Buddy Tech Limited - Privacy Policy

Buddy Tech Limited (NZCN 8723468) (we, us or our), understands that protecting your personal information is important.This Privacy Policy sets out our commitment to protecting the privacy of personal information provided to us, or collected by us, when interacting with you.This Privacy Policy takes into account the requirements of the Privacy Act 2020. In addition to the New Zealand laws, individuals located in the European Union or European Economic Area (EU) may also have rights under the General DataProtection Regulation 2016/679 and individuals located in the United Kingdom (UK) may have rights under the GeneralData Protection Regulation (EU) 2016/679) (UK GDPR) and the Data Protection Act 2018 (DPA 2018) (together, the GDPR).Appendix 1 outlines the details of the additional rights of individuals located in the EU and UK as well as information on how we process the personal information of individuals located in the EU and UK.

The information we collect

Personal information: is information or an opinion, whether true or not and whether recorded in a material form or not,about an individual who is identified or reasonably identifiable.The types of personal information we may collect about you include:

  • Identity Data including your name, date of birth, profession, photographic identification, pronouns, and gender.
  • Contact Data including your telephone number, address and email.
  • Financial Data including bank account details.
  • Background Verification Data including your government-issued identification details requested as part of our onboarding OR verification OR Know Your Customer process to comply with our due diligence obligations, anti-money laundering laws and related ongoing monitoring commitments.
  • Transaction Data including details about payments between counterparties and from you to us and otherdetails of products transacted on your account.
  • Technical and Usage Data when you access any of our websites or platforms, details about your internetprotocol (IP) address, login data, browser session and geo-location data, statistics on page views and sessions,device and network information, acquisition sources, search queries and/or browsing behaviour, access anduse of our website (including through the use of Internet cookies), and communications with our website.
  • Profile Data including your username and password for Buddy, profile picture, transactions you have conducted on platform, content you post, send receive and share through our platform, and support requestsyou have made.• Interaction Data including information you provide to us when you participate in any interactive features, including surveys, contests, promotions, activities or events.
  • Marketing and Communications Data including your preferences in receiving marketing from us and our thirdparties and your communication preferences.
  • Commercial Information including information about your business’ location, reputation, tenure in industry, industry ratings (where relevant) and approved images and video of your premises.
  • Buyer Information if you register as a buyer, including your current industry and you proposed materials to purchase.

How we collect personal information

We collect personal information in a variety of ways, including:

  • when you interact directly with us, including face-to-face, over the phone, over email, or online;
  • when you complete a form, such as registering for any events or newsletters, or responding to surveys;
  • from third parties, such as google analytics; or
  • from publicly available sources, such as social media or the New Zealand Companies Office.

Why we collect, hold, use and disclose personal information

We have set out below, in a table format, a description of the purposes for which we plan to collect, hold, use and disclose your personal information.

Purpose of use / disclosure

Type of Personal Information

To enable you to access and use our software, including to provide you with a login

  • Identity Data
  • Contact Data

To assess whether to take you on as a new client, including to perform anti money laundering, anti-terrorism, sanction screening, fraud and other relevant industry background checks on you.

  • Identity Data
  • Contact Data
  • Background Verification Data
  • Financial Data

To do business with you, including to assess your application, manage your buyer/seller preferences.

  • Identity Data
  • Contact Data
  • Background Verification Data

To contact and communicate with you about our business, including in response to any support requests you lodge with us or other enquiries you make with us.

  • Identity Data
  • Contact Data
  • Profile Data

To contact and communicate with you about any enquiries you make with us via any website we operate.

  • Identity Data
  • Contact Data

For internal record keeping, administrative, invoicing and billing purposes.

  • Identity Data
  • Contact Data
  • Financial Data
  • Transaction Data

For analytics (including profiling on our website), market research and business development, including to operate and improve our business, associated applications and associated social media platforms.

  • Profile Data
  • Technical and Usage Data

For advertising and marketing, including to send you promotional information about our events and experiences and information that we consider may be of interest to you.

  • Identity Data
  • Contact Data
  • Technical and Usage Data
  • Profile Data
  • Marketing and Communications Data

To run promotions, competitions and/or offer additional benefits to you.

  • Identity Data
  • Contact Data
  • Profile Data
  • Interaction Data
  • Marketing and Communications Data

If you have applied for employment with us, to consider your employment application.

  • Identity Data
  • Contact Data
  • Professional Data

To comply with our legal obligations or if otherwise required or authorised by law.

