Last updated, 20 June
1.1 Your privacy is important to CREATIVA Design Studio Ltd Trading as CREATIVA Design Studio (CREATIVA Design Studio, us, we, our).
Privacy and confidentiality is key to our business. This means your Personal Information is stored securely within cloud-based systems (specified below), protected actively maintained, industry-standard security.
1.2 CREATIVA is committed to ensuring that any Personal Information you provide to us is held and used only in accordance with the privacy principles contained in the Privacy Act 2020.
1.3 In addition to our privacy obligations under New Zealand Privacy Law, we are a data controller for the purpose of the General Data Protection Regulation (GDPR). You can contact us in writing at the below address:
3.2 If you do not agree to any change we make, you should immediately stop using our services and our website.
4. Why do we collect Personal Information?
4.1 CREATIVA Design Studio collects, uses and discloses Personal Information to provide you with services, to market our services and to meet our legal obligations.
5. Who do we collect and hold Personal Information about?
(a) Persons we deal with in the course of carrying out our services and individuals associated with those persons;
(b) Individuals and organisations that we provide services to;
(c) Suppliers and their employees and contractors;
(d) Prospective employees, employees and contractors; and
(e) Other individuals and organisations who come into contact with us.
6. What Personal Information do we collect?
6.1 The type of Personal Information we collect depends on the purpose for collection and circumstances of collection, but may include:
(a) Identifying information, to verify your identity such as your CREATIVA Design Studio, date of birth, citizenship or residency;
(b)Information to enable us to comply with our obligations under anti-money laundering and countering financing of terrorism laws, including verifying your identity, and the identity of relevant persons in your organisation.
(c) Contact information, such as your postal address, residential address, telephone number, next of kin information, and email address;
(d) Payment information (if you are paying us), such as bank account or credit card details, including number, expiry date, cardholder name and billing address;
(e) Payment information (if we are paying you), such as bank account details, including number, branch, SWIFT code, account holder, and New Zealand Inland Revenue number;
(f) Any interactions you have with us (this includes time and date of contact, and relevant emails and documents)
(g) Other personal information we require from, or about, you to provide the advice that has been requested. This may be in the context of advice you have asked for, or that a third party has asked for (for example, your employer, if we are acting for your employer)
(h) Information about your work history, such as your occupation, employment history and/or details, credit history, education and qualifications, personal and professional skills and attributes, testimonials and feedback, including your curriculum vitae and other documents that may contain further Personal Information. In certain circumstances we may also ask for information such as your New Zealand Inland Revenue number;
(i) Information about your preferences, such as how you would prefer to be contacted;
(j) Website user data, collected when you visit our website. Website user data may include your IP address, cookies, device information, unique device identifiers, operating system and version and mobile network information.
7. Special categories of Personal Information
7.1 Some Personal Information, including information that reveals racial or ethnic origin, political opinions, religious or philosophical belief, trade union membership, genetic data, biometric data, health status, sex life or sexual orientation is treated as a special category of personal data under the GDPR. Generally, we will limit our collection of Personal Information that falls into this category, however, occasionally this type of information may be relevant to our interactions with you. By providing us with Personal Information that falls within this category, you explicitly consent to this information being processed for the purposes in clause 4.
8. Non-personal information
8.1 We may from time to time collect information that is not Personal Information (i.e, it is not attributable to you individually). The purpose of this is to ensure we can further develop and improve our services.
8.2 If we do combine non-personal information with Personal Information the combined information will be treated as Personal Information.
9. How do we collect Personal Information?
9.1 We may collect Personal Information directly from you, including in the following circumstances:
(a) when you interact with us in person, on the phone or via email;
(b) when you provide us with your Personal Information in another kind of document, for example, a contract for services or a curriculum vitae;
(c) when you enter information into an online form; and
(d) when you interact with us on our social media.
9.2 We collect some information automatically when you visit our website and interact with us on social media.
From third parties
9.3 We may collect Personal Information about you from third parties, including:
(a) contractors that we work with to provide you with services;
(b) a person you have provided as a referee;
(c) from credit check agencies, or educational establishments for qualification checks; and
(d) in certain circumstances, publicly available information to carry out customer due diligence or as part of the provision of our services to you.
