Privacy Policy
This Privacy Policy relates to [Citation HR Limited (New Zealand) (NZBN 9429047141728) / enableHR Limited (New Zealand) (NZBN 9429041375488)] (“the Company”), the Citation Group entity operating in New Zealand.
Introduction
The Company is committed to safeguarding the privacy of information provided to us and information about visitors to our website and users of our platforms. This Privacy Policy explains how we may collect and use information that we obtain about you, and your rights in relation to that information. Your use of our online services or your provision of information to us constitutes your acknowledgment of the terms of this Privacy Policy. Please do not send us any information which we have not requested, or which is not necessary or relevant to the purpose for which Company is engaged by you.
- 1.1. From time to time the Company is required to collect, hold, use and/or disclose personal information relating to individuals (including, but not limited to prospective employees, clients, suppliers, investors, referees, contractors and employees) in the performance of its business activities.
- 1.2. This Privacy Policy sets out the Company’s policy in relation to the protection of personal information, as under the Privacy Act 2020 (“the Act”).
- 1.3. The Act sets out Information Privacy Principles (“IPPs”) which regulate the handling of personal information.
- 1.4. References in this Privacy Policy to “Group Company” or “Group Companies” mean Citation Group entities operating in Australia, New Zealand and the United Kingdom. Details of relevant group entities can be provided upon request.
Last Updated: 12/08/2026
What is personal information
- 2.1. Personal information means information about an identifiable individual as defined in the Act. Personal information can include anything that can contain personal information, including notes, emails, recordings, photos and scans, whether they are in hard copy or electronic form.
Kinds of information that the Company collects and holds
- 4.1. The Company collects personal information that is reasonably necessary for one or more of its functions or activities.
- 4.2. The type of information that the Company collects and holds may depend on your relationship with the Company. For example:
- a. Prospective Employee: if you are someone seeking employment with the Company, the Company may collect and hold information including your name, address, email address, contact telephone number, gender, age, employment history, references, resume, medical history, emergency contact, taxation details, qualifications and payment details.
- b. Employee: if you are an employee of the Company, the Company may collect and hold employee records such as about your engagement, training, performance, health, disciplining, resignation, termination, and terms and conditions of employment.
- c. Client: if you are a client of the Company, the Company may collect and hold information including your name (including name prefix or title), contact details (such as your postal address, email address and phone number(s)), nationality, identification, gender, organisation, business interests, employment, positions held, billing and financial information (such as billing address, bank account and payment information) and enquiry/complaint details. We may also collect personal information about your other dealings with us and our clients, including any contact we have with you in person, by telephone, email or online.
- d. Supplier: if you are a supplier of the Company, the Company may collect, hold, use and disclose information including your name, address, email address, contact telephone number, business records, billing information, information about goods and services supplied by you.
- e. Referee: if you are a referee of a prospective employee, the Company may collect and hold information including your name, contact details, current employment information and professional opinion of the prospective employee.
- f. End User: if you are an employee, contractor or other individual whose personal information is provided to us by a client (such as your employer) for the purpose of accessing or being administered through our HR, safety, learning or related platforms, we may collect and hold information including your name, contact details, employment details, role and reporting information, and other information relevant to the services provided to our client.
- 4.3. Personal information that may be considered sensitive: the Company will only collect personal information that may be considered sensitive (for e.g. an opinion about racial or ethnic origin, political opinions, religious beliefs, philosophical beliefs, membership of a trade union, sexual preferences, criminal record, health information or genetic information) where you consent to the collection of the information and the information is necessary for the Company’s lawful purpose or as otherwise permitted under the Act.
- 4.4. By providing this information to us, or consenting to a third party (such as your employer) providing that information to us, you consent to our collection and use of that information as set out in this Privacy Policy.
How the Company collects and holds personal information
- 5.1. The Company will only collect personal information for lawful purposes connected with its functions and the information is necessary for that purpose. The Company will collect personal information directly from you if it is reasonable or practicable to do so.
- 5.2. The Company and any Group Company may collect personal information in a number of ways, including without limitation:
- a. through application forms;
- b. by email or other written mechanisms;
- c. over a telephone call;
- d. in person;
- e. through transactions;
- f. through our website;
- g. through surveillance cameras;
- h. by technology that is used to support communications between us; from third parties, including but not limited to:
- i. from past and present employers and referees when conducting reference checks, clients of the Company and contract management services in relation to assignments;
- ii. through publicly available information sources (which may include telephone directories, the internet and social media sites); and
- iii. direct marketing database providers;
- i. by the disclosure of the personal information between the Group Companies.
