1. PURPOSE AND APPLICATION
1.2.2 how Nicovape uses/discloses that information;
1.2.3 how Nicovape stores that information; and
1.2.4 your entitlement to access personal information
By personal information, we mean information or an opinion about an identified individual or an individual who is reasonably identifiable. Information which cannot be reasonably linked to your identity (for example, an IP address, browser information, favourite websites or the number of users of a website) does not constitute personal information and is not regulated by the Privacy Act 1993 (New Zealand).
1.4 You consent to our collection and use of your personal information in the manner detailed in this Policy, including the disclosure of your personal information to overseas recipients as set out in section 7 below.
2. WHAT PERSONAL INFORMATION NICOVAPE COLLECTS
2.2 Nicovape will only collect personal information which you have voluntarily provided to us, or consented to us collecting (please note that use of the Nicovape website does not directly reveal your identity). If you choose not to provide information, this may affect our ability to provide personalised products and services to you.
2.3 The main points at which your personal information may be collected by Nicovape are:
2.3.2 when applying to join Nicovape’s subscriptions service;
2.3.3 when purchasing any Nicovape products;
2.3.4 when applying for a medical prescription;
2.3.5 when applying to and joining Nicovape as an employee;
2.3.6 when investing in or participating in the vision and mission of Nicovape;
2.3.7 when otherwise contacting or communicating with Nicovape.
2.4.2 personal medical history;
2.4.3 bank account details and/or credit card information;
2.4.4 qualifications, experience, training and work history if applying to be an employee of Nicovape;
2.4.5 the amount of any investment made.
2.6 Where Australian law applies, some information we collect is called ‘Sensitive Information’ (as defined in the Privacy Act 1988 (Clth), such as membership of a professional association). Where we collect sensitive information, it will only be collected with your consent.
2.7 The only personal information Nicovape collects from you via its website is that which you agree to provide, for example, when you complete an online registration form for a Nicovape subscription product.
3. HOW NICOVAPE USES/DISCLOSES THAT INFORMATION
3.2 We may also evaluate anonymous or de-identified data sets for statistical purposes.
3.3 Your personal information will not be sold, exchanged or transferred, or given to any other company for any reason whatsoever, without your consent, other than for the purposes of working with you, verifying your details, and providing Nicovape services to you.
3.4 Nicovape has business relationships with third parties. In some instances, Nicovape may disclose your personal information to third parties that we have engaged to provide us with services on your behalf, including but not limited to, the verification of your details against government records, the issue of medical prescriptions, the dispatch of Nicovape products, payment processing and the preparation of mailings. Wherever possible, these third parties have agreed to treat personal information they receive from us in a confidential manner in accordance with this policy.
3.5 In general terms, personal information held by Nicovape may be used by Nicovape or disclosed to third parties for one or more of the following purposes:
3.5.2 subscription registration. This may involve the disclosure of personal information to third parties connected with our prescription service, identity verification, payment processing, and our delivery service;
3.5.3 inviting you to attend Nicovape events (including those endorsed by or supported by Nicovape);
3.5.4 offering customer benefits and other services to you, such as product and service assessments, e-bulletin updates and product discounts. You may request that this information not be sent to you, other than notification of matters we are required to by law, for example product re-call;
3.5.5 reporting to regulators and government departments as required by law, monitoring and reviewing compliance, codes of conduct and lists of customers for market research purposes;
3.5.6 providing information about customers to medical research institutions, academic research institutions, as Nicovape considers appropriate to share information about customers with;
3.5.7 procuring funding or other support for the activities of Nicovape;
3.5.8 conducting or facilitating research or surveys for purposes related to Nicovape or its activities;
3.5.9 otherwise collecting, using or disclosing personal information about you in a manner consistent with the purposes, objectives and functions of Nicovape.
3.6.2 law enforcement bodies to assist with their functions, Courts of law or as otherwise required or authorised by law;
3.6.3 debt collection agencies and other parties that assist with debt recovery functions;
3.6.4 regulatory or government bodies for the purposes of resolving customer complaints or disputes both internally and externally or to comply with any investigation by one of these bodies.
4. HOW NICOVAPE STORES THAT INFORMATION
Nicovape is committed to ensuring the security of your personal information. Nicovape is responsible for ensuring that personal information held by Nicovape about you is protected by such security safeguards as is reasonable under the circumstances to take against loss, unauthorised access, modification, disclosure or other misuse of your personal information.
5. ENTITLEMENT TO ACCESS PERSONAL INFORMATION
5.2 In normal circumstances Nicovape will give you full access to your information.
5.3 However, there may be some legal or administrative reasons to deny access. If Nicovape decides to deny access, you will be provided with the reason why.
