Privacy Policy
Introduction
MirrorWave Limited (we, us, our) complies with the New Zealand Privacy Act 2020 (the NZ Privacy Act) and other applicable privacy and data protection laws when dealing with personal information. Personal information is information about an identifiable individual (a natural person).
This policy sets out how we will collect, use, disclose and protect your personal information.
If you are based in the European Union and use our website and/or services, the additional terms in the addendum to this policy (GDPR Addendum) apply to you.
This policy does not limit or exclude any of your rights under the NZ Privacy Act and other applicable laws. If you wish to seek further information on the NZ Privacy Act, see www.privacy.org.nz.
Changes to this policy
We may change this policy by uploading a revised policy onto the website. The change will apply from the date that we upload the revised policy.
This policy was last updated on 24 August 2026.
What personal information do we collect
We collect, hold and process two categories of personal information. MirrorWave does not ordinarily request sensitive personal information unless it is reasonably necessary for an agreed client programme. Because participants may provide free-text feedback, a participant may voluntarily include information of a sensitive nature in a response. Where this occurs, MirrorWave will handle that information in accordance with this Privacy Policy, its contractual obligations and applicable privacy law.
- Account and Marketing Data is personal information that we collect about you:
- in connection with the creation or administration of a customer account
- if you ask to receive information about us or our services or sign up to access certain resources
- when you contact us directly (e.g. telephone call, website enquiry form, email or through your user dashboard) or visit our website.
The Account and Marketing Data we collect may include company/personal names, usernames, phone numbers, email addresses, your location, billing information, information about how you use our website or services (for example, traffic volumes, time spent on pages), your IP address and/or other device identifying data, and other information required to provide a service or information you have requested from us.
- Personal information that forms part of the Client Data (as defined in our Terms and Conditions). This may include the names and email addresses of Program Participants (as defined in our Terms and Conditions) and response data collected from Program Participants.
We will not collect or process Client Data except as provided in our Terms and Conditions and/or other agreements with our clients that govern the processing of Client Data (as applicable) and we require our clients to comply with applicable privacy and data protection laws.
Program Participants and Client Data:
MirrorWave provides relationship feedback and relationship strengthening services to organisations.
If you are invited to participate in a MirrorWave programme, the relevant MirrorWave client may provide MirrorWave with information about you so that we can administer the programme on its behalf. This may include your name, organisation or employer, job title or role, business email address and telephone number, your relationship with the relevant client, and other information agreed with the client as necessary for the programme.
MirrorWave may then collect additional personal information from you when you participate in a Wave, provide feedback or otherwise interact with the programme.
The relevant client determines the purposes for which your personal information is collected and used. MirrorWave holds and processes that information on the client's behalf in order to provide the MirrorWave services.
The client or MirrorWave, on the client's behalf, will take reasonable steps to ensure that you are informed about the collection and use of your personal information as required by applicable privacy law. The relevant client will normally be identified in the invitation or other communication you receive about the programme.
You have rights to request access to and correction of your personal information, as explained below.
This Privacy Policy also explains how MirrorWave handles personal information contained in Client Data when providing services to our clients. Where MirrorWave holds or processes Client Data on behalf of a client, the client determines the purposes for which that information is collected and used and MirrorWave acts as its service provider. The client may also have its own privacy policy that applies to that information.
Who do we collect your personal information from?
We may collect personal information:
- directly from you;
- where you are a Program Participant, from the MirrorWave client that nominates or invites you to participate in a programme;
- from another person or organisation you have authorised to provide information to us;
- from publicly available sources where collection is lawful; and
- from our service providers where necessary and lawful in connection with our services.
Where MirrorWave receives personal information from a client in order to provide services on that client's behalf, MirrorWave processes that information as the client's service provider.
Where applicable, the client is responsible for ensuring that individuals receive the information required under the Privacy Act 2020 in relation to indirect collection, including Information Privacy Principle 3A.
How we use your personal information
We use your personal information:
- to verify your identity
- to provide the website and our services to you
- to market our services and products to you, including contacting you electronically (e.g. by text or email for this purpose) that you may choose (or opt in) to receive. You can stop receiving our promotional emails or service related communications by following the unsubscribe instructions included in those communications
- to tailor content or advertisements to you
- to improve the website and services that we provide to you
- to respond to communications from you.
