01Who We Are#
This Privacy Policy is issued by DRAW DREAM GROUP LIMITED (“NZDDG”, “we”, “us” or “our”), a technology company based in New Zealand. We are responsible for the personal information we collect and use as described in this policy.
You can contact us about privacy matters at info@nzddg.com.
02Scope#
This policy applies to personal information collected through or in connection with:
- our website at nzddg.com;
- UTRIP, our intelligent travel platform;
- IUB, our booking platform for service businesses;
- NZDDG Support, including support requests made through nzddg.com/support and related email communication; and
- NZDDG GP, our internal business management platform, including its web and iOS applications.
Some products may provide additional privacy information within the product itself. Where they do, that information applies together with this policy.
03Information We Collect#
Depending on how you interact with us, we may collect:
- Contact information — such as your name and email address.
- Request and communication content — such as the subject and content of support requests, emails and other messages you send us, and our replies.
- Account and profile information — for users of our products, such as name, work email, role and account settings.
- Authentication and security information — such as sign-in and verification events and multi-factor authentication settings.
- Device and technical information — such as IP address, browser or device type, and, for mobile apps, device identifiers needed to deliver notifications.
- Call information — for NZDDG GP voice features, such as phone numbers, call times, call duration and text transcripts (see Voice Communications and Transcripts).
- Product usage information — information needed to operate, secure and improve our products.
The nzddg.com website does not use advertising cookies or third-party advertising trackers.
04How We Use Information#
We use personal information to:
- respond to enquiries and support requests and communicate with you about them;
- provide, operate, maintain and secure our products and services;
- verify identity and email ownership, and prevent fraud, spam and abuse;
- manage business communications and keep accurate business records;
- improve our products and services; and
- comply with legal obligations and enforce our terms.
We do not sell personal information.
05Support Requests and Email Verification#
When you submit a request through nzddg.com/support, we collect:
- your full name;
- your email address, which must be verified;
- the product or service you select;
- the subject and message of your request; and
- technical and security information reasonably needed for verification, security and abuse prevention, such as your IP address.
To verify your email address we send a one-time 6-digit code to that address. The code expires after 10 minutes. We store only a protected (hashed) form of the code, never the code itself, and verification records are deleted automatically within 24 hours. IP addresses and email addresses used for rate limiting are stored only in hashed form and expire automatically.
Your request is recorded in our case management system and given a reference number. We send an acknowledgement to your verified email address, and you can reply to that email to add further information.
06Business Communications and Case Management#
We use an internal case management system to manage customer and business communications. Support requests, emails sent to or from our managed business mailboxes, and related notes and attachments may be recorded in a case together with a case reference number, so that our team can respond consistently and keep an accurate record.
Access to case records is limited to authorised personnel who need it for their role. Case records may include text transcripts of business calls handled through NZDDG GP.
07NZDDG GP#
NZDDG GP is an internal business management platform used by authorised NZDDG personnel to manage business operations, communications and case management. It is available on the web and as an iOS application. It is not offered to the general public.
In providing NZDDG GP we process:
- user account, role and access information;
- authentication and security information, including multi-factor authentication;
- device information and notification tokens used to deliver notifications to the app;
- business communications content and case records, including emails and text transcripts; and
- call information for voice features, such as phone numbers, call times and duration.
NZDDG GP may also process personal information about external parties, such as customers or business contacts, where it is contained in business communications handled through the platform.
The NZDDG GP iOS application may be distributed through an Apple Developer account held by SMART IOT LIMITED. This distribution arrangement does not change the operation of NZDDG services or the privacy practices described in this policy.
08Voice Communications and Transcripts#
NZDDG GP includes voice calling features for business communication. Voice communications may be processed in real time to provide calling functionality and to generate text transcripts.
NZDDG does not retain audio recordings of these calls as part of this service. Only the resulting text transcript and related call information are retained, as business communication records in our case management system, and are handled under the Business Communications and Case Management and Data Retention sections of this policy.
09Service Providers#
We use trusted service providers to help us operate our services. They process personal information on our behalf and only as needed to provide their services. These include providers of:
- cloud hosting, databases and file storage;
- business email;
- telephony and voice services;
- mobile push notifications; and
- AI-assisted processing, such as generating transcripts, summaries or draft text.
We may also disclose information where required by law or to protect our rights, users or the public.
10International Processing#
Some of our service providers store or process information outside New Zealand, including in Australia and the United States. When we use overseas providers, we take reasonable steps to ensure that personal information is protected in a way that, overall, provides comparable safeguards to those under the New Zealand Privacy Act 2020.
11Data Retention#
We keep personal information only for as long as it is needed for the purposes described in this policy. In particular:
- email verification records are deleted automatically within 24 hours;
- hashed rate-limiting data expires automatically within hours;
- support requests, case records, business communications and text transcripts are kept for as long as needed to respond, maintain accurate business records and meet legal, accounting or reporting obligations; and
- account information is kept while the account is active and for a reasonable period afterwards.
When information is no longer needed, we delete or de-identify it.
12Security#
We use reasonable technical and organisational safeguards to protect personal information. These include encrypted connections (HTTPS), access controls and role-based permissions, multi-factor authentication for internal users, hashing of verification codes and tokens, and rate limiting to prevent abuse. No method of transmission or storage is completely secure, but we work to protect your information and to respond promptly to any security issue.
13Your Rights#
Under the New Zealand Privacy Act 2020, you have the right to ask for access to the personal information we hold about you and to ask us to correct it. To make a request, contact us at info@nzddg.com. We may need to verify your identity before responding.
If you have a concern about how we have handled your personal information, please contact us first so we can try to resolve it. You can also contact the Office of the Privacy Commissioner at privacy.org.nz.
14Children#
Our website, support service and NZDDG GP are not directed to children under 16, and we do not knowingly collect personal information from children under 16 through them. If you believe a child has provided us with personal information, please contact us so we can delete it.
15Changes to This Policy#
We may update this policy from time to time. The current version will always be published at nzddg.com/privacy with its “last updated” date. If we make material changes, we will take reasonable steps to let affected users know.
16Contact Us#
If you have any questions about this policy or our privacy practices, please contact: