New Zealand Privacy Act 2020 Compliance

BizLiveGo New Zealand Privacy Notice

Statutory disclosure for individuals in Aotearoa New Zealand under the Privacy Act 2020. Defining our adherence to the 13 Information Privacy Principles (IPPs), overseas transfer safeguards (IPP 12), mandatory privacy breach notifications, and individual access and correction mechanisms.

Agency: BizLiveGo | Operator: MD Joshim Biswas | Malda, WB, India - 732206 | Version: 2026.1

1. Legislative Scope

Extraterritorial Jurisdiction (Section 4)

This Notice applies to personal information collected and processed by BizLiveGo concerning individuals located in New Zealand, pursuant to the Privacy Act 2020.

Under Section 4 of the Act, an overseas agency carrying on business in New Zealand is bound by the Act regardless of where its commercial headquarters or computing databases are geographically located.

2. Collection Standard

Lawful Purpose & Direct Ingestion

BizLiveGo collects personal information strictly in accordance with IPPs 1 and 2:

  • Connected Purpose (IPP 1): Data is collected only for purposes directly related to business profile publishing, digital storefronts, and dynamic QR routing.
  • Direct Source (IPP 2): Information is collected directly from the individual concerned, unless specific statutory exceptions apply.
3. Principles Framework

The 13 Information Privacy Principles (IPPs)

How BizLiveGo structures data operations in compliance with Section 22 of the Privacy Act 2020:

IPP 1: Purpose of Collection

Personal information is gathered solely for lawful and necessary platform hosting, catalog indexing, and account operations.

IPP 2: Source of Information

Data is collected directly from the individual through transparent dashboard inputs, avoiding clandestine third-party data scraping.

IPP 3: Collection Notice

Individuals are informed before or during collection regarding our identity, operational purpose, intended recipients, and access rights.

IPP 4: Manner of Collection

Collection is conducted by lawful, fair, and non-intrusive means, respecting user privacy without deceptive interface mechanisms.

IPP 5: Storage & Security

Securing records against loss, unauthorized access, or disclosure through robust TLS 1.3 in transit and AES-256 resting encryption.

IPP 6: Access to Information

Giving individuals the statutory right to confirm and obtain access to personal information held about them within our 7–15 days SLA.

IPP 7: Correction

Empowering users to correct inaccurate data or attach a statement of correction where disputed.

IPP 8: Accuracy Checks

Taking reasonable steps to ensure data is accurate, complete, and relevant before active commercial use.

IPP 9: Retention Limits

Retaining records no longer than required for verified business purposes or statutory tax compliance.

IPP 10: Limits on Use

Using personal records only for the original purpose specified at collection, unless express consent is obtained.

IPP 11: Limits on Disclosure

Never disclosing personal records to external commercial entities unless authorized by the individual or mandated by law.

IPP 12: Cross-Border Safeguards

Disclosing personal information outside New Zealand strictly under comparable privacy protections and contractual terms.

IPP 13: Unique Identifiers

Never assigning New Zealand government identifiers (e.g., IRD numbers) as internal customer account keys.

IPP 13 & Sensitive Identity Restrictions

4. Exclusion of New Zealand Official Identifiers & Sensitive Credentials

In strict accordance with IPP 13 (Unique identifiers), BizLiveGo prohibits the ingestion or display of New Zealand government identity documents:

Prohibited New Zealand Identifiers

Users and clients must never upload or submit:

  • Inland Revenue Department (IRD) numbers, NHI (National Health Index) numbers, or driver licence numbers.
  • Unredacted New Zealand passports, Kiwi Access cards, or official citizen certificates.
  • Credit/debit card CVVs, private banking PINs, or confidential password keys.

Voluntary Sensitive Parameters

Elective profile fields (such as emergency blood registries or matrimonial bios):

  • Collected strictly on the basis of explicit, informed opt-in consent.
  • Shielded from third-party advertising pixels and commercial marketing trackers.
  • Expunged immediately upon user deletion directive without secondary retention.
5. Cross-Border Routing

Overseas Disclosure Safeguards Under Principle 12 (IPP 12)

How BizLiveGo ensures comparable protection when routing personal data outside New Zealand:

1. Primary Storage (India)

Core application databases and profile configurations are hosted in secure, certified cloud clusters in India (Mumbai / Bengaluru regions).