We may also combine information we collect (aggregate) or remove personally identifiable (anonymise) information to conduct research and statistical analysis. This privacy policy does not apply to our use of such aggregated or anonymous information.
We may also use your personal information:
- to protect and/or enforce our legal rights and interests, including defending any claim
- for any other purpose authorised by you, the Act or other applicable law
- to respond to lawful requests by public authorities, including to meet law enforcement requirements
- to transfer your information in the case of a sale, merger, consolidation, liquidation, reorganisation or acquisition.
Where personal information relates to a Program Participant, MirrorWave may process it on behalf of the relevant client to:
- administer and deliver the relevant MirrorWave programme;
- contact the Program Participant in connection with Waves, reminders, feedback or agreed follow-up activities;
- record and analyse responses and changes in relationship feedback over time;
- provide reports, analysis and access to the MirrorWave Control Panel to authorised users of the relevant client;
- provide technical support, security, maintenance and administration; and
- comply with legal and regulatory obligations.
MirrorWave may also create aggregated or de-identified information that does not identify Program Participants or clients. MirrorWave may use this aggregated or de-identified information to improve its Software and Methodology, undertake benchmarking, research and analysis, and for other legitimate business purposes.
MirrorWave does not use identifiable Client Data for unrelated marketing or other unrelated business purposes.
Who we share your personal information with
We may disclose personal information where reasonably necessary to:
- the relevant MirrorWave client and its authorised users in connection with the programme;
- our employees, contractors and service providers who require access in order to provide, support, maintain or secure our services;
- our professional advisers;
- a prospective purchaser or successor in connection with a proposed sale, merger, restructuring or transfer of MirrorWave's business, subject to appropriate confidentiality and privacy obligations;
- a regulator, law enforcement agency, court or other person where disclosure is required or permitted by law; or
- another person where you have authorised the disclosure.
Our contractors and service providers that handle personal information are required to be subject to appropriate confidentiality, privacy and information security obligations.
MirrorWave may disclose aggregated or de-identified information that does not identify individuals or clients.
A business that supports our services and products may be located outside the European Economic Area (EEA) or New Zealand. This may mean your personal information is held and processed outside the EEA or New Zealand. Please see the GDPR Addendum for further information about personal information transfers from the EEA.
We share information about your use of the website with our trusted social media, advertising and analytics partners through the use of cookies, web beacons and similar storage technologies. Please refer to the Cookies section of the GDPR Addendum for further information.
Where personal information is stored and processed
MirrorWave hosts Client Data using Microsoft Azure infrastructure located in Australia Southeast (Victoria). Microsoft Azure's paired Australia East region is used for backup and disaster recovery purposes.
MirrorWave may also use service providers located in New Zealand, Australia or other countries in connection with its services.
Where a service provider stores or processes personal information on our behalf, we require appropriate privacy, confidentiality and information security protections. Where personal information is disclosed overseas rather than simply stored or processed on behalf of MirrorWave or its client, we will comply with the applicable requirements of the Privacy Act 2020.
How long we retain personal information
MirrorWave retains personal information only for as long as reasonably necessary for the purposes for which it was collected or held, or as required by law.
Client Data is generally retained while the relevant client's agreement with MirrorWave remains in force. If the client requires a copy of its Client Data following termination, it should request that copy before or at the time the agreement terminates.
Following termination, and after providing any copy requested by the client, MirrorWave will delete the relevant Client Data from its active systems.
Deleted Client Data may remain within system backups for up to 30 days following deletion from active systems. During this period the data will remain protected and will not be used except where required for authorised data recovery. At the end of the 30-day backup retention period, the data will be permanently deleted or overwritten.
MirrorWave may retain information that has been aggregated or de-identified so that it no longer identifies individuals or clients.
Protecting your personal information
We will take reasonable steps to keep your personal information safe from loss, unauthorised activity, or other misuse. We implement appropriate technical and organisational measures which may include encryption, access controls and other security practices to ensure a level of security appropriate to risks inherent in processing personal information.
You can play an important role in keeping your personal information secure by maintaining the confidentiality of any password used in relation to our products and services. Please do not disclose your password to third parties. Please notify us immediately if there is any unauthorised use of your account or any other breach of security.
Accessing and correcting your personal information
You have the right to request access to personal information held about you and to request correction of that information.
