Privacy Policy
In this Privacy Policy we, us or our means Kiwi Smile and any of our related entities, as set out below. The following entity is responsible for the collection and processing of your personal data in connection with your use of the Site, depending on the region in which you are located:
New Zealand: Kiwi Smile Alignment Limited
The information we collect
Personal information: is information or an opinion, whether true or not and whether recorded in a material form or not, about an individual who is identified or reasonably identifiable. The types of personal information we may collect about you include:
- your name;
- images of you if you share them with us;
- your contact details, including email address, street address and/or telephone number;
- your credit card or payment details (through our third party payment processor);
- information you provide to us through customer surveys;
- details of products and services we have provided to you and/or that you have enquired about, and our response to you;
- where you have opt-ed in to our Outbound Marketing Program Terms and Conditions or made a purchase from our Site, the details of your shopping cart and/or any products you have purchased from us;
- your browser session and geo-location data, device and network information, statistics on page views and sessions, acquisition sources, search queries and/or browsing behaviour;
- information about your access and use of our Services, including through the use of Internet cookies, your communications with our online Services, the type of browser you are using, the type of operating system you are using and the domain name of your Internet service provider;
- additional personal information that you provide to us, directly or indirectly, through your use of our Services, associated applications, associated social media platforms and/or accounts from which you permit us to collect information; and
- any other personal information requested by us and/or provided by you or a third party.
We may collect these types of personal information directly from you or from third parties.
Collection and use of personal information
We will collect and process personal information where we have lawful basis. This includes collecting and processing personal information based on your consent, the performance of a contract with you and/or our legitimate interests. We may collect, hold, use and disclose personal information for the following purposes:
- to enable you to access and use our Services, including to enable the supply and delivery of goods purchased through our Site;
- to contact and communicate with you;
- for internal record keeping, administrative purposes, invoicing and billing purposes;
- to provide you with location-based Services (such as radius search and other content that is personalised on the basis of your general location data);
- for analytics, market research and business development, including to operate and improve our Services, associated applications and associated social media platforms;
- to run promotions, competitions and/or offer additional benefits to you;
- for advertising and marketing, including to send you promotional information about our products and services and information about third parties that we consider may be of interest to you;
- to call or message you for targeted marketing and feedback purposes, if you have opted into our Outbound Marketing Program Terms and Conditions;
- to comply with our legal obligations and resolve any disputes that we may have; and
- for any other purpose for which the information was collected.
If you are under the age of majority in your state or province of residence, you should not use our Services or Site. We do not knowingly collect personal information from anyone under the age of majority. If we become aware that anyone under this age has provided us with personal information, we will take steps to remove such information.
Your personal information will:
- be processed securely and in a way that protects against unauthorised or unlawful processing and against accidental loss, destruction or damage;
- only be collected for the specific purposes we have identified in the ‘collection and use of personal information’ clause above and personal information will not be further processed in a manner that is incompatible with the purposes we have identified;
- be kept up to date, where it is possible and within our control to do so (please let us know if you would like us to correct any of your personal information); and
- be kept in a form which permits us to identify you, but only be retained for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.
To determine the appropriate retention period for personal information, we consider the amount, nature, and sensitivity of the personal information, the potential risk of harm from unauthorised use or disclosure of your personal information, the purposes for which we process your personal information, whether we can achieve those purposes through other means and the applicable legal requirements.
Disclosure of personal information to third parties
We may disclose personal information to:
- third party service providers for the purpose of enabling them to provide their services, including (without limitation) IT service providers, data storage, web-hosting and server providers, debt collectors, maintenance or problem-solving providers, marketing or advertising providers, professional advisors and payment systems operators;
- Shopify, to power the online store on our Site. You can read more about how Shopify uses your personal data here: https://www.shopify.com/legal/privacy;
- our employees, contractors and/or related entities;
- our existing or potential agents or business partners;
- sponsors or promoters of any promotions or competition we run;
- anyone to whom our business or assets (or any part of them) are, or may (in good faith) be, transferred;
- credit reporting agencies, courts, tribunals and regulatory authorities, in the event you fail to pay for goods or services we have provided to you;
- courts, tribunals, regulatory authorities and law enforcement officers, as required by law, in connection with any actual or prospective legal proceedings, or in order to establish, exercise or defend our legal rights; and
- third parties, including agents or sub-contractors, who assist us in providing information, products, services or direct marketing to you.
Overseas disclosure: Where we disclose your personal information to third parties listed above, these third parties may store, transfer or access personal information overseas. Upon request, we may provide you with a list of the third parties we use to process your personal information.
Unless we seek and receive your consent to an overseas disclosure of your personal information, we will only disclose your personal information to countries with laws which protect your personal information in a way which is substantially similar to the New Zealand Privacy Principles and/or we will take such steps as are reasonable in the circumstances to require that overseas recipients protect your personal information.
Your rights and controlling your personal information
Access, erasure and data portability: You may have the right to request details of the personal information we hold about you, or to request that we erase the personal information we hold about you, or that we transfer this information to a third party.
Complaints: If you wish to make a complaint about how we have handled your personal information, please contact us using the details below and provide us with full details of the complaint. We will promptly investigate your complaint and respond to you, in writing, setting out the outcome of our investigation and the steps we will take to deal with your complaint. You also have the right to contact the relevant authority.
