Jitbug - Privacy and Data Policy
Last updated: 14 July 2026
Social Recruitment Technology Limited trading as Jitbug (“Jitbug”, “we”,
“us” and “our”) is committed to protecting Personal Information in
accordance with the New Zealand Privacy Act 2020, including the
Information Privacy Principles. Where applicable, we also take account of
other privacy and data protection requirements, including the European
Union General Data Protection Regulation (“GDPR”).
This Privacy and Data Policy explains how we collect, use, disclose, store
and transfer Personal Information supplied by Users or collected by us,
how we comply with these legal requirements, and the ways in which Users
can protect their privacy.
Our Privacy and Data Policy also specifies other requirements, such as how
Users may access, correct and delete information held about them.
By using our services (including our Scissors™ app), or accessing our
website, Users agree to comply with the terms and conditions of this
Privacy and Data Policy and agree that Jitbug may process (i.e. collect,
use, store, transfer, disclose or otherwise process) User’s Personal
Information in accordance with this Privacy and Data Policy (as well as
for any other use authorised by the User).
Our Privacy and Data Policy explains:
- (1) Consent;
- (2) What information we collect and how;
- (3) How we use Personal Information;
- (4) Who we share Personal Information with and why;
- (5) Our security safeguards and privacy breach response;
- (6) Users’ data protection rights;
- (7) Communications;
- (8) Links and connections to third party services;
- (9) International data transfers;
- (10) How Jitbug retains and deletes Personal Information;
- (11) How to access and update Personal Information; and
- (12) How to contact us.
1. USER CONSENT
Jitbug provides a mobile application (Scissors™) to assist the recruitment
of teachers by early childhood centres, which includes services supplied
by third party providers (together, “our services”). We collect Personal
Information in order to be able to provide and improve our services, and
for the other uses described below.
By using our services, accessing our website or providing Personal
Information to us, Users consent to our collection, storage, use and
disclosure of Personal Information (including any sensitive information
provided) in accordance with this Privacy and Data Policy.
2. INFORMATION WE COLLECT
There are three ways we collect information:
- (1) Information Users give us.
- (2) Information we collect when Users use our services.
- (3) Information we collect from third parties.
(A) Information Users Give Us
In order to purchase or use our services, a User must provide us with
certain contact, billing and Personal Information including name, address,
phone number, email address, industry specific information and company
information. Users may also at times provide financial information.
Users may also provide us with information when they:
- Purchase our services;
- Register with us;
- Create and verify User accounts and logins;
-
Send correspondence to us, including job listings or applications;
- Register for events promoted or hosted by us;
-
Participate in surveys, promotions or competitions we organise or
promote;
- Interact with our Facebook page;
-
Subscribe to receive the latest news on our services, and the services
of our third party service providers; or
- Contact our support team.
Users can always choose not to provide us with Personal Information,
however this may mean that we are unable to supply our services
effectively, or at all.
(B) Information We Collect from Use of Our Services
We may automatically collect information (which may include Personal
Information) when Users interact with or use our services by visiting our
website or communicating with us. This information may include:
-
System information: We may collect information about
User system(s) including, but not limited to, the User operating system,
applications, IP address, and where applicable, host ID, and other User
system environment information.
-
Usage information: We collect information about how
Users and their system environment interact with our services.
Information that may be collected includes:
- Information relating to the features Users use;
-
The performance of the services and any problems experienced by
Users;
- The pages that Users visit on our website;
- Website content accessed by Users;
- Length of the Users’ stay on a specific page; and
- Browser information.
-
Location: When Users use our services (including our
website and mobile application), we may collect and process information
about the User’s location. We use various technologies to determine
location, including IP addresses and web analytics.
-
Device information: When Users use some of our
services, we may receive information about the User’s device, such as
the hardware model, operating system version, unique device identifier
and mobile network information (including phone number).
