EASTWARD DIGITAL
Legal draft · ED-005 · Version 1.0

Privacy Policy

How Eastward collects, uses, stores, shares and protects personal information in New Zealand.

Controlled privacy draft. Before public issue, complete Eastward’s legal identity, NZBN, privacy contact, address, supplier list, analytics/cookie details, overseas processing and retention settings.
Scope & collection

Privacy information should be clear and specific.

1. Scope

This policy applies when people visit Eastward websites, make enquiries, become clients, use an Eastward-operated portal or system, interact with content or otherwise communicate with Eastward. Client-controlled personal information inside a system built for a client may be governed primarily by that client’s privacy obligations.

2. Information Eastward may collect
  • Names, roles, business names and contact details.
  • Enquiry, discovery, proposal, contract, project and support information.
  • Billing and transaction references.
  • Content, files, brand assets and project access information supplied by a client.
  • Website/device information where analytics or security tools are used.
  • Communications, feedback, approvals and support records.
3. Why information is collected

For enquiries, project delivery, account administration, security, support, service improvement, legal compliance and other purposes that are connected with the reason the information was collected or are otherwise authorised by law.

Use, sharing & storage

Keep collection proportionate to the job.

4. Collection methods

Information may be supplied directly through forms, email, meetings, project tools or client systems, or collected automatically through approved website, analytics and security services.

5. When information may be shared

Eastward may use appropriate employees, contractors, advisers, payment providers, hosting/cloud providers, domain/email providers, analytics/security services and other suppliers where reasonably necessary. Eastward does not sell personal information.

6. Overseas services

Some providers may process or store information outside New Zealand. The final published policy should identify material providers and describe the safeguards Eastward relies on where overseas disclosure rules apply.

7. Security and retention

Eastward should use reasonable technical and organisational safeguards and retain personal information only for as long as there is a lawful business, contractual, security or record-keeping need.

8. Access and correction

Individuals may request access to or correction of personal information held about them, subject to the Privacy Act 2020 and any lawful grounds for withholding information.

Cookies, breaches & complaints

Operational privacy obligations.

9. Website technology

The final policy should identify the analytics, cookies or similar technology actually used by Eastward rather than listing tools that are not in operation.

10. Client systems

Where Eastward processes personal information on behalf of a client, responsibilities should also be documented in the relevant project agreement, privacy schedule or system terms.

11. Privacy breaches and complaints

Eastward will assess privacy breaches under the Privacy Act 2020. A breach that has caused or is likely to cause serious harm may require notification to the Office of the Privacy Commissioner and affected people as soon as practicable, subject to the Act’s exceptions. Privacy concerns should be raised with Eastward first at info@eastward.co.nz until a dedicated privacy contact is formally adopted.

12. Policy changes

The current published version should show its effective date. Material changes may be communicated directly where appropriate.

Publication checklist: legal name, NZBN, address, privacy officer/contact, cloud providers, FormSubmit/email processing, analytics/cookies, overseas processing, retention periods and any portal-specific practices.

← Document studio