Privacy Policy
This Privacy Policy explains how GridSync Limited (“GridSync”, “we”, “us”, “our”), a company registered in New Zealand (company number 9429053797568), collects, uses, discloses, and protects personal information when you use the GridSync platform, websites, and related services (the “Platform”). It forms part of, and should be read with, our Terms of Service.
We handle personal information in accordance with the Privacy Act 2020 and the Information Privacy Principles (“IPPs”). If there is any inconsistency between this Policy and the Privacy Act 2020, the Act prevails.
Who this Policy covers and our role
- The Platform standardises how applications to connect distributed generation (“DG”) are prepared, submitted, paid for, and routed to electricity lines companies in New Zealand. It serves Installers, Customers, and Lines Companies (as defined in our Terms of Service).
- GridSync is an “agency” under the Privacy Act 2020 and is responsible for the personal information it collects and holds in its own right. Where we process personal information solely on the instructions of, and on behalf of, an Installer or Lines Company, and not for our own purposes, that party remains responsible for that information under the Act, and we act as their agent for that processing only.
- We use personal information to operate the Platform as described in this Policy. Separately, we may create and use aggregated and de-identified data (information that does not identify, and cannot reasonably be used to identify, any individual or any individual property) for our own purposes. This includes producing market and trend insights (for example, aggregate statistics on the types of equipment being installed and how installation volumes change over time and by region) which we may report on, share, or license to third parties, and developing and improving our products and analytical models. We only do this with data aggregated or de-identified so that no individual or property is reasonably identifiable. We do not sell personal information.
Personal information we collect
We collect personal information that is reasonably necessary to operate the Platform and provide our services. Depending on how you use the Platform, this may include the following.
- Information needed to identify and set up your account and your business, and to verify your identity and your authority to use the Platform.
- Information needed to prepare, submit, and progress a DG connection Application, including details about the installation site and the equipment involved.
- Information needed to process payments for Applications and Platform fees. Card payments are processed entirely by our third-party payment provider through a provider-hosted checkout; GridSync does not receive, handle, or store your full card details.
- Information needed to make reasonable contact with you, respond to your enquiries, and provide support.
- Technical information about how you access and use the Platform, including via cookies and similar technologies (see clause 10).
- Any other reasonable information required for the smooth operation of GridSync. We do not seek to collect sensitive information (such as health or criminal history) unless it is directly required for a specific purpose, which will be made abundantly clear at the time of collection.
How we collect personal information
- We collect personal information directly from you when you create an account, prepare or submit an Application, make a payment, or contact us.
- We also collect personal information about Customers from Installers who submit Applications on their behalf. Before an Installer can enter any Customer information, the Platform requires the Installer to give a single confirmation, at the start of the Application process, that both: (a) the Customer has been informed that their information will be provided to GridSync and shared with the relevant Lines Company to progress the Application; and (b) the Installer has the Customer’s authority to provide it. The Installer cannot proceed until this confirmation is given.
- Where we collect a Customer’s personal information indirectly (for example from an Installer rather than from the Customer), we rely on an exception in IPP 2(2) that permits collection from another source, including that the individual has authorised it, or that collection directly from the individual is not reasonably practicable. In these cases, the Installer must confirm at the start of the Application process, before entering any Customer information, that it has informed the Customer of the matters required under IPP 3 (including that GridSync holds their information, why, and that it will be shared with the relevant Lines Company) and has the Customer’s authority to provide it. The Platform does not allow the Installer to proceed until this confirmation is given.
How we collect and use data: personal information and aggregated, de-identified data
We collect and use personal information for the following purposes.
- Create and administer your account and verify your identity and authority.
- Prepare, standardise, route, and process DG connection Applications to the relevant Lines Company.
- Process and facilitate payments for Applications and Platform fees through our third-party payment provider.
- Provide support, respond to enquiries, and send service-related communications.
- Maintain the security, integrity, and proper operation of the Platform.
- Comply with our legal, regulatory, accounting, and audit obligations, including record-keeping expected under the Electricity Industry Participation Code.
- Improve and develop the Platform and our services.
- Send you marketing about GridSync where you have not opted out. We offer the choice to opt out of marketing when you sign up and during onboarding, and you can opt out at any time afterwards. Any electronic marketing we send will comply with the Unsolicited Electronic Messages Act 2007 and will include a functional unsubscribe facility.
- Aggregated and de-identified data. Separately from the personal-information uses above, we may create aggregated and de-identified data (information that does not identify, and cannot reasonably be used to identify, any individual or any individual property). This is not personal information, and we use it without restriction, including but not limited to: develop, train, and improve analytical and machine-learning models and other GridSync products and services; and produce market and trend insights (for example, aggregate statistics on the types of equipment being installed and how installation volumes change over time and by region) which we may report on, share, sell, or license to third parties such as equipment manufacturers and suppliers, wholesalers and other stockists, industry bodies, and government and regulatory agencies. We only do this with data aggregated or de-identified so that no individual or property is reasonably identifiable.
When we disclose personal information
We disclose personal information only as needed to operate the Platform and as permitted by the Privacy Act 2020:
- To Lines Companies: Application data, which may include a Customer’s personal information, is disclosed to the relevant Lines Company so it can assess and process the connection. By submitting an Application you authorise this disclosure.
- To service providers: such as our payment provider and hosting and infrastructure providers, who handle personal information on our behalf under confidentiality and security obligations.
- Where required or permitted by law: for example to a regulator, or to comply with a lawful request.
