1. Who we are
This Privacy Policy describes how THEBRG Enterprise (Business Registration No. 003120480-W), the headquarters company registered and operating in Malaysia, trading under the brand NAX ("NAX", "we", "us", "our"), collects, uses, discloses and protects personal information in connection with the website nax.co.nz and the services we provide.
NAX serves clients throughout Aotearoa New Zealand. For our New Zealand clients and website visitors, this Policy is governed by the New Zealand Privacy Act 2020 and we handle personal information in accordance with the thirteen Information Privacy Principles (IPPs). Where our headquarters jurisdiction applies we also comply with the Personal Data Protection Act 2010 of Malaysia ("PDPA"), and, where applicable, the EU General Data Protection Regulation ("GDPR").
Privacy Officer. As required by section 201 of the Privacy Act 2020, we have appointed a Privacy Officer who is responsible for compliance with this Policy and for handling privacy requests and complaints. You can reach our Privacy Officer at hello@nax.co.nz.
2. Information we collect
We collect the following categories of information:
- Contact data — name, email address, phone number, company name and role when you contact us, request a proposal or subscribe.
- Project data — information you share with us to scope, deliver and support an engagement, including credentials and content you grant us access to.
- Technical data — IP address, browser type, device identifiers, referring URL, pages visited and approximate location, collected automatically by our hosting and analytics providers.
- Cookies & similar technologies — strictly necessary cookies for site operation and, with consent where required, analytics cookies to understand usage.
- Billing data — company name, billing address, tax identifiers and transaction records for invoicing.
3. How we use your information
We process personal data for the following purposes:
- Responding to enquiries and providing the services you request.
- Delivering, supporting and improving our products and engagements.
- Issuing invoices, collecting payment and meeting tax and accounting obligations.
- Sending service updates, security notices and — only with your consent — marketing communications.
- Detecting, preventing and addressing fraud, security incidents and abuse.
- Complying with applicable laws and lawful requests from authorities.
4. Lawful basis for collection
Under the Privacy Act 2020 we collect personal information only for a lawful purpose connected with our business, directly from you wherever practicable, and only where the information is necessary for that purpose (IPPs 1–4). We do not collect personal information by unlawful, unfair or unreasonably intrusive means, and we tell you at the point of collection why we need it, who will hold it and that you may access and correct it.
Where the GDPR applies, we rely on performance of a contract, our legitimate interests in operating the business, your consent, and compliance with legal obligations. Under the Malaysian PDPA, we rely on your consent and the applicable exemptions in Section 39 of that Act.
5. Sharing & sub-processors
We do not sell personal information and we do not use it for a purpose other than the one it was collected for, except as permitted by IPPs 10 and 11 (for example, with your authorisation, or where disclosure is required by law). We share information only with carefully selected sub-processors who help us run the business — hosting, email, analytics, accounting, payment processing and CRM providers — under written agreements that require them to protect the information and use it only on our instructions.
6. Sending information overseas (IPP12)
Because our headquarters and some providers are located outside New Zealand, your information may be processed in New Zealand, Australia, Malaysia, Singapore, the European Union, the United Kingdom and the United States. Before disclosing personal information to an overseas recipient we satisfy ourselves, as required by IPP12, that the recipient is subject to privacy laws or contractual safeguards providing comparable protection to the Privacy Act 2020, or we obtain your express authorisation to the transfer.
7. Retention
Consistent with IPP9, we keep personal information only for as long as it is required for the purposes for which it may lawfully be used, including legal, accounting and reporting requirements. Project and financial records are typically retained for seven (7) years from project completion to meet New Zealand Inland Revenue and Malaysian tax and audit requirements, after which they are securely deleted or anonymised.
8. Security
As required by IPP5 we apply organisational and technical safeguards appropriate to the risk — including encryption in transit and at rest, least-privilege access controls, audit logging, multi-factor authentication, regular backups and documented incident response procedures. No system is completely secure, and we ask you to also do your part by keeping your account credentials confidential.
9. Privacy breach notification
If a privacy breach occurs that it is reasonable to believe has caused, or is likely to cause, serious harm, we will notify the Office of the Privacy Commissioner and the affected individuals as soon as practicable, as required by Part 6 of the Privacy Act 2020. We maintain an internal breach register and assess every incident against that threshold.
10. Marketing & electronic messages
Commercial electronic messages are sent only where you have consented or where consent can be inferred from an existing business relationship, in accordance with the Unsolicited Electronic Messages Act 2007. Every marketing message identifies NAX as the sender and includes a functional unsubscribe facility, which we action promptly. Service, security and transactional messages relating to an active engagement are not marketing.
11. Your rights
Under IPPs 6 and 7 you may ask us to confirm whether we hold personal information about you, request access to it, and request correction of anything that is inaccurate. We will respond to a request as soon as reasonably practicable and no later than 20 working days after receiving it, and we will tell you if we need to rely on a lawful ground to refuse or extend. You may also withdraw consent, ask us to delete information we no longer need, and object to marketing at any time. There is no charge for a standard request.
If you are not satisfied with our response, you may complain to the Office of the Privacy Commissioner (New Zealand) — 0800 803 909, enquiries@privacy.org.nz — or, where relevant, to the Personal Data Protection Department of Malaysia or your local supervisory authority.
12. Contact us
Privacy questions, access and correction requests can be sent to our Privacy Officer at hello@nax.co.nz. Postal address: THEBRG Enterprise (003120480-W), headquarters in Malaysia. New Zealand operations: NAX, Auckland, New Zealand.
13. Updates
We may update this Policy from time to time. The "Last updated" date at the top reflects the latest revision. Material changes will be communicated through the website or directly where appropriate.
