New Zealand privacy supplement
About this document
| Field | Value |
|---|---|
| Version | 1.0 |
| Effective date | 1 August 2026 |
| Publication date | 1 August 2026 |
| Last reviewed | 18 July 2026 |
| Status | Approved public document |
Version history
| Version | Effective date | Change summary | How this version applies |
|---|---|---|---|
1.0 | 1 August 2026 | Initial public version | Applies with the core Privacy Notice; no separate acceptance is required |
1. Scope and roles
This supplement applies when Alessia handles personal information connected with an individual account, website use, marketing, security, support or its own business administration in New Zealand. An individual professional normally controls personal information they choose for their professional User Content and Alessia handles it under the Individual Customer Terms. Where an Institution decides why and how portfolio information is handled, the Institution is responsible for it and Alessia handles it under the Institution's instructions and contract. Alessia remains responsible for processing it determines for its own purposes.
This contractual role allocation does not remove any direct responsibility that the New Zealand Privacy Act 2020 places on Alessia or another agency.
Contact Alessia's Privacy Officer at privacy@alessiahq.com.
2. Collection, purpose and minimisation
The core Privacy Notice describes the account, portfolio, professional, transaction, communication, device and usage information that may be handled. Entry fields are optional unless a feature says otherwise.
Alessia is not an electronic health record. Information that identifies or could reasonably identify a patient is prohibited, including indirect combinations. Alessia also prohibits intentional entry of the user's own health or other sensitive/special-category information because the standard Service does not need it.
Alessia collects and uses only information reasonably necessary for the disclosed portfolio, account, subscription, support, security and legal purposes. It does not sell personal information or use it for cross-context behavioural advertising.
3. Information collected from someone else
Alessia may receive professional information about supervisors, assessors, educators or colleagues from a user or Institution. Where New Zealand law requires, Alessia or the responsible Institution will take reasonable steps to tell that person about the collection, its purposes, intended recipients, relevant contact details, and their access and correction rights. Notification may not be required where an exception under the Privacy Act 2020 applies.
4. Overseas processing
Alessia uses overseas providers for hosting, identity, analytics, communications, subscriptions/payments and optional AI. The current entities, purposes, locations, retention and safeguards are maintained in the Subprocessor List.
Before relying on an overseas disclosure, Alessia will ensure a ground under Information Privacy Principle 12 applies - principally that the overseas recipient is subject to privacy safeguards that, overall, provide comparable protection to the New Zealand Privacy Act 2020, including through binding contractual safeguards - and will apply technical and organisational measures appropriate to the information and recipient. Selecting an Institution hosting region does not mean that every support function or service provider processes information in that region. The exact scope of any data-residency commitment is stated in the Institution's Order Document and provider schedule.
5. Access, correction and complaints
Subject to applicable exceptions, a person may ask Alessia to confirm whether it holds their personal information, obtain access and request correction. Alessia will respond as soon as reasonably practicable and generally within 20 working days, subject to any extension permitted by law. To request access or correction, email privacy@alessiahq.com with the subject “New Zealand Privacy Request”. To make a privacy complaint, use the subject “Data Protection Complaint”. The privacy complaints page explains the complaint process. Do not send patient information or unnecessary portfolio evidence by ordinary email. Alessia may verify identity proportionately and will explain any lawful refusal.
Where an individual professional or Institution controls the relevant User Content, Alessia will direct the request to or assist that controller. A person may also complain to the Office of the Privacy Commissioner of New Zealand.
6. Security, retention and breaches
Alessia uses access controls, encryption, logging, provider controls and incident processes designed for the risk. Retention follows the core Retention Schedule and any Institution Order Document.
Alessia will assess suspected privacy breaches promptly. Where a breach has caused, or is likely to cause, serious harm, Alessia or the responsible Institution will notify the New Zealand Privacy Commissioner and affected people as soon as practicable, subject to any exceptions or permitted delay under the Privacy Act 2020.