-
Cookies and similar technology: We ask Users for their
consent on our website and mobile application before using cookies. We
use cookies, web beacons and similar technologies to provide our
services, and to help collect data. For example, when Users visit our
website, we collect information about the pages visited, the User’s
browser and the User’s device. A cookie is a small element of data that
a website can send to the User’s browser, which may then be stored on
the hard drive (session ID cookies will terminate once Users simply
close the browser, persistent cookies may however be stored on the
User’s hard drive for an extended period of time). A persistent
auto-login cookie is also stored when Users select the "remember me"
option when logging in. The auto-login cookie is removed if Users log
out on our website or uninstall our mobile application. A cookie does
not identify a User personally, but it does identify the User’s computer
or mobile phone. Cookies allow us, among other things, to monitor
traffic patterns, store User preferences and settings to personalise the
User experience, analyse how our services are performing, track Users,
help us identify Users misusing our services and enable Users to login
automatically. Users should be aware that most web browsers are set to
accept cookies by default, but allow settings to be adjusted to remove
or block cookies. Please note however that rejecting or removing cookies
could affect the availability and functionality of our website features,
or our services.
-
Interest-based advertising (IBA): IBA allows us to
deliver targeted advertising to Users of our services. IBA works by
showing you advertisements that are based on the type of content you
access or read. For example, as you browse our services, one of the
cookies placed on your device will be an advertising cookie so we can
better understand what sort of pages or content you are interested in.
The information collected about Users’ devices enable us to group Users
with other devices that have shown similar interests. We can then
display advertising to categories of Users that is based on common
interests. For example, we display advertising to categories of Users on
Facebook that are based on common interests using Facebook’s Lookalike
Audiences. Check out Facebook’s privacy policy to learn more about
protecting your privacy:
https://www.facebook.com/about/privacy/. You can also deactivate the custom audiences remarketing feature in
the Ads Settings section at
https://www.facebook.com/ads/preferences/?entry_product=ad_settings_screen.
-
Analytics and advertising: Our website may use the
following analytics and advertising services to assist our marketing and
promotional activities:
-
Google Analytics: For the purpose of customizing and
continually optimizing our website, we may use Google Analytics, a web
analytics service provided by Google Inc. ("Google"), including Google
Analytics Demographics and Interest reporting. In this service,
pseudonymised usage profiles are created and cookies are used to
generate information about your use of this website such as browser type
/ version, operating system, referrer URL (the previously visited page),
IP address for your computer or device, date, time and any demographic
and interests information available in the cookie such as your age and
gender, along with your interests expressed through your online
behaviour and purchases. This information is transmitted to a Google
server in the US and stored there. The information is used to evaluate
the use of our website, to compile reports on website activity and to
provide other services related to website activity and internet usage
for the purposes of market research and our website design. For example,
this information is used to remarket to you using
Google Display Network and/or
Google Marketing Platform which displays Jitbug
advertising for you when you later visit other websites. This
information may also be transferred to third parties if required by law
or if third parties process this data. Under no circumstances will your
IP address be merged with any other data provided by Google. The IP
addresses are anonymized. You can prevent the collection of data
generated by the cookie and related to your use of the website
(including your IP address) and the processing of this data by Google by
downloading and installing a browser add-on (
https: //tools.google.com/dlpage/gaoptout?hl=en
). For more information about privacy related to Google Analytics, see
the Google Analytics information at
https://support.google.com/analytics/answer/6004245?hl=en
).
To statistically record the use of our website and to evaluate it for the
purpose of optimizing our website, we may also use Google conversion
tracking. In doing so, Google Adwords will set a cookie on your computer
if you have reached our website via a Google ad. These cookies lose their
validity after 30 days and are not used for personal identification. If
the User visits certain pages of the Adwords customer's website and the
cookie has not yet expired, Google can detect that the User had previously
clicked on the ad and was redirected to this page. Every Adwords customer
receives a different cookie. Cookies cannot be tracked via the websites of
Adwords customers. The information obtained through the conversion cookie
is used to generate conversion statistics for Adwords customers who have
opted for conversion tracking. Adwords customers are informed about the
total number of Users who clicked on their ad and were redirected to a
conversion tracking tag page. However, they do not receive information
that personally identifies Users. If you do not want to participate in the
tracking process, you can also refuse the setting of a cookie - for
example, via a browser setting that generally disables the automatic
setting of cookies. You can also disable cookies for conversion tracking
by setting your browser to block cookies from the domain
"www.googleadservices.com". Google's privacy policy on conversion tracking
can be found here (https://services.google.com/sitestats/en.html).
