
Get in touch with us at heartleadnz@gmail.com
Privacy Policy - HeartLead NZ
How HeartLead handles personal information
Effective date: 8 September 2026
HeartLead NZ is committed to handling personal information responsibly under the Privacy Act 2020. This policy applies to heartleadnz.com, the HeartLead Internal Evaluation Workspace, purchases, enquiries, workshops, coaching, email communications and related services.
What we collect
We may collect:
-
Your name, email address, phone number, organisation or centre name, and account details.
-
Information you provide through enquiries, bookings, purchases, downloads, workshops, coaching or mentoring.
-
Order and payment information. Full card details are handled by the relevant payment provider, not stored by HeartLead.
-
Internal Evaluation Workspace information, including centre membership, evaluation questions, notes, professional reflections, uploaded evidence and activity needed to operate the service.
-
Questions sent to Ask HeartLead AI and the responses generated.
-
Technical information such as device, browser, IP address, cookies, analytics and service logs.
How we use information
We use information to provide and improve HeartLead services; create and administer accounts; manage subscriptions, invitations and renewals; respond to enquiries and support requests; deliver purchases, workshops and professional support; send service messages and, where you have opted in, marketing; maintain security, backups and system reliability; and meet legal obligations.
Internal Evaluation Workspace
The workspace is designed for professional evaluation using anonymised or summarised evidence. Do not enter or upload children’s names, identifiable photographs, full learning stories, confidential individual records, or other details that could identify a child, whānau member or colleague. Do not include identifying information in Ask HeartLead AI.
Centre owners control who is invited to their workspace and should remove access when a person leaves or no longer needs it. HeartLead’s administrator can manage accounts and may access information only when reasonably necessary to provide support, investigate security or reliability issues, comply with law, or act on the centre’s request.
Service providers and overseas processing
HeartLead uses trusted providers including Wix, Supabase, Vercel, Brevo, OpenAI, payment providers, Zoom and Meta where relevant. They may process or store information outside New Zealand, including in Australia, the European Union, the United States and other locations used by those providers. They process information to provide services to HeartLead under their own security and privacy terms. HeartLead remains responsible for taking reasonable steps to protect information and does not sell personal information.
Ask HeartLead AI
When you use Ask HeartLead AI, your question is sent to OpenAI to generate a response. Avoid all identifying or confidential details. AI responses may be incomplete or incorrect and should support, not replace, professional judgement. API content is not used to train OpenAI models by default; limited retention may still occur for safety, security or legal purposes under OpenAI’s applicable terms.
Storage, security and retention
HeartLead uses authentication, access controls, private file storage, temporary file links and other reasonable safeguards. No online service can guarantee absolute security, so users must also protect their sign-in access and use anonymised evidence.
Workspace records are retained while a subscription is active. When a subscription ends, access is paused and records are retained for 90 days so the centre can request an export or reactivate. After 90 days, records may be permanently deleted from active systems unless retention is required by law. Deleted information may remain in protected backups until those backups expire through the provider’s normal cycle. Business, tax and transaction records may be kept for the period required by law.
Emails, cookies and sharing
Service emails, such as invitations, access messages and renewal reminders, are sent as needed to operate the workspace. Marketing emails are sent only where permitted, and you can unsubscribe using the link in the email. The website may use cookies and analytics to operate and improve the service; browser settings can restrict cookies.
HeartLead does not sell or rent personal information. Information is shared only with service providers needed to deliver the service, with your direction or consent, or where required or authorised by law.
Your rights
You may ask for access to or correction of personal information HeartLead holds about you. You may also request account closure or deletion, subject to legal and operational requirements. Workspace requests should normally come from the centre owner so HeartLead can verify authority.
Privacy breaches
If a privacy breach has caused or is likely to cause serious harm, HeartLead will notify the Office of the Privacy Commissioner and affected people as soon as practicable, and will take reasonable steps to contain and respond to the breach.
Contact and complaints
Privacy Officer: Gabby Dyet
Email: heartleadnz@gmail.com
Phone: 027 529 6006
Contact HeartLead with any privacy question, access or correction request, deletion request or complaint. You may also contact the Office of the Privacy Commissioner at privacy.org.nz.
We may update this policy as HeartLead services change. The effective date above will show the latest revision.