This policy explains what personal information nzphotos.com collects, why, how long it is kept, who it is shared with, and what you can ask us to do with it. It is written to satisfy both the New Zealand Privacy Act 2020 and, for visitors and customers in the European Union and the United Kingdom, the General Data Protection Regulation.
Clause 20 of our Standard and Extended Licence Terms and Conditions refers to this policy for the detail of how we handle personal information.
The controller of your personal information is:
DAY Investments Limited
16/160 Kepa Road, Ōrākei
Auckland 1071, New Zealand
Contact us
Privacy questions are handled personally by:
Harald Hochmann, EUR ING, PFIAP
Director, DAY Investments Limited
at the address above, or through the
contact page
We have not appointed a Data Protection Officer under Article 37 of the GDPR, and are not required to: we are not a public authority, our core activity is not large-scale monitoring, and we process no special categories of data at scale. The person named above is your point of contact for anything in this policy, and will answer you directly.
We collect only what a licensing shop needs to work. The table sets out each category, why we hold it, and the lawful basis under the GDPR. Where the basis is "legitimate interests", we have weighed those interests against your rights and describe the interest concerned.
| Account | Salutation, first and last name, email address, password (stored only as a hash, never in
readable form), the date you accepted our terms and the version you accepted, whether your
email has been verified, and the date of your last sign-in. Why: to give you an account, let you sign in, and prove what you agreed to. Basis: performance of a contract. |
| Billing and licence holder details | Name or company name, address, city, region, postcode, country, email, telephone, and any
tax, VAT or GST number you give us. Why: to issue a valid invoice and to name the correct licence holder on the Licence Certificate. Basis: performance of a contract, and legal obligation for the tax elements. |
| Purchases and licences | Invoice number and date, the images licensed, licence type and number, prices, currency,
tax treatment, discount or voucher used, payment method, and the payment reference returned
by the payment provider. We keep a snapshot of your billing details as they stood at the
time of purchase, because an invoice must not change afterwards. Why: to deliver the licence, to issue the invoice and certificate, and to keep the records tax law requires. Basis: performance of a contract, and legal obligation. |
| Invoices and Licence Certificates | The PDF documents themselves, which carry your name and address. They are generated once, at
the time of purchase, and stored so that the document you received never changes. Why: so you can download them again, and so our records match yours. Basis: performance of a contract, and legal obligation. |
| Favourites | The images you have marked, linked to your account. Why: so the list is there when you come back. Basis: performance of a contract. |
| Account activity | A log of actions in your own account — sign-ins, downloads, licence views — with
the time they happened. Why: so you can see what has happened on your account, and so we can investigate if something looks wrong. Basis: legitimate interests in the security of the service. |
| Emails we send you | Address, subject, message text, any link contained in it, whether sending succeeded, and the
IP address the triggering request came from. Why: to prove a verification or password-reset message was sent, and to diagnose delivery problems. Basis: legitimate interests in a working, auditable sign-up process. |
| Sign-in attempts | IP address, the email address used, whether the attempt succeeded, and the time. Why: to slow down password guessing. Basis: legitimate interests in protecting accounts. |
| Contact messages | Your name, email address and message. We do not store the IP address of the
sender; we store a one-way hash of it, so we can recognise that several messages came from
the same connection without being able to work out which connection. Why: to answer you, and to keep the form from being used to send bulk mail. Basis: legitimate interests in replying to enquiries and in preventing abuse. |
| Newsletter | Your email address and the fact that you opted in. Why: to send you the newsletter. Basis: consent, which you can withdraw at any time. |
| Page statistics | Counts only: date, hour, which page or image was viewed, and how often. No identifier of any
kind is stored alongside them, so these figures cannot be traced to a person. Why: to see which images and pages are of interest. Basis: legitimate interests; the data is not personal information. |
| Domain forwarding statistics | For the domains we forward to this site: the date, the domain, and a shortened IP address
— the last block of an IPv4 address is set to zero and only the first half of an IPv6
address is kept — together with a one-way hash used to count repeat visits. Why: to see how much traffic a domain brings. Basis: legitimate interests in understanding our own traffic. |
| Server logs | Our hosting provider records the usual web-server log entries, including full IP addresses,
for a short period. Why: to keep the server running and to investigate attacks. Basis: legitimate interests in the security and availability of the service. |
We do not carry out profiling, and no decision about you is made by automated means. We do not buy personal information from anyone, and we do not build a picture of you from sources outside this site.
