Privacy Policy

Purpose

We know that how we collect, use, disclose and protect your information is important to you, and we value your trust. That’s why protecting your information and being clear about what we do with it is a vital part of our relationship with you.

The purpose of this Privacy Policy is to inform our clients and any users of our digital platforms (i.e. our website & social media pages) about how we comply with the requirements of the New Zealand Privacy Act 2020 (“the Privacy Act”) in managing personal information.

 
Consent to Privacy Policy

Please note that when you contact us through our website & social media you are agreeing to this Privacy Policy. If you do not agree with this Privacy Policy, please do not contact us through any of our digital platforms but call us on +64 (09) 610 5810 or email us at admin@vcfinance.co.nz

 
Collection of personal information

Personal Information is defined in the Privacy Act as information about an identifiable individual (a natural person as opposed to a company or other legal entity).

 
Types of personal information we collect

The types of personal information we collect will vary depending on the nature of your dealings with us. We only collect personal information that is necessary. Where reasonable and practicable, we will collect your personal information directly from you and inform you that we are collecting it.

We mainly collect personal information directly from you, for example:

  • Over the telephone or a video call (such as over Google Meet, Microsoft Teams, Zoom or Skype) e.g. when you contact our staff;
  • Through one of our digital platforms like our website & social media pages (including through any online chat, virtual assistant or bots);
  • When you email or write to us; or
  • When you participate in a marketing campaign, competition or promotion (or a similar event) administered by us or our representatives.
  • Face to face meetings.

If it is not obvious that we are collecting personal information from you, we will do our best to make it clear to you so that you are always aware when information is being collected.

Generally, the types of personal information we collect, and hold include your (not limited to):

  • Name
  • Date of birth
  • Contact details (such as your email address, postal address, phone number)
  • Details relating to your use of any product and/or service offered by us
  • Details of your enquiry
  • Details of any preferences you tell us about (such as subscription preferences)
  • Financial information
  • Employment and income information
  • Identity verification documents

We collect your personal information from the above parties (other than publicly available sources) where we have received your express consent to do so. We are not responsible for the privacy or security practices of the above parties and the parties described above are not covered by this Privacy Policy.

 
Online device information and cookies

If you are visiting us through our website or social media, then we collect information about your use and experience on these by using cookies. Cookies are small pieces of information stored on your hard drive or on your mobile browser. They can record information about your visit to the site, allowing it to remember you the next time you visit and provide a more meaningful experience.

The cookies we send to your computer, mobile phone or other device cannot read your hard drive, obtain any information from your browser or command your device to perform any action. They are designed so that they cannot be sent to another site or be retrieved by any non-VC Finance website.

When you interact with us through our website or social media the information collected through the cookies may include:

  • The date and time of visits;
  • Website page (or pages) viewed;
  • The website from which you accessed the internet and our website or other digital platform;
  • How you navigate through the website and interact with pages (including any fields completed in forms and applications completed (where applicable));
  • Information about your location;
  • Information about the device used to visit our digital platform; and
  • IP address (or addresses), and the type of web browser used.

We will not ask you to supply personal information publicly over e.g. Facebook, Instagram, LinkedIn, or any other social media platform that we use. Sometimes we may invite you to send your details to us through a private message, for example, to answer a question. You may also be invited to share your personal information through secure channels to participate in other activities, such as competitions, but we would require your express consent prior to us including you in such activities.

 
Indirect Collection of Personal Information (IPP3A)

In some circumstances, we may collect personal information about you from third parties (rather than directly from you).

