Affinity NZ t/a CoDrive Financial Privacy Policy
How we collect, use, disclose, and protect personal information is important to our business.
We all have a part to play ensuring we comply with our privacy obligations in relation to the
use and protection of personal information and our goal to be completely transparent about
what we do with personal information.
Under the Privacy Act 2020, there are 13 Information Privacy Principles (IPPs) our business
must comply with. When collecting, using and disclosing, and protecting personal
information of any description, we must do so in accordance with the IPPs. The IPPs can be
summarised as follows:
1. Only collect information the business needs.
2. Wherever possible, get the personal information directly from the individual.
3. Be transparent about what you are going to do with the personal information.
4. Be fair about how you get it.
5. Keep personal information secure.
6. Enable personal information to be accessed by the person it relates to.
7. Enable personal information to be corrected if it is incorrect.
8. Ensure personal information is correct before you use it.
9. Dispose of personal information securely once you no longer need it.
10. Only use personal information for the reason it was collected.
11. Only share personal information if you have a good reason.
12. Only send it overseas if it will be adequately protected.
13. Only use unique identifiers when it is clearly allowed.
This Privacy Policy sets out how our business collects, uses, discloses and protects the
personal information we deal with in a way that complies with the Privacy Act 2020. The
Employee/ Contractor Privacy Statement (Appendix B) sets out how we collect and use the
personal information of our employees and contractors. We make a Client Privacy Statement
and Privacy Policy available to clients and prospective clients, which sets out how our
business deals with client information.
Failure to comply with this Privacy Policy
All employees and contractors should be aware that a failure to comply with this Privacy
Policy, including any policies, processes and controls which are put in place under it, will be
investigated and may lead to disciplinary action being taken.
Procedure
Collecting personal information
Personal information is defined in the Privacy Act 2020 as information about an identifiable
individual (a natural person as opposed to a company or other legal entity).
Types of personal information we collect
Our business collects personal information from:
-
Employees;
-
Prospective employees;
-
Contractors;
-
Authorised bodies;
-
Outsource providers;
-
Clients; and
-
Prospective clients.
We only collect information we need. Where practicable, we collect personal information
directly from the source. E.g. directly from the employee. We only keep personal
information for as long as it is necessary. The amount of time that we hold the personal
information for (retention period) varies, depending on the nature of the personal information.
All employees receive training to enable them to understand how the Privacy Act 2020
impacts on how we provide our services to clients and manage our business. Employees
also receive training on the IPPs, how they impact the process of collecting information, and
the ways in which they can and cannot collect personal information in their roles.
Storage and protection of personal information
We only keep personal information for as long as it is necessary. The amount of time that
we hold the personal information for (retention period) varies, depending on the nature of the
personal information. Our records are systematically checked [through our CRM software]
to ensure that personal information is only kept while there is a lawful or legitimate business
purpose.
Most of the data we collect through our business (including most personal information we
collect) is stored electronically. We take all reasonable steps to keep it secure and prevent
unauthorised disclosure. Employees and contractors also play an important role in keeping
the information safe. All our employees and contractors are required to adhere to CoDrive
Financial’s policies, processes and controls to help meet our Privacy Act 2020 obligations.
This includes keeping passwords and devices secure, adhering to email and internet usage
guidelines and being subject to employee monitoring, as set out in our IT and cybersecurity
policies.
Privacy and remote working (working from home)
Remote working introduces additional risks in relation to potential breaches of privacy. We
take all reasonable steps to ensure personal information is protected in these circumstances,
including:
-
Requiring a trusted WiFi network to be used (e.g. home WiFi);
-
Having multifactor authentication enabled;
-
Locking out a user after numerous failed logins;
-
Ensuring staff can only access information they need;
-
Storing devices in a safe location;
-
Ensuring work conversations are not overheard by other members of the household;
-
Locking devices when they are not in use; and
-
Increased vigilance of unexpected emails.
If there is a privacy breach
We work hard to keep all personal information safe. However, despite applying strict security
measures and following industry standards to protect personal information, there is still a
possibility that our security could be breached. If you are aware of a privacy breach, where
there is a loss or unauthorised access or disclosure of personal information, whether or not
you think it is likely to cause serious harm, you must notify a manager as soon as you
become aware of the breach. This will allow us to:
-
Seek to quickly identify and secure the breach to prevent any further breaches and reduce the harm caused by the breach;
-
Assess the nature and severity of the breach, including the type of personal information involved and the risk of harm to affected individuals;
-
Advise and involve the appropriate authorities where criminal activity is suspected;
-
Where appropriate, notify any individuals who are affected by the breach (where possible, directly);
-
Where appropriate, put a notice on our website advising our clients of the breach;
-
Notify the Privacy Commissioner.
All employees receive training to enable them to identify a privacy breach, how to reduce the
risk of a privacy breach occurring and how to respond to a privacy breach if one does occur.