  • Any relevant PersonalInformation

Our disclosures of personal information to third parties

  • Google Analytics: We have enabled Google Analytics Advertising Features. We and third-party vendors may use first-party cookies (such as the Google Analytics cookie) or other first-party identifiers, and third-party cookies (such as Google advertising cookies) or other third-party identifiers together. These cookies and identifiers may collect Technical and UsageData about you.

    You can opt-out of Google Analytics Advertising Features including using a Google Analytics Opt-out Browser add-on found here. To opt-out of personalised ad delivery on the Google content network, please visit Google’s Ads Preferences Manager here or if you wish to opt-out permanently even when all cookies are deleted from your browser you can install their plugin here. To opt out of interest-based ads on mobile devices, please follow these instructions for your mobile device: On android open the Google Settings app on your device and select “ads” to control the settings. On iOS devices with iOS 6 and above use Apple’s advertising identifier. To learn more about limiting ad tracking using this identifier, visit the settings menu on your device.

    To find out how Google uses data when you use third party websites or applications, please see here.

Overseas disclosure

  • Personal Information: We may store personal information overseas, including in, Australia, Where we disclose your personal information to the third parties listed above, these third parties may also store, transfer or access personal information outside of New Zealand, including but not limited to, Australia. We will only disclose your personal information overseas in accordance with the New Zealand Privacy Principles and all third party partners are required to comply with the New Zealand Privacy Principles.

Your rights and controlling your personal information

  • Your choice: Please read this Privacy Policy carefully. If you provide personal information to us, you understand we will collect, hold, use and disclose your personal information in accordance with this Privacy Policy. You do not have to provide personal information to us, however, if you do not, it may affect our ability to do business with you.
  • Information from third parties: If we receive personal information about you from a third party, we will protect it as set out in this Privacy Policy. If you are a third party providing personal information about somebody else, you represent and warrant that you have such person’s consent to provide the personal information to us.
  • Restrict and unsubscribe: To object to processing for direct marketing/unsubscribe from our email database or opt-out of communications (including marketing communications), please contact us using the details below or opt-out using the opt- out facilities provided in the communication.
  • Access: You may request access to the personal information that we hold about you. An administrative fee may be payable for the provision of such information. Please note, in some situations, we may be legally permitted to withhold access to your personal information. If we cannot provide access to your information, we will advise you as soon as reasonably possible and provide you with the reasons for our refusal and any mechanism available to complain about the refusal. If we can provide access to your information in another form that still meets your needs, then we will take reasonable steps to give you such access.
  • Correction: If you believe that any information we hold about you is inaccurate, out of date, incomplete, irrelevant or misleading, please contact us using the details below. We will take reasonable steps to promptly correct any information found to be inaccurate, out of date, incomplete, irrelevant or misleading. Please note, in some situations, we may be legally permitted to not correct your personal information. If we cannot correct your information, we will advise you as soon as reasonably possible and provide you with the reasons for our refusal and any mechanism available to complain about the refusal.
  • Complaints: If you wish to make a complaint, please contact us using the details below and provide us with full details of the complaint. We will promptly investigate your complaint and respond to you, in writing, setting out the outcome of our investigation and the steps we will take in response to your complaint. If you are not satisfied with our response, you may contact the Office of the New Zealand Privacy Commissioner.
  • Storage: we may hold information about you up to seven (7) years from the date of your last transaction through our platform, or the date you ceased membership to our Services, whichever is the later. You may contact us on privacy@buddytech.io to request the early deletion of your data. In all circumstances we will endeavour to permanently delete all data in a prompt manner, however under New Zealand regulations we may not be able to comply with all data deletion requests. If we are unable to comply we will provide you with the reasons for our refusal and any mechanisms available to you to complain about the refusal.

Storage and security

We are committed to ensuring that the personal information we collect is secure. In order to prevent unauthorised access or disclosure, we have put in place suitable physical, electronic and managerial procedures, to safeguard and secure personal information and protect it from misuse, interference, loss and unauthorised access, modification and disclosure.

While we are committed to security, we cannot guarantee the security of any information that is transmitted to or by us over the Internet. The transmission and exchange of information is carried out at your own risk.

We may use cookies on our website from time to time related to Google Analytics and for functional purposes for our site performance only. Cookies are text files placed in your computer's browser to store your preferences. Cookies, by themselves, do not tell us your email address or other personally identifiable information. However, they do recognise you when you return to our online website and allow third parties to cause our advertisements to appear on your social media and online media feeds as part of our retargeting campaigns. If and when you choose to provide our online website with personal information, this information may be linked to the data stored in the cookie. You can block cookies by activating the setting on your browser that allows you to refuse the setting of all or some cookies. However, if you use your browser settings to block all cookies (including essential cookies) you may not be able to access all or parts of our website.