This may occur where it is necessary to (not limited to):

  • Verify your identity
  • Credit reporting agencies
  • Lenders and financial institutions
  • Employers (current or previous)
  • Government agencies and public registers
  • Product providers, insurers, or other advisers
  • Assess your eligibility for financial products
  • Comply with legal obligations, including the Anti-Money Laundering and Countering Financing of Terrorism Act (AML/CFT)
  • Obtain information required to provide accurate financial advice

Where VC Finance Limited collects personal information about an individual indirectly from third parties, we will take reasonable steps to notify the individual concerned of the collection (unless an exception under the Privacy Act 2020 applies). This notification will ensure individuals are made aware of:

  • The fact that their personal information has been collected
  • The purpose for which the information has been collected
  • The intended recipients of the information
  • The name and contact details of the agency that collected the information and the agency that holds the information
  • Whether the collection is authorised or required by law (for example, under the Anti-Money Laundering and Countering Financing of Terrorism Act 2009)
  • Their rights to access and request correction of their personal information

This information will be provided as soon as reasonably practicable after collection, unless the information has already been provided by VC Finance Limited or by another agency.

 
Lender Privacy Notification (IPP3A)

VC Finance Limited may provide your personal information to one or more lenders, banks, or product providers / industry related professionals for the purpose of assessing, processing, and managing the application for lending or other financial products and services.

Where your personal information is provided to any lender or product provider by VC Finance Limited, that organisation may collect, hold, use, and disclose your information in accordance with its own privacy statement or policy.

The relevant lender’s or product provider’s privacy statement is available on their website or upon request and outlines how personal information will be collected, used, stored, and disclosed.

In case you are an existing customer of that lender or provider, it may be deemed that you have previously received or had access to that organisation’s privacy statement. But still refer to their website for privacy policy.

 
Purpose of collection and use of personal information

Any personal information you provide to us may be used to:

  • Check whether you are eligible for the product or services offered by us;
  • Facilitate those services;
  • Provide information that you request; and / or
  • Provide you with further information about our other products and services.

We also have an obligation to maintain personal information to disclose to regulatory and similar bodies – see “Disclosure of your personal information” below. These bodies have a legal right to such information.

 
Storage and protection of your personal information

We may electronically record and store personal information which we collect from you. When we do so, we will take all reasonable steps to keep it secure and prevent unauthorised disclosure.

However, we cannot promise that your personal information will not be accessed by an unauthorised person (e.g. a hacker) or that unauthorised disclosures will not occur. If we provide you with any passwords or other security devices, it is important that you keep these confidential and do not allow them to be used by any other person. You should notify us immediately if the security of your password or security device is breached, this will help prevent the unauthorised disclosure of your personal information.

Some information we hold about you will be stored in paper files, but most of your information will be stored electronically on physical hard drives and/or on the cloud, by cloud service providers – see “Cloud-based service providers” below.

We use a range of physical and electronic security measures to protect the security of the personal information we hold, including:

  • Access to information systems is controlled through identity and access management;
  • Our buildings are secured with a combination of locks and monitored alarms to prevent unauthorized access;
  • Employees are bound by internal information security policies and are required to keep information secure;
  • Employees are required to complete training about information security and privacy;
  • When we send information overseas or use service providers to process or store information, we put arrangements in place to protect your information;
  • We regularly monitor and review our compliance (and our service providers’ compliance) with internal policies and industry best practice.
  • We only keep information for as long as we need it, or if the law requires us to. We have a records management policy that governs how we manage our information and records to make sure we destroy any information that is outdated, irrelevant or unnecessary.
 
Cloud-based service providers

We use third party service providers to store and process most of the information we collect. We use, including but not limited to, Google Drive / Workspace / ClickUp CRM / digital signing platforms. We ensure that our cloud-based service providers are subject to appropriate security and information handling arrangements and that the information stored or processed by them remains subject to confidentiality obligations.

 
Timeframes for keeping personal information

We take reasonable steps to destroy or permanently de-identify any personal information as soon as practicable after the date of which it has no legal or regulatory purpose, or we have no legitimate business purpose with it.

In the case of information that relates to our advice services or products or services we have provided, we are required by law to hold this information for seven years.

After this time, provided that the personal information is no longer relevant to any service we are providing you, we will take reasonable steps to safely destroy or de-identify any personal information.

