Privacy Policy
Last updated: 25 June 2026
This Privacy Policy is a privacy statement that explains how Jointsradiant.ddd ("we", "us", "our", "the agency") collects, uses, discloses, stores, and protects personal information when you visit our website or contact us.
We are an agency under the Privacy Act 2020 (New Zealand) and comply with its Information Privacy Principles (IPPs). Where the EU General Data Protection Regulation (GDPR) applies to you, we also respect the rights described in Section 12 below.
1. Agency Details
The agency responsible for your personal information is:
Jointsradiant.ddd
Physical address: 54 Holmwood Road, Merivale, Christchurch 8014, New Zealand
Email: talk@jointsradiant.world
Phone: +64 22 125 3011
For privacy enquiries, contact us using the details above. We will respond within 20 working days of receiving a valid request, as required under IPP 6, or sooner where possible.
2. Personal Information We Collect
"Personal information" means information about an identifiable individual, as defined in the Privacy Act 2020.
- Contact form: your name, email address, message content, and confirmation that you consent to processing.
- Technical information: IP address, browser type and version, device type, operating system, pages viewed, time and date of visits, referring URL, and general location derived from IP (country/region level).
- Cookie and similar technologies data: preferences stored in your browser or local storage, as described in our Cookie Policy.
- Communications: any additional information you voluntarily provide by email or phone.
We do not intentionally collect sensitive information (such as health records or financial account details) through this website. Please do not include sensitive information in contact form messages unless necessary, and never include payment card numbers.
3. How We Collect Information
3.1 Direct collection (IPP 3)
When you submit our contact form or email us directly, we collect personal information from you. At or before collection we inform you (via the form and this policy) of:
- the fact that information is being collected;
- what information is collected and why;
- who will receive it (see Section 6);
- your right to access and request correction of your information;
- that providing contact details is voluntary, but we cannot respond to your enquiry without a valid email address and message;
- our contact details as the collecting agency.
3.2 Indirect collection (IPP 3A)
From 1 May 2026, IPP 3A requires agencies that collect personal information indirectly to take reasonable steps to inform individuals. We may receive technical data indirectly through hosting providers, analytics tools (only if you consent to analytics cookies), or embedded services such as Google Maps. Where practicable, we inform you through this policy and our cookie banner before or as soon as possible after such collection.
3.3 Collection from children and young people
Our website is intended for a general adult audience. We do not knowingly collect personal information from anyone under 16 without verifiable parental or guardian consent. If you believe a child has provided us personal information, contact us and we will take reasonable steps to delete it.
4. Purpose of Collection and Use (IPP 1, IPP 10)
We collect personal information only for lawful purposes connected with our functions and activities, and we use information only for the purpose for which it was collected or a directly related purpose, unless you authorise otherwise or an exception under the Privacy Act applies.
| Information | Purpose |
|---|---|
| Contact form data | To read, respond to, and maintain a record of your enquiry |
| Technical data | To operate, secure, and troubleshoot the website; detect abuse |
| Analytics data (with consent) | To understand aggregate site usage and improve content |
| Cookie preferences | To remember your cookie choices |
We will not use your personal information for direct marketing unless you have given express consent or an exception under the Unsolicited Electronic Messages Act 2007 and Privacy Act applies. We do not sell personal information.
5. Storage and Security (IPP 5)
We take reasonable safeguards to protect personal information against loss, unauthorised access, use, modification, or disclosure. Measures include:
- HTTPS/TLS encryption for data transmitted between your browser and our servers;
- access controls limiting staff access to personal information on a need-to-know basis;
- confidentiality obligations for anyone handling enquiries;
- periodic review of security practices and hosting arrangements;
- secure deletion or anonymisation when information is no longer required.
No method of electronic storage or transmission is completely secure. You are responsible for maintaining the security of your own devices and email accounts.
