GDPR Rights & Data Protection
Your rights under the General Data Protection Regulation
Introduction
At Kiwi Reels, we are committed to protecting your personal data and respecting your privacy rights. This page explains your rights under the General Data Protection Regulation (GDPR) and how you can exercise them.
The GDPR is a European Union regulation that provides strong data protection rights to individuals. While we are based in New Zealand, we extend these rights to all our users regardless of location.
Data Controller: directbillpo.com
Address: 56 Avondale Road, Zealandia, New Zealand
Contact: support@directbillpo.com
Your GDPR Rights
Under GDPR, you have the following rights regarding your personal data:
1. Right to Access
You have the right to request a copy of the personal data we hold about you. This is commonly known as a "data subject access request."
2. Right to Rectification
You have the right to ask us to correct personal data about you that is incomplete or inaccurate.
3. Right to Erasure (Right to be Forgotten)
You have the right to request deletion of your personal data in certain circumstances, such as when the data is no longer necessary for the purpose it was collected.
4. Right to Restriction of Processing
You have the right to ask us to limit how we use your personal data in certain situations, such as when you contest the accuracy of the data.
5. Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transfer it to another service provider.
6. Right to Object
You have the right to object to our processing of your personal data in certain circumstances, particularly for direct marketing purposes.
7. Rights Related to Automated Decision Making
You have the right not to be subject to decisions based solely on automated processing, including profiling, which produces legal effects or similarly significant effects.
8. Right to Withdraw Consent
Where we process your data based on your consent, you have the right to withdraw that consent at any time.
How to Exercise Your Rights
Making a Request
To exercise any of your GDPR rights, please contact us using the details below. We aim to respond to all requests within 30 days.
Submit Your Request:
Primary Contact: support@directbillpo.com
Alternative: info@directbillpo.com
Business Enquiries: contact@directbillpo.com
Postal Address:
directbillpo.com
56 Avondale Road
Zealandia
New Zealand
What to Include in Your Request
When making a request, please provide:
- Your full name and contact information
- A clear description of the right you wish to exercise
- Any relevant details that will help us locate your data
- Proof of identity if we need to verify your identity
Verification Process
To protect your privacy, we may need to verify your identity before processing your request. This is a security measure to ensure personal data is not disclosed to unauthorized persons.
We may ask you to provide:
- Additional identifying information
- Answers to security questions
- Documentation proving your identity
Response Time
We will respond to your request within one month of receipt. In complex cases, we may extend this period by two additional months, and we will inform you of any such extension.
Detailed Rights Explanations
Right to Access
When you request access to your personal data, we will provide:
- Confirmation of whether we process your personal data
- A copy of your personal data
- Information about how we use your data
- Details about data retention periods
- Information about your other rights
- Details of any third parties with whom we share your data
The first copy of your data is provided free of charge. We may charge a reasonable fee for additional copies.
Right to Rectification
If you believe any personal data we hold about you is inaccurate or incomplete, you can ask us to correct it. We will:
- Correct inaccurate data without undue delay
- Complete incomplete data
- Notify any third parties to whom we have disclosed the data
Right to Erasure
You can request deletion of your personal data when:
- The data is no longer necessary for the purpose collected
- You withdraw consent and there is no other legal basis for processing
- You object to processing and there are no overriding legitimate grounds
- The data has been unlawfully processed
- Deletion is required to comply with a legal obligation
Limitations: We may not be able to delete your data if we need to keep it for:
- Legal compliance
- Establishing, exercising, or defending legal claims
- Public interest purposes
Right to Restriction
You can ask us to restrict processing of your data when:
- You contest the accuracy of the data
- Processing is unlawful but you prefer restriction to deletion
- We no longer need the data but you need it for legal claims
- You have objected to processing and verification is pending
When processing is restricted, we will store the data but not use it except for legal claims, protecting another person's rights, or with your consent.
Right to Data Portability
This right allows you to:
- Receive your personal data in a portable format
- Transmit your data to another service provider
- Have your data transmitted directly to another controller where technically feasible
This right applies when:
- Processing is based on consent or contract
- Processing is carried out by automated means
Right to Object
You have the right to object to processing based on:
- Legitimate interests
- Performance of a task in the public interest
- Direct marketing purposes
- Scientific or historical research
For direct marketing, we will stop processing immediately. For other cases, we will stop unless we can demonstrate compelling legitimate grounds.
Managing Cookies and Consent
Cookie Management
You can manage your cookie preferences through:
- Our cookie consent tool when you first visit the site
- Your browser settings
- Contacting us to update your preferences
Types of Cookies We Use
Essential Cookies
These are necessary for the website to function. They include:
- Age verification status
- Cookie consent preferences
- Basic functionality cookies
You cannot opt out of essential cookies, but you can delete them through your browser.
Analytics Cookies
With your consent, we use analytics cookies to:
- Understand how visitors use our site
- Improve user experience
- Track site performance
You can opt out of analytics cookies through our consent tool.
Withdrawing Consent
To withdraw consent for cookies or other data processing:
- Clear your browser cookies
- Use our cookie management tool on your next visit
- Contact us at support@directbillpo.com
Withdrawing consent does not affect the lawfulness of processing based on consent before withdrawal.
Data Protection Officer
While we are not required to appoint a Data Protection Officer, all data protection enquiries are handled by our dedicated privacy team.
Contact our privacy team at support@directbillpo.com for:
- Questions about how we process your data
- Concerns about data protection
- Requests to exercise your rights
- Complaints about data handling
Complaints and Supervisory Authority
Making a Complaint
If you are not satisfied with how we handle your personal data or your rights request, you have the right to lodge a complaint with a supervisory authority.
New Zealand Privacy Commissioner
As we are based in New Zealand, you can contact:
Office of the Privacy Commissioner
Website: www.privacy.org.nz
Email: enquiries@privacy.org.nz
Phone: 0800 803 909
European Data Protection Authorities
If you are in the EU, you can contact your local data protection authority. Find your authority at: edpb.europa.eu
International Data Transfers
Your data may be transferred to and processed in countries outside New Zealand and the European Economic Area. When we transfer data internationally, we ensure appropriate safeguards are in place:
- Standard contractual clauses approved by the European Commission
- Adequacy decisions where applicable
- Other approved transfer mechanisms
Children's Privacy
Our service is not intended for individuals under 18. We do not knowingly collect data from children. If you believe we have collected data from a child, please contact us immediately at support@directbillpo.com.
Data Retention
We retain personal data only as long as necessary for the purposes set out in our Privacy Policy. Retention periods depend on:
- The nature of the data
- The purpose for collection
- Legal and regulatory requirements
- Legitimate business needs
When data is no longer needed, we securely delete or anonymize it.
Updates to This Information
We may update this GDPR rights information to reflect changes in:
- Data protection laws
- Our data processing practices
- Regulatory guidance
We will notify you of significant changes through our website or by email if we have your contact information.
Additional Resources
For more information about data protection and privacy:
- Our Privacy Policy - Detailed information about data processing
- Terms of Use - General terms governing use of our services
- GDPR Official Website - General information about GDPR
- NZ Privacy Commissioner - New Zealand privacy information
Contact Information
For all GDPR-related enquiries and requests:
Data Controller: directbillpo.com
Address: 56 Avondale Road, Zealandia, New Zealand
Email Contacts:
Primary: support@directbillpo.com (24-hour support)
General: info@directbillpo.com
Business: contact@directbillpo.com
We are committed to protecting your privacy rights and handling your data responsibly. If you have any questions or concerns about your GDPR rights, please do not hesitate to contact us.
Last Updated: January 2025