Your privacy is important to us. This privacy policy (“the Policy”), explains how we collect, process, use, store and disclose your personal data, as well as your rights associated with that data.
This policy is provided in a layered format so you can click through to the specific areas set out below. Please also use the Glossary at the end of the document to understand the meaning of some of the terms used.
1.1
Tourism Holdings Limited (thl) is New Zealand's premier tourism company. We are listed on the New Zealand Stock Exchange under the ticker code THL and are the largest provider of holiday vehicles for rent and sale globally. In Australia and New Zealand we operate under the maui, Britz and Mighty rentals brands, and the RV sales brands - RV Sales Centre and RV Super Centre. In the USA we own and operate both Road Bear RV Rentals and Sales and El Monte RV Rentals and Sales brands. We operate as Just go in the UK and Europe. We also operate the iconic Kiwi Experience and the Discover Waitomo Group, which includes Waitomo Glowworm Caves, Ruakuri Cave, Aranui Cave and The Legendary Black Water Rafting Co. Details of our legal entities can be found here.
1.2
Together we are the data controllers for the purposes of this policy, which is issued on behalf of all brands and entities within the thl group of companies (thl group). When we mention "thl", "we", "us" or "our" in this privacy Policy, we are referring to the relevant entity in the thl group responsible for processing your data.
1.3
We also use a network of independent agents and licensees when providing our services around the world. Please note that those agents and licensees are not covered by this Policy and we are not responsible for the privacy practices of any agent, licensee or other third party with whom you may transact before or at the same time as using our products or services.
2.1
We may collect, use, store and transfer different kinds of personal data about you, which we have grouped together as follows:
2.2
We also collect, use and share Aggregated Data such as statistical or demographic data, which may be derived from your personal data but is not personal data as it does not directly or indirectly reveal your identity. For example, we may aggregate your Usage Data to calculate the percentage of users accessing a specific website feature. However, if we combine or connect Aggregated Data with your personal data so that it can directly or indirectly identify you, we treat that combined data as personal data which will be used in accordance with this Privacy Policy.
2.3
We do not collect any Sensitive Data about you (such as details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your health and genetic and biometric data). We do not collect any information about criminal convictions and offences, although we may be required to briefly hold and pass on any driving infringements that you incur while renting our vehicles.
2.4
Refusal to provide your personal data: You do not have to provide your personal data when we request it, but if you choose not to, we may not be able to respond to your queries and perform any contract we have or are trying to enter into with you (for example, to provide you with a rental vehicle). That may mean we have to cancel a product or service you have with us. We will notify you at the time if that is the case.
3.1
We use different methods to collect personal data from and about you including through:
We will only use your personal data when the law allows us to and typically only in the circumstances and for the purposes set out in the table below. Please see the Glossary for an explanation of the expressions used in the table.
Purpose/Activity | Type of data | Lawful basis for processing |
---|---|---|
New customers: To register you as a new customer and to respond to your inquiries and any complaints |
(a) Identity |
Performance of a contract with you |
Facilitate bookings: To provide and store quotes for retrieval and to process bookings including:
|
(a) Identity |
(a) Performance of a contract with you (b) Necessary for our legitimate interests (to recover debts due to us) |
Provide services: To provide our services to you, including:
|
(a) Identity |
(a) Performance of a contract with you |
Relationship management: To manage our relationship including:
|
(a) Identity |
(a) Performance of a contract with you |
Improve services: To constantly improve our products and services, tailor them to your needs, develop new product/service ideas and inform you of any changes to our products/services |
(a) Identity |
a) Performance of a contract with you |
Promotions:
|
(a) Identity |
(a) Performance of a contract with you |
Technical maintenance: |
(a) Identity |
(a) Necessary for our legitimate interests (for running our business, provision of
administration and IT services, network security and to prevent fraud) |
Advertising: |
(a) Identity |
Necessary for our legitimate interests (to define types of customers for our products/services, to keep our website updated and relevant, to develop business and to inform our marketing strategy) |
Data analytics:
|
(a) Technical |
Necessary for our legitimate interests (to define types of customers for our products and services, to keep our website updated and relevant, to develop our business and to inform our marketing strategy) |
Promote our products and services: |
(a) Identity |
Necessary for our legitimate interests (to develop our products/services and grow our business) |
Safety and security: to track vehicle location and provide real-time safety alerts to customers (such as low bridge warnings), notifications of access to unauthorised territories, information about points of tourism interest, to contact you about security, safety and/or operational issues we have identified from the data collected, and to understand and manage the performance, location and security of our vehicle fleet and to assist with the management of accident claims involving our vehicles. |
(a) Identity |
(a) Performance of a contract with you |
5.1
We aim to provide you with choices about how your personal data is used for marketing and advertising purposes. We have established a privacy centre where you can view and make certain decisions about your personal data use.
5.2
You will only receive marketing communications from us if you have opted in or consented to receiving those communications. We may use your personal data collected in those circumstances to contact you and keep you up to date with the latest news, events, special offers and promotions of our brands, including by email, text messages or post.
