Effective date: 17 June 2026
Version: 1.4
This Privacy Policy sets out PowerStats Limited's ("we", "us" or "our"), and your, rights and obligations in relation to personal information you provide when using the service. Please read this Privacy Policy carefully before you use the website (www.powerstats.com) or the service.
Your privacy is important to us. We will handle all personal information you provide to us in accordance with this Privacy Policy and the governing laws and standards set out in Section 2.
This Privacy Policy may be varied by us at any time, effective when we post modified terms on the website, or as otherwise notified to you in writing (including by email). You should ensure that you have read, understood and agree to the most recent terms posted on the website, or as otherwise notified to you.
Our address is:
Level 4, BDO Centre, 4 Graham Street, Auckland Central, New Zealand.
If you need to contact us about this Privacy Policy you can do so by emailing support@powerstats.com or calling on +64-(0)9-320-5144.
1. Definitions
In this Privacy Policy:
(a) Service means the PowerStats platform, portals, and any related services we provide to you or your organisation.
(b) Website means www.powerstats.com.
(c) End User means any individual who accesses or uses the Service through an account.
(d) Personal Information means information about an identifiable individual, as defined in the Privacy Act 2020.
2. Governing law and standards
We comply with:
(a) the Privacy Act 2020 (New Zealand), as amended by the Privacy Amendment Act 2025 (New Zealand), which introduces Information Privacy Principle 3A (IPP 3A) — a requirement to notify individuals when their personal information is collected from a source other than the individual themselves;
(b) the Privacy Act 1988 (Australia), as amended by the Privacy Legislation Amendment (Enforcement and Other Measures) Act 2022, which applies to organisations carrying on business in Australia;
(c) the General Data Protection Regulation (EU) 2016/679, which applies where we process personal data of individuals located in the European Union;
(d) the requirements of ISO/IEC 27701:2019 (Privacy Information Management System), which extends our existing ISO/IEC 27001 information security certification to the management of personal information.
3. Lawful basis for processing
We process your personal information on the following lawful bases:
(a) Performance of our service: we process the personal information you provide at registration (name, email, phone number, organisation) because it is necessary to create and maintain your account, deliver the Service to you, and communicate with you about the Service.
(b) Compliance with legal obligations: we process certain personal information where required by New Zealand law, including the Privacy Act 2020, the Privacy Amendment Act 2025, and applicable tax and business records legislation.
(c) Legitimate interests: we may process personal information where we have a legitimate business interest that is not overridden by your rights — for example, to improve and secure the Service, to detect and prevent fraud, and to respond to support inquiries.
(d) Consent: where no other lawful basis applies, we will obtain your consent before processing your personal information and will inform you of your right to withdraw that consent at any time.
4. Collection
We may collect two types of information about you:
(a) Personal Information, provided by you at the time of registering for the Service, and also when you use the Website or the Service; and
(b) aggregate or anonymous information, which is generated by our Service but does not relate to you personally.
We will only collect Personal Information that is necessary to support our business activities. This may include:
(a) first and last names;
(b) email address;
(c) phone number (including mobile number, where provided for the purpose of receiving service notifications via SMS or other messaging platforms);
(d) your organisation's name;
(e) data collected using a cookie, web beacon, pixel tracker, web bug or similar tracking device;
(f) any other information relating to you that you provide to us through other methods (such as discussions with our customer service team) or that is publicly available.
If you fail to provide necessary personal information when requested, this may result in certain services or functionality not being available to you.
5. Indirect collection of personal information (IPP 3A)
From 1 May 2026, where we collect personal information about you from a source other than you — for example, where an administrator at your organisation creates a user account on your behalf — we are required to take reasonable steps to ensure you are made aware of certain matters. We meet this obligation as follows:
(a) The fact that your information has been collected: you will receive an invitation email notifying you that an account has been created for you.
(b) The purpose for which your information was collected: your account is created to provide you with access to the PowerStats platform and the market statistics service your organisation subscribes to. This is stated in the invitation email and described further in this Privacy Policy.
(c) The intended recipients of your information: the categories of recipients with whom your information may be shared are described in Section 7 of this Privacy Policy, which you are required to review and accept before activating your account.
(d) The identity of the person who provided your information, and the identity of PowerStats as the agency holding it: the invitation email identifies the person who created your account, including their name and email address. The email is sent by PowerStats Limited, and this Privacy Policy (which you must accept at account activation) provides our full contact details.
(e) Whether the collection is required by law: your personal information is collected for contractual and service-delivery purposes, not because it is required by statute.
(f) Your rights of access to and correction of your information: these rights are described in Section 12 of this Privacy Policy. You are required to review and accept this Privacy Policy when you set your password and activate your account.