We maintain a Breaches Register (Appendix C) to record all privacy breaches that occur in
our business, whether or not they pose a risk of serious harm or require us to notify any
external parties. It is important that you notify the Privacy Officer as soon as you become
aware of any privacy breach, so that the breach can be logged on the Breaches Register
and any necessary further action can be considered.
Use of AI tools, recording and other record keeping tools and providers
We may use AI-powered tools to record, transcribe, and summarise meetings (including
phone/video/in-person). This may involve audio recordings and transcripts of discussions
about your financial situation. The Purpose of this use is:
-
To improve accuracy of advice records
-
To ensure compliance with regulatory requirements
-
To reduce administrative errors
We use Third-party service providers for various aspects of our business. They are all
contractually bound to protect your information. Data may be stored overseas. Some examples of categories for third party providers are:
-
CRM System
-
IT Provider
-
AI Note-Taker
-
Accounting and Bookkeeping Services
-
Accounting and Bookkeeping Software
Retention and Security: Recordings, transcripts and general records will be kept for a
minimum of 7 years (as that is our regulatory requirement), or longer if deemed necessary. All client records, including recordings and transcripts are protected in the same way that all other electronic files are safeguarded within our system.
Disclosure of personal information
We only disclose personal information to others outside CoDrive Financial, where:
-
It is necessary to enable us to achieve the purpose that we collected the information for;
-
We are required or authorised by law or where we have a public duty to do so;
-
We have received express consent for the disclosure from the person the information relates to, or consent can be reasonably inferred from the circumstances; or
-
We are permitted to disclose the information under the Privacy Act 2020.
Please contact the Privacy Officer if you are not sure whether you are permitted to disclose
personal information either internally or externally.
We have legal obligations to maintain personal information to disclose to regulatory and
similar bodies.
Before entering into an agreement with an outsourcing provider or other third party, we
undertake due diligence checks of the third party. All agreements that are entered into with
third parties include provisions to ensure personal information is dealt with as required by the
Privacy Act 2020.
Sending personal information out of New Zealand
We may send personal information outside New Zealand, including to overseas members of
CoDrive Financial, related companies and overseas service providers or other third parties
who process or store our information, or provide certain services to the business.
Where we do this, it does not change any of our commitments to safeguard privacy. We
must make sure that appropriate security and information handling arrangements are in
place and the information remains subject to confidentiality obligations.
All employees receive training about their Privacy Act 2020 obligations when sending
personal information overseas and also our business’ policy on when this may be done and
the processes that must be followed before the information is sent.
All countries have different privacy laws and information protection standards. If we need to
send personal information outside of New Zealand, our Privacy Officer will undertake due
diligence to confirm this is permitted. You can gain guidance from the Privacy Officer if you
are unsure about whether you can send personal information outside of New Zealand.
Accessing and correcting personal information
Every person has a right to access personal information that is held about them and ask for
it to be corrected if they think it is wrong. Our business has a legal duty to respond to
requests for access to information or correction of that information within 20 working days of
receiving the request, although our policy is to respond to the request as soon as possible.
If an employee or contractor receives a request from a person who wants to access the
personal information the business holds about them, or make a correction to it, they need to
send all the details of the request, along with the individual’s contact details to the Privacy
Officer as soon as possible after receiving it. The Privacy Officer will then follow the process
set out below.
Access/Correction request process
Before processing the request, the Privacy Officer may contact the relevant individual to
verify their identity, confirm the request and advise the individual of any charges that apply.
The Privacy Officer will then take steps to provide the individual with access to their
information, take steps to update or change the requested information, or otherwise address
the query within a reasonable period after the request is received.
There are some circumstances in which our business is not required to give an individual
access to their personal information or correct it upon their request. If one of these
circumstances applies, the Privacy Officer will let the individual know the reasons for the
refusal, unless the law prevents them from doing so. If a request to correct or delete
personal information is refused, the individual has the right to request that a statement be
associated with their personal information, noting that they disagree with its accuracy. We
are only able to delete or remove an individual’s personal information from our records if we
are not required to hold the information to satisfy any legal, regulatory, or similar
requirements. If the Privacy Officer refuses a request to access, correct or delete personal
information, the individual will be provided with information about how they can make a
complaint about the refusal.
Complaints
We have a strict timeframe for responding to any privacy related complaints received by our
business. Our policy is to acknowledge all complaints within three working days of their
receipt, and we aim to resolve complaints within five working days, but some take longer to
resolve.
If an employee or contractor receives a privacy related complaint, they must contact a
manager and send them all relevant details of the complaint as soon as possible. The
manager will then contact the individual to acknowledge the complaint and work to resolve
the complaint as quickly as possible.
Controls
-
Cybersecurity policy
-
IT policy
-
Training and development policy
-
Client onboarding policy
-
Recruitment and selection policy
-
Job descriptions
-
Outsourcing policy and due diligence checklist
-
Employment agreements
-
Authorised body agreements
-
Independent contractor agreements
-
Business continuity plan