Protected by comprehensive Data Processing Agreements (DPAs) ensuring comparable safeguards.

2. Global Edge CDN (Cloudflare)

Static media assets, profile layouts, and dynamic QR SVG images are cached on Cloudflare's international edge nodes (including New Zealand edge servers in Auckland).

Guarantees low-latency rendering across New Zealand.

3. IPP 12 Contractual Safeguards

Under IPP 12, overseas disclosures are permitted where the recipient is subject to comparable privacy laws, bound by model contract clauses, or operating pursuant to explicit user authorization to render public profile links.

6. Individual Rights

Access and Correction Workflows (IPPs 6 & 7)

New Zealand users maintain statutory rights under Principles 6 and 7:

  • Self-Service Updates: Edit business listings, hours, catalogs, and images in real-time.
  • Right of Access: Request an intelligible copy of all stored personal records.
  • Correction Statements: Where a correction is declined, users may request that a statement of correction be attached to their record.
  • Execution SLA: Standard requests are completed within 7 to 15 working days (statutory limit under the Privacy Act: 20 working days).
7. Mandatory Breach Reporting

Notifiable Privacy Breaches (Part 6)

BizLiveGo maintains an active breach management framework in full compliance with Part 6 of the Privacy Act 2020:

  • Serious Harm Threshold: If an incident creates a reasonable likelihood of serious harm to an affected individual, notification is mandatory.
  • Regulator Notification: The Privacy Commissioner is notified as soon as practicable after becoming aware of the breach.
  • Individual Notice: Affected individuals are notified directly unless statutory exceptions apply.
8. Regulatory Recourse

Privacy Complaints & Escalation to the Privacy Commissioner

How New Zealand users can resolve concerns and access independent statutory dispute resolution:

Step 1: Contact Privacy Officer

Lodge a formal written complaint with our Privacy Officer at support@bizlivego.com detailing the alleged interference with privacy under the Privacy Act 2020.

Step 2: Internal Resolution

Our Privacy Officer will acknowledge receipt within 24 to 48 hours and provide a substantive written finding and corrective action plan within 20 working days.

Step 3: Office of the Privacy Commissioner

If you are not satisfied with our response, you have the statutory right to escalate your complaint to the Office of the Privacy Commissioner (OPC).

Office of the Privacy Commissioner (Te Mana Mātāpono Matatapu) Contact Information

The independent national privacy regulator for New Zealand:

  • Website: www.privacy.org.nz
  • Enquiries Line: 0800 803 909 (New Zealand) / +64 4 474 7590 (International)
  • Postal Address: PO Box 10-094, The Terrace, Wellington 6143, New Zealand
Quick Summary

New Zealand Privacy Notice Quick Reference

Consolidated review of New Zealand privacy governance, IPP standards, and operational benchmarks:

Compliance Dimension BizLiveGo Operational Policy Privacy Act 2020 Reference
Primary Governing Statute Privacy Act 2020 and the 13 Information Privacy Principles (IPPs). Section 22 (IPPs)
Extraterritorial Reach Applies to BizLiveGo as an agency carrying on commercial business in New Zealand. Section 4
Prohibited Identifiers IRD numbers, NHI health numbers, driver licences, and passport copies are barred. IPP 13 (Unique Identifiers)
Cross-Border Disclosures Disclosed overseas strictly under comparable protection and enforceable DPAs. IPP 12
Data Security Controls Protected via TLS 1.3 encryption in transit, AES-256 at rest, and Cloudflare WAF. IPP 5 (Storage & Security)
Mandatory Breach Notification Breaches causing serious harm reported to Privacy Commissioner and individuals. Part 6 (Privacy Breaches)
Access & Correction SLA Fulfilled within our internal 7 to 15 working days SLA (statutory limit: 20 working days). IPPs 6 & 7 / Section 44
Regulatory Oversight Office of the Privacy Commissioner (Te Mana Mātāpono Matatapu). OPC Enforcement

New Zealand Privacy Enquiries & Privacy Officer Contact

If you have questions regarding our compliance with the Information Privacy Principles, wish to exercise your access or correction rights, or need assistance from our Privacy Officer, contact our privacy desk.

Privacy Officer: Joshim Biswas | Location: Masimpur, Kaliachak, Malda, West Bengal, India - 732206