1. Introduction
Schooled Limited and Hail.IM Limited (“we,” “us,” or “our”) is committed to protecting your privacy and safeguarding any personal information you provide when using our election management services and application. This Privacy Policy outlines how we collect, use, disclose, store, and protect your personal information in accordance with the Privacy Act 2020 (New Zealand).
By using our services, you consent to the practices described in this Privacy Policy.
2. Scope of this Privacy Policy
This policy applies whenever we collect personal information from you, whether through our School Election application, website, or related services. It covers how we handle information from candidate profiles, election administration, voting and informing schools of the results.
3. Information We Collect
We may collect the following types of personal information:
- Account information: Email address, username, and password.
- Usage Data: Metadata about your interactions with the application, including IP address, device type, operating system, browser type, and activity logs (e.g., pages viewed, buttons clicked).
- Communication Data: Records of changes within the application, activity and system logs.
- Election Data: Information uploaded by users, such as candidate profiles, voter details, and other election-related content.
- Third-Party Data: Data received from third-party platforms (e.g., Student Management Systems) as authorised by you or your organisation.
4. How We Use Your Information
We use your personal information for the following purposes:
- Service Provision: To enable the operation of elections, manage candidate profiles, and voting processes and provide technical support.
- Identity Verification: To confirm your identity and ensure authorised access.
- Communication: To send updates, and notifications to voters and you.
- Improvement and Development: To analyse user interactions and improve the performance and features of our application.
- Compliance: To meet legal, regulatory, and contractual obligations.
We reserve our right to use data (on an anonymous basis) in relation to assess the performance of the service and statistical returns.
No marketing materials or correspondence will be sent by the Election Manager.
5. Sharing of Information
We do not sell or share your personal information to third parties. However, our technology provider (Hail.IM) does share information in the following circumstances:
- With Service Providers: For hosting, data storage, and application development.
- Legal Compliance: To comply with legal obligations or respond to lawful requests from legitimate public authorities.
- With Your Consent: When you explicitly authorise us to share specific information on statistical returns to the Ministry and District Office.
6. Data Storage and Security
We take reasonable steps to ensure your personal information is stored securely and protected against unauthorised access, alteration, or disclosure.
Measures include:
- Encryption of sensitive data during transmission.
- Regular security assessments and updates to our technical software to maintain system security and operational performance.
- Restricting access to authorised personnel only via a secure administrative portal.
We also engage service providers outside of New Zealand to host and maintain the underlying IT system that we use to provide the application. We take all reasonable steps to ensure that your personal information held outside New Zealand is secure and held in compliance with this privacy policy.
7. Cookies and Tracking Technologies
We use cookies and similar technologies to enhance your user experience. Cookies help us understand how you interact with our services and allow us to:
- Maintain your session and preferences.
- Monitor site performance and usage trends.
Cookies are stored for varying durations depending on their purpose—session cookies are temporary and expire when you close your browser, while persistent cookies remain on your device until they expire or are deleted.
You can manage or disable cookies through your browser settings or directly within the application, where available, to tailor your cookie preferences. Note that disabling cookies may affect certain functionalities of the application.
8. Access and Control of Your Information
You have the following rights concerning your personal information:
- Access: Request a copy of your personal data held in the election manager.
- Correction: Request correction of inaccurate or incomplete information.
- Deletion: Request deletion of your personal information, subject to legal obligations.
- Objection: Object to processing for specific purposes, such as marketing.
To exercise these rights, contact us at [email protected].
Note: The Data Retention clause (point 9) and that election roll data, candidate profiles and activity will be deleted in 60 days after the close of the election. This is a requirement for the Ministry of Education (NZ).
9. Data Retention
We retain personal information only as long as necessary for:
- Providing election services.
- Meeting legal, regulatory, or contractual obligations.
- Resolving disputes and enforcing agreements.
Personal information related to elections will be retained for a period of 60 days following the conclusion of the election process. After this period, the data will be securely deleted unless otherwise required by law.
The retention period depends on the nature and sensitivity of the data, as well as applicable laws and policies.
10. Sub-Processes
Hail uses the third-party entities below (each, a “sub-processor”) to process personal data to deliver the election manager.
| Sub-Process | Nature and Purpose | Data category | Location | Security |
|---|---|---|---|---|
| Amazon Web Services | Data processing, data storage, mail processing. | Hosting Provider | Australia | High level of Security and data encryption. Information |
| Hail | Synchronising contact information from the Student Management System. | Data Integration | Australia | Encrypted application level data integration. |
11. Incident Management
In the event of a major business incident, we are committed to promptly and effectively responding to mitigate the impact on information systems, data, and overall operations. A major business is defined as any unauthorised access, disclosure, disruption, modification, or destruction of information systems or data. Customers are to raise any incidents via [email protected].
Notification and Communication.
Upon detection of a cyber incident, the designated Incident Response Team (IRT) at Hail will be activated immediately to assess and respond to the threat. The IRT will be led by the General Manager of Schooled and Hail or a nominated representative. Users will be informed of any incidents affecting their data within 48 hours of detection through email notifications and updates on our website.
Containment, Eradication and Communications.
The IRT will take immediate steps to contain and mitigate the impact of the incident. A communication strategy will be implemented to manage both internal and external messaging during and after the incident. This includes notifying the Ministry if a breach occurs as well what actions have been taken.
Legal and Regulatory Compliance.
We will comply with all.
12. Changes to This Privacy Policy
We reserve the right to modify this Privacy Policy at any time. Changes will be posted on our application, and significant updates may be communicated directly to users through email notifications or in-app alerts.
Continued use of our services indicates acceptance of the revised policy.
13. Contact Us
If you have questions or concerns about this Privacy Policy or our data practices, please contact us:
Email: [email protected]
This Privacy Policy was last updated on 10 April 2025.