5.3
You can update your subscription preferences or unsubscribe from marketing communications at any time by following the update preferences or unsubscribe instructions provided in each such communication, or alternatively by contacting us.
5.4
We may display advertising for you to see on third party websites, including social media sites such as Facebook. We do this by matching information about your activity on thl group websites with information collected on third party sites. That may involve using your Identity, Contact, Technical, Usage and Profile Data to form a view on what we think you may want or need, or what may be of interest to you.
6.1
We will only use your personal data for the purposes for which we collected it, unless we reasonably consider we need to use it for another reason compatible with the original purpose. If you wish to get an explanation as to how the processing for the new purpose is compatible with the original purpose, please contact us.
6.2
If we need to use your personal data for an unrelated purpose, we will notify you and we will explain the legal basis which allows us to do so.
6.3
Please note that we may process your personal data without your knowledge or consent, in compliance with the above rules, where this is required or permitted by law.
7.1
We may have to share your personal data with the following parties for the purposes set out in the table in paragraph 4 above or for other purposes directly related to the purpose for which the information was collected.
7.2
We require all third parties to respect the security of your personal data and to treat it in accordance with the law. We do not allow our third-party service providers to use your personal data for their own purposes and only permit them to process your personal data for specified purposes and in accordance with our instructions.
8.1
For the most part, your personal data is collected, stored and processed outside the European Economic Area (EEA).
8.2
Certain entities in the thl group may collect personal data inside the EEA. Skewbald Ltd, trading as Just go, collects personal data in the United Kingdom.
8.3
If we transfer your personal data out of the EEA, we ensure a similar degree of protection is afforded to it by ensuring at least one of the following safeguards is implemented.
8.3.1
We will only transfer your personal data to countries that have been deemed to provide an adequate level of protection for personal data by the European Commission.
8.3.2
Where we have entered into EU-approved standard contractual clauses with the recipient to give personal data the same protection it has in Europe.
8.3.3
Where we use providers based in the US, we may transfer data to them if they are part of the Privacy Shield which requires them to provide similar protection to personal data shared between the Europe and the US.
8.4
Please contact us if you want further information on the specific mechanism used by us when transferring your personal data out of the EEA.
9.1
You have the following rights in relation to your personal data.
9.2
If you wish to exercise any of the rights set out above, please contact our Data Protection Officer (see section 12 below).
9.3
No fee usually required: You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. Alternatively, we may refuse to comply with your request in these circumstances. If we choose to deny your request, we will inform you of the decision and your right to complain to the supervisory authority within the one month deadline.
9.4
What we may need from you: We may need to request specific information from you to help us confirm your identity and ensure that personal data is not disclosed to any person who has no right to receive it.
9.5
Time limit to respond: We respond to all legitimate requests without undue delay and at the latest within one month. Occasionally, if your request is particularly complex or you have made a number of requests, we may need to extend this by up to a period of two months, in which case we will notify you and keep you updated.
10.1
We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions and they are subject to a duty of confidentiality.
10.2
We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.
11.1
We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting or reporting requirements.
11.2
To determine the appropriate retention period for personal data, we consider the amount, nature and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means and the applicable legal requirements.
12.1
EU Supervisory Authorities: If you are an EU data subject and feel that your personal data has been processed in a way that does not comply with the GDPR, you may lodge a complaint with the relevant supervisory authority in your country. We would, however, appreciate the chance to deal with your concerns before you approach them, so please contact us in the first instance.
12.2
Data Protection Officer: We have appointed a data protection officer (DPO) who is responsible for overseeing privacy issues for the thl group. If you have any questions or complaints about this Policy, including any requests to exercise your rights in relation to your personal data, please contact the DPO using the details set out below.
12.3
EU Representative: We have appointed an EU Representative whose tasks are to serve as a contact person for supervisory authorities and data subjects and can be contacted as follows:
13.1
This version was last updated on 25 May 2018. Historic versions are archived here.
13.2
We reserve the right to update and change this Privacy Policy at any time by posting changes on this webpage or applicable mobile apps. Changes will take effect from the time they are posted. We will use reasonable endeavours to communicate those changes to you on our website and mobile apps or via other channels that we think are suitable.
13.3
It is important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes during your relationship with us.
Comply with a legal or regulatory obligation means processing your personal data where that is necessary for compliance with one of more of our legal or regulatory obligations.
Data controller means whomever determines the purposes and means of processing personal data.
Legitimate Interest means our interests in conducting and managing our business to enable us to give you the best service/product and the best and most secure experience. We make sure we consider and balance any potential impact on you (both positive and negative) and your rights before we process your personal data for our legitimate interests. We do not use your personal data for activities where our interests are overridden by the impact on you (unless we have your consent or are otherwise required or permitted to by law).
Performance of Contract means processing your data where that is necessary under a contract with you or to take steps at your request before entering into such a contract.
Personal data means any information about an individual that can be used to identify that person directly or indirectly by reference to a range of identifiers. It does not include anonymous data where the identity of the individual has been removed.
Processing means any operation or set of operations performed on personal data.
Processor means the entity that processes personal data on behalf of the controller.