10. Are you required to provide Personal Information to us?
10.1 In general, we will let you know at the time of collection whether the provision of Personal Information to us is optional or whether it is required for us to provide you with services in relation to you.
10.2 If we have indicated that the requested Personal Information is required and you do not provide it, we will not be able to provide you with some or all the services you have requested in relation to you.
11.1 We do not provide services to, or collect Personal Information about, minors, however we cannot distinguish the age of persons who access and use our website. If a minor (according to applicable laws) has provided us with Personal Information without parental or guardian consent, the parent or guardian should contact us to remove the Personal Information.
12. How we use your Personal Information
12.1 We use your Personal Information to:
(a) Reply to your queries or to provide services to you (or your employer);
(b) Provide services to our clients;
(c) Verify your identity or perform customer due diligence;
(d) Engage or provide information to third parties on your behalf;
(e) Check for and manage commercial conflicts of interest;
(f) Comply with our legal and professional obligations under the Anti-Money Laundering and Countering Financing of Terrorism Act 2009, and under any court orders, and under the Privacy Act 2020 and all other applicable New Zealand laws;
(g) Send you CREATIVA Design Studio newsletters (with your consent) and invite you to events;
(h) Help us improve and better market the services we provide
(I) Recruit staff and/ or contractors
(j) Enable us to undertake our business processes (such as invoicing).
To carry out the activities or to achieve the purposes specified above, we may disclose your personal information to:
(h) People and organisations to whom you have authorised us to disclose your personal information
(I) Parties involved in a matter for which you (or your employer) have engaged our services
(j) Service providers that enable us to store, manage, audit, and analyse the information we hold
(k) Communicate with you in the context in which you have engaged with us;
(l) Communicate essential notifications and other information to you;
(m) Facilitate the development, maintenance and marketing of our website;
(n) Perform statistical analysis of user behaviour, and of characteristics and use of our website;
13. Disclosure to third parties
13.1 CREATIVA Design Studio works with clients in providing website design and graphics services. CREATIVA Design Studio uses third party providers to provide services on our behalf. We may share your Personal Information with the third parties we work with or who provide us with services on our behalf. These third parties include:
(a) Our clients, for whom we provide services;
(b) Our professional advisors and consultants;
(c) Persons who assist us to provide services, including in relation to:
(d) the development, operation and maintenance of our website;
(e) secure payment processing;
(f) information processing and storage;
(g) managing and enhancing customer data;
(h) providing customer service;
(i) assessing your interest in our services and conducting customer research or satisfaction surveys;
(j) Social Media sites on which we have a presence; and
(k) Anyone else to whom you authorise us to disclose it.
14. Disclosure by Law
14.1 We may be required by law to disclose your Personal Information.
14.2 We may also disclose your Personal Information to a third party if we have a belief that either you have consented to the action, or that such action is necessary to:
(b) comply with a judicial proceeding, court order, or legal process; or
(c) protect the rights, property, or personal safety of us or our agents, personnel and subcontractors, or others.
14.3 You authorise us to disclose any information about you to law enforcement or government officials as we, in our sole discretion, believe is necessary or appropriate.
15. Transfer of information overseas
15.1 We are based in New Zealand. This means that if you are an EU resident, your Personal Informational information will be transferred and stored outside the European Economic Area. New Zealand has ‘adequacy’ for the purpose of Article 45 of Regulation (EU) 2016/679.
15.2 Certain Personal Information may be transferred to third countries and/or international organisations outside New Zealand and the European Union for the provision of our services to our clients. Where Personal Information is transferred outside of the European Economic Area or New Zealand, it will be:
(a) to a country or organisation that has ‘adequacy’ for the purpose of Article 45 of Regulation (EU) 2016/679 (including organisations subject to the Privacy Shield); or
(b) transferred subject to the European Commission’s model contracts for the transfer of personal data to third countries (i.e., the standard contractual clauses), pursuant to Decision 2004/915/EC and Decision 2010/87/EU as appropriate; and
(c) safeguarded with enforceable data subject rights and effective legal remedies, pursuant to Article 46 (2) (c) of Regulation (EU) 2016/679 and, with respect to data transfers from controllers to processors and/or processors to processors, standard contractual clauses pursuant to Article 28(7) of Regulation (EU) 2016/679 with respect to data protection safeguards.
