Our commitment to privacy

Using data to achieve social and environmental impact is at the heart of what we hold true at Toha, so we know how important it is to have a solid privacy policy in place. We are committed to being fully transparent and honest in our approach to using and storing your data. We are taking all steps to ensure that this information remains secure.

This Privacy Policy outlines the details of how we collect, use, share and protect your personal information. This applies to information that we collect both online and offline. This policy relates to the Toha and East Coast Exchange  websites, and all Toha subsidiaries and services as they exist today. We will update this policy regularly and notify you by email when this occurs.

Your information will never be shared, leased or given to any third parties in ways other than disclosed in this Privacy Policy. The Office of the Privacy Commissioner (www.privacy.org.nz) provides further details of the Privacy Act 2020 and how it protects personal information in Aotearoa New Zealand.

If you have any questions about your privacy or this policy, please contact us.

What information is collected by the East Coast Exchange & Toha?

We collect personal information and data about your actions to be displayed on the ECX public record. We also collect data so that we can provide, design and build products that support the Toha Network, including Toha’s subsidiaries.

We may collect information from or about you in the following ways:

Information that you voluntarily provide us, such as

  • ECX registration. We collect personally identifiable information such as your address, email address, name, phone number and land.

  • ECX Action Record. We collect details about the actions you have undertaken including date and location. You own this data and can ask for it to be edited or removed at any time.

  • Communications and phone calls. When you communicate with a member of the Toha team, we may collect and store information about your communication and the information you provide, in our Client Relationship Manager (CRM) tool, HubSpot, and third party reporting tools including Pledge Reporter, Claim/Pledge Template Developer and other third party data storage. HubSpot privacy terms and conditions can be found here. For more on Security at HubSpot, please see https://legal.hubspot.com/security

Information we collect automatically, such as

  • Web Server Logs. Our web servers may collect certain information such as IP address, pages visited, time of visits, and referring website.

  • Via our CRM tool, Hubspot, which may track or use your activity on the ECX Website. Hubspot privacy terms and conditions can be found here. For more on Security at HubSpot, please see https://legal.hubspot.com/security

  • Via cookies. Cookies are small files temporarily stored on your hard drive. We use cookies to retrieve aggregate information of the characteristics and behaviours of Website users so we can make improvements to the Website. We use cookies to keep track of your preferences so we can present the Website to best meet your requirements. The information collected is non-personally identifiable information such as: Internet domain and IP address from which you are accessing the Website; the browser and operating system you are using (e.g. Chrome, Internet Explorer and Firefox or Windows and Mac); the date and time you access the site; and whether you arrived at the Website via a link from another site and the address of such site. You can disable the use of cookies in your browser settings. You may continue to use this Website even if you deactivate cookies, however deactivating cookies may mean that you might no longer be able to enjoy offers from Toha in their entirety.

  • Geolocation data We log all access to all accounts by full IP address so that we can always verify no unauthorised access has happened. We keep this login data for as long as required.

  • Web analytics data Web analytics data is also tied temporarily to IP addresses to assist with troubleshooting cases. Web analytics data is collected either in the platform, Google Analytics, Hubspot, Google Data Studio or other third party web analytics tools.

  • Website interactions When you browse Toha web pages or tools, your browser automatically shares certain information such as which operating system and browser version you are using. We track that information, along with the pages you are visiting, page load timing, and which website referred you for statistical purposes like conversion rates and to test new designs. We sometimes track specific link clicks to help inform some design decisions. These web analytics data are tied to your IP address and user account if applicable and you are signed into our Services.

  • Anti-bot assessments We use CAPTCHA services across our applications to mitigate brute force logins and in Loomio as a means of spam protection. We have a legitimate interest in protecting our apps and the broader Internet community from credential stuffing attacks and spam. When you log into your accounts and fill specific forms in Loomio, the CAPTCHA service evaluates various information (e.g IP address, how long the visitor has been on the app, mouse movements) to check whether the data is possibly filled out by an automated program instead of a human.

How do we use your information?

Your action data will be added to the ECX’s transparent and verifiable public record of actions on the East Coast. Some of your action data will be public and other pieces of data will only be visible to ECX verifiers so they can confirm the details of action undertaken.

We may also use your information in the following ways:

  • For internal purposes (to better understand our community) and develop products and services that best serve them.

  • For analytical purposes (to respond to requests for information and to improve our website, support network, and outreach).

  • To undertake analysis and record keeping (either internally or with trusted partners) to help build the Toha Network. All third parties are prohibited from using your personal information with the exclusion of the provision of support to Toha, and are required to maintain the confidentiality of your information at all times.

Who do we disclose your information to?

We will never sell, rent or lease your personal information or data to third parties.