- 5.3. When the Company collects personal information about you through third parties, it will manage such information in accordance with the IPPs.
- 5.5. When the Company speaks to you on the phone, or holds video conferences with you, calls may be recorded for security, training and quality assurance purposes.
Purposes for which the Company collects, holds, uses and/or discloses personal information
- 6.1. The Company will collect personal information if it is reasonably necessary for one or more of its functions or activities.
- 6.2. In most cases, you will be required to identify yourself when you deal with us, such as when you (or an associated company or other entity) become a client of ours. If you do not provide us with the personal information detailed above, some or all of the following may happen:
- we may not be able to accept you (or your associated company or other entity) as a client or provide our services to you or your associated company or other entity;
- we may not be able to provide you with our publications, brochures and newsletters; and
- we may be unable to tailor the content of our website to your preferences and your experience of our website may not be as relevant or useful as it could be.
- 6.3. We will normally hold your personal information in a database. We collect, hold, use and disclose your personal information for some or all of the following purposes:
- administering our relationship with you, including providing services, responding to enquiries and obtaining payment for our services;
- to manage and enhance our platforms, products and services;
- processing applications for employment;
- business development – to provide you with information about the Company’s and the Group Company’s existing and new products and services (including for direct marketing purposes as described in clause 7 below, sending legal and other updates, publications, and details of events and tracking and recording your opening of our email communications and clicking on any links in our email communications);
- providing and administering legal and consulting services;
- meeting legal or other regulatory obligations imposed on us;
- auditing and managing the usage of our website;
- to update our records and keep your contact details up to date;
- to process and respond to any complaint made by you; and
- to comply with any law, rule, regulation, lawful and binding determination, decision or direction of a regulator, or other governmental authority.
- 6.4. The Company may also collect, hold, use and/or disclose personal information if you consent or if required or authorised under New Zealand law. For example, the Company may collect your Inland Revenue Number (IRD) where required to do so for lawful purposes.
Direct marketing
- 7.1. The Company or any of the Group Companies may use or disclose personal information about you for the purpose of direct marketing (for example, advising you of new goods and/or services being offered by the Company and the Group Companies).
- 7.2. The Company or any of the Group Companies may use or disclose personal information about you to the other Group Companies for the purpose of cross promotions and direct marketing of the other Group Company’s products and services consistent with the limits set out in the Act.
- 7.3. You can opt out of receiving direct marketing communications from the Company by contacting our Privacy Officer in writing or if permissible accessing the Company’s website and unsubscribing appropriately.
Disclosure of personal information
- 8.1. The Company may disclose your personal information for any of the purposes for which it is was collected, as indicated under clause 6 of this Privacy Policy, or where it is under a legal duty to do so.
- 8.2. Disclosure will usually be internally, to related entities but may otherwise include third parties such as contracted service suppliers (CSP). Examples of CSPs include, but are not limited to, financial institutions for payment processing, information technology service providers, marketing and communications agencies, printers and distributers of direct marketing material and external business advisors.
- 8.3. Before the Company discloses personal information about you to a third party, the Company will take steps as are reasonable in the circumstances to ensure that the third party does not breach the IPPs in relation to the information. While we take all reasonable steps to ensure the security of our system, we cannot provide any guarantee regarding security of the personal information and other data transmitted to us and we will not be held responsible for events arising from unauthorised access of your personal information.
Access to personal information
- 9.1. If the Company holds personal information about you, you may request access to that information by putting the request in writing and sending it to our Privacy Officer. The Company will respond to any request within a reasonable period, but no more than 20 days. Access requests will generally be provided free of charge. However, where permitted under the Act, the Company may charge a reasonable fee in exceptional circumstances.
- 9.2. There are certain circumstances in which the Company may refuse to grant you access to the personal information. For example, we may need to refuse access if granting access would interfere with the privacy of others or if it would result in a breach of confidentiality or legal professional privilege.
- 9.3. In such situations the Company will give you written notice that sets out:
- a. the reasons for the refusal; and
- b. the mechanisms available to you to make a complaint.
Correction of personal information
- 10.1. If you wish to access, verify, or correct of any of the personal information you have submitted to us, you may do so by contacting us via hello@citationgroup.co.nz. As soon as practicable after your request, we will take reasonable steps to allow for corrections to be made to this information unless an exception under the relevant privacy or data protection laws apply.