Links to other websites

Our website may contain links to other party’s websites. We do not have any control over those websites and we are not responsible for the protection and privacy of any personal information which you provide whilst visiting those websites. Those websites are not governed by this Privacy Policy.

Amendments

We may, at any time and at our discretion, vary this Privacy Policy by publishing the amended Privacy Policy on our website. We recommend you check our website regularly to ensure you are aware of our current Privacy Policy.

For any questions or notices, please contact us at:

Buddy Tech Limited (NZCN 8723468)

Email: privacy@tradebuddy.io

Last updated: [07.02.2024]

© LegalVision NZ Limited

APPENDIX 1: ADDITIONAL RIGHTS AND INFORMATION FOR INDIVIDUALS LOCATED IN THE EU OR UK

Under the GDPR individuals located in the EU and the UK have extra rights which apply to their personal information. Personal information under the GDPR is often referred to as personal data and is defined as information relating to anidentified or identifiable natural person (individual). This Appendix 1 sets out the additional rights we give to individuals located in the EU and UK, as well as information on how we process the personal information of individuals located in theEU and UK. Please read the Privacy Policy above and this Appendix carefully and contact us at the details at the end of thePrivacy Policy if you have any questions.

What personal information is relevant?

This Appendix applies to the personal information set out in the Privacy Policy above. This includes any SensitiveInformation also listed in the Privacy Policy above which is known as ‘special categories of data’ under the GDPR.

Purposes and legal bases for processing

We collect and process personal information about you only where we have legal bases for doing so under applicable laws.We have set out below, in a table format, a description of all the ways we plan to use your personal information, and which of the legal bases we rely on to do so. We have also identified what our legitimate interests are where appropriate. Note that we may process your personal information for more than one lawful ground depending on the specific purpose for which we are using your data. Please reach out to us if you need further details about the specific legal ground, we are relying on to process your personal information where more than one ground has been set out in the table below.

Purpose of use / disclosure

Type of Data

Legal Basis for processing

To enable you to access and use our software, including to provide you with a login.

  • Identity Data
  • Contact Data
  • Performance of a contract with you

To assess whether to take you on as anew client, including to perform anti money laundering, anti-terrorism, sanction screening, fraud and other background checks on you.

  • Identity Data
  • Contact Data
  • Background Verification Data
  • Financial Data
  • Performance of a contract with you
  • To comply with a legal obligation
  • Public interest
  • Ensuring we do not deal with proceeds of criminal activities or assist in any other unlawful or fraudulent activities for example terrorism

To do business with you, including to connect you with relevant sellers or buyers, dispatch and deliver our products to you, assess your application.

  • Identity Data
  • Contact Data
  • Performance of a contract with you

To contact and communicate with you about our business [including in response to any support requests you lodge with us or other enquiries you make with us].

  • Identity Data
  • Contact Data
  • Profile Data
  • Performance of a contract with you

To contact and communicate with you about any enquiries you make with us via our website.

  • Identity Data
  • Contact Data
  • to ensure we provide the best client experience we can offer by answering all of your questions.

For internal record keeping, administrative, invoicing and billing purposes.

  • Identity Data
  • Contact Data
  • Financial Data
  • Trasnsaction Data
  • Performance of a contract with you
  • To comply with a legal obligation
  • to recover debts due to us and ensure we can notify you about changes to our [terms of business]and any other administrative points.

For analytics, including profiling on our website, market research and business development, including to operate and improve our business, associated applications and associated social media platforms.

  • Profile Data
  • Technical and Usage Data
  • to keep our website updated and relevant, to develop our business, improve our business and to inform our marketing strategy

For advertising and marketing, including to send you promotional information about our events and experiences and information that we consider may be of interest to you.

  • Identity Data
  • Contact Data
  • Technical and Usage Data
  • Profile Data
  • Marketing and CommunicationsData
  • to develop and grow our business

To run promotions, competitions and/or offer additional benefits to you.

  • Identity Data
  • Contact Data
  • Profile Data
  • Interaction Data
  • Marketing and CommunicationsData
  • to facilitate engagement with our business and grow our business

To comply with our legal obligations orif otherwise required or authorised bylaw.

All Data

  • To comply with a legal obligation

If you have consented to our use of data about you for a specific purpose, you have the right to change your mind at anytime, but this will not affect any processing that has already taken place. Where we are using your data because we or athird party have a legitimate interest to do so, you have the right to object to that use though, in some cases, this maymean no longer doing business with us. Further information about your rights is available below.