16. Third-party sites and services
16.1 CREATIVA Design Studio’s website and other materials may contain links or references to third-party websites, services.
16.2 Information collected by such third parties, which may include such your location data or contact details, is governed by the third party’s privacy practices or policies. We recommend that you check the privacy policies of those third parties. We accept no responsibility or liability for any third party’s practices or policies or your provision of Personal Information to them.
17.1 “Cookies” are a small piece of data sent from a website and stored in a user’s web browser while the user is browsing that website. Every time the user loads the website, the browser sends the cookie back to the server to notify the website of the user’s previous activity.
17.2 The CREATIVA Design Studio website uses “cookies” to make the service as easy for you to use as possible and helps us better understand user behaviour.
17.3 We treat information collected by cookies and other similar technologies as non-personal information unless:
(a) applicable laws require us to treat them as Personal Information; and
17.4 You can disable cookies on your computer if you wish, but please note that if you disable caching or choose to block sites from sending any data, this may cause the website not to work.
17.5 To find out more about the way cookies work, how to see what cookies have been set and how to manage and delete them, visit allaboutcookies.org.
18. Google Analytics
18.2 Google Analytics follows your progress through a website, collecting anonymous data on where you have come from, which pages you visit, and how long you spend on the site. Google then stores this data in order to create reports.
18.3 Google will track your IP address. This information may be transmitted to and stored by Google on servers in the United States. Google may use this information for the purpose of evaluating your use of the website, compiling reports on website activity for us, and providing other services relating to website activity and Internet usage.
18.4 Google may also transfer this information to third parties where required to do so by law, or where such third parties process the information on Google’s behalf. Google will not associate your IP address with any other data held by Google. When you use our website, you consent to the processing of data about you by Google in the manner and for the purposes set out above.
18.6 To opt-out of being tracked by Google Analytics across all websites, visit http://tools.google.com/dlpage/gaoptout
19. LinkedIn Analytics
19.1 We use LinkedIn Analytics and tracking pixels to:
(a) help us understand what kinds of people are interacting with our LinkedIn page;
(b) target our LinkedIn posts towards particular groups of people;
(c) understand the activity of people who visit our LinkedIn page and/or access our website through LinkedIn;
20. Security of your Personal Information
20.1 Security of personal information is important to us, and we take all reasonable precautions to protect personal information from misuse, loss, unauthorised access, modification or disclosure.
20.2 To prevent unauthorized access, maintain data accuracy, and ensure the correct use of Personal Information, we have put in place reasonable and appropriate physical, electronic, and managerial procedures to safeguard and secure the Personal Information we collect.
20.3 CREATIVA Design Studio and our third-party providers store Personal Information in a secure environment accessed only by authorised persons. We use generally accepted security standards to protect Personal Information collected from you from misuse and loss and from unauthorised access, modification and disclosure.
20.4 CREATIVA Design Studio also maintains internal privacy procedures to ensure its staff handle Personal Information in an appropriate way.
20.5 CREATIVA Design Studio provides training on the Privacy Act to staff and to its contractors.
20.4 Given the nature of the internet we cannot guarantee security of information transmitted through the internet. We will do our best to protect your personal data, however any transmission is at your own risk.
21. How long will we keep your Personal Information?
21.1 CREATIVA Design Studio will retain your Personal Information for as long as it is needed for the purpose for which it was collected (or any other purpose you have consented to) or for so long as we are required by law to retain it.
22. Non-EU Data subjects
22.1 If you are not an EU resident, you have the following rights in relation to access and correction of your Personal Information:
Access to your Personal Information
22.2 You may request access to Personal Information that we hold about you by contacting us firstname.lastname@example.org
22.3 You may request that we correct factual errors in your Personal Information by sending us an email request that shows the error(s) to:
If we choose not to correct errors that you have identified in your Personal Information, you may request that we make reasonable efforts to note the correction request, to be held (if possible) together with the relevant Personal Information.
22.4 To protect your privacy and security, we may also take reasonable steps to verify your identity before granting access or making corrections. We may refuse access to or correction of your Personal Information for any reason of refusal permitted by law.