-
Facebook Pixel: Our website measures conversions using
visitor action pixels from Facebook, Facebook Inc., 1601 S. California
Ave, Palo Alto, CA 94304, USA (“Facebook”). These allow the behaviour of
site visitors to be tracked after they click on a Facebook ad to reach
the provider’s website. This allows an analysis of the effectiveness of
Facebook advertisements for statistical and market research purposes and
their future optimization. The data collected is anonymous to us as
operators of our website and we cannot use it to draw any conclusions
about our Users’ identities. However, the data is stored and processed
by Facebook, which may make a connection to your Facebook profile and
which may use the data for its own advertising purposes, as stipulated
in the Facebook privacy policy. This will allow Facebook to display ads
both on Facebook and on third-party sites. We have no control over how
this data is used. Check out Facebook’s privacy policy to learn more
about protecting your privacy: https://www.facebook.com/about/privacy/.
You can also deactivate the custom audiences remarketing feature in the
Ads Settings section at
https://www.facebook.com/ads/preferences/?entry_product=ad_settings_screen.
You will first need to log into Facebook. If you do not have a Facebook
account, you can opt out of usage-based advertising from Facebook on the
website of the European Interactive Digital Advertising Alliance:
http://www.youronlinechoices.com/de/praferenzmanagement/.
-
Social Media Plug-ins: Our website has built in social
media plug-ins from the social networks Facebook, YouTube and LinkedIn
to make our company better known, and personalise usage.
-
Facebook: On our website, social media plugins from
Facebook are used. If you visit a page of our website that contains a
Facebook plugin, your browser establishes a direct connection to the
Facebook servers. The content of the plugin is transmitted by Facebook
directly to your browser. By integrating the plugins, Facebook receives
the information that your browser has accessed the corresponding page of
our website, even if you do not have a Facebook account or are currently
not logged in to Facebook. This information (including your IP address)
is transmitted from your browser directly to a Facebook server in the US
and stored there. If you are logged in to Facebook, Facebook can assign
the visit to our website directly to your Facebook account. If you
interact with the plugins, for example by pressing the "LIKE" or "SHARE"
button, the corresponding information is also transmitted directly to a
Facebook server and stored there. The information will also be posted on
Facebook and displayed to your Facebook friends. Facebook may use this
information for the purpose of advertising, market research and
tailoring Facebook pages. For this purpose, Facebook uses user, interest
and relationship profiles (for example, to evaluate your use of our
website with regard to the advertisements displayed on Facebook, to
inform other Facebook users about your activities on our website and to
further inform you about the use of related services). If you do not
want Facebook to assign the data collected via our website to your
Facebook account, you must log out of Facebook before visiting our
website. The purpose and scope of the data collection and the further
processing and use of the data by Facebook, as well as your related
rights and settings options for the protection of your privacy, please
refer to the privacy policy of Facebook at
https://www.facebook.com/about/privacy/.
-
Youtube: If you visit a page of our website that
contains a Youtube plugin, your browser connects directly to the servers
of Youtube. The content of the plugin is transmitted from Youtube
directly to your browser and integrated into the page. Through this
integration Youtube receives the information that your browser has
accessed the corresponding page of our website, even if you do not have
a Youtube profile or are currently not logged in to Youtube. This
information (including your IP address) is transmitted by your browser
directly to a server of Youtube and stored there. If you are logged in
to Youtube, Youtube can directly assign your visit to our website to
your Youtube account. If you interact with the plugins, for example by
pressing the "Youtube" button, this information will also be transmitted
directly to a Youtube server in the USA and stored there. If you do not
want Youtube to directly assign the data collected via our website to
your Youtube account, you must log out of Youtube before visiting our
website. For more information, see Youtube’s privacy policy at
https://policies.google.com/privacy/en.
