Last updated: 1 August 2022
BrightSpark Recruitment Limited (“BrightSpark”) is committed to respecting the privacy and security of information received from User(s) of our website or services. This Privacy and Data Policy sets out our compliance with both New Zealand privacy laws (including the Privacy Act 2020) and the European Union General Data Protection Regulations (“GDPR”).
We’ve updated our Privacy and Data Policy to ensure that we communicate to Users, in the clearest way possible, how we comply with these legal requirements, how we collect, use, disclose or transfer Personal Information supplied by Users or collected by us and the ways in which Users can protect their privacy.
Our Privacy and Data Policy also specifies other requirements, such as how Users may access, correct and delete information held about them.
By using our services or accessing our website, Users agree to comply with the terms and conditions of this Privacy and Data Policy and agree that BrightSpark may process (i.e. collect, use, store, transfer, disclose or otherwise process) User’s Personal Information in accordance with this Privacy and Data Policy (as well as for any other use authorised by the User).
Our Privacy and Data Policy explains:
(2) What information we collect and how;
(3) How we use Personal Information;
(4) Who we share Personal Information with and why;
(5) The steps taken to protect Personal Information under our control;
(6) Users’ data protection rights;
(8) Links and connections to third party services;
(9) International data transfers;
(10) How BrightSpark retains and deletes Personal Information;
(11) How to access and update Personal Information; and
(12) How to contact us.
1. USER CONSENT
BrightSpark provides recruitment consultancy services for the information technology, digital and data sectors in New Zealand, which includes services supplied by third party providers (together, “our services”). We collect Personal Information in order to be able to provide and improve our services, and for the other uses described below.
By using our services, accessing our website or providing Personal Information to us, Users consent to our collection, storage, use and disclosure of Personal Information (including any sensitive information provided) in accordance with this Privacy and Data Policy.
2. INFORMATION WE COLLECT
There are three ways we collect information:
(1) Information Users give us.
(2) Information we collect when Users use our services.
(3) Information we collect from third parties.
(a) Information Users Give Us
In order to purchase or use our services, a User must provide us with certain contact and Personal Information including name, address, phone number, email address, educational history, employment history, criminal history, industry specific information and company information. Users may also at times provide billing and financial information.
Users may also provide us with information when they:
• Register with us;
• Create and verify User accounts and logins;
• Complete psychometric assessments or other assessments;
• Send correspondence to us, including job listings, applications or CV’s;
• Register for events promoted or hosted by us;
• Participate in surveys we organise;
• Interact with our social media pages;
• Subscribe to receive the latest news on our services, and the services of our third party service providers; or
• Contact our support team.
Users can always choose not to provide us with Personal Information, however this may mean that we are unable to supply our services effectively, or at all.
(b) Information We Collect from Use of Our Services
We may automatically collect information (which may include Personal Information) when Users interact with or use our services by visiting our website or communicating with us. This information may include:
• System information: We may collect information about User system(s) including, but not limited to, the User operating system, applications, IP address, and where applicable, host ID, and other User system environment information.
• Usage information: We collect information about how Users and their system environment interact with our services. Information that may be collected includes:
Information relating to the features Users use;
The performance of the services and any problems experienced by Users;
The pages that Users visit on our website;
The job advertisements that Users view on our website or third party websites;
Website content accessed by Users;
Length of the Users’ stay on a specific page; and
• Location: When Users use our services (including our website), we may collect and process information about the User’s location. We use various technologies to determine location, including IP addresses and web analytics.
• Device information: When Users use some of our services, we may receive information about the User’s device, such as the hardware model, operating system version, unique device identifier and mobile network information (including phone number).
For example, when Users visit our website, we collect information about the pages visited, the User’s browser and the User’s device. A cookie is a small element of data that a website can send to the User’s browser, which may then be stored on the hard drive (session ID cookies will terminate once Users simply close the browser, persistent cookies may however be stored on the User’s hard drive for an extended period of time). A persistent auto-login cookie is also stored when Users select the "remember me" option when logging in. The auto-login cookie is removed if Users log out on our website. A cookie does not identify a User personally, but it does identify the User’s computer or mobile phone. Cookies allow us, among other things, to monitor traffic patterns, store User preferences and settings to personalise the User experience, analyse how our services are performing, track Users, help us identify Users misusing our services and enable Users to login automatically. Users should be aware that most web browsers are set to accept cookies by default, but allow settings to be adjusted to remove or block cookies. Please note however that rejecting or removing cookies could affect the availability and functionality of our website features, or our services.