- 10.2. There are certain circumstances in which the Company may refuse to correct the personal information. In such situations the Company will give you written notice that sets out:
- a. the reasons for the refusal; and
- b. the mechanisms available to you to make a complaint.
- 10.3. If the Company corrects personal information that it has previously supplied to a third party and you request us to notify the third party of the correction, the Company will take such steps as are reasonable to give that notification unless impracticable or unlawful to do so.
Integrity and security of personal information
- 11.1. The Company will take such steps (if any) as are reasonable in the circumstances to ensure that the personal information that it:
- a. collects is accurate, up-to-date and complete; and
- b. uses or discloses is, having regard to the purpose of the use or disclosure, accurate, up-to-date and complete.
- 11.2. The Company will take steps as are reasonable in the circumstances to protect the personal information from misuse, interference, loss and from unauthorised access, modification or disclosure.
- 11.3. If the Company holds personal information, it no longer needs the information for any purpose for which the information may be used or disclosed, and the Company is not required by law to retain the information, it will take such steps as are reasonable in the circumstances to destroy the information or to ensure it is de-identified.
Anonymity and pseudonymity
- 12.1. You have the option of not identifying yourself, or using a pseudonym, when dealing with the Company in relation to a particular matter. This does not apply
- a. where the Company is required or authorised by or under a New Zealand law, or a court/tribunal order, to deal with individuals who have identified themselves; or
- b. where it is impracticable for the Company to deal with individuals who have not identified themselves or who have used a pseudonym.
- 12.2. However, in some cases if you do not provide the Company with your personal information when requested, the Company may not be able to respond to your request or provide you with the goods or services that you are requesting.
Overseas disclosure and cloud
- 13.1. The Company may disclose Personal information about an individual overseas. This is likely to occur where the Company uses “cloud” service providers.
- 13.2. We will disclose information overseas only where the recipient is subject to comparable safeguards (e.g. binding contractual clauses or equivalent law) or with your consent after we inform you that the recipient may not be required to protect it comparably. We will comply with the requirements of IPP 12 of the Act when assessing overseas disclosures.
Notifiable privacy breaches
What is a Notifiable Privacy Breach?
- 14.1. A Notifiable Privacy Breach occurs when Personal information of an individual held by the Company is accessed by, or is disclosed to, an unauthorised person, or is lost, and:
- a. it is reasonable to believe that the unauthorised access or disclosure has caused serious harm to the relevant individual or would likely result in serious harm to the relevant individual; or
- b. in the case of loss unauthorised access or disclosure of Personal information is likely to occur, and it is reasonable to believe that the unauthorised access or disclosure would likely result in serious harm to the relevant individual.
Assessment
- 14.2. If the Company suspects that a Notifiable Privacy Breach has occurred, it will conduct a reasonable and expeditious assessment to determine if there are reasonable grounds to believe that a Notifiable Privacy Breach has occurred.
- 14.3. The Company will take all reasonable steps to ensure that the assessment is completed as soon as practicable.
Notification
- 14.5. Subject to the Act, in the event a Notifiable Privacy Breach occurs, the Company will, as soon as practicable, prepare a statement outlining details of the breach and:
- a. notify the individual of the unauthorised access, disclosure or breach; and
- b. notify the Office of the Privacy Commissioner of the unauthorised access, disclosure or breach.
Complaints
- 15.1. You have a right to complain about the Company’s handling of your personal information if you believe the Company has breached the IPPs.
- 15.2. If you wish to make such a complaint to the Company, you should first contact the Privacy Officer in writing. Your complaint will be dealt with in accordance with the Company’s complaints procedure and the Company will provide a response within a reasonable period.
- 15.3. If you are unhappy with the Company’s response to your complaint, you may refer your complaint to the Office of the Privacy Commissioner.
Cookies and statistical analysis
- 16.1. We use cookies. When you use our platforms or visit our website, certain information may be recorded for statistical purposes. Such information enables us to improve our products and services. The information that may be recorded includes information regarding your:
- a. server address;
- b. domain name;
- c. date and time of visit;
- d. previous websites visited;
- e. browser type and operating system; and location data; and
- f. more information about the types of cookies we use, why, and how you can control them please read our cookie notice.
Company and Privacy Officer contact details
The Company’s Privacy Officer can be contacted in the following ways:
Company Privacy Officer
Telephone number: 09 200 3555
Email address: hello@citationgroup.co.nz
Postal address: Unit 4, Level 1/101 Main Highway Ellerslie, Auckland 1051