We have a records management policy that governs how we manage our information and records to enable us to destroy any information that is outdated, irrelevant or no longer necessary.

 
If there is a privacy breach

We work hard to keep your personal information safe. However, despite applying strict security measures and following industry standards to protect your personal information, there is still a possibility that our security could be breached. If we experience a privacy breach, where there is a loss or unauthorised access or disclosure of your personal information that is likely to cause you serious harm, we will, as soon as we become aware of the breach:

  • Seek to quickly identify and secure the breach to prevent any further breaches and reduce the harm caused.
  • Assess the nature and severity of the breach, including the type of personal information involved and the risk of harm to affected individuals;
  • Advise and involve the appropriate authorities where criminal activity is suspected;
  • Where appropriate, notify any individuals who are affected by the breach (where possible, directly);
  • Where appropriate, put a notice on our website advising our clients of the breach; and
  • Notify the Privacy Commissioner.
 
Disclosure of your personal information

We may disclose your personal information to others outside VC Finance Limited where:

  • It is necessary to enable us to achieve the purpose that we collected the information for;
  • We are required or authorised by law or where we have a public duty to do so;
  • Internal / External Audits.
  • You have expressly consented to the disclosure, or your consent can be reasonably inferred from the circumstances; or
  • We are permitted to disclose the information under the Privacy Act 2020.
  • We will never sell your personal information.
 
Parties we may disclose your information to

Your personal information may be used by us for the purpose of providing advice and services to you and may also be used by agencies such as, but not limited to:

  • Any outsourced service provider who assists in the services we are required to carry out such as auditors and external compliance reviewers.
  • Our external dispute resolution service.
  • The Regulator.
  • Credit reporting and debt collecting organizations.
  • Lenders, solicitors or any other associated parties.

If we don’t need to share your information with a third party to provide advice and services to you, we will not pass on your information to them without your consent.

Under no circumstances will we sell or receive payment for disclosing your personal information.

 
Third party websites

Through our website or our other social media pages, you may be able to link to other websites which are not under our control. We are not responsible for the privacy or security practices of those third-party websites, and the sites are not covered by this Privacy Policy. Third party websites should have their own privacy and security policies, and we encourage you to read them.

In addition, we have no knowledge of (or control over) the nature, content, and availability of those websites. We do not sponsor, recommend, or endorse anything contained on these linked websites. We do not accept any liability of any description for any loss suffered by you by relying on anything contained or not contained on these linked websites.

 
Right to access, correct and delete personal information

You have the right to request access to, correct and, in some circumstances, delete your personal information.

You can do so by contacting us at:

Email: admin@vcfinance.co.nz
Phone: +64 (09) 6105810

When you contact us with such a request, we will take steps to update your personal information, provide you with access to your personal information and/or otherwise address your query within a reasonable period after we receive your request.

To protect the security of your personal information, you may be required to provide identification before we update or provide you with access to your personal information.

 
What happens if you do not provide us your information?

If you do not provide information we have requested, you may be unable to obtain or access our services for which the information is required.

Please ask us if you are unsure what information is important and how this might affect you.

 
Changes to this Privacy Policy

We review this Privacy Policy periodically to keep it current and available on our website.

If the changes are significant, we may advise you directly.

You may also obtain a copy of the latest version by contacting us at admin@vcfinance.co.nz

 
Privacy Policy queries and concerns

If you are concerned about how your personal information is being handled or if you feel that we have compromised your privacy in some way, please contact us by email at admin@vcfinance.co.nz

We will acknowledge your complaint within two working days of its receipt. We will let you know if we need any further information from you to investigate your complaint.

If you are not satisfied with our response to any privacy related concern, you may lodge a complaint on the Privacy Office website or send a complaint form to the Privacy Commissioner at:

Office of the Privacy Commissioner
P O Box 10-094
Wellington 6143
New Zealand

Office of the Privacy Commissioner NZ