6. Disclosure of Personal Information (IPP 2, IPP 11)
We may disclose personal information to:
- Hosting and IT providers that store website data and server logs on our behalf;
- Analytics providers (e.g. Google Analytics), only where you have consented to analytics cookies;
- Professional advisers (such as lawyers) where reasonably necessary;
- Government agencies or courts when required or authorised by New Zealand law, including a court order or statutory direction.
We require service providers to handle personal information only for specified purposes and in accordance with applicable privacy law.
7. Overseas Disclosure (IPP 12)
Some recipients of personal information may be located outside New Zealand — for example, cloud hosting in Australia, the United States, or the European Union; Google LLC (Maps, Analytics); or Cloudflare CDN services.
Before disclosing personal information overseas, we take reasonable steps under IPP 12 to ensure the recipient is subject to comparable privacy safeguards, such as:
- contractual clauses requiring protection equivalent to the Privacy Act 2020;
- using providers that participate in recognised privacy frameworks; or
- your informed consent to the overseas disclosure where appropriate.
By using optional analytics cookies or embedded Google Maps, you acknowledge that information may be processed overseas. You may decline analytics cookies via our cookie banner.
8. Retention (IPP 9)
We retain personal information only for as long as necessary to fulfil the purposes for which it was collected, unless a longer retention period is required or permitted by law.
- Contact form submissions: up to 24 months from last correspondence, then securely deleted or anonymised.
- Server and security logs: typically up to 90 days.
- Cookie consent records: 12 months, after which we request renewed consent.
- Analytics data: according to the analytics provider's settings, generally up to 26 months, only if you consented.
9. Access and Correction (IPP 6, IPP 7)
You have the right to request access to personal information we hold about you and to request correction of any information you believe is inaccurate, incomplete, out of date, or misleading.
To make a request, email talk@jointsradiant.world with sufficient detail to identify you and the information concerned. We may need to verify your identity before releasing information.
We will respond within 20 working days. If we refuse access or correction, we will explain the reasons (where permitted by law) and inform you of your right to complain to the Office of the Privacy Commissioner.
There is no charge for reasonable access requests. We may charge a reasonable fee for extensive or repetitive requests as allowed under the Privacy Act.
10. Notifiable Privacy Breaches
Under the Privacy Act 2020, if a privacy breach has caused or is likely to cause serious harm, we are required to notify the Office of the Privacy Commissioner and affected individuals as soon as practicable.
We maintain internal procedures to assess, contain, and respond to suspected breaches, including:
- identifying and containing the breach;
- assessing whether serious harm is likely;
- notifying the Commissioner and affected individuals where required;
- reviewing the incident and improving safeguards to prevent recurrence.
If you believe your personal information held by us has been compromised, contact us immediately at talk@jointsradiant.world.
11. Cookies and Similar Technologies
We use cookies and local storage as described in our Cookie Policy. Non-essential cookies are placed only after you provide consent through our cookie banner, in line with transparency obligations under the Privacy Act.
12. Rights of Individuals in the European Economic Area (GDPR)
If GDPR applies to our processing of your personal data, you may also have the right to:
- restrict or object to certain processing;
- data portability for information you provided with consent;
- withdraw consent at any time (without affecting prior lawful processing);
- lodge a complaint with your local EU/EEA supervisory authority.
Our legal bases under GDPR include consent (contact form, optional cookies), legitimate interests (website security and operation), and legal obligation.
13. Automated Decision-Making
We do not use automated decision-making or profiling that produces legal or similarly significant effects on individuals.
14. Complaints
If you have a concern about how we have handled your personal information, contact us first so we can try to resolve it.
If you are not satisfied with our response, you may complain to:
Office of the Privacy Commissioner (New Zealand)
Website: www.privacy.org.nz
Phone: 0800 803 909 (within New Zealand)
Email: enquiries@privacy.org.nz
15. Changes to This Policy
We review this policy at least annually and whenever we introduce new services or technologies that affect personal information. Material changes will be reflected by updating the "Last updated" date at the top of this page. Continued use of the website after changes constitutes acceptance of the updated policy where permitted by law.
16. Contact
Privacy enquiries: talk@jointsradiant.world or our contact form.