Privacy Policy - Illuminai limited

Effective: 20 October 2025

Last updated: 20 October 2025

Version: 1.0

How Illuminai limited collects, uses and protects personal information under the New Zealand Privacy Act 2020.

Introduction

This Privacy Policy explains how illuminai limited (we, us, our) collects, uses, discloses and protects personal information in accordance with the New Zealand Privacy Act 2020. It applies to personal information collected through our website, services, products and other interactions.

Scope

This policy applies to all personal information about identifiable natural persons that we hold, regardless of format (electronic, paper or verbal).

Key definitions

  • Personal information: information about an identifiable individual.
  • Sensitive information: a subset of personal information that warrants greater protection (e.g. race, health, criminal record).
  • User / you: any individual who interacts with our website, products or services.

Information we may collect

We collect only the personal information necessary for the purposes set out below. Examples include:

  • Identity & contact: name, email, phone number, postal address, organisation and job title.
  • Account & payment: account credentials, billing and payment details.
  • Service usage: account activity, service settings, preferences.
  • Device & technical: IP address, browser, operating system, device identifiers, cookies and analytics data.
  • Communications: messages, support requests, survey responses.
  • Other information you choose to provide (including uploaded files).
  • We may also collect limited sensitive information only where legally permitted and with your explicit consent.

How we collect information

  • Directly: when you sign up, contact us, complete forms, subscribe or use our services.
  • Automatically: via cookies, server logs and analytics when you visit our website.
  • From third parties: service providers, publicly available sources or with your authorisation.

Purposes of collection and use

We collect and use personal information to:

  • Provide, operate and improve our services;
  • Verify identity, manage accounts and process payments;
  • Communicate with you (support, notices, updates);
  • Personalise and improve user experience and carry out analytics;
  • Detect, prevent and respond to security incidents and fraud;
  • Comply with legal obligations and enforce our rights;
  • Carry out anonymised research and reporting; and
  • Any other purpose you authorise.
  • We will not use personal information for purposes incompatible with those at the time of collection without notifying you.

We comply with the Privacy Act 2020. We collect information only where it is necessary for our functions and activities, or with your consent where required. We take reasonable steps to ensure information is accurate and not misleading.

Disclosure and third parties

We may disclose personal information to:

  • Service providers and suppliers who help deliver our services (hosting, payment processors, analytics, professional advisers);
  • Government, regulatory, law enforcement or other authorised bodies where required by law;
  • A purchaser or successor in connection with a sale, merger or reorganisation (with notice where appropriate);
  • Other parties where you have consented to that disclosure.
  • Third parties may process information outside New Zealand. Where we transfer information offshore we will take reasonable steps to ensure comparable protections are in place.

Automated decision-making and AI

We may use automated systems, including AI-driven tools, to support provision or improvement of services (for example: analytics, recommendation engines or automated support). If automated decision-making materially affects you, you may request human review — contact us (details below).

Cookies and tracking

We use cookies and similar technologies to operate the website, maintain sessions, enable functionality and for analytics. You can manage or disable cookies in your browser settings; note that disabling cookies may limit functionality.

Data security

We take reasonable administrative, technical and physical measures to protect personal information from loss, unauthorised access, use, modification or disclosure. No system is completely secure; if a significant privacy breach occurs, we will notify affected individuals and the Office of the Privacy Commissioner as required by law.

Retention

We retain personal information only as long as necessary to fulfil the purposes for which it was collected, to meet legal or regulatory requirements, or to resolve disputes. Retention periods vary by data type; we will securely delete or de-identify information when no longer required.

Access, correction and complaints

You have the right to request access to personal information we hold about you and to request correction of inaccurate information, subject to permitted exceptions under the Privacy Act 2020. To request access or correction, or to raise a privacy concern, contact us (details below).

If you remain unsatisfied after contacting us you may make a complaint to the Office of the Privacy Commissioner in New Zealand.

Children

Our services are not directed at children under 13. We do not knowingly collect personal information from children without parental consent. If you believe we have collected such information, contact us and we will take steps to delete it.

Changes to this policy

We may update this policy from time to time. We will publish the updated policy on our website with the effective date. Continued use of our services after changes indicates acceptance of the updated policy.

Contact us

For questions, access or correction requests, complaints or to request human review of an automated decision, please contact our Privacy Officer at: privacy@illuminai.nz