• Interest-based advertising (IBA): IBA allows us to deliver targeted advertising to Users of our services. IBA works by showing you advertisements that are based on the type of content you access or read. For example, as you browse our services, one of the cookies placed on your device will be an advertising cookie so we can better understand what sort of pages or content you are interested in. The information collected about Users’ devices enable us to group Users with other devices that have shown similar interests. We can then display advertising to categories of Users that is based on common interests.
• Analytics and advertising: Our website may use the following analytics and advertising services to assist our marketing and promotional activities:
Google Analytics: For the purpose of customising and continually optimising our website, we may use Google Analytics, a web analytics service provided by Google Inc. ("Google"), including Google Analytics Demographics and Interest reporting.
In this service, pseudonymised usage profiles are created and cookies are used to generate information about your use of this website such as browser type / version, operating system, referrer URL (the previously visited page), IP address for your computer or device, date, time and any demographic and interests information available in the cookie such as your age and gender, along with your interests expressed through your online behaviour. This information is transmitted to a Google server in the US and stored there. The information is used to evaluate the use of our website, to compile reports on website activity and to provide other services related to website activity and internet usage for the purposes of market research and our website design.
This information may also be transferred to third parties if required by law or if third parties process this data. Under no circumstances will your IP address be merged with any other data provided by Google. The IP addresses are anonymized. You can prevent the collection of data generated by the cookie and related to your use of the website (including your IP address) and the processing of this data by Google by downloading and installing a browser add-on (https: //tools.google.com/dlpage/gaoptout?hl=en). For more information about privacy related to Google Analytics, see the Google Analytics information at https://support.google.com/analytics/answer/6004245?hl=en).
• Social Media Plug-ins: Our website has built in social media plug-ins from the social networks Facebook, LinkedIn, Twitter, Instagram and WhatsApp to make our company better known, and personalise usage.
• Other Third Party Service Providers: We may use other third party service providers for the following reasons:
(a) To assist our communications and other interactions with Users;
(b) Website hosting;
(c) Data processing, storage and management;
(d) Data analysis and report automation;
(e) Payroll management;
(f) Client relationship management;
(g) Electronic sign-ins;
(h) Backgrounds checks;
(i) To create, manage and send emails and surveys to Users for advertising and marketing; and
(j) User account and password management, storage and security.
For example, we use:
Consent to Disclosure/Collection: By using our website or other services, or otherwise interacting with us, you:
• Acknowledge that, for information transmitted to Google (through use of Google Analytics, Google Ads, cookies or similar technology), the other analytics, advertising and social media plug-ins identified above, and the other third party service providers described above, those third parties may not be required to protect the information in a way that, overall, provides comparable safeguards to those in the Privacy Act 2020; and
• Authorise the disclosure of your information to those third parties, or collection of your information by those third parties.
(c) Information We Collect from Third Parties
We work closely with third parties (for example, our service providers) in order to be able to develop and supply our services, and provide them to Users.
We may receive the same kinds of information described in (a) and (b) above from third parties.
Personal Information Received from Users about Others
When using our services, Users may disclose, and we may collect, Personal Information about someone else. For example, data supplied by Users may contain Personal Information relating to the employers, or employees of Users.
Before disclosing Personal Information to us about someone else, Users must ensure that they have obtained sufficient consent to disclose that information to us, and that, without taking any further steps required by applicable data protection or privacy laws, we may collect, use, transfer and disclose such information for the purposes described in this Policy.
Users shall remain responsible for all Personal Information collected and processed by the User, and for compliance with applicable privacy and data protection laws.
3. HOW WE USE PERSONAL INFORMATION
We collect and use Personal Information in order to be able to provide and improve our services.