How this works in practice:
- When another person creates a PowerStats account for you, you receive an invitation email identifying who created the account and inviting you to set your password.
- At the password-setting stage, you must review and agree to this Privacy Policy before your account is activated.
- Once activated, you receive a welcome email — which is also copied (CC) to the person who created your account, so that they are aware your account is now active.
- The welcome email includes a link to this Privacy Policy.
NB: IPP 3A does not apply to personal information collected before 1 May 2026.
6. Use
Any personal information you provide may be used for the following purposes:
(a) to send you emails and service notifications (including via SMS or messaging platforms) that you have subscribed to through your nominated email address or phone number;
(b) to obtain feedback or provide information on the Service;
(c) to contact you as part of creating and maintaining an account for our Service or verifying your identity as an End User;
(d) to monitor, develop and improve our Service and ensure that content of the Website is presented in the most effective way;
(e) to investigate any complaints relating to the misuse of the Website or Service;
(f) to comply with our legal obligations;
(g) to respond to any questions or comments you have sent to us; and
(h) any other purpose that you authorise.
7. Disclosure of information
We will only share your personal information with other organisations or individuals in the following limited circumstances:
(a) We engage other companies and individuals to perform services on our behalf (Third Party Providers). Examples include: providing hosting services, sending communications and analysing data. In particular, we store most of the personal information we collect and generate electronically on Microsoft Azure cloud servers. Third Party Providers may be based outside New Zealand, Australia or the EU. We will ensure that Third Party Providers agree to use personal information only as required to perform services on our behalf (and not for their own or other purposes), and to process the personal information in accordance with applicable privacy laws and contractual obligations. We can provide more specific information about data transfers to Third Party Providers on request.
(b) We may share your personal information with any member of our corporate group for any of the purposes set out in this Privacy Policy.
(c) Where we (or any of our group companies) sell a business, we may provide your personal information to the buyer, so that they can contact you about their plans for the business and/or to enable the buyer to continue to provide the Service/s to you. In that case, we may also retain your information within our group and use it in accordance with this Privacy Policy (or any other terms we agree with you).
(d) We may need to disclose personal information to satisfy any applicable law, regulation, legal process or government request.
8. Sub-processors
We engage certain third-party service providers ("sub-processors") to assist in delivering the Service. Sub-processors are contractually required to process personal information only in accordance with our instructions and applicable privacy laws.
We will not use your personal information for marketing, advertising, or any purpose outside the scope of the Service without your prior consent. Consent for marketing is never a condition of receiving the Service.
A list of our current sub-processors is available on request.
9. International transfers of personal information
Your personal information may be transferred to, and processed in, countries other than New Zealand. We use the following third-party service providers who may process personal information outside New Zealand:
(a) Microsoft Azure (cloud hosting) — our primary data store. Data is hosted in Australia;
(b) other service providers as required to deliver and support the Service.
Where personal information is disclosed to a recipient outside New Zealand, we take reasonable steps to ensure the recipient is subject to privacy laws that, overall, provide comparable safeguards to those in the New Zealand Privacy Act 2020, or is otherwise contractually required to protect the information to a comparable standard, as required by Information Privacy Principle 12 of the Privacy Act 2020.
For personal data subject to the General Data Protection Regulation, we rely on New Zealand's adequacy decision issued by the European Commission, or on Standard Contractual Clauses approved by the European Commission, as the lawful transfer mechanism. For personal information subject to the Australian Privacy Act 1988, we take such steps as are reasonable in the circumstances to ensure that overseas recipients do not breach the Australian Privacy Principles in relation to the information, as required by Australian Privacy Principle 8.
A current list of our third-party service providers and their hosting locations is available to anyone who has personal information held by us, on request by contacting support@powerstats.com.
10. Cookies, tracking and activity logs
This section describes how we use cookies, email tracking, and platform activity logs.
10.1 The PowerStats Website
We use analytical cookies, including Google Analytics, to understand how visitors use and move through our website. Our objective is to learn how to make the website more useful for our visitors. We do not use advertising cookies on the website, and we do not use cookies to track you across other websites.
The website may also set a small number of functional cookies required for site operation (for example, contact form submission and session handling).
10.2 The PowerStats Platform (our portals and services)
Within the PowerStats portals accessible via our platform, we use functional cookies to remember your preferences and settings — for example, your last location, dashboard layout, and display options. Our objective is to provide you with the best possible experience when using the Service. We do not use advertising cookies within the platform.
10.3 How to control the use of cookies
You can manage or disable cookies through your browser settings. Please note that disabling cookies may affect the functionality of the website or the service. For guidance, consult the help section of your browser.
