1. PURPOSE

This Privacy Policy explains how Vega Global New Zealand Limited collects, uses, discloses, and protects personal information in accordance with the Privacy Act 2020.

2. SCOPE

Personal information is any information about an identifiable individual. This includes customers, employees, contractors, and other individuals.

3. POLICY STATEMENT

Vega NZ manages the collection and use of personal information in line with the Privacy Act 2020 through internal processes and contractual arrangements where applicable.

Vega NZ is committed to protecting personal information through a risk-based approach that ensures confidentiality, integrity, and availability.

4. COLLECTION OF PERSONAL INFORMATION

We collect personal information directly from individuals where possible, including when:

  • You engage our services
  • You communicate with us (email, phone, forms)
  • You enter into a contract or agreement with us

We may also collect personal information from third parties where:

  • You have authorised this, or
  • The information is publicly available, or
  • It is necessary to deliver our services

We only collect personal information that is necessary for our business activities.

If you choose not to provide certain information, this may impact our ability to provide services.

5. COOKIES

We may use cookies and similar technologies on our website to improve user experience and analyse website usage. Cookies are small text files stored on your device.

You can control or disable cookies through your browser settings. Please note that disabling cookies may affect the functionality of our website.

6. PURPOSE OF COLLECTION

We collect personal information directly from individuals where possible, including when:

  • You engage our services
  • You communicate with us (email, phone, forms)
  • You enter into a contract or agreement with us

We may also collect personal information from third parties where:

  • You have authorised this, or
  • The information is publicly available, or
  • It is necessary to deliver our services

We only collect personal information that is necessary for our business activities.

If you choose not to provide certain information, this may impact our ability to provide services

7. STORAGE AND SECURITY

We take reasonable steps to protect your information from loss, misuse or unauthorised access. See below.

8. MARKETING COMMUNICATIONS

We may use your personal information to send you updates, newsletters, or other communications related to our products and services where permitted by law.

We comply with the Unsolicited Electronic Messages Act 2007. You may opt out of receiving marketing communications from us at any time by using the unsubscribe function or contacting us directly.

9. COMPLIANCE AND MONITORING

Privacy is managed within the Integrated Management System (IMS) and supported by:

  • Risk Register
  • Systems Matrix
  • Incident and Breach Logs
  • Internal audits and management review
  • Cybersecurity awareness and privacy obligation training for staff

10. SHARING YOUR INFORMATION

We may share your information with trusted third parties who assist us in operating our business, or where by required by law.

This may include:

  • Service providers and partners who support our operations
  • Technology providers and system hosts
  • Professional advisors
  • Regulatory or government authorities where required

We take reasonable steps to ensure third parties handle personal information in accordance with applicable privacy and security requirements.

11. INFORMATION TECHNOLOGY (IT) AND DATA SECURITY STATEMENT

We take reasonable technical and organisational measures to protect personal information from loss, misuse, and unauthorised access. This includes access controls, system security measures, and working with trusted third-party providers who meet our data protection standards. These measures are supported by our internal management systems and security practices, which are regularly reviewed and improved.

12. OVERSEAS DISCLOSURE

Some of our service providers may be located outside New Zealand.

Where personal information is transferred overseas, we take reasonable steps to ensure it is protected in a manner consistent with New Zealand privacy law.

13. INCIDENCE RESPONSE PLAN

Vega NZ manages incidents through established processes for identification, escalation, and response, including notification where required.

This includes processes for managing privacy and information security incidents in line with our internal management systems.

14. ACCESS AND CORRECTION

You have the right to request access to the personal information we hold about you, and to request correction of that information if you believe it is inaccurate.

To make a request, please contact our Privacy Officer at ims.nz@vega-global.com. We may need to verify your identity before processing your request.

We will respond to your request in accordance with the Privacy Act 2020.

15. REVIEW

This policy is reviewed regularly, at least annually, as part of operations and/or as regulatory changes require update.

16. ROLES AND RESPONSIBILITIES

Privacy Officer (Operations Director)Owns policy
IMS LeadsMaintain framework, monitoring and audit readiness
System OwnersEnsure secure systems and access control
All EmployeesHandle personal information in accordance with this policy
Privacy Officer (Operations Director)Owns policy
IMS LeadsMaintain framework, monitoring and audit readiness
System OwnersEnsure secure systems and access control
All EmployeesHandle personal information in accordance with this policy

17. CONTACT US

If you have any questions, please contact the Privacy Officer at Vega NZ via ims.nz@vega-global.com.

Vega Technology Limited (NZ)

41-45 Ireland Street, Freemans Bay, Auckland, 1011
T: 0800 487 269
E: general.nz@vega-global.com