However, we need to disclose your information to third party suppliers to provide you with services and support. In order to provide and manage our Services, we may need to disclose some of your personal information to our third party service providers. These providers have limited access to your personal information to perform tasks on our behalf (such as cloud-storage providers; marketing partners; data analytics or research partners; third parties that help us to enhance the safety and security of the Service; where required, to international regulators (for example, for tax purposes); and our consultants, lawyers, accountants, insurers, and professional advisors) and are contractually obliged to use your personal information consistently with this Privacy Policy. These disclosures will be consistent with the Service-specific terms and the rest of this privacy policy.

We may disclose your information in the following ways:

  • External service providers. In the case that Toha engages third party agencies to to support operational activities and the services (e.g. to develop a newsletter to send you via Hubspot). These providers have limited access to your personal information to perform tasks on our behalf, and are contractually obliged to use your personal information consistently with this Privacy Policy. Some of these service providers are located outside of New Zealand and may not be subject to New Zealand privacy laws. However, we will take such steps as are reasonable in the circumstances to confirm that those organisations are required to protect the information in a way that, overall, provides comparable safeguards to those under the Privacy Act 2020. By using the Service and otherwise providing us with your information, you authorise such disclosure.

  • Authorised third party access. We may ask for your consent to share your personal data and information to a third party that is offering services to Toha e.g. in the case where your data is contributing to a visual footprint of biodiversity action in New Zealand.

  • For legal compliance or law enforcement purposes. We may disclose your personal information to courts, law enforcement or government agencies, or third parties, to the extent we believe that disclosure is appropriate or permitted by the Privacy Act.

  • To facilitate legal processes. If you wish to take Disputes Tribunal (or other) proceedings against another User, you can access the Ministry of Justice statutory declaration form which must be completed before we will consider releasing anyone else's information to you. You may only request contact details for the sole purpose of making a claim.

  • To protect the rights, property or safety of us, our Users or others. This includes collecting money you owe us and making such disclosures as are necessary for the purpose of trust, safety and assurance.

To our other Subsidiaries.

  • We may disclose your personal information to entities partly or fully owned by Toha Foundry Limited which are governed by this privacy policy, subject to your privacy options and the service-specific terms. In relation to Toha Affiliated Services, unless you opt out, we may disclose your personal information to businesses that provide a Toha Affiliated Service. We won’t allow your information to be disclosed for a Toha Affiliated Service unless we trust the business providing it and we’ll ensure that all Toha Affiliated Services have robust privacy arrangements in place. 

How do we store and protect your personal information?

We hold your personal information in accordance with the requirements set out in the Privacy Act 2020. Your personal information may be held by Toha electronically or in hardcopy (in New Zealand or elsewhere) but in all cases we will control that information and keep it secure.

Residents of some other countries, including residents of the European Union, should be aware that the laws of New Zealand do not offer the same protections as the laws of your home country.

Location of site and data

Our products and other web properties are operated from New Zealand. If you are using one of our websites or tools located outside of the country you reside in, please be aware that any information you provide to us will be transferred to and stored in Australia, the United States, Germany and New Zealand. By using our service, participating in any of our services and/or providing us with your information, you consent to this transfer.

Sending you electronic messages and Unsubscribing

By submitting your email address, via a contact form on any Toha website, you’ll be accepting the terms and conditions of the use of the site. This includes agreeing to us sending you both automated and unsolicited information about Toha in electronic form to the registered email address.

We may use your email to send automated communications based on your activity on the website, such as an email notification to confirm your registration or we may send you information about our progress with the ECX or Toha.

All emails we send you will include an unsubscribe facility that you can use to remove your email address from the mailing database. If you are unable to see an unsubscribe function in electronic messages from Toha, please forward the email with the subject UNSUBSCRIBE to info@nzclimateimpactmarket.com.

Your data, your rights

By making an email or written request, you may request for us to:

  • Provide a copy of the information we hold about you

  • Update your personal information in our database,

  • Delete your personal information. In the case of deletion, if your data is connected to an aggregated data set we may require that while we remove any of your identifiable personal information, the de-personalised data remains as part of the complete set.

Please remember it is your responsibility to ensure that personal information provided to us is accurate.

Updates

We may update this policy as needed to comply with relevant regulations and reflect any new practices. Whenever we make a significant change to our policies, we will also announce them on our company blog.

Additional info

As the organisation evolves, we may make changes to the Toha privacy policy as it relates to how your personal information is used and stored both online and offline. We will notify you when changes are going to be made via the email you have registered with us.

If we need, or are required to, contact you about the privacy or security of your information we may do so by phone or email. If you have any questions, concerns, requests, or comments about this privacy policy, you can contact us by email or mail at:

eastcoastexchange@toha.nz 

Toha Foundry Limited, t/a East Coast Exchange, 114 Bright Street, Gisborne, 4010 NEW ZEALAND