safeguards and procedures in order to protect Personal Information from unauthorised access, use, interference, modification or disclosure.

Our safeguards may include access controls, password protection, role-based access, secure cloud hosting, encrypted transmission where appropriate, system monitoring, backup and recovery processes, staff confidentiality obligations, and limiting access to authorised personnel and service providers who need the information for authorised business purposes.

Some of our services do require use of the internet, and the internet is not itself a secure environment. We therefore cannot give an absolute assurance or guarantee that User information will be secure at all times. Transmission of information over the internet or third-party networks is at the User’s own risk.

Privacy Breaches

If we become aware of a privacy breach involving Personal Information we hold, we will contain and assess the breach in accordance with the Privacy Act 2020.

If it is reasonable to believe the breach has caused, or is likely to cause, serious harm to an affected individual, we will notify the Office of the Privacy Commissioner as soon as practicable. We will also notify affected individuals as soon as practicable, unless an exception or permitted delay applies under the Privacy Act 2020. If direct notification to an affected individual is not reasonably practicable, we will give public notice as required by the Act.

We will also take reasonable steps to mitigate harm, prevent further unauthorised access, and reduce the likelihood of a similar breach occurring again.

To help maintain the security of information, Users agree to keep their passwords and account details private and confidential.

6. USERS’ DATA PROTECTION RIGHTS

Under data protection and privacy laws, Users have rights regarding the Personal Information that we hold/collect. The rights available to Users depend on our reason for processing Users’ Personal information. These rights include:

All requests should be sent to us at admin@jitbug.co.nz, and include the words “Attention: The Privacy Officer”. User choices in relation to Personal Information may affect our ability to provide our services, or the performance of the services. We will respond to Users as soon as reasonably practicable regarding the impact of the User’s requests on the services, any other issues arising and to confirm the User’s intention to proceed. If we are unable to comply with the request, we will give the User reasons for this decision when we respond (for example, the information may not be readily retrievable and it may not be reasonable or practicable for us to process the request in the manner sought. In some instances, it may also be necessary for us to arrange access to User Personal Information through a third party e.g. a third party service provider).

7. COMMUNICATIONS

We are committed to full compliance with the Unsolicited Electronic Messages Act 2007.

By subscribing to email communications, or otherwise providing an email address, Users consent to receiving emails which promote and market our services, or the services of others, from time to time.

Users can unsubscribe from our email communications at any time by clicking the "Unsubscribe" link in any promotional or marketing email, or by emailing admin@jitbug.co.nz, and include the words “Attention: The Privacy Officer”.

Once a User has unsubscribed from the email communications, the User will be removed from the corresponding email/distribution list as soon as is reasonably practicable.

8. LINKS AND CONNECTIONS TO THIRD PARTY SERVICES

Our website contains links to (and may be used by Users in conjunction with) third-party services, tools, and websites that are not controlled or managed by us. This Privacy and Data Policy does not cover how these organisations process Personal Information. These websites may use cookies. It is the responsibility of those third parties to collect appropriate consents from Users in order to permit their own cookies (to the extent this is required by law) and to inform Users about the cookies they use. Users should check the privacy policy on all third-party websites to ensure they are comfortable with third party cookies.

We have no responsibility for linked websites, and provide them solely for Users’ information and convenience. We specifically disclaim responsibility for their content, privacy practices and terms of use, and we make no endorsements, representations or warranties about their accuracy, content or thoroughness.

Disclosure of Personal Information by Users to third party service providers is at the User’s own risk, and we encourage Users to read the privacy policies applicable to these third-party services. We are not responsible for the security or privacy of any information collected by these third-parties.

9. INTERNATIONAL DATA TRANSFERS

When we use service providers to store or process Personal Information, it may be transferred to, and processed in, countries other than New Zealand. In those countries, there may be differences from New Zealand’s privacy laws. Where a service provider stores or processes Personal Information solely on our behalf, we remain responsible for that information and take reasonable steps to ensure it is protected.

For example:

Before disclosing Personal Information to a foreign Person or entity, we will take reasonable steps to satisfy ourselves that a permitted basis for the disclosure applies under Information Privacy Principle 12. This means that the recipient will:

Alternatively, we may disclose Personal Information to a foreign Person or entity if another basis permitted by the Privacy Act 2020 applies. This may include the User expressly authorising the disclosure after we have informed them that the recipient may not be required to protect the information in a way that, overall, provides comparable safeguards to the Privacy Act 2020.