LinkedIn:
Our website also uses LinkedIn's social plug-in operated by the LinkedIn
Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland.
When you visit a page of our website that contains such a plug-in, your
browser connects directly to LinkedIn's servers. The content of the
plug-in is transmitted by LinkedIn directly to your browser and integrated
into the page. Through this integration, LinkedIn receives the information
that your browser has accessed the corresponding page of our website, even
if you do not have a LinkedIn profile or are currently not logged in to
LinkedIn. This information (including your IP address) is sent directly
from your browser to a LinkedIn server and stored there. If you are logged
in to LinkedIn, LinkedIn can instantly associate your visit to our website
with your LinkedIn account. If you interact with the plug-ins, for example
by clicking on the "LinkedIn" button, this information will also be
transmitted directly to a LinkedIn server in the US and stored there. If
you do not want LinkedIn to directly associate the data collected through
our website with your LinkedIn account, you must log out of LinkedIn
before visiting our website. For more information, see LinkedIn’s Privacy
Policy at https://www.linkedin.com/legal/privacy-policy.
-
Other Third Party Service Providers: We may use other
third party service providers to assist our communications, surveys and
other interactions with Users.
- For example, we use:
-
Microsoft Outlook to send surveys and promotions to
Jitbug employees. Outlook may collect Personal Information, such as
distribution lists which contain email addresses, and other information
relating to those email addresses. For further information about the
type of Personal Information Microsoft collects, refer to Microsoft’s
Privacy Policy at https://privacy.microsoft.com/en-us/PrivacyStatement.
Microsoft is based in Australia and the data will be transmitted to and
stored by Microsoft on servers located outside New Zealand.
-
Google Accounts to store and sync contact details of
Users. For further information about the type of Personal Information
Google collects, refer to Google’s Privacy Policy at
https://policies.google.com/privacy.
-
Disclosure to overseas providers: Some analytics,
advertising, social media and service providers described above may
collect information directly from Users under their own privacy
policies. Where we disclose Personal Information to a foreign Person or
entity, we will comply with section 9 of this Policy. If we rely on a
User’s authorisation because the recipient may not provide comparable
safeguards, we will expressly inform the User of that fact before
obtaining their authorisation.
(C) Information We Collect from Third Parties
We work closely with third parties (for example, our service providers) in
order to be able to develop and supply our services, and provide them to
Users.
We may receive the same kinds of information described in (a) and (b)
above from third parties.
Indirect Collection and Notice (Information Privacy Principle 3A)
We may collect Personal Information about an individual from early
childhood centres, employers, referees, service providers, government
agencies, verification providers, or other Users of our services.
When we collect Personal Information about an individual from someone
other than that individual, we will take reasonable steps to make the
individual aware of the collection as soon as reasonably practicable after
we collect it, unless we have already done so.
Our notice will explain:
- That we have collected the individual’s Personal Information;
- The purpose for which we collected it;
- The intended recipients of the information;
-
The name and address of the agency that collected the information and
the agency that holds it;
-
The particular law authorising or requiring the collection, where
applicable; and
-
The individual’s rights to access and request correction of the
information.
We may not provide a separate notice where an exception under the Privacy
Act 2020 applies.
Personal Information Received from Users about Others
When using our services, Users may disclose, and we may collect, Personal
Information about someone else. For example, data supplied by Users may
contain Personal Information relating to the customers, or employees of
Users.
Before disclosing Personal Information to us about someone else, Users
must ensure that they are authorised to disclose it and that the
disclosure complies with applicable privacy and data protection laws. This
does not limit our responsibility to meet our own obligations under the
Privacy Act 2020, including Information Privacy Principle 3A where it
applies.