We also use Personal Information to:
• Communicate, interact and build our relationship with Users, including to better understand Users’ needs and interests, and ensure a quality experience for Users;
• Allow you to submit your CV, apply for specific jobs or subscribe to our job alerts, so that we can notify you when relevant job vacancies arise;
• Facilitate the recruitment process, including matching candidates’ details against job vacancies in order to assess candidates’ suitability for them;
• Conduct a reference check on Users;
• Undertake background checks, including verifying work permit status, criminal history, credit record, skills and qualifications, and employment and educational history;
• Monitor, develop or optimise the performance of our services, including to conduct internal research;
• Protect and enhance the safety and security of our services and Users;
• Provide information and technical support;
• Carry out billing administration;
• Market and make recommendations on our services;
• Allow our third party providers to provide their services and support to Users;
• Conduct, manage, develop and protect our business;
• Enforce our terms and conditions of service and other agreements;
• Comply with laws and regulations in applicable jurisdictions;
• Verify Users’ identities and prevent fraud or other unauthorised or illegal activity; and
• Enable third parties to provide services to us.
For these purposes we may receive, use, store, share, send, combine, transform, reformat, encrypt, mask, organise, geomap, update and delete Personal Information (and undertake any further processing activities expressed or implied in this Policy). The Personal Information that we collect will not be further processed in ways that are incompatible with the initial purposes for which the data was collected.
4. WHO WE SHARE INFORMATION WITH
We share information, including Personal Information, as necessary to provide Users the service requested or authorised. For example, we may share information with:
• Banks and other entities which process payment transactions when a payment is made;
• Affiliates, subsidiaries and related companies;
• Your referees;
• Potential employers of jobs you have applied for;
• Your past employers and relevant educational institutions;
• Your professional bodies;
• Our third party providers to provide services to the User, to communicate with Users (for example, information shared with communication service providers), to provide Users with information on the performance of our services or the services supplied by our third party providers or, to provide Users with remote access or to provide notifications;
• Our service providers or suppliers acting and working on our behalf. For example, companies we have hired to assist in pre-employment screening and background checking, may need access to Personal Information to provide those services. In such cases, we will require these entities to abide by our data privacy and security requirements, and restrict use of any Personal Information received from us;
• To other third parties, when we have a good faith belief that doing so is necessary to:
(1) Comply with any applicable law, regulation, legal process or enforceable governmental request;
(2) Protect our Users;
(3) Operate and maintain the security of our services, including to prevent or stop an attack on our computer systems or networks;
(4) Detect, prevent or otherwise address fraud; or
(5) Protect our rights and property, including enforcing our terms.
• A purchaser, as part of a corporate transaction such as an acquisition, merger or sale of assets.
From time to time we may use third-party data processors to provide elements of services for us, which may be located outside of New Zealand. We will have contracts in place with all of our data processors, to prevent them from doing anything with Users’ Personal Information unless we or the User has instructed them to do so.
Unless the User agrees otherwise, our data processors will:
• Not share Users’ Personal Information with any organisation apart from us; and
• Hold Users’ Personal Information securely and retain it for the period we instruct.
We require that our service providers and suppliers (data processors) agree to keep all User information we share with them confidential. While we provide these third parties with no more information than is necessary to perform the function for which we engaged them, Users should be aware that any information provided by the User to these third parties independently/directly is subject to the third parties' respective privacy policies and practices.
We may also share or use non-Personal Information (i.e. information that is related to a Person but does not personally identify that individual, such as aggregated, anonymised or de-identified data) publically or with third parties, such as our third party suppliers. For example, we may share or use information publically to show trends about the general use of our services. This data or information will in no way identify Users or any other individual.
5. STEPS TAKEN TO PROTECT PERSONAL INFORMATION
Protecting the security of User Personal Information is of the utmost importance to BrightSpark. We maintain a variety of safeguards and procedures in order to protect Personal Information from unauthorised access, use, interference, modification or disclosure.
For example, we store Personal Information on computer systems that have password-controlled access. We also use multi-factor authentication technology to prevent unauthorised access. Users’ Personal Information will only be accessed by people at BrightSpark who need to use the information for the purposes discussed above.