For further information, please contact us using the details set out in the contact section below.

10. RETENTION AND DELETION OF PERSONAL INFORMATION

We retain Personal Information only for as long as it is reasonably required for the purposes for which it may lawfully be used. These purposes may include providing our services, maintaining business records, meeting legal and regulatory obligations, resolving disputes, enforcing agreements, and maintaining security and audit records.

When Personal Information is no longer required for a lawful purpose, we will take reasonable steps to delete it, securely destroy it, or anonymise it.

11. ACCESSING AND UPDATING USER PERSONAL INFORMATION

Users are responsible for ensuring that Personal Information provided to us is accurate, complete and up-to-date. This includes personal or sensitive information contained in their User content. We will also take reasonable steps to ensure that any Personal Information that we collect (i.e. information obtained from other sources) is accurate, up-to-date, complete and not misleading.

Subject to the Privacy Act 2020, Users may ask us to confirm whether we hold Personal Information about them and request access to that information. Users may also request that we update, correct or delete Personal Information that is inaccurate or inappropriate for the purposes for which it was collected.

Requests for access to, or the correction of, Personal Information should be emailed to admin@jitbug.co.nz, and include the words “Attention: The Privacy Officer”.

We will respond to requests for access or correction as soon as reasonably practicable and no later than 20 working days after receiving the request, unless a lawful extension applies. If we are unable to meet a User’s request, we will explain the reasons why when we respond, except where the law permits us to withhold those reasons.

12. HOW TO CONTACT US

Social Recruitment Technology Limited has appointed a Privacy Officer to oversee our compliance with the Privacy Act 2020. Please contact our Privacy Officer if you have any questions or complaints about this Privacy and Data Policy, if you wish to access or request correction of Personal Information, or if you otherwise have a question or complaint about the manner in which we or our service providers treat Personal Information.

Users may write to our Privacy Officer by email, including any supporting documentation, at admin@jitbug.co.nz, and include the words “Attention: The Privacy Officer”.

Alternatively, you can write to us at:

Social Recruitment Technology Limited T/A Jitbug
Attention: Privacy Officer
4B/20 Emily Place
Auckland 1010
New Zealand

We will respond to privacy enquiries and complaints as soon as reasonably practicable.

If you are not satisfied with our response to a privacy complaint, you may contact the Office of the Privacy Commissioner at https://www.privacy.org.nz/.

Application of this Privacy and Data Policy

Our Privacy and Data Policy applies to all of the services offered by us. Our Privacy and Data Policy does not cover the information practices of other companies and organisations (such as our third party service providers) that supply, contract and advertise using our website.

Changes to this Privacy and Data Policy

We keep this Policy under regular review to make sure it is up to date and accurate. We also reserve the right to change this Policy from time to time, as our practices evolve to meet new requirements, standards, technologies and customer feedback. We will post any privacy policy changes on our website (https://www.jitbug.co.nz/privacy) and will update the “last updated” date at the top of this Policy. Continued use of our services by Users will be deemed acceptance of any amended Policy.

We recommend that Users regularly review this Policy to learn how we protect Personal Information.

Definitions

In this Policy, unless the context requires otherwise:

Binding Scheme: means a binding scheme specified in regulations made under section 213 of the Privacy Act 2020 (NZ);

Person: means and includes any natural person, company, corporation, firm, partnership, joint venture, society, organisation or other group or association of Persons (whether incorporated or not), trust, state or agency of state, statutory or regulatory body, local authority, government or governmental or semi-governmental body or agency (in each case whether or not having separate legal personality);

Personal Information: means information about an identifiable individual and includes, without limitation, names, addresses, phone numbers, email addresses and IP addresses;

Prescribed Country: means a country specified in regulations made under section 214 of the Privacy Act 2020 (NZ);

User(s) means all Persons accessing our website and/or using our services (including any part of the services), including Persons that load and/or manage content on our website or our mobile application, or that receive or subscribe for any other paid services, and/or any Persons providing Personal Information to us;

User account means any User’s account with us;

we, us, our, Jitbug means Social Recruitment Technology Limited trading as Jitbug.