Users shall remain responsible for all Personal Information collected and
processed by the User, and for compliance with applicable privacy and data
protection laws.
3. HOW WE USE PERSONAL INFORMATION
We collect and use Personal Information in order to be able to provide and
improve our services.
We also use Personal Information to:
-
Communicate, interact and build our relationship with Users, including
to better understand Users’ needs and interests, and ensure a quality
experience for Users;
-
Monitor, develop or optimise the performance of our services, including
to conduct internal research;
-
Protect and enhance the safety and security of our services and Users;
- Provide information and technical support;
- Carry out billing and licence administration;
- Market and make recommendations on our services;
-
Allow our third party providers to provide their services and support to
Users;
- Conduct, manage, develop and protect our business;
- Enforce our terms and conditions of service and other agreements;
- Comply with laws and regulations in applicable jurisdictions;
-
Verify Users’ identities and prevent fraud or other unauthorised or
illegal activity; and
- Enable third parties to provide services to us.
For these purposes we may receive, use, store, share, send, combine,
transform, reformat, encrypt, mask, organise, geomap, update and delete
Personal Information (and undertake any further processing activities
expressed or implied in this Policy). The Personal Information that we
collect will not be further processed in ways that are incompatible with
the initial purposes for which the data was collected.
4. WHO WE SHARE INFORMATION WITH
We share information, including Personal Information, as necessary to
provide Users the service requested or authorised. For example, we may
share information with:
-
Banks and other entities which process payment transactions when a
payment is made;
-
Our third party providers to provide services to the User, to
communicate with Users (for example, information shared with
communication service providers), to provide Users with information on
the performance of our services or the services supplied by our third
party providers or, to provide Users with remote access or to provide
notifications;
-
Our service providers or suppliers acting and working on our behalf. For
example, companies we have hired to assist in protecting and securing
our systems and services may need access to Personal Information to
provide those services, or may obtain. In such cases, we will require
these entities to abide by our data privacy and security requirements,
and restrict use of any Personal Information received from us;
-
The New Zealand Qualifications Authority (NZQA) to provide evidence for
Early Childhood Education (ECE) qualifications; Other third parties,
when we have a good faith belief that doing so is necessary to:
-
(1) Comply with any applicable law, regulation, legal process or
enforceable governmental request. For example, to comply with:
- (i) Education Review Office audits; or
-
(2) New Zealand Police vetting requirements under both the
Children’s Act 2014 and the Education and Training Act 2020. Protect
our Users;
-
(3) Operate and maintain the security of our services, including to
prevent or stop an attack on our computer systems or networks;
- (4) Detect, prevent or otherwise address fraud;
-
(5) Protect our rights and property, including enforcing our terms
and conditions of service and other agreements; or
-
A purchaser, as part of a corporate transaction such as an acquisition,
merger or sale of assets.
From time to time we may use third-party data processors to provide
elements of services for us. We will have contracts in place with all of
our data processors, to prevent them from doing anything with Users’
Personal Information unless we or the User has instructed them to do so.
Unless the User agrees otherwise, our data processors will:
-
Not share Users’ Personal Information with any organisation apart from
us; and
-
Hold Users’ Personal Information securely and retain it for the period
we instruct.
We require that our service providers and suppliers (data processors)
agree to keep all User information we share with them confidential. While
we provide these third parties with no more information than is necessary
to perform the function for which we engaged them, Users should be aware
that any information provided by the User to these third parties
independently/directly is subject to the third parties' respective privacy
policies and practices.
We may also share or use non-Personal Information (i.e. information that
is related to a Person but does not personally identify that individual,
such as aggregated, anonymised or de-identified data) publically or with
third parties, such as our third party suppliers. For example, we may
share or use information publically to show trends about the general use
of our services. This data or information will in no way identify Users or
any other individual.
5. STEPS TAKEN TO PROTECT PERSONAL INFORMATION
Protecting the security of User Personal Information is of the utmost
importance to Jitbug. We maintain a variety of safeguards and procedures
in order to protect Personal Information from unauthorised access, use,
interference, modification or disclosure.
