Privacy and Data Policy
Last Updated 18th of June 2025
This Privacy Policy explains how Willot Group Limited TA. Websonic ("we," "us," or "our") collects, uses, protects, and shares personal information when you visit our website, use our services, or engage with us as a client. We are committed to protecting your privacy and complying with the New Zealand Privacy Act 2020 and, where applicable, the European Union General Data Protection Regulation (GDPR).
Company Information
Willot Group Limited TA. Websonic
Privacy Officer: Isaac Edward Wilson
Email: hello@websonic.co.nz
Phone: 0800 454 707
Address: 1373 Dairy Flat Highway, Dairy Flat 0794, Auckland New Zealand
New Zealand Company Number: 9429050783311
Information We Collect
Personal Information You Provide
When you interact with our website or services, we may collect:
- Name, email address, phone number, and postal address
- Company name and job title
- Website URLs and business information
- Payment and billing information
- Communications you send to us
- Project requirements and preferences
- Marketing preferences and consent records
Information Automatically Collected
We automatically collect certain information about your device and website usage:
- IP address and geographical location
- Browser type, operating system, and device information
- Pages visited, time spent on pages, and click patterns
- Referral sources and search terms used
- Date and time of visits
Cookies and Tracking Technologies
We use cookies, pixels, and similar technologies to:
- Remember your preferences and settings
- Analyze website performance and user behavior
- Provide personalized content and advertisements
- Measure the effectiveness of our marketing campaigns
For detailed information about our cookie usage, see our Cookie Policy section below.
Legal Basis for Processing (GDPR)
Where GDPR applies, we process personal information based on the following legal bases:
- Consent: When you explicitly agree to processing for specific purposes (marketing communications, cookies)
- Contract Performance: To fulfill our service agreements and client obligations
- Legitimate Interests: For business development, fraud prevention, and service improvement
- Legal Obligation: To comply with applicable laws and regulations
How We Use Your Information
Service Delivery
- Providing website design, SEO, and digital marketing services
- Managing client projects and communications
- Processing payments and maintaining accounts
- Delivering performance reports and analytics
- Providing technical support and maintenance
Business Operations
- Responding to inquiries and service requests
- Improving our services and website functionality
- Conducting market research and analysis
- Managing our relationship with you
- Protecting against fraud and security threats
Marketing Communications
With your consent, we may use your information to:
- Send newsletters and promotional emails
- Provide relevant content and service updates
- Conduct surveys and feedback requests
- Invite you to events and webinars
You can withdraw consent and unsubscribe at any time using the links in our communications.
Third-Party Service Providers
We work with trusted third-party services to deliver our services effectively. These providers may process your personal information on our behalf:
Analytics and Performance Monitoring
- Google Analytics: Website traffic analysis and user behavior insights
- Google Tag Manager: Managing tracking codes and conversion measurement
- Microsoft Clarity: User session recording and heatmap analysis
- SEMrush: SEO performance tracking and competitive analysis
Advertising and Marketing
- Google Ads: Search and display advertising campaigns
- Facebook/Meta Ads: Social media advertising and remarketing
- LinkedIn Ads: Professional network advertising
- Mailchimp/ConvertKit: Email marketing and automation
Website Infrastructure
- Webflow: Website hosting and content management
- Cloudflare: Content delivery network and security services
- AWS/Google Cloud: Data storage and processing infrastructure
Business Tools
- Stripe/PayPal: Payment processing
- Xero: Accounting and invoicing
- Calendly: Appointment scheduling
- Slack: Internal communications (client data may be discussed)
Client Service Tools
- Google Workspace: Email, document sharing, and collaboration
- Dropbox/Google Drive: File storage and sharing
- Zoom: Video conferencing and client meetings
Each third-party provider is contractually obligated to protect your information and use it only for specified purposes. We maintain Data Processing Agreements with all providers handling personal information.
Data Sharing and International Transfers
When We Share Information
We may share your personal information:
- With third-party service providers as described above
- With our professional advisors (lawyers, accountants, consultants)
- To comply with legal obligations or respond to lawful requests
- To protect our rights, property, or safety
- In connection with business transfers or mergers
International Data Transfers
Some of our service providers are located outside New Zealand. When transferring data internationally:
- To European Union: We rely on New Zealand's adequacy status under GDPR
- To United States: We use providers participating in recognized frameworks like EU-US Data Privacy Framework
- To Other Countries: We implement Standard Contractual Clauses or other approved safeguards
We ensure all international transfers include appropriate protections for your personal information.
Data Security
We implement comprehensive security measures to protect your information:
- Technical Safeguards: Encryption, secure servers, access controls, and regular security updates
- Administrative Safeguards: Staff training, data access policies, and regular security audits
- Physical Safeguards: Secure facilities and equipment protection
While we strive to protect your information, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security but will notify you of any material breaches as required by law.
Data Retention
We retain personal information only as long as necessary for the purposes described in this policy:
- Website Analytics Data: 26 months (Google Analytics default)
- Marketing Communications: Until you unsubscribe, then archived for legal compliance
- Client Project Data: 7 years after project completion for business and legal requirements
- Payment Information: 7 years for accounting and tax compliance
- Support Communications: 3 years after resolution
When data is no longer needed, we securely delete or anonymize it according to our data retention schedule.