22.5 If you have any questions about privacy related issues or wish to complain about the handling of your Personal Information by us, please contact:
email address: email@example.com
We may ask you to lodge your complaint in writing. Any complaint will be investigated by the Privacy Officer and you will be notified of the decision in relation to your complaint as soon as practicable after it is made, usually within 20 working days.
22.6 If we are unable to satisfactorily resolve your concerns about our handling of your Personal Information, you can contact:
The Office of the Privacy Commissioner
PO Box 10-094,
phone 0800 803 909
23. EU Data Subject Rights
23.1 If you are an EU resident, you may have certain rights in relation to the Personal Information we hold about you. We set out these rights and how to exercise them below. Some of these rights only apply in certain circumstances.
23.2 These rights include:
(d) restriction of processing;
(e) data portability; and
How to exercise your rights
23.3 Please note that we will require you to provide us with proof of identity before responding to any requests to exercise your rights. We must respond to a request by you to exercise those rights without undue delay and at least within one month (although this may be extended by a further two months in certain circumstances). To exercise any of your rights, please send the following details to email address:
(a) proof of identity (one of the following: passport, driving licence, national identity card or birth certificate. The documents must include your full Name and date of birth, nationality, and include proof of any Name change). If you exercising rights on behalf of another EU resident (the data subject), please include both your proof of identity and the proof of identity of the data subject. You will also need a signed consent from the data subject, authorising you to exercise these rights on their behalf. If the data subject is a minor, you will not need signed consent, but will require proof of your status as the data subject’s parent or guardian;
(b) contact details;
(c) details of country of residence;
(d) details of the data right(s) you wish to exercise, including any relevant details; and
(e) confirmation that you understand that CREATIVA Design Studio may require further details from you in order to confirm your identity and/or process your request.
23.4 Please note, if you make a request in relation to your data rights and we do not hold information in a form that allows us to identify you, we will inform you of that. We will not be obliged to comply with those data rights unless you provide additional information that allows us to identify what information we hold about you. If we do not take action on your request in relation to your data subject rights, we will advise you within one month of the reasons we will not be taking action. You may make a complaint to us or to your data protection authority, and you may seek a judicial remedy in accordance with the provisions of the GDPR.
23.5 We will communicate any correction or erasure of Personal Information or restriction of processing that we undertake in accordance with your instructions to any third parties who have received that Personal Information, unless that notification is impossible or involves a disproportionate effort. If you request, we will provide you with details of those third parties that have received your Personal Information.
23.6 In the event that you wish to make a complaint about how we process your Personal Information or respond to any request by you in relation to your data rights, please contact us and we will endeavour to deal with your request as soon as possible. You also have the right to launch a claim with your data protection authority.
Legal basis for using your Personal Information
23.7 The GDPR requires us to tell you the legal basis for processing your Personal Information.
23.8 The principal bases on which we process your Personal Information are:
(a) Consent: Applies where you have freely given an informed, specific and unambiguous indication that we are permitted to collect and process your Personal Information. At any time, you may revoke your consent to the processing of some or all of your Personal Information by:
(i) emailing us or
(ii) using the “unsubscribe” function in any communication that we send to you.
If you revoke your consent, we may need to stop providing you with products, services, funding or support if consent is the only legal basis for our processing of your Personal Information. The withdrawal of consent will not affect processing of Personal Information that occurs before you notify us that you have withdrawn your consent.
(b) Contract: Applies if processing your Personal Information is necessary for the performance of a contract you are a party to. For example:
(i) if we are providing services to you as a client or candidate, we will need to use your Personal Information to carry out those services and any related activities (such as billing you);
(ii) if you are providing services to us, we will need to store and use certain Personal Information (such as bank account details) in order to pay you.
(c) Legitimate interests: Applies if the processing is necessary for our legitimate interests or the legitimate interests pursued by a third party, except where such interests are overridden by your interests or fundamental rights and freedoms which require protection of Personal Information.
23.9 You have the right to know whether we process Personal Information about you, and if we do, to access Personal Information we hold about you and certain information about how we use it and who we share it with.
23.10 We may not provide you with certain Personal Information if providing it would interfere with another’s rights (e.g., where providing the personal information we hold about you would reveal information about another person) or where another exemption applies.
23.11 You have the right to one copy of the information set out above. If you request further copies of that information, we may charge a reasonable fee for our administrative costs.