Our safeguards may include access controls, password protection,
role-based access, secure cloud hosting, encrypted transmission where
appropriate, system monitoring, backup and recovery processes, staff
confidentiality obligations, and limiting access to authorised personnel
and service providers who need the information for authorised business
purposes.
Some of our services do require use of the internet, and the internet is
not itself a secure environment. We therefore cannot give an absolute
assurance or guarantee that User information will be secure at all times.
Transmission of information over the internet or third-party networks is
at the User’s own risk.
Privacy Breaches
If we become aware of a privacy breach involving Personal Information we
hold, we will contain and assess the breach in accordance with the Privacy
Act 2020.
If it is reasonable to believe the breach has caused, or is likely to
cause, serious harm to an affected individual, we will notify the Office
of the Privacy Commissioner as soon as practicable. We will also notify
affected individuals as soon as practicable, unless an exception or
permitted delay applies under the Privacy Act 2020. If direct notification
to an affected individual is not reasonably practicable, we will give
public notice as required by the Act.
We will also take reasonable steps to mitigate harm, prevent further
unauthorised access, and reduce the likelihood of a similar breach
occurring again.
To help maintain the security of information, Users agree to keep their
passwords and account details private and confidential.
6. USERS’ DATA PROTECTION RIGHTS
Under data protection and privacy laws, Users have rights regarding the
Personal Information that we hold/collect. The rights available to Users
depend on our reason for processing Users’ Personal information. These
rights include:
-
Right of access: Users have the right to ask us for
copies of their Personal Information. This right always applies.
-
Right to correction: Users have the right to ask us to
update or correct information they think is inaccurate. Users also have
the right to ask us to complete information that the User thinks is
incomplete. Users are responsible for ensuring that Personal Information
provided to us is accurate, complete and up-to-date. We will take
reasonable steps to ensure that any further Personal Information that we
collect (i.e. information obtained from other sources) is accurate,
up-to-date, complete and not misleading. If we do not make a requested
correction, Users may ask us to attach a statement of the correction
requested to the information.
-
Right to erasure: Users have the right to ask us to
erase their Personal Information in certain circumstances.
-
Right to restriction of processing: Users have the
right to ask us to restrict or cease the processing of their information
in certain circumstances. This may (depending upon the circumstances)
include the collection of Personal Information from third parties,
collection of sensitive information, disclosure of Personal Information
to third parties, transfer of Personal Information overseas, or
processing of Personal Information in a particular way, or for a
particular purpose, including direct marketing.
-
Right to data portability: This only applies to
information Users have given us. Users have the right to ask that we
transfer the information Users have given us from one organisation to
another, or give it to the User. This right only applies if we are
processing information based on Users’ consent, or under (or in talks
about entering into) a contract and the processing is automated.
All requests should be sent to us at admin@jitbug.co.nz, and include the
words “Attention: The Privacy Officer”. User choices in relation to
Personal Information may affect our ability to provide our services, or
the performance of the services. We will respond to Users as soon as
reasonably practicable regarding the impact of the User’s requests on the
services, any other issues arising and to confirm the User’s intention to
proceed. If we are unable to comply with the request, we will give the
User reasons for this decision when we respond (for example, the
information may not be readily retrievable and it may not be reasonable or
practicable for us to process the request in the manner sought. In some
instances, it may also be necessary for us to arrange access to User
Personal Information through a third party e.g. a third party service
provider).
7. COMMUNICATIONS
We are committed to full compliance with the Unsolicited Electronic
Messages Act 2007.
By subscribing to email communications, or otherwise providing an email
address, Users consent to receiving emails which promote and market our
services, or the services of others, from time to time.
Users can unsubscribe from our email communications at any time by
clicking the "Unsubscribe" link in any promotional or marketing email, or
by emailing admin@jitbug.co.nz, and include the words “Attention: The
Privacy Officer”.
Once a User has unsubscribed from the email communications, the User will
be removed from the corresponding email/distribution list as soon as is
reasonably practicable.
