Effective as of May 8, 2018.
In the course of our business dealings with you we may collect, use, disclose, and hold information about identified or identifiable persons (Personal Information), as well as other business or technical data.
Information that we collect from you
During the course of your relationship with us, your using our apps or websites, or your use of our aimy Plus online management service (aimy Plus), we may collect the following information:
1) We will collect personal details from you during the course of your establishing and maintaining an account or user profile with us via aimy Plus, such as your name, user name, passwords, address, email address and phone numbers.
2) We will collect data that is inputted or uploaded by users into aimy Plus, or that is inputted, uploaded or provided by users via any helpdesk or online chat service we may provide in connection with aimy Plus. The information inputted or uploaded into aimy Plus may include information about children and their parents, including in some circumstances medical information and other sensitive data.
3) We will collect data related to the use of aimy Plus, including details of the pages visited, the reports generated and the data accessed.
4) We may collect other Personal Information and data during the course or as a result of your relationship with us, including where necessary to enable us to provide products and services to you or to respond to requests for further information.
We don’t collect credit card information
We do not collect, store or process any credit card information. Any credit card payments made by usersin connection withaimy Plus will be processed by third-party payment platform providers.
How we use Personal Information and other data
We will use, disclose and hold Personal Information and data collected by us for the following purposes:
1) to enable us to operate aimy Plus (where applicable) for the benefit of you or the applicable organisation subscriber;
2) to establish and maintain any account you hold with us;
3) to complete sales transactions, including billing, payment, receipt, credit check and verification services;
4) to respond to your queries or requests for additional information or support;
5) to provide any after-sales service required by you;
6) to maintain our records;
7) to provide technical support and administration services in relation to aimy Plus;
9) for product development or research purposes; and
10) to evaluate customer satisfaction and the performance of marketing activities.
Lawful basis for processing Personal Information
We will always make sure that we have a lawful basis for the processing of your Personal Information.
In particular, we may need to process your Personal Information to pursue our legitimate business interests. This includes to enable us to operate our aimy Plus service, and our other apps or websites on which we may make available products, services or information from time to time (Apps and Websites), for the benefit of users and subscribers. In claiming legitimate business interests to process your Personal Information, we will balance those legitimate business interests against your own interests – which may in some cases override our legitimate business interests.
In addition to our legitimate business interests:
2) some of the Personal Information is collected and processed to assist with medical emergencies or to keep children safe from harm. For example, medical information, information about allergies, and parental contact details. This information may be used, collected and disclosed where necessary to protect the vital interests of natural persons; and
3) In some circumstances, we will have a legal obligation to process certain Personal Information.
Our cookies will only use information about your personal preferences and user settings so that aimy Plus or our Apps and Websites will remember your details next time you visit. We may use, disclose or sell other data collected by us from cookies for other purposes, but only on an aggregated basis and in a way that ensures that no individual is able to be identified from such information.
Statistical data that we collect
During your use of aimy Plus or our Apps and Websites we may collect statistical data about such use, such as the date, time and length of your use, the pages of aimy Plus or our Apps and Websites that you visit, and information about the device you are using to access aimy Plus or our Apps and Websites. This information may be collected by software operating on aimy Plus or our Apps and Websites, or by third party service providers on our behalf.
We may use and disclose such statistical data for the following purposes:
1) to measure the effectiveness of any services or features provided via aimy Plus and our Apps and Websites;
2) to identify user behaviour and user trends on aimy Plus and our Apps and Websites;
3) to maintain and optimise the technical performance, operation and security of any products or services (including aimy Plus and our Apps and Websites) provided by us; and
4) to assist in resource planning.
We may disclose or sell such statistical data to others for any purpose, but only on an aggregated basis and in a way that ensures that no individual is able to be identified from such data.
User and subject data
We may use Personal Information and other data collected by us or via aimy Plus or our Apps and Websites to send or email to your marketing or promotional information about our services or products, or the services or products of other companies (Direct Marketing Information), but only if you have expressly given us permission to do so.
We will not sell your Personal Information or other data to direct marketers unless you have expressly given us permission to do so.
We may transfer your Personal Information and other data to another entity in connection with a sale of our business or assets, or a merger or consolidation or restructuring of our business or company, or any other transaction in which a third party acquires ownership of any rights in aimy Plus and our Apps and Websites.
If we transfer any of your Personal Information and other data in such circumstances, we will ensure that such Personal Information and other data remain protected and that the recipient of that Personal Information and other data agrees to be bound by privacy practices and obligations that are consistent with our own under this Policy.
Disclosure of information to third-parties
We will not use your Personal Information and other data, or disclose your Personal Information and other data to third parties, except:
2) where we reasonably believe that such use or disclosure is required or expressly permitted under any applicable law.