5.4 You are entitled to request the correction of any personal information, and if there is a reasonable basis for declining the correction request, you are entitled to request that a statement of correction sought but not made be attached to the information.
5.5. If you would like to access your personal information, or if you believe that your personal information may be inaccurate, out of date or incomplete, you can make a request for access or correction by sending an email to Nicovape’ Privacy Officer at firstname.lastname@example.org . We will respond to your request for access and/or correction within 20 days after the request is made.
6. KEEPING INFORMATION ACCURATE AND UP TO DATE
Nicovape makes every reasonable effort to keep your personal information accurate, up to date and complete, in order to provide the best possible service to you. You can assist by keeping Nicovape informed of any updates such as address change, email change or legal name change. Please contact us as soon as practicable when your information changes by emailing us at email@example.com
7. DISCLOSURE TO RECIPIENTS OUTSIDE AUSTRALIA AND NEW ZEALAND
7.2 Where Australian or New Zealand law applies, the information you provide to Nicovape may be accessed by or given to staff and third parties in the US (this is not exhaustive and may change from time to time.)
7.3 Where disclosures are made in accordance New Zealand Privacy Principles, it requires that Nicovape, before it discloses personal information to an overseas recipient, to take such steps as is reasonably practicable to ensure that the overseas recipient does not breach the New Zealand Privacy Principles. If you consent to Nicovape’s disclosure of your information to overseas recipients, New Zealand Privacy Principles will not apply to that disclosure, so that if an overseas recipient handles your information in a manner which breaches the Principles, Nicovape will not be accountable under the Privacy Act 1993 (New Zealand) for the breach, nor will you be able to seek redress under the Privacy Act 1993 (New Zealand). We also note that the recipient may not be subject to laws or principles which are similar to New Zealand Privacy Principles.
9. SESSION ID’S
Session IDs are used to allow us to identify visitors as they browse various websites. No personal information is collected or saved through our use of session IDs.
10.2 Our security precautions are regularly updated and improved in line with technical developments. Unfortunately, no data transmission over the internet can be guaranteed to be 100% secure, so we cannot give an absolute assurance that the information you provide to us will be secure at all times.
10.3 Nicovape will not be held responsible for unauthorised access to personal information where it has taken reasonable steps to protect and secure that information.
10.4 Please note that we may use overseas facilities to process, store or back up information. If you provide any personal information to us, you also consent to the transfer by us of your information to our overseas facilities. However, this does not change any of our commitments to safeguard your privacy to the standard required by the New Zealand Privacy Principles.
10.5 Our site is secure for credit card purchase. In fact, more secure than if you use your credit card in a retail shop. We understand that in order for us to have a long-term relationship with you, we need to offer more than just great service – we need to earn your trust. We have therefore gone to great lengths to provide you with the safest online shopping around – and you can confirm our claims for yourself.
10.6 Safe Information Handling
10.6.2 If someone somehow attempts to read the sensitive information you send us then all they see is an unreadable (encrypted) message;
10.6.3 The technology we use is called “Extended Validation SSL Certificates”, provided by one of the most established Certification Authorities worldwide called GeoTrust.
We have gone that extra mile to obtain an EV SSL certificate, offering the highest levels of trust and authentication available. When you proceed to our eCommerce section of the site, the green address bar prominently displays our company name and provides highly visual assurance that our site is secure.
10.8 Safe Information Storage
We secure our servers using best-practice software and networking technologies to prevent unauthorised access (called “hacking”) to our servers. We pay a trusted third-party called Symantec to attempt to breach our server security each and every day of the year using the latest hacking techniques. If a security weakness is ever found then we are alerted immediately.
10.9 Best-Practice Security
We follow best-practice security procedures, such as:
10.9.2 We use networking security measures such as firewalling and VPNs.
11. REPORTING A BREACH OF YOUR PRIVACY
If you have any concerns that your privacy has been compromised, or have any other privacy related complaints, please contact our Nicovape’ Privacy Officer by telephoning 1300 NICOVAPE (AUS), 0800 NICOVAPE (NZ), emailing firstname.lastname@example.org, or by sending a letter to the Privacy Officer, Nicovape Limited, 28c Hugo Johnston Drive, Penrose, Auckland 1061, New Zealand, and we will contact you within 10 business to confirm receipt of your request. We will then investigate your complaint, take any necessary steps to resolve your complaint, and provide you with our response within a reasonable time. If, after receiving our response, you still consider that your privacy complaint remains unresolved, you may then, for example, take your complaint to the Office of the Australian Information Commissioner (www.oaic.gov.au ), or the New Zealand Office of the Privacy Commissioner (www.privacy.org.nz )
Nicovape Limited 2018