8. LINKS AND CONNECTIONS TO THIRD PARTY SERVICES
Our website contains links to (and may be used by Users in conjunction
with) third-party services, tools, and websites that are not controlled or
managed by us. This Privacy and Data Policy does not cover how these
organisations process Personal Information. These websites may use
cookies. It is the responsibility of those third parties to collect
appropriate consents from Users in order to permit their own cookies (to
the extent this is required by law) and to inform Users about the cookies
they use. Users should check the privacy policy on all third-party
websites to ensure they are comfortable with third party cookies.
We have no responsibility for linked websites, and provide them solely for
Users’ information and convenience. We specifically disclaim
responsibility for their content, privacy practices and terms of use, and
we make no endorsements, representations or warranties about their
accuracy, content or thoroughness.
Disclosure of Personal Information by Users to third party service
providers is at the User’s own risk, and we encourage Users to read the
privacy policies applicable to these third-party services. We are not
responsible for the security or privacy of any information collected by
these third-parties.
9. INTERNATIONAL DATA TRANSFERS
When we use service providers to store or process Personal Information, it
may be transferred to, and processed in, countries other than New Zealand.
In those countries, there may be differences from New Zealand’s privacy
laws. Where a service provider stores or processes Personal Information
solely on our behalf, we remain responsible for that information and take
reasonable steps to ensure it is protected.
For example:
-
Microsoft: We use Office 365, a suite of cloud-based
office software services and Power Platform, a group of business
intelligence, app development, and app connectivity software
applications, provided by Microsoft Inc., within our business. Office
365 and Power Platform currently process and store New Zealand User data
in data centres in New South Wales and Victoria, Australia. For more
information on Microsoft’s protection and privacy, see Microsoft’s
Privacy Policy at
https://privacy.microsoft.com/en-us/PrivacyStatement.
-
Google Cloud Platform: We may use third-party database
and storage providers. We currently store data on the Google Cloud
Platform, a cloud service provided by Google Inc. For more information
on the privacy practices of Google Cloud, please visit the Google Cloud
Privacy web page at
https://cloud.google.com/security/privacy/. This data is currently stored on servers located in Australia.
-
Xero: For accounting functions, we use Xero. Xero is a
cloud-based accounting service provided by Xero Limited and related
companies. Xero processes and stores New Zealand User data in the United
States. For more information on Xero’s data protection and privacy, see
https://www.xero.com/nz/about/privacy/
and
https://www.xero.com/nz/about/security/.
-
SignNow: We use SignNow for signing contracts and the
completion of tax and KiwiSaver forms. SignNow is a cloud-based provider
of electronic signature technology provided by airSlate Inc. SignNow
processes and stores User data in Europe and the United States. For more
information on SignNow’s data protection and privacy, see
https://www.signnow.com/securityandcompliance.
Before disclosing Personal Information to a foreign Person or entity, we
will take reasonable steps to satisfy ourselves that a permitted basis for
the disclosure applies under Information Privacy Principle 12. This means
that the recipient will:
-
Be subject to the Privacy Act 2020 or privacy laws that, overall,
provide comparable safeguards to those in the Privacy Act 2020; or
-
Be a participant in a prescribed Binding Scheme or be located in a
Prescribed Country; or
-
Be required by contract or other binding arrangement to protect the
information in a way that, overall, provides comparable safeguards to
those in the Privacy Act 2020.
Alternatively, we may disclose Personal Information to a foreign Person or
entity if another basis permitted by the Privacy Act 2020 applies. This
may include the User expressly authorising the disclosure after we have
informed them that the recipient may not be required to protect the
information in a way that, overall, provides comparable safeguards to the
Privacy Act 2020.
For further information, please contact us using the details set out in
the contact section below.
10. RETENTION AND DELETION OF PERSONAL INFORMATION
We retain Personal Information only for as long as it is reasonably
required for the purposes for which it may lawfully be used. These
purposes may include providing our services, maintaining business records,
meeting legal and regulatory obligations, resolving disputes, enforcing
agreements, and maintaining security and audit records.