Holding Personal Information
We will not hold your Personal Information and other data for longer than is reasonably required for the purposes for which we may lawfully use that Personal Information or data.
In particular, we will hold your Personal Data for so long as you continue to use aimy Plus and our Apps and Websites, and for a period of five years after this. The only reason why we may hold any Personal Information for longer than this period is where we are required by law to do so.
Following that period (or following such longer period that we may be required by law to hold Personal Information) we will delete your Personal Information, or mask or anonymise your Personal Information so that it can no longer be used to identify you.
We will use all reasonable endeavours to effect and maintain adequate security measures to safeguard your Personal Information and other data we hold from loss or unauthorised access, use, modification or disclosure.
Transfer of Information
In particular, aimy Plus and our Apps and Websites are operated using servers and systems located in New Zealand and Australia. Personal Information is also transferred to Xero for billing, invoicing and accounting purposes. Xero is an online accounting platform with servers based in New Zealand and the United States.
The European Commission has recognised New Zealand and the United States (limited to the Privacy Shield framework) as providing adequate protection for the personal data of European Union subjects.
We will ensure that appropriate safeguards are in place as prescribed by the European Union’s General Data Protection Regulation (GDPR), before we transfer any Personal Information of any European Union subjects to any data processor based in any country that the European Commission has not recognised as providing adequate protection for the personal data of European Union subjects. As a minimum, we will ensure that the data processor agrees to be bound by the European Commission’s Standard Contractual Clauses for the protection of personal data, or (in the case of the US) will ensure that the entity is Privacy Shield certified.
When Xero processes the Personal Information of European Union subjects it also ensures that appropriate safeguards are in place that are prescribed by the GDPR – i.e., by entering into the European Commission’s Standard Contractual Clauses with the entity the data is transferred to, or by ensuring that the entity is Privacy Shield certified (for transfers to US based entities).
Use of third-party websites
If you access any third-party websites via a link from any of aimy Plus or our Apps and Websites, you will leave aimy Plus or thatApp or Website. By accessing these links you are not covered by the policies relating to aimy Plus or thatApp or Website. We are not responsible for the content of any third-party websites, or their use of your Personal Information or other data.
Subscriber privacy practices
We have no control over the privacy practices of organisations that subscribe to aimy Plus. In particular, we cannot control what such organisations may do with the information you input or upload into aimy Plus, or the information that you provide to such organisations for the purposes of their inputting or uploading that information into aimy Plus. You should ensure that any organisation you provide Personal Information or other valuable data to has appropriate privacy practices in place that protect that Personal Information or data from misuse and unauthorised disclosure.
Your rights to access, correct and delete Personal Information
We provide users of aimy Plus and our Apps and Websites with tools and portals that enable them to manage their privacy settings, and to delete or disable certain Personal Information or our access to that Personal Information. Users may access these tools and portals at any time.
Please note that the deletion or disablement of Personal Information may have an impact on the features and functionality of aimy Plus and our Apps and Websites. In particular, some features and functions of aimy Plus and our Apps and Websites will not work without the requested Personal Information being made available to us.
You also have additional rights to information about your Personal Information that we collect and process. This information includes:
1) details of the Personal Information that we collect and process, including the categories of Personal Information concerned, and purposes of any processing;
2) the recipients or categories of recipient to whom the Personal Information have been or will be disclosed;
3) where possible, the envisaged period for which the Personal Information will be stored, or, if not possible, the criteria used to determine that period; and
4) where your Personal Information is not collected from you, any available information as to the source of that Personal Information.
You also have the right to request from us the rectification or erasure of your Personal Information, to request from us the restriction of processing of your Personal Information, and to object to our processing of your Personal Information.
If you want to access, correct or seek the erasure of your Personal Information or data, please contact our Data Protection Officer (see below) and he/she will tell you how to make a request and if any charges will apply.
EU subjects may complain to a supervisory authority
European Union subjects have the right to lodge a complaint about our Personal Information processing activities with a supervisory authority in the EU Member State where they are based or where the data processing activity took place.
Our Data Protection Officer can help you to identify who your supervisory authority is.
Data Protection Officer
Aimy Data Protection Officer
63B Apollo Drive, Rosedale,
Auckland 0632, New Zealand
+ 64 9 972 9484
As we are not based in the European Union, we have designated the following person to act as our representative in the European for the purposes of Article 27 of the GDPR:
DPR (Our EU GDPR Representative)
Office 29, Clifton House,
Fitzwilliam Street Lower,
For contact information click here
Our GDPR Representative is authorised to act on our behalf with regard to all questions or issues concerning our collection and processing of the Personal Information of European Union subjects.
Who we are
For the purposes of the GDPR, Aimy Limited is both a controller and processor of data.
Our registered office is located at;
63B Apollo Drive, Rosedale,
Auckland 0632, New Zealand.