Your Privacy Rights
Under New Zealand Privacy Act 2020
You have the right to:
- Access your personal information we hold
- Correct inaccurate or incomplete information
- Request deletion where no longer required
- Complain to the Privacy Commissioner if unsatisfied with our response
Additional Rights Under GDPR
If you're in the European Union, you also have:
- Right to rectification of inaccurate data
- Right to erasure ("right to be forgotten") in certain circumstances
- Right to restrict processing where you contest accuracy or object to processing
- Right to data portability to transfer data to another service
- Right to object to processing based on legitimate interests
- Rights regarding automated decision-making and profiling
How to Exercise Your Rights
To exercise any of these rights:
- Email: hello@websonic.co.nz with "Privacy Request" in the subject line
- Phone: 0800 454 707 during business hours
- Post: Write to our Privacy Officer at the address above
We will respond to all requests within 20 working days (New Zealand) or 30 days (GDPR). We may need to verify your identity before processing requests.
Making a Complaint
If you're unsatisfied with our response, you can complain to:
- New Zealand Privacy Commissioner: privacy.org.nz or 0800 803 909
- EU Data Protection Authority: If you're in the EU, contact your local supervisory authority
Cookie Policy
Types of Cookies We Use
Essential Cookies (Always Active)
- Website functionality and security
- User preferences and settings
- Session management
Analytics Storage (Your Choice)
- Google Analytics for traffic analysis and user behavior
- Microsoft Clarity for session recordings and heatmaps
- Performance monitoring and website optimization
Ad Storage (Your Choice)
- Google Ads conversion tracking and campaign measurement
- Advertising performance analytics
- Marketing campaign attribution
Ad User Data (Your Choice)
- Facebook Pixel for remarketing and audience building
- LinkedIn Ads measurement and targeting
- Cross-platform advertising optimization
Ad Personalisation (Your Choice)
- Personalized advertising based on your interests
- Tailored marketing content and recommendations
- Custom audience targeting
Personalisation Storage (Your Choice)
- Website personalization and content customization
- User preference storage
- Customized user experience features
Security Storage (Your Choice)
- Advanced fraud prevention and security monitoring
- Enhanced protection against malicious activity
- Security analytics and threat detection
Managing Cookie Preferences
You can control cookie settings through:
- Our cookie consent banner on first visit
- Our cookie consent modal, bottom left of every page
- Browser settings to block or delete cookies
- Opt-out links provided by advertising networks
Third-Party Cookies
We use cookies from third-party services for analytics and advertising. These companies have their own privacy policies:
- Google: policies.google.com/privacy
- Facebook/Meta: facebook.com/privacy
- Microsoft: privacy.microsoft.com
Children's Privacy
Our services are not intended for children under 13 years old. We do not knowingly collect personal information from children under 13. If we become aware that we have collected information from a child under 13, we will delete it promptly. Parents or guardians who believe we may have collected information from a child should contact us immediately.
Client Data Processing
Our Role as Data Processor
When providing services to clients, we may process personal information on their behalf. In these situations:
- The client remains the data controller
- We act as a data processor under their instructions
- We maintain separate Data Processing Agreements with clients
- Client data is kept confidential and separate from our marketing data
Client Website Access
When managing client websites, we:
- Access only the minimum data necessary for service delivery
- Use secure, authorized access methods
- Maintain logs of system access and changes
- Separate development and production environments
- Never use personal or production data for testing
Business Transfers
If Websonic is involved in a merger, acquisition, or sale of assets, your personal information may be transferred as part of that transaction. We will notify you via email and/or prominent notice on our website of any change in ownership or uses of your personal information.
Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices, services, or legal requirements. When we make material changes:
- We will notify you by email if you have an account with us
- We will post a prominent notice on our website
- The "Last Updated" date at the top will be revised
Continued use of our services after changes take effect constitutes acceptance of the updated policy.
Regional Specific Information
For New Zealand Users
This policy complies with the Privacy Act 2020. For questions about your privacy rights in New Zealand, visit privacy.org.nz or call 0800 803 909.
For European Union Users
This policy complies with GDPR requirements. Our legal basis for processing and your enhanced rights are outlined above. For EU-specific privacy questions, contact your local Data Protection Authority.
For Other International Users
We apply privacy principles consistent with international standards. Contact us for region-specific information about your privacy rights.
Contact Information
Privacy Officer: Isaac Edward Wilson
Email: hello@websonic.co.nz
Phone: 0800 454 707
Business Hours: Monday-Friday, 10:00 AM - 6:30 PM NZST
Postal Address: 1373 Dairy Flat Highway, Dairy Flat 0794, Auckland New Zealand
For general inquiries: hello@websonic.co.nz
For privacy-specific questions: Include "Privacy Request" in your subject line
For urgent privacy matters: Call during business hours
Acknowledgment
By using our website or services, you acknowledge that you have read, understood, and agree to this Privacy Policy. If you do not agree with our privacy practices, please do not use our services.
This Privacy Policy is designed to be comprehensive and compliant with current privacy laws. It will be reviewed regularly and updated as needed to reflect changes in our practices, services, or legal requirements.