Privacy Statement Introduction

Hoed Research collects and processes personal information, or personal data, relating to its clients (which may include our client’s employees) and prospective clients to manage the working relationship. This personal information may be held by HOED RESEARCH on paper or in electronic format. HOED RESEARCH is committed to being transparent about how it handles personal information, to protecting the privacy and security of personal information and to meeting its data protection obligations.

The purpose of this privacy notice is to make it clear how and why we will collect and use personal information before, during and after the working relationship with HOED RESEARCH. If you have any questions about this privacy notice or about how we handle your personal information, please email sales@hoed.co.nz.

WHAT TYPES OF PERSONAL INFORMATION DO WE COLLECT ABOUT OUR CLIENTS AND THEIR EMPLOYEES?

Personal information is any information about an individual from which that person can be directly or indirectly identified. It doesn’t include anonymised data, i.e. where all identifying particulars have been removed. There are also “special categories” of personal information, and personal information on criminal convictions and offences, which requires a higher level of protection because it is of a more sensitive nature. The special categories of personal information comprise information about an individual’s racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, health, sex life or sexual orientation and genetic and biometric data. HOED RESEARCH collects, uses and processes a range of personal information about their clients. This includes: • Client contact details, including contact name, company address, telephone number and e-mail address • Contractual information • Mystery Shopping data • Client’s employees’ performance data where applicable to commissioned programme • Client’s employees’ name, location and contact details if applicable to commissioned programme.

HOW DO WE COLLECT PERSONAL INFORMATION?

Personal information is collected when clients or prospective clients give HOED RESEARCH the information to enable us to quote or run a mystery shopping programme. We will also collect additional information throughout the period of the contract through the mystery shopping programme itself. The personal information may be stored in different places, including in HOED RESEARCH’s contact management system, HOED RESEARCH Online (mystery shopping online portal) and in other IT systems, such as the e-mail system.

WHY AND HOW DO WE USE THE PERSONAL INFORMATION?

We will only use the personal information when the law allows us to. These are known as the legal bases for processing. We will use personal information in one or more of the following circumstances: • Where we need to do so to perform the contract for services we have entered into with clients. • Where we need to comply with a legal obligation. • Where it is necessary for our legitimate interests (or those of a third party), and the data subject’s interests or fundamental rights and freedoms do not override HOED RESEARCH’s interests. We may also occasionally use the personal information where we need to protect the data subject’s vital interests (or someone else’s vital interests). The purposes for which we are processing, or will process, personal information are to: • Enable us to maintain accurate and up-to-date records and contact details. • Administer the contract we have entered into with the client. • Administer the request for information received by the prospective client. • Provide useful information regarding services that may interest the prospective or existing client. • Ensure network and information security and prevent unauthorised access and modifications to systems. • Ensure effective business administration, including accounting and auditing. Please note that we may process personal information without your consent, in compliance with these rules, where this is required or permitted by law.

CHANGE OF PURPOSE

We will only use the personal information for the purposes for which we collected it. If we need to use the personal information for a purpose other than that for which it was collected, we will provide, prior to that further processing, information about the new purpose, we will explain the legal basis which allows us to process the personal information for the new purpose and we will provide relevant further information. We may also issue a new privacy notice.

WHO HAS ACCESS TO THE PERSONAL INFORMATION?

Client’s personal information may be shared internally within HOED RESEARCH. We may also share the information with third party service providers (and their designated agents), including: • The company that provide HOED RESEARCH with HOED RESEARCH Online, which is an external mystery shopping software provider. • Professional advisers, such as lawyers and accountants. HOED RESEARCH may also share personal information with other third parties in the context of a potential sale or restructuring of some or all its business. In those circumstances, personal information will be subject to confidentiality undertakings. We may also need to share personal information with a regulator or to otherwise comply with the law.

HOW DOES HOED RESEARCH PROTECT PERSONAL INFORMATION?

HOED RESEARCH has put in place measures to protect the security of our client’s personal information. It has internal policies, procedures, and controls in place to try and prevent personal information from being accidentally lost or destroyed, altered, disclosed, or used or accessed in an unauthorised way. In addition, we limit access to all personal information to those employees, workers, agents, contractors and other third parties who have a business need to know in order to perform their job duties and responsibilities. Where personal information is shared with third-party service providers, we require all third parties to take appropriate technical and organisational security measures to protect personal information and to treat it subject to a duty of confidentiality and in accordance with data protection law. We only allow them to process personal information for specified purposes and in accordance with our written instructions and we do not allow them to use personal information for their own purposes. HOED RESEARCH also has in place procedures to deal with a suspected data security breach, and we will notify the Information Commissioner’s Office (or any other applicable supervisory authority or regulator) and the data subject of a suspected breach where we are legally required to do so.

FOR HOW LONG DOES HOED RESEARCH KEEP PERSONAL INFORMATION?

HOED RESEARCH will only retain personal information for as long as is necessary to fulfil the purposes for which it was collected and processed, including for the purposes of satisfying any legal, tax, health, and safety, reporting or accounting requirements. HOED RESEARCH will generally hold the client’s personal information for the duration of the contract unless otherwise specified. We will hold tax information for seven years after the termination of the contract. Contractual information such as order confirmations will be kept indefinitely in case of future work.

DATA SUBJECT RIGHTS IN CONNECTION WITH PERSONAL INFORMATION

 It is important that the personal information we hold about our clients and their employees is accurate and up to date. Please keep us informed if any personal information changes. HOED RESEARCH cannot be held responsible for any errors in personal information in this regard unless we have been notified of the relevant change. The data subjects have a number of statutory rights. Subject to certain conditions, and in certain circumstances, they have the right to: • Request access to their personal information • Request rectification of their personal information • Request the erasure of their personal information • Restrict the processing of their personal information • Object to the processing of their personal information • Data portability If our prospective or existing clients, or their employees, wish to exercise any of these rights. We may need to request specific information to verify the identity and check the right to access the personal information or to exercise any of the other rights. This is a security measure to ensure that personal information is not disclosed to any person who has no right to receive it. If you believe that HOED RESEARCH has not complied with data protection rights, you have the right to make a complaint to the Information Commissioner’s Office.

CHANGES TO THIS PRIVACY NOTICE

HOED RESEARCH reserves the right to update or amend this privacy notice at any time, including where the Company intends to further process your personal information for a purpose other than that for which the personal information was collected or where we intend to process new types of personal information. We will issue you with a new privacy notice when we make significant updates or amendments. We may also notify you about the processing of your personal information in other ways.

CONTACT

If you have any questions about this privacy notice or how we handle your personal information, please contact sales@hoed.co.nz or by writing to PO Box 87-007, Meadowbank, Auckland 1742.