When Personal Information is no longer required for a lawful purpose, we
will take reasonable steps to delete it, securely destroy it, or anonymise
it.
11. ACCESSING AND UPDATING USER PERSONAL INFORMATION
Users are responsible for ensuring that Personal Information provided to
us is accurate, complete and up-to-date. This includes personal or
sensitive information contained in their User content. We will also take
reasonable steps to ensure that any Personal Information that we collect
(i.e. information obtained from other sources) is accurate, up-to-date,
complete and not misleading.
Subject to the Privacy Act 2020, Users may ask us to confirm whether we
hold Personal Information about them and request access to that
information. Users may also request that we update, correct or delete
Personal Information that is inaccurate or inappropriate for the purposes
for which it was collected.
Requests for access to, or the correction of, Personal Information should
be emailed to admin@jitbug.co.nz, and include the words “Attention: The
Privacy Officer”.
We will respond to requests for access or correction as soon as reasonably
practicable and no later than 20 working days after receiving the request,
unless a lawful extension applies. If we are unable to meet a User’s
request, we will explain the reasons why when we respond, except where the
law permits us to withhold those reasons.
12. HOW TO CONTACT US
Social Recruitment Technology Limited has appointed a Privacy Officer to
oversee our compliance with the Privacy Act 2020. Please contact our
Privacy Officer if you have any questions or complaints about this Privacy
and Data Policy, if you wish to access or request correction of Personal
Information, or if you otherwise have a question or complaint about the
manner in which we or our service providers treat Personal Information.
Users may write to our Privacy Officer by email, including any supporting
documentation, at admin@jitbug.co.nz, and include the words “Attention:
The Privacy Officer”.
Alternatively, you can write to us at:
Social Recruitment Technology Limited T/A Jitbug
Attention: Privacy Officer
4B/20 Emily Place
Auckland 1010
New Zealand
We will respond to privacy enquiries and complaints as soon as reasonably
practicable.
If you are not satisfied with our response to a privacy complaint, you may
contact the Office of the Privacy Commissioner at
https://www.privacy.org.nz/.
Application of this Privacy and Data Policy
Our Privacy and Data Policy applies to all of the services offered by us.
Our Privacy and Data Policy does not cover the information practices of
other companies and organisations (such as our third party service
providers) that supply, contract and advertise using our website.
Changes to this Privacy and Data Policy
We keep this Policy under regular review to make sure it is up to date and
accurate. We also reserve the right to change this Policy from time to
time, as our practices evolve to meet new requirements, standards,
technologies and customer feedback. We will post any privacy policy
changes on our website (https://www.jitbug.co.nz/privacy) and will update the “last updated” date at the top of this Policy.
Continued use of our services by Users will be deemed acceptance of any
amended Policy.
We recommend that Users regularly review this Policy to learn how we
protect Personal Information.
Definitions
In this Policy, unless the context requires otherwise:
Binding Scheme: means a binding scheme specified in
regulations made under section 213 of the Privacy Act 2020 (NZ);
Person: means and includes any natural person, company,
corporation, firm, partnership, joint venture, society, organisation or
other group or association of Persons (whether incorporated or not),
trust, state or agency of state, statutory or regulatory body, local
authority, government or governmental or semi-governmental body or agency
(in each case whether or not having separate legal personality);
Personal Information: means information about an
identifiable individual and includes, without limitation, names,
addresses, phone numbers, email addresses and IP addresses;
Prescribed Country: means a country specified in
regulations made under section 214 of the Privacy Act 2020 (NZ);
User(s) means all Persons accessing our website and/or
using our services (including any part of the services), including Persons
that load and/or manage content on our website or our mobile application,
or that receive or subscribe for any other paid services, and/or any
Persons providing Personal Information to us;
User account means any User’s account with us;
we, us, our, Jitbug means Social Recruitment Technology Limited trading as
Jitbug.