Correction: If you believe that any information we hold about you is inaccurate, out of date, incomplete, irrelevant or misleading, please contact us using the details below. We will take reasonable steps to correct any information found to be inaccurate, incomplete, misleading or out of date.
Information from third parties: If we receive personal information about you from a third party, we will protect it as set out in this Privacy Policy. If you are a third party providing personal information about somebody else, you represent and warrant that you have such person’s consent to provide the personal information to us.
Objecting to processing: You may have the right to object to processing of your personal information that is based on our legitimate interests or public interest. If this is done, we must provide compelling legitimate grounds for the processing which overrides your interests, rights and freedoms, in order to proceed with the processing of your personal information.
Restricting processing: You may have the right to request that we restrict the processing of your personal information if (i) you are concerned about the accuracy of your personal information; (ii) you believe your personal information has been unlawfully processed; (iii) you need us to maintain the personal information solely for the purpose of a legal claim; or (iv) we are in the process of considering your objection in relation to processing on the basis of legitimate interests.
Unsubscribe: If you have previously agreed to us using your personal information for direct marketing purposes, you may change your mind at any time by contacting us using the details below. You may also unsubscribe from our e-mail database or opt-out of marketing communications by using the opt-out facilities provided in the communication.
Your choice: Please read this Privacy Policy carefully. If you provide personal information to us, you understand we will collect, hold, use and disclose your personal information in accordance with this Privacy Policy. You do not have to provide personal information to us, however, if you do not, it may affect your use of our Services.
Storage and security
We are committed to ensuring that the personal information we collect is secure. In order to prevent unauthorised access or disclosure, we have put in place suitable physical, electronic and managerial procedures to safeguard and secure the personal information and protect it from misuse, interference, loss and unauthorised access, modification and disclosure.
We cannot guarantee the security of any information that is transmitted to or by us over the Internet. The transmission and exchange of information is carried out at your own risk. Although we take measures to safeguard against unauthorised disclosures of information, we cannot assure you that the personal information we collect will not be disclosed in a manner that is inconsistent with this Privacy Policy.
Cookies and web beacons
We may use cookies on our online Services from time to time. Cookies are text files placed in your computer's browser to store your preferences. Cookies, by themselves, do not tell us your email address or other personally identifiable information. However, they do allow third parties, such as Google and Facebook, to cause our advertisements to appear on your social media and online media feeds as part of our retargeting campaigns. If and when you choose to provide our online Services with personal information, this information may be linked to the data stored in the cookie.
You can block cookies by activating the setting on your browser that allows you to refuse the setting of all or some cookies. However, if you use your browser settings to block all cookies (including essential cookies) you may not be able to access all or parts of our online Services.
We may use web beacons on our website from time to time. Web beacons (also known as Clear GIFs) are small pieces of code placed on a web page to monitor the visitor’s behaviour and collect data about the visitor’s viewing of a web page. For example, web beacons can be used to count the users who visit a web page or to deliver a cookie to the browser of a visitor viewing that page.
We may use Google Analytics to collect and process data. To find out how Google uses data when you use third party websites or applications, please see www.google.com/policies/privacy/partners/ or any other URL Google may use from time to time.
Links to other websites
Our Services may contain links to other websites. We do not have any control over those websites and we are not responsible for the protection and privacy of any personal information which you provide whilst visiting those websites. Those websites are not governed by this Privacy Policy.
Advertising related third parties
In terms of third parties, we use Shopify to power the online store on our Site. You can read more about how Shopify uses your personal data here: https://www.shopify.com/legal/privacy.
We also use Google Analytics to help us understand how our customers use the Site – you can read more about how Google uses your personal data here: https://www.google.com/intl/en/policies/privacy/.
You can also opt-out of Google Analytics here: https://tools.google.com/dlpage/gaoptout.
Targeted advertising
For more information about how targeted advertising works, you can visit the Network Advertising Initiative’s (“NAI”) educational page at http://www.networkadvertising.org/understanding-online-advertising/how-does-it-work.
You can opt out of targeted advertising by using the links below:
- Facebook: https://www.facebook.com/settings/?tab=ads
- Google: https://www.google.com/settings/ads/anonymous
- Bing: https://advertise.bingads.microsoft.com/en-us/resources/policies/personalized-ads
Additionally, you can opt out of some of these services by visiting the Digital Advertising Alliance’s opt-out portal at: http://optout.aboutads.info/. Please note that we do not alter our Site’s data collection and use practices when we see a Do Not Track signal from your browser.
How to stop receiving communications from us
To stop receiving email correspondence from us, simply click on the link in the email communication to unsubscribe.
To stop receiving the SMS communications from us reply to any SMS with the word 'STOP".
To remove your details from any of our marketing and communication databases simply email the relevant Data Protection Officer listed in section 3 above.
Amendments
We may, at any time and at our discretion, vary this Privacy Policy. We will notify you if we amend this Privacy Policy, by contacting you through the contact details you have provided to us. Any amended Privacy Policy is effective once we notify you of the change.
Data Protection Officer and Contact
In those countries where we are required to do so by law, we have appointed data protection officers to oversee the protection of your personal data. If you have any questions about this Privacy Notice or about data protection in general, you can contact the data protection officer responsible for your country at any time. Details of the relevant data protection for your country are as follows:
- New Zealand: Privacy Office Email: support@kiwismile.co.nz
For any questions or notices, please contact the relevant Privacy Officer above.
Last update: 5 April 2022