Skip to main content

Privacy Policy

  1. Outline of this Privacy Policy
    • Community Energy Action Charitable Trust (we and us) is committed to protecting the personal information of you as a user of our website (you).
    • In this privacy policy we explain:
      1. how and why we collect personal information;
      2. how that information is stored;
      3. how you can access and correct that information; and
      4. when we might disclose personal information to other people.
    • This privacy policy does not limit or exclude any rights that you have or may have under the Privacy Act 2020a (or any replacement Act) (Privacy Act)
  2. Application of this Privacy Policy
    • This privacy policy applies whenever we collect personal information from you.
    • By accessing our website and/or using content on our website and/or purchasing products or services offered by us (Products), you consent to the collection, use, disclosure, storage and processing of personal information in accordance with this privacy policy.
  3. Collection of Personal Information
    • We may collect the following personal information:
      1. Your name, phone number, physical address, postal address, email address, ethnicity and whether you have any chronic health conditions.
      2. Metadata obtained through your use of our website, including your IP address, computer and connection information, referring web page, standard web log information, language settings, and time zone.
      3. Your payment information, such as your credit or debit card details.
      4. Any communication with us either directly, via phone or email.
      5. Information about the device you use to access our website, including device identifier, device type, device plugins, and hardware capabilities.
      6. Information obtained by or submitted to us from you through your use (or prospective use) of our website, including information and documents submitted by you, your GPS position, pages viewed, buttons clicked, viewing time, keyword searches.
      7. Information you elect to disclose by answering questions made available on our website.
    • We may receive information about you through our website, communication systems, or other communication.
    • We may also receive information about you from third parties, including in the following circumstances:
      1. We may collect data from your accounts on other platforms that you give us permission to connect to. These platforms include, but are not limited to, Facebook, LinkedIn, and Google.  You can stop us from collecting data from those other platforms by removing our access on the platform or by contacting us at info@cea.co.nz;
      2. Your payment provider may provide us with information about the payments you make; and
      3. We may collect information from public sources.
    • If you choose not to provide information when we ask for it, then you may not be able to use our website.
  4. Use of Personal Information
    • We use personal information we collect about you:
      1. To verify your identity.
      2. In connection with the provision (or potential provision) of Products to you.
      3. To communicate with you in relation to the Products.
      4. To market our Products to you, including contacting you electronically (for example, by text, email or an online messaging platform).
      5. To collect money that is owed by you.
      6. To respond to communications from you, including any complaints;
      7. To co-operate with any government, industry, legislative or regulatory authorities.
      8. To protect and/or enforce our legal rights and interests, including defending any claim.
      9. For any other purpose authorised by you and/or the Privacy Act.
    • We reserve our right to use:
      1. data (on an anonymous basis) in relation to your use of our website for marketing and accounting purposes; and
      2. your personal information (on an anonymous basis) when communicating with funders or potential funders in relation to the grant or potential grant of funding to allow CEA to continue its work in the community.
    • You may request that we stop sending marketing or promotional messages at any time, by contacting us at info@cea.co.nz or by using any unsubscribe link in our message.
  5. Cookies
    • We may use cookies (being an alphanumeric identifier that we transfer to your computer’s hard drive so that we can recognise your browser) in order to monitor your use of our website.
    • You may disable cookies by changing the settings on your browser, although this may mean that you cannot use all of the features of our website.
  6. Links to other websites
    • Our website may provide links to other websites. We may provide those links or they may be provided by other users.  We have no control over the organisations operating those websites or the content on those websites.  Before you disclose your personal information to another website, we recommend you check its terms and conditions, including any privacy policy.
  7. Disclosure of Personal Information
    • Unless expressly authorised to do so by you or under this privacy policy, we will not disclose any of your personal information to any third party except where disclosure relates to the purposes for which the information was collected (as stated in clause 4 above) or where it may be required by law to do so.
  8. Storage of Personal Information
    • We will take all reasonable steps to ensure the personal information collected, used or disclosed in accordance with this privacy policy is stored in a secure environment protected from unauthorised access, modification or disclosure.
    • When you use our website, we may engage service providers for the purposes outlined in this policy that are located outside New Zealand, such as service providers that host or maintain any underlying IT system or data centre that we use to provide our website. We take all reasonable steps to ensure that your personal information held outside New Zealand is secure and held in compliance with this privacy policy.  For example, when we engage service providers located outside New Zealand we ensure that our contractual terms require the service providers to protect the information provided to them.
    • We will hold personal information collected in accordance with this privacy policy both before and after the provision of Products to you, but only for so long as we are legally entitled to do so, including for the purposes of satisfying any legal, regulatory, tax, accounting or reporting requirements. To determine the appropriate period of time to hold your personal information, we consider the amount, nature and sensitivity of your personal information, the potential risk of harm from unauthorised use or disclosure of your personal information, the purposes for which we process your personal information and whether we can achieve those purposes through other means, and the applicable legal, regulatory, tax, accounting and other requirements.
  9. Accessing and Updating Personal Information
    • You have the right to access and correct personal information held by us by contacting us at info@cea.co.nz.
    • In particular, you have the following rights in relation to your personal information:
      1. To request access to your personal information.
      2. To request a correction to your personal information.
      3. To request the deletion or removal of your personal information.
      4. To object to the processing of your personal information.
      5. To request a restriction on the processing of your personal information.
      6. To request a transfer of your personal information to you or a third party.
      7. To withdraw consent to the use of your personal information.
    • You may request to see the personal information that is held by us on your behalf or to correct or update any personal information.
  10. Amendments to this Policy
    • We reserve the right to make changes to this privacy policy by uploading an updated privacy policy on our website. You will be bound by the privacy policy that is in effect at the time you access our website and/or order the Products.  Your continued use of our website represents your agreement to be bound by the privacy policy as amended.  If you do not agree with our amended privacy policy, you must stop using our website.
  11. Severability
    • If any part of this privacy policy is not enforceable for any reason, whether under the Privacy Act or any other applicable law, that part will be deleted and the rest of this privacy policy will continue to apply.
  12.  Systems Currently in Place to ensure security
    • Email is running on Microsoft 365 with spam and virus scanning managed by Microsoft.
    • Firewall separates internal systems from internet.
    • Server has security updates applied monthly and antivirus is managed.
    • Server backups occur hourly, replicated offsite immediately, and is monitored.
    • Computers run Windows 10, modern operating system with less security flaws.
    • Computers run ESET Antivirus v7.3 with Outlook plugin for email scanning.