- For reporting and analytics: we use Application and Platform data to produce reporting, analytics, and market insights. Where these are shared outside GridSync, they are in aggregated and de-identified form only (see clause 4.9) and do not identify any individual or property. We do not disclose your personal information for this purpose.
- To Viewers (regulators and industry bodies): we may grant a regulator, government body, or government-adjacent or industry organisation (such as the Electricity Authority or SEANZ) read-only access to specified data for monitoring, reporting, or oversight purposes, as described in our Terms of Service. Where the data made available to a Viewer includes personal information, we disclose it only as needed for that purpose and as permitted by the Privacy Act 2020.
- On a business transfer: if GridSync is involved in a merger, acquisition, or sale of assets, personal information may be disclosed to a prospective or actual purchaser. Any disclosure for due diligence will be limited to what is reasonably necessary and made under confidentiality, and any successor will be required to handle personal information in accordance with this Policy or a materially equivalent policy. Where required under a separate agreement with a Lines Company, we will give that Lines Company notice of a change of control.
- We do not sell personal information. While we may sell or license aggregated and de-identified data as described in clause 4.9, that data is not personal information and does not identify any individual or property.
Storage, security, and retention
- We maintain reasonable technical and organisational security measures appropriate to the nature of the information held, designed to protect personal information against loss and unauthorised access, use, modification, or disclosure (IPP 5).
- We retain personal information only for as long as needed for the purposes described in this Policy, or as required by law, after which we delete or de-identify it. Application and payment records may be retained to meet our legal, regulatory, accounting, and audit obligations, including record-keeping expected under the Electricity Industry Participation Code.
- Where personal information is no longer required for any lawful purpose, we will take reasonable steps to dispose of it securely (IPP 9).
- While your account is active, you can access and export your information and your Application records through the tools available in the Platform. For a period after your account ends, we will, on request, make your information available for export before we delete it, except where we are required to retain it under this clause 6. This reflects the data export arrangements in our Terms of Service.
- Aggregated and de-identified data (which does not identify, and cannot reasonably be used to identify, any individual or property) is not personal information, and we may retain and use it without time limit, as described in clause 4.9.
Overseas storage and disclosure
- Our databases and websites are hosted in Australia (Sydney), which means your personal information is stored on servers located in Australia. Some of our other service providers may also store or process personal information outside New Zealand.
- Where we store or disclose personal information in Australia or any other country, we take reasonable steps to ensure it is protected by safeguards comparable to those under the Privacy Act 2020, as required by IPP 12. In practice, we rely on this being met because our overseas service providers are required, under binding contractual obligations, to protect personal information to a comparable standard, and because Australia (where our hosting is located) is generally treated as having privacy protections comparable to New Zealand’s.
Accessing and correcting your information
- You have the right to ask for access to the personal information we hold about you, and to request correction of it (IPPs 6 and 7).
- To make a request, contact us using the details in clause 13. We may need to verify your identity. For access requests, we will respond as soon as reasonably practicable and in any event no later than 20 working days after we receive the request, as required by the Privacy Act 2020. We will action correction requests within a reasonable time. We do not charge for access to information that can be readily provided. However, where a request is repetitive, or relates to such a large volume of information that responding would require a disproportionate amount of staff time and divert it from our normal operations, we reserve the right to discuss a reasonable charge with you in advance, as permitted under the Privacy Act 2020.
- If we decline a request, we will tell you why and how you can seek a review by the Office of the Privacy Commissioner. If we decline to correct information, you may ask us to attach a statement of the correction you sought, and we will take reasonable steps to do so (IPP 7).
Privacy breaches
- If a notifiable privacy breach occurs, one that we assess is likely to cause, or has caused, serious harm, we will notify the Office of the Privacy Commissioner as soon as practicable after becoming aware of it, and will notify affected individuals (or issue a public notice) as required under Part 6 of the Privacy Act 2020, subject to the exceptions that Part allows.
- Where the breach affects Application data we handle on behalf of an Installer or Lines Company, we will also notify that party without undue delay and in any event within 72 hours of becoming aware, consistent with our Terms of Service.
Cookies and analytics
- We use cookies and similar technologies that are necessary to operate the Platform, keep you logged in, and remember your preferences. We do not use analytics or advertising cookies within the Platform. Our public website displays a cookie notice; if we introduce any analytics or advertising cookies in the future, we will update this Policy and, where required, ask for your consent before they are used. See our Cookie Policy for more detail.
- You can control cookies through your browser settings. Disabling some cookies may affect how the Platform works.
Children
- The Platform is intended for users aged 18 or over, whether business users (Installers and Lines Companies) or property owners connecting generation at their own property. We do not knowingly collect personal information from children. If you believe a child’s information has been provided to us, contact us using the details in clause 13 and we will take appropriate steps.
Changes to this Policy
- We may update this Policy from time to time. We will post the updated Policy with a new effective date and, for material changes, take reasonable steps to notify you (for example by email or in-Platform notice).
How to contact us or make a complaint
- If you have questions about this Policy, want to exercise your privacy rights, or wish to make a complaint about how we handle personal information, contact our privacy contact:
GridSync Limited · Privacy Officer · privacy@gridsync.nz · 70 Sullivan Avenue, Woolston, Christchurch 8023, New Zealand. - If you are not satisfied with our response, you may complain to the Office of the Privacy Commissioner at privacy.org.nz.
Definitions
- Capitalised terms not defined in this Policy (including “Application”, “Installer”, “Customer”, “Lines Company”, and “Lines Company Fee”) have the meaning given in our Terms of Service. “Personal information” and “agency” have the meanings given in the Privacy Act 2020.