23.12 You have the right to correct any Personal Information we hold about you that is inaccurate. You may have incomplete Personal Information we hold about you completed, including by means of a supplementary statement (taking into account the purposes of processing of the relevant Personal Information). During the period while we assess whether the Personal Information we hold about you is inaccurate or incomplete, you may exercise your right to restrict our processing of the applicable data as described below.
23.13 You may request that we erase the Personal Information we hold about you in the following circumstances:
(a) you believe that it is no longer necessary for us to hold the Personal Information we hold about you;
(b) we are processing the Personal Information we hold about you on the basis of your consent, and you wish to withdraw your consent and there is no other ground under which we can process the Personal Information;
(c) you have exercised your right of objection and there are no overriding legitimate grounds for the processing;
(d) you no longer wish us to use the Personal Information we hold about you in order to send you information about CREATIVA Design Studio and our services; or
(e) you believe the Personal Information we hold about you is being unlawfully processed by us.
23.14 During the period while we consider your request for erasure, you may exercise your right to restrict our processing of the Personal Information as described below.
23.15 Please provide as much detail as possible on your reasons for the request to assist us in determining whether you have a valid basis for erasure. After deleting the Personal Information, we may not be able to provide services to you, or the same level of service that we were previously able to provide.
23.16 Where you have requested that we erase Personal Information that we have made public and there are grounds for erasure, we will use reasonable steps try to tell others that are displaying the Personal Information or providing links to the Personal Information to erase that Personal Information.
Restriction of Processing to Storage Only
23.17 You have a right to require us to stop processing the Personal Information we hold about you other than for storage purposes, in certain circumstances. Please note, however, that if we stop processing the Personal Information, we may use it again if there are valid grounds under data protection law for us to do so (e.g., for the defence of legal claims or for another individual’s protection).
23.18 You may request we stop processing and just store the Personal Information we hold about you when:
(a) you believe the Personal Information is not accurate, for the period it takes for us to verify whether the Personal Information is accurate;
(b) the processing we are doing is unlawful and we wish to erase the Personal Information, but you require us to store the Personal Information instead;
(c) the Personal Information is no longer necessary for our purposes and we wish to erase it, but you require us to store that personal information for the establishment, exercise or defence of legal claims; or
(d) you have exercised your right to object, pending the verification of whether our legitimate grounds of processing override your interests, rights and freedoms.
23.19 If you have obtained a restriction on processing, we will inform you before that processing restriction is lifted.
23.20 You have the right to receive certain parts of the Personal Information that we collect from you in a structured, commonly used and machine-readable format and a right to request that we transfer such Personal Information to another party.
23.21 The Personal Information that you can request under this “portability” right is data that you have provided us with your consent, or that you provided for the purposes of performing our contract with you, and the processing of that Personal Information is carried out by automated means.
23.22 If you wish for us to transfer the Personal Information to another party, please ensure you provide the details that party and note that we can only do so where it is technically feasible. We are not responsible for the security of the Personal Information or its processing once received by the third party. We also may not provide you with certain Personal Information if providing it would interfere with another individual’s rights, for instance where providing the Personal Information we hold about you would reveal information about another person.
23.23 At any time you have the right to object to our processing of Personal Information about you in order to send you information about CREATIVA Design Studio and our services, and any marketing messages, including where we build profiles for such purposes. If you object to this processing of your Personal Information, we will stop processing the Personal Information for that purpose.
23.24 You may also object where we are processing the Personal Information we hold about you (including where the processing is profiling) on the basis of our legitimate interest and you object to such processing.
23.25 Please provide as much detail as possible on your reasons for the request to assist us in determining whether there is a compelling overriding interest in us continuing to process such data or we need to process it in relation to legal claims. You may exercise your right to request that we stop processing the Personal Information during the period while we make the assessment on an overriding interest. Please advise us if you would like to make that processing restriction request at the time you provide the details of your objection to processing.
24. Privacy questions
Or email: firstname.lastname@example.org
EU Resident means an individual who is in the European Union at the time their Personal Information is processed;
GDPR means the European General Data Protection Regulation;
Social Media means LinkedIn and Facebook
Personal Information means information relating to an identified or identifiable natural person.