Some of our services do require use of the internet, and the internet is not itself a secure environment. We therefore cannot give an absolute assurance or guarantee that User information will be secure at all times. Transmission of information over the internet or third-party networks is at the User’s own risk. We will notify Users at the first reasonable opportunity if we discover or are advised of a material security breach which has resulted in unauthorised access, disclosure or loss of User Personal Information.
To help maintain the security of information, Users agree to keep their passwords and account details private and confidential.
6. USERS’ DATA PROTECTION RIGHTS
Under data protection and privacy laws, Users have rights regarding the Personal Information that we hold/collect. The rights available to Users depend on our reason for processing Users’ Personal information. These rights include:
• Right of access: Users have the right to ask us for copies of their Personal Information. This right always applies.
• Right to correction: Users have the right to ask us to update or correct information they think is inaccurate. Users also have the right to ask us to complete information that the User thinks is incomplete. Users are responsible for ensuring that Personal Information provided to us is accurate, complete and up-to-date. We will take reasonable steps to ensure that any further Personal Information that we collect (i.e. information obtained from other sources) is accurate, up-to-date, complete and not misleading.
• Right to erasure: Users have the right to ask us to erase their Personal Information in certain circumstances.
• Right to restriction of processing: Users have the right to ask us to restrict or cease the processing of their information in certain circumstances. This may (depending upon the circumstances) include the collection of Personal Information from third parties, collection of sensitive information, disclosure of Personal Information to third parties, transfer of Personal Information overseas, or processing of Personal Information in a particular way, or for a particular purpose, including direct marketing.
• Right to data portability: This only applies to information Users have given us. Users have the right to ask that we transfer the information Users have given us from one organisation to another, or give it to the User. This right only applies if we are processing information based on Users’ consent, or under (or in talks about entering into) a contract and the processing is automated.
All requests should be sent to us at firstname.lastname@example.org, and include the words 'Attention: The Privacy Officer'. User choices in relation to Personal Information may affect our ability to provide our services, or the performance of the services. We will respond to Users as soon as reasonably practicable regarding the impact of the User’s requests on the services, any other issues arising and to confirm the User’s intention to proceed. If we are unable to comply with the request, we will give the User reasons for this decision when we respond (for example, the information may not be readily retrievable and it may not be reasonable or practicable for us to process the request in the manner sought. In some instances, it may also be necessary for us to arrange access to User Personal Information through a third party e.g. a third party service provider).
We are committed to full compliance with the Unsolicited Electronic Messages Act 2007.
By subscribing to email communications, or otherwise providing an email address, Users consent to receiving emails which promote and market our services, or the services of others, from time to time.
Users can unsubscribe from our email communications at any time by clicking the "Unsubscribe" link in any promotional or marketing email, or by emailing email@example.com, and include the words 'Attention: The Privacy Officer’.
Once a User has unsubscribed from the email communications, the User will be removed from the corresponding email/distribution list as soon as is reasonably practicable.
8. LINKS AND CONNECTIONS TO THIRD PARTY SERVICES
Disclosure of Personal Information by Users to third party service providers is at the User’s own risk, and we encourage Users to read the privacy policies applicable to these third-party services. We are not responsible for the security or privacy of any information collected by these third-parties.
9. INTERNATIONAL DATA TRANSFERS
When we disclose, use or store data, it may be transferred to, and processed in, countries other than New Zealand. In those countries, there may be differences with New Zealand's privacy laws.
• Xero: For accounting functions, we use Xero. Xero is a cloud-based accounting service provided by Xero Limited and related companies. Xero processes and stores New Zealand User data in the United States. For more information on Xero’s data protection and privacy, see https://www.xero.com/nz/about/privacy/ and https://www.xero.com/nz/about/security/.
• Other third party providers: We also use the other third party service providers described in part 2(b) of this Policy.