This site sets a session cookie when you sign in or use the basket. It holds a random identifier and nothing else; without it the site cannot remember that you are signed in, so it is strictly necessary and no consent is required for it. A second cookie records your answer to the cookie banner, so we do not have to ask again.
Anything beyond that is asked for in the banner and set only if you agree. You can change your answer at any time through Cookie Settings in the footer, and you can delete our cookies in your browser at any time.
We share personal information only with the parties below, only for the purpose named, and never for their own marketing:
The site, its database and the stored invoices and certificates are held on servers in the European Union, operated by our hosting provider in Germany. Backups are held in the same region.
For customers in the EU or the UK: your information stays within the European Economic Area for storage and processing. It is accessible to us in New Zealand for the purposes described above. New Zealand has an adequacy decision from the European Commission, so no additional transfer safeguards are required.
For customers in New Zealand: your information is held overseas, in the European Union. Information Privacy Principle 12 of the Privacy Act 2020 permits this, because the European Union provides comparable safeguards to the Act.
If the hosting arrangement changes, this section is updated before the change takes effect.
| Invoices, purchase records and Licence Certificates | Seven years after the end of the income year in which the transaction fell. This is not a choice: section 22 of the Tax Administration Act 1994 requires it. These records cannot be deleted on request before that period ends. |
| Account, billing details and favourites | For as long as you have an account. If you ask us to close it, we delete these within 30 days, apart from what the row above obliges us to keep. |
| Contact messages | Twelve months, then deleted automatically. |
| Unconfirmed registrations and password reset links | Until the link expires, then deleted. |
| Sign-in attempts and email send logs | Kept while they are useful for security and delivery diagnosis, and cleared periodically. |
| Page and forwarding statistics | Kept indefinitely in aggregated form. They contain no identifier and no full IP address. |
| Server logs | As set by our hosting provider, typically a small number of days. |
Whether you are in New Zealand, the European Union or the United Kingdom, you may ask us to:
Write to us through the contact page. We answer within 20 working days, which is the limit the Privacy Act 2020 sets; where the GDPR applies the limit is one month, and we work to whichever is shorter. There is no charge. If a request is unusually large or repetitive we will say so and explain what we can do.
The one thing we cannot do is delete an invoice, purchase record or Licence Certificate before the seven years in section 7 have run.
Please raise it with us first — most things are a misunderstanding and are quicker to fix directly. If that does not resolve it, you may complain to a regulator:
Passwords are stored only as hashes and cannot be read back, by us or by anyone who obtained the database. The whole site runs over an encrypted connection. Invoices and certificates are held outside the public web root and are served only after we have checked that the person asking is signed in and that the document belongs to them. Repeated failed sign-ins are slowed down. Administrative access is restricted and separately protected.
No system is perfect. If a breach occurs that is likely to cause you serious harm, we will notify you and the Office of the Privacy Commissioner as the Privacy Act 2020 requires, and where the GDPR applies, the relevant supervisory authority within 72 hours.
This is a shop for licensing photographs and is not directed at children. We do not knowingly collect information from anyone under 16. If you believe a child has given us personal information, tell us and we will delete it.
Where we link to another site, that site's own privacy policy applies to it. We have no control over what other operators do and take no responsibility for it.
We may update this policy. The date at the top always shows the current version. If a change materially affects how we handle your information, we will tell account holders by email before it takes effect, rather than relying on you to notice.