10.4 Transactional communications tracking
Our platform sends transactional communications related to account creation, password resets, data upload reminders, and other notifications related to the delivery of our core service. These communications are delivered by email and, where you have provided a mobile number, may also be delivered by SMS or messaging platforms. We track the delivery, open events, and clicks of each transactional email — and delivery receipts for SMS/messaging notifications — to understand uptake, assess the effectiveness of our communications, and — importantly — to monitor for bounced emails and undeliverable messages, which helps us keep our system secure.
We do not currently send mass marketing emails or messages. If we begin doing so in the future, your email address or phone number will not be automatically added to any mailing list or messaging group for bulk delivery without you opting in first.
10.5 Platform activity logs
We collect detailed user activity logs within the platform, including login events, pages visited, actions performed, IP addresses, and timestamps. These logs are collected for audit, troubleshooting, and security purposes — including detecting unauthorised access, investigating incidents, and maintaining the integrity of the Service. Activity logs are not used for marketing or profiling.
10.6 Disclosure of usage information to account administrators
Where an organisation subscribes to the Service, the organisation's designated administrator may request information about their users' engagement with the platform. In such cases, we may provide high-level usage summaries — for example, how frequently a user has accessed the platform in a given period, or whether a user has not logged in at all. This information supports the organisation's ability to assess platform adoption and return on investment.
We will not disclose detailed user activity logs — such as specific pages visited, actions taken, or the content a user viewed — to an administrator or any other person within the user's organisation. Detailed activity logs remain confidential to the individual user and are used only for the audit, troubleshooting, and security purposes described in Section 10.5.
11. Data retention
We retain your personal information only for as long as necessary for the purposes for which it was collected, or as required by law.
Specifically:
(a) Active accounts: we retain your personal information for the duration of your or your organisation's subscription to the Service.
(b) Deactivated accounts: when your account is deactivated, your personal information is moved to an archived state within the Service. We retain archived user records for as long as necessary to support audit, legal, and contractual obligations, and review the continued need for retention periodically.
(c) Backups: personal information may exist in system backups. Backup data is retained in accordance with our backup schedule and is not actively used.
(d) Email delivery logs: transactional email delivery records (such as delivery confirmations and bounce reports) are retained in accordance with our backup schedule.
When personal information is no longer required for any lawful purpose, we will delete it where technically possible. If not possible to delete, we will archive it. If not possible to delete or archive in all systems and sub-systems, we will delete or archive it where possible.
12. Your rights
Under the Privacy Act 2020 and ISO/IEC 27701, you have the following rights in relation to your personal information held by us:
(a) Right of access: you may request confirmation of whether we hold personal information about you and, if so, request access to that information.
(b) Right of correction: you may request that we correct any personal information about you that is inaccurate, out of date, incomplete, or misleading. If we are not willing to make a correction you have requested, you may ask us to attach a statement of correction to the information.
(c) Right of deletion: you may request that we delete your personal information. We will do so where it is no longer necessary for the purposes for which it was collected, subject to any legal obligations requiring us to retain it, and subject to Section 11.
(d) Right to a copy of your data: you may request a copy of the personal information we hold about you, provided in a structured and commonly used format where reasonably practicable. Where technically feasible and where you request it, we will transmit your personal information directly to another controller nominated by you.
(e) Right to object: you may object to the processing of your personal information where you believe our processing is not necessary or proportionate. We will consider any such objection and respond within the timeframe set out below.
(f) Right to restriction of processing: where you contest the accuracy of your personal information, where processing is unlawful but you oppose erasure, where we no longer need the information but you require it for the establishment or exercise of legal claims, or where you have objected to processing pending verification of our legitimate grounds — you may request that we restrict processing of your personal information to storage only. We will inform you before any restriction is lifted.
(g) Right to withdraw consent: where processing is based on your consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
Where we have disclosed your personal information to third parties, we will take reasonable steps to inform them of any correction, erasure, or restriction you have requested.
To exercise any of these rights, contact us at support@powerstats.com or call +64-(0)9-320-5144. You may also update certain personal information and communication preferences directly through the Personal Settings page within the Service.
We will acknowledge your request within five (5) working days and will respond substantively within twenty (20) working days. If we need more time, we will let you know and explain the reason.
13. Data minimisation and privacy by default
We collect only the minimum personal information necessary for the purposes described in this policy. We take reasonable steps to ensure that the personal information we hold is accurate, complete, and not misleading, having regard to the purpose for which it is held. Where the Service collects optional information, such fields are disabled by default and are only enabled at your or your organisation's explicit choice.
14. Security
We take all reasonable steps to ensure the personal information collected is protected against loss or unauthorised access and disclosure. We maintain an information security management system certified to ISO/IEC 27001, and apply technical and organisational measures appropriate to the risk.
