Privacy Policy
Política de Privacidad. This page is separate from the main landing page and explains the terms that apply to eDigital360 website visitors, clients and service enquiries.
How eDigital360 handles personal information
| Business / Trading name | eDigital360 |
|---|---|
| Website | https://edigital360.com |
| info@edigital360.com | |
| Phone | +64 27 466 2925 |
| Location | Hawke’s Bay, New Zealand |
| Effective date | 3 August 2026 |
| Version | 1.0 – draft for review |
2. Privacy Policy
This Privacy Policy explains how eDigital360 collects, uses, stores, shares and protects personal information. It applies to visitors, prospects, clients, client team members, and people whose information may be processed through our automation systems.
2.1 Controller / agency details
Agency / business name: eDigital360.
Email for privacy requests: info@edigital360.com.
Phone: +64 27 466 2925.
Business location: Hawke’s Bay, New Zealand.
2.2 Scope of this policy
This policy covers personal information we collect directly from you, personal information collected automatically when you use our website, and personal information that business clients provide to us or connect to systems we build. Where we process personal information on behalf of a business client, the client may also be a separate controller/agency and may have its own privacy obligations.
2.3 Personal information we may collect
Identity and contact details: name, business name, job title, email address, phone number, location and social media handle.
Business enquiry details: business type, website URL, preferred automation, problem description, budget, project goals and communication history.
Technical data: IP address, device type, browser type, operating system, pages visited, timestamps, referral source and cookie identifiers.
Client account data: login/user details for systems we configure, project notes, workflow requirements, form submissions, CRM fields, calendar data, sheet data, API connection details and support requests.
Client customer data: names, contact details, booking details, message content, enquiry history or other data that a client chooses to process through an automation system.
Billing and contract data: invoices, payment status, plan type, service history and transaction-related information. We do not intentionally store full payment card details unless a payment provider requires this for processing.
Call and voice automation data: caller number, call time, transcript, recording, booking request or summary, if a client uses voice receptionist or calling services and has enabled such features.
2.4 How we collect information
When you fill in a website form, email us, call us, message us on social media, book a demo, request a quote or become a client.
Through cookies, analytics tools, server logs, website security tools and performance monitoring tools.
From third-party providers used to deliver our services, such as form providers, email services, hosting providers, automation platforms, calendar tools, CRM platforms, social media platforms, AI providers, SMS/calling providers and payment processors.
From business clients who connect their systems or provide customer/enquiry data for the purpose of building or operating automation systems.
2.5 Why we use personal information
To respond to enquiries and provide quotes, demos, audits and service recommendations.
To design, build, test, deliver, maintain and improve automation systems.
To configure chatbots, booking systems, workflow automations, AI assistants, calling receptionists, spreadsheet automations, CRM workflows and integrations.
To communicate about projects, support, billing, system updates, account changes and service issues.
To operate, secure, monitor, troubleshoot and improve our website and services.
To send marketing or service-related communications where permitted by law and with any required consent.
To comply with legal, tax, accounting, security, privacy, regulatory and dispute-resolution obligations.
To prevent fraud, misuse, unauthorised access, spam, abuse, security incidents or unlawful activity.
2.6 Lawful basis and legal grounds
Where New Zealand law applies, we collect and use personal information for lawful purposes connected with our business and only where the information is necessary for those purposes. Where GDPR or similar laws apply, our legal bases may include consent, contract necessity, legitimate interests, compliance with legal obligations and, where applicable, protection of vital interests or public interest. Our legitimate interests include operating our business, responding to enquiries, improving services, securing systems and supporting clients, provided those interests are not overridden by individual rights.
2.7 AI systems and automated processing
We may use AI tools to assist with drafting responses, analysing workflows, summarising enquiries, generating automation logic, supporting chatbots, processing support requests or improving client systems.
AI outputs may be inaccurate, incomplete or context-sensitive. We recommend human review for important decisions, sensitive matters and business-critical actions.
We do not knowingly use sensitive personal information to train our own public AI model. However, third-party AI providers may process data according to their own terms and data processing agreements.
Clients must not provide unnecessary sensitive, confidential or regulated data to AI systems unless this has been assessed, agreed and configured appropriately.
2.8 Client customer data
If we process personal information about your customers on your behalf, you are responsible for ensuring that you have a lawful basis to provide that information to us and to instruct us to process it. You must maintain appropriate privacy notices, consents, opt-outs and customer communications for your own business. We will use client customer data only to provide, maintain, support, secure and improve the agreed services, unless otherwise agreed in writing or required by law.
2.9 Indirect collection
Where we receive personal information from a source other than the individual, including from a business client, a connected CRM, spreadsheet, form, email inbox, calendar, social media account or third-party integration, we will take reasonable steps required by applicable law. Clients remain responsible for informing their own customers where they collect or disclose customer data for automation purposes.
2.10 Sharing information with service providers
We may share personal information with trusted service providers where reasonably necessary to operate the website, provide services, communicate, process payments, host data, automate workflows, send emails/SMS, provide voice/calling features, analyse performance or maintain security. These may include providers such as WordPress, website hosting providers, domain/DNS providers, email providers, form processors, Google services, Meta platforms, OpenAI or other AI providers, Make, n8n, CRM systems, payment processors, analytics providers, calendar tools, spreadsheet tools, communication tools and SMS/calling providers. Update this list before publishing with the exact providers you use.
2.11 International transfers
Some providers may store or process data outside New Zealand, including in Australia, the United States, the European Union or other locations. Where required, we take reasonable steps to ensure appropriate safeguards are in place, such as contractual protections, provider security commitments, data processing terms or transfer mechanisms required by applicable law.
2.12 Security
We use reasonable technical and organisational safeguards to protect personal information, including access controls, password/security practices, role-based access where available, secure hosting, encrypted transmission where available, provider security controls, backups where appropriate and limitation of access to those who need it. No online system is completely secure, and you should not send unnecessary sensitive information through ordinary website forms or email.
2.13 Retention
We retain personal information only for as long as reasonably needed for the purpose for which it was collected, including to provide services, maintain records, comply with legal/tax/accounting obligations, resolve disputes, enforce agreements, secure systems and improve services. Enquiry data is generally retained for up to 24 months unless you become a client or ask us to delete it earlier where legally possible. Client project records may be retained for up to 7 years for business, tax, legal and continuity purposes unless a different period is agreed.
2.14 Your rights
You may request access to personal information we hold about you.
You may request correction of inaccurate or incomplete information.
You may request deletion, restriction or objection where available under applicable law.
You may withdraw consent where processing is based on consent.
You may opt out of marketing messages using the unsubscribe method provided or by contacting us.
If GDPR applies, you may also have rights to portability and to lodge a complaint with an EU/UK supervisory authority.
2.15 Privacy complaints
If you have a privacy concern, contact us first at info@edigital360.com. If you are not satisfied, you may contact the New Zealand Office of the Privacy Commissioner. EU/UK individuals may also contact their local data protection authority where applicable.
2.16 Children
Our services are intended for businesses and are not directed to children. We do not knowingly collect personal information from children through this website. If you believe a child has provided us personal information, contact us so we can review and delete it where appropriate.
2.17 Changes to this policy
We may update this Privacy Policy from time to time. The updated version will be posted on our website with a new effective date. Material changes may be notified by website notice or email where appropriate.