If the information forms part of Client Data that MirrorWave holds or processes on behalf of one of our clients, we may refer your request to, or consult with, the relevant client before responding.
To request access to or correction of your personal information, please contact our Privacy Officer at support@mirrorwave.com. We will respond to requests in accordance with applicable privacy law.
Internet use
While we take reasonable steps to maintain secure internet connections, if you provide us with personal information over the internet, the provision of that information is at your own risk.
If you follow a link on our website to another site, the owner of that site will have its own privacy policy relating to your personal information. We suggest you review that site’s privacy policy before you provide personal information.
Contact us
If you have any questions about this privacy policy, our privacy practices, or if you would like to request access to, or correction of, your personal information, you can contact us here: support@mirrorwave.com.
Privacy Officer and complaints
If you have a question, concern or complaint about how MirrorWave handles personal information, please contact:
Privacy Officer
MirrorWave Limited
PO Box 300-361
Albany 0752
New Zealand
support@mirrorwave.com
We will investigate privacy concerns and respond as soon as reasonably practicable.
If you are not satisfied with our response, you may also make a complaint to the Office of the Privacy Commissioner in New Zealand or another applicable privacy regulator.
--------------------------------------------------
MirrorWave privacy policy - GDPR addendum
If you are based in the European Union (EU) and use our website and/or our services, these additional terms (GDPR Addendum) form part of our privacy policy.
Capitalised terms used in this GDPR Addendum have the same meaning given to them in our privacy policy.
The General Data Protection Regulation (GDPR) regulates the collection, processing and transfer of EU individuals’ personal data (as defined in the GDPR). The personal information described in our privacy policy is personal data under the GDPR. We are committed to complying with the GDPR when dealing with Account and Marketing Data about our website visitors and service users based in the EU.
This GDPR Addendum was drafted with brevity and clarity in mind. It does not provide exhaustive detail of all aspects of our collection and use of personal data. However, we are happy to provide any additional information or explanation needed. Any requests for further information should be sent to support@mirrorwave.com.
For the purposes of the GDPR:
- we are the data controller (as defined in the GDPR) when processing Account and Marketing Data; and
- our clients are the data controller when processing Client Data.
We will not process Client Data except as provided in our Terms and Conditions and/or other agreements with our clients that govern the processing of Client Data (as applicable) and we require our clients to comply with applicable privacy and data protection laws. If we receive any data subject requests relating to Client Data, such as requests to access personal data, we will forward this request to the relevant client.
The remainder of this GDPR Addendum applies to Account and Marketing Data only, and does not apply to Client Data.
Processing personal data
The Account and Marketing Data we may process is described in our privacy policy. This Account and Marketing Data may be processed for the purposes outlined in our privacy policy.
The legal basis for our processing of Account and Marketing Data is your consent and, for certain Account and Marketing Data, processing is necessary for the performance of a contract to which you are a party.
Despite the above, we may process any of your personal data where such processing is necessary for compliance with applicable laws.
You do not have to provide us with your name or contact information to access and use certain parts of the website. However, you must provide us with your name and contact information to access some of our other services such as downloading resources. The consequence of not providing your name and contact information is that we will not be able to provide all of our services to you.
Your rights
Your rights in relation to your personal data under the GDPR include:
- right of access - if you ask us, we will confirm whether we are processing your personal data and provide you with a copy of that personal data.
- right to rectification - if the personal data we hold about you is inaccurate or incomplete, you have the right to have it rectified or completed. We will take every reasonable step to ensure personal data which is inaccurate is rectified. If we have shared your personal data with any third parties, we will tell them about the rectification where possible.
- right to erasure - we delete your personal data when it is no longer needed for the purposes for which you provided it. You may request that we delete your personal data and we will do so if deletion does not contravene any applicable laws. If we have shared your personal data with any third parties, we will take reasonable steps to inform those third parties to delete such personal data.
- right to withdraw consent - if the basis of our processing of your personal data is consent, you can withdraw that consent at any time.
- right to restrict processing - you may request that we restrict or block the processing of your personal data in certain circumstances. If we have shared your personal data with third parties, we will tell them about this request where possible.
- right to object to processing - you may request that we stop processing your personal data at any time and we will do so to the extent required by the GDPR.