This means that Users’ Personal Information may be transferred outside of New Zealand. However, where we disclose Personal Information to a third party in another country, we place or obtain safeguards to ensure Users’ Personal Information is protected (except as expressly disclosed in this Policy). Where Users’ Personal Information is transferred outside New Zealand, it will (except as expressly disclosed in this Policy) only be transferred to:
• Countries that have been identified as being subject to privacy laws that, overall, provide comparable safeguards to those under privacy laws in New Zealand); or
• A foreign Person or entity where we have transfer mechanisms in place to protect Users’ Personal Information; or
• A foreign Person or entity that we believe on reasonable grounds is subject to the Privacy Act 2020 (NZ), or is a participant in a prescribed Binding Scheme, or is subject to privacy laws of a Prescribed Country; or
• A recipient that has agreed to data protection and privacy commitments that, overall, provide comparable safeguards to those under privacy laws in New Zealand.
For further information, please contact us using the details set out in the contact section below.
10. RETENTION AND DELETION OF PERSONAL INFORMATION
The period of time for which we hold Personal Information that we have collected varies according to what the Personal Information is used or required for, and whether we have an ongoing need to retain it (for example, to provide Users with a service they have requested or to comply with applicable legal requirements such as financial record-keeping legislation).
Unless there is a legal requirement or justification for us to keep the Personal Information, we will retain it for no longer than is necessary:
• To provide the services requested by the User;
• As part of our usual business record-keeping practices;
• To fulfil the purpose(s) for which the Personal Information was originally collected;
• In accordance with our internal retention policies and practices; or
• For any other purpose(s) authorised by the User.
Once Personal Information is no longer required, the Personal Information will be deleted, securely destroyed or anonymised.
11. ACCESSING AND UPDATING USER PERSONAL INFORMATION
Users are responsible for ensuring that Personal Information provided to us is accurate, complete and up-to-date. This includes personal or sensitive information contained in their User content. We will also take reasonable steps to ensure that any Personal Information that we collect (i.e. information obtained from other sources) is accurate, up-to-date, complete and not misleading.
We endeavour to provide Users with reasonable access to Personal Information we hold about Users, and Users may request that we update, correct or delete any Personal Information that is inaccurate or inappropriate for the purposes for which it was collected.
Requests for access to, or the correction of, Personal Information should be emailed to firstname.lastname@example.org , and include the words 'Attention: The Privacy Officer’.
We will process requests as soon as reasonably practicable, provided we are not otherwise prevented from doing so by law. If we are unable to meet a User’s request, we will explain the reasons why when we respond to the User’s request. For example, the information may not be readily retrievable and it may not be reasonable or practicable for us to process the request in the manner requested.
12. HOW TO CONTACT US
Please contact us if you have any questions or complaints about this Privacy and Data Policy, if you wish to access, update, erase and/or correct Personal Information, or if you otherwise have a question or complaint about the manner in which we or our service providers treat Personal Information.
Users may write to BrightSpark’s Privacy Officer by email, including any supporting documentation, at email@example.com, and include the words 'Attention: The Privacy Officer’.
Alternatively, you can write to us at:
BrightSpark Recruitment Limited
Attention: Privacy Officer
Level 25, 151 Queen Street,
Auckland CBD 1010,
We will endeavour to respond within 30 days.
Application of this Privacy and Data Policy
Our Privacy and Data Policy applies to all of the services offered by us. Our Privacy and Data Policy does not cover the information practices of other companies and organisations (such as our third party service providers) that supply, contract and advertise using our website.
Changes to this Privacy and Data Policy
We recommend that Users regularly review this Policy to learn how we protect Personal Information.
In this Policy, unless the context requires otherwise:
Binding Scheme means a binding scheme specified in regulations made under section 213 of the Privacy Act 2020 (NZ);
Person means and includes any natural person, company, corporation, firm, partnership, joint venture, society, organisation or other group or association of Persons (whether incorporated or not), trust, state or agency of state, statutory or regulatory body, local authority, government or governmental or semi-governmental body or agency (in each case whether or not having separate legal personality);
Personal Information means information about an identifiable individual and includes, without limitation, names, addresses, phone numbers, email addresses and IP addresses;
Prescribed Country means a country specified in regulations made under section 214 of the Privacy Act 2020 (NZ);
User(s) means all Persons accessing our website and/or using our services (including any part of the services), including Persons that load and/or manage content on our website, or that submit a request for our services, and/or any Persons providing Personal Information to us;
User account means any User’s account with us; and
we, us, our, BrightSpark means BrightSpark Recruitment Limited, trading as “BrightSpark”.