15. Notifiable privacy breaches
In the event of a privacy breach that we reasonably believe has caused, or is likely to cause, serious harm to you, we will:
(a) notify the New Zealand Privacy Commissioner as soon as practicable;
(b) notify you (or, if that is not reasonably practicable, give public notice) as soon as practicable, providing a description of the breach, the personal information involved, what we have done or intend to do in response, and how to contact us for further information;
(c) take all reasonable steps to contain the breach and reduce the risk of further harm;
(d) where the breach involves personal data of individuals in the European Union, notify the relevant EU supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach, as required by Article 33 of the General Data Protection Regulation;
(e) where the breach constitutes an eligible data breach under Part IIIC of the Australian Privacy Act 1988, notify the Office of the Australian Information Commissioner and affected individuals as required by that Act.
This section reflects our obligations under Part 6 of the Privacy Act 2020.
16. Automated decision-making
PowerStats does not currently use automated decision-making or profiling that produces legal or similarly significant effects for individuals. If this changes, we will update this policy and inform you of the nature of the automated processing, its significance, and your right to object.
17. Third-party websites
The Website may contain links to other websites that are not operated by us. We are not responsible for the privacy practices of those websites and recommend that you review their privacy policies before providing them with any personal information.
18. Communication preferences
You have the option to choose not to receive certain types of communications from us. Any non-essential emails we send will always contain a link enabling you to unsubscribe. SMS or messaging notifications can be managed via the Notification Preferences section of the Personal Settings page of your Service, or you can contact us by emailing support@powerstats.com or calling on +64-(0)9-320-5144.
If you elect not to receive communications or ask to be removed from a mailing list we may still send you essential communications, e.g. where it is necessary to provide you with details of your Service, or changes to the Service or the way the Website operates.
19. Complaints
If you believe we have breached your privacy, the Australian Privacy Principles, or have not complied with this policy, you may lodge a complaint with us by emailing support@powerstats.com or calling +64-(0)9-320-5144. We will acknowledge your complaint within five (5) working days and will investigate and respond within twenty (20) working days.
If you are not satisfied with our response:
- If you are located in New Zealand, you may refer your complaint to the New Zealand Privacy Commissioner at www.privacy.org.nz;
- If you are located in Australia, you may also complain to the Office of the Australian Information Commissioner at www.oaic.gov.au;
- If you are located in the European Union, you have the right to lodge a complaint with your local data protection supervisory authority.
20. European Union — applicability and representative
The General Data Protection Regulation (EU) 2016/679 applies to our processing of personal data of individuals located in the European Union. PowerStats Limited is not established in the European Union. We process personal data of individuals located in the EU on an occasional basis, and this processing does not include large-scale processing of special categories of data and is unlikely to result in a risk to the rights and freedoms of individuals. On this basis, we rely on the exemption in Article 27(2)(a) of the General Data Protection Regulation and have not appointed a representative in the EU. If you are located in the EU and wish to exercise your rights or raise a concern, you may contact us directly using the details in Section 21.
21. Artificial intelligence
Some PowerStats features are assisted by third-party artificial intelligence - for example voice-to-text, text-to-voice and validating uploaded data in real time. This clause explains how we use AI and what it means for you.
What AI does and its limits. Where AI assists a feature, its output is a tool to support your work. AI-assisted outputs can contain errors and should be reviewed before being relied on; they are not a separate source of truth and do not replace professional judgement. A warning generated by an AI assisted feature may be a false positive. A person at PowerStats remains accountable for AI-assisted outputs we present.
Your data and AI. Where we use AI to process information (for example, converting voice queries to text), we limit the data shared with the AI service to what the task needs, use providers under terms that prevent your data being used to train their models where that option is available, and apply the controls in our Data Masking Policy and Information Security Policy. We do not use participant data to train AI models. We do not make automated decisions about individuals that produce legal or similarly significant effects without human involvement.
Raising an AI concern. If you believe an AI-assisted output is wrong, or you have any concern about an AI feature, contact us at support@powerstats.com. We log and handle such reports through our incident management process and act on them.
22. Contact and privacy officer
The person responsible for privacy matters at PowerStats Limited is:
Dima Ivanov, Chief Executive Officer
PowerStats Limited
Level 4, BDO Centre, 4 Graham Street, Auckland Central, New Zealand
Email: dima.i@powerstats.com
Phone: +64-(0)9-320-5144
23. Previous versions
Change log:
v1.3: Major rewrite from version 1.2 to address additional conformances documented in section 2. Governing law and standards
v1.4: Addition of section 21. Artificial intelligence