- right to data portability - you may obtain your personal data from us that you have consented to give us or that is necessary to perform a contract with you. We will provide this personal data in a commonly used, machine-readable and interoperable format to enable data portability to another data controller. Where technically feasible, and at your request, we will transmit your personal data directly to another data controller.
- the right to complain to a supervisory authority - you can report any concerns you have about our privacy practices to the relevant data protection supervisory authority.
Where personal data is processed for the purposes of direct marketing, you have the right to object to such processing, including profiling related to direct marketing.
If you would like to exercise any of your above rights, please contact us at support@mirrorwave.com. If you are not satisfied by the way your query is dealt with by our data protection officer, you may refer your query to your local data protection supervisory authority e.g. in the United Kingdom, this is the Information Commissioner’s Office.
We do not intend to collect personal data from children aged under 16. If you have reason to believe that a child under the age of 16 has provided personal data to us through our website and/or by using our services, please contact our Data Protection Officer at jeannie.stewart@mirrorwave.com.
Cookies
We use cookies (an alphanumeric identifier that we transfer to your computer’s hard drive so that we can recognise your browser) to monitor your use of the website. We use the following types of cookies for the following purposes:
- strictly necessary cookies served by us – these cookies are essential for the full functionality of our website and are used to secure your session and grant access to resources while you are using the website or services. These are session cookies which expire automatically 20 minutes after using the website or services
- tailored content cookies served by Google Analytics – these cookies help our website provide enhanced features and are used for service improvement and to deliver content relevant to you
- targeting cookies served by Google Advertising – these cookies are used to deliver advertising relevant to your interests
Information about Google’s cookies is available from: https://www.google.com.au/policies/technologies/types/. Google’s privacy policy relating to its cookies is available at https://www.google.com/policies/privacy/partners/. If you would like to customise or opt out of these settings please visit: https://tools.google.com/dlpage/gaoptout.
Google Advertising presents advertising relevant to your interests when you access the website or our services, generated from data relating to your access and use of the website or our services. Google Advertising places cookies on your browser to collect information about your past use of the website and then places ads on sites across the Internet that are more likely to be of interest to you. If you would like to customise or opt out of AdWord’s behavioural advertising, you can visit Google’s Ads Settings at https://adssettings.google.com/authenticated.
You can learn more about interest-based advertising and opt out of interest-based advertising from participating online advertising companies at the following links:
Network Advertising Initiative (NAI) – http://optout.networkadvertising.org/
Digital Advertising Alliance (DAA) – http://optout.aboutads.info/
Digital Advertising Alliance EU (EDAA) – http://www.youronlinechoices.com/
DAA AppChoices page – http://www.aboutads.info/appchoices
Please note that opting out of interest-based advertising does not mean you will no longer be served advertising. You will continue to receive generic ads.
You can control and/or delete cookies as you wish. You can delete all cookies that are already on your computer and you can set most browsers to prevent them from being placed. If you do this, however, you may have to manually adjust some preferences every time you visit our website and attempt use our services, you may not be able to access certain parts of our website or services, and some functionalities may not work. You can find out more information about how to change your browser cookie settings at http://www.aboutcookies.org.uk.
International transfer of data
The Account and Marketing Data may be transferred to, and stored in, a country operating outside the European Economic Area (EEA). Under the GDPR, the transfer of personal data to a country outside the EEA may take place where the European Commission has decided that the country ensures an adequate level of protection. In the absence of an adequacy decision, we may transfer personal data provided appropriate safeguards are in place.
The personal data we collect is processed by the third-party processors set out the table below.
Some of the Account and Marketing Data we collect is processed in New Zealand (where our registered office is located). New Zealand is recognised by the European Commission as a country that ensures an adequate level of data protection and we rely on this decision in transferring personal data to New Zealand.
Some of the Account and Marketing Data we collect is processed by us and/or third-party data processors in other countries, including the United States. These countries are not subject to an adequacy decision by the European Commission. In transferring your personal data to these countries, we implement appropriate safeguards as required by the GDPR, such as Standard Contractual Clauses (SCCs) approved by the European Commission. We ensure that our data processors in the United States comply with these safeguards to maintain the protection of your personal data.
List of third party processors as at 24 August 2026:
| Third party processor | Purpose | Location of processor | Policy pages |
| Google, Inc. | Analytics Advertising |
USA | https://policies.google.com/privacy?hl=en&gl=nz |
