Privacy Policy

Effective Date: August 15, 2023

OVERVIEW

We are Veuve Ventures NZ Limited NZBN 9429 0490 28034 trading as Pinot & Picasso (referred to in these terms as “Pinot & Picasso”, “we”, “us”, and “our”) we operate www.pinotandpicasso.nz (Site) and have Studios all across New Zealand.

This Privacy Policy applies to the products and/or services we provide on our Site, our Events and our social media channels, and explains how we collect, hold, use and disclose data and comply with the requirements of the Privacy Act 2020  and constitutes part of our Website Terms & Conditions. 

This Privacy Policy does not cover information that you submit on other websites, even if we communicate with you on those sites. For example, if you post something on Instagram, Facebook, Pinterest, Twitter, or YouTube, that information is governed by the privacy policies on those websites, and is not governed by this Privacy Policy. 

We will only use your personal information in compliance with New Zealand Privacy Laws (Privacy Act 2020), New Zealand Privacy Principles and to the extent applicable, with the EU General Data Protection Regulation (GDPR) and any replacement legislation or regulation or guidelines and standards governing the use, storage or transmission of personal data.

If you have any privacy-related questions, please email us at: hello@pinotandpicasso.nz

UPDATES TO OUR PRIVACY POLICY

Please make sure to check in on our Privacy Policy periodically, as we may update this Privacy Policy from time to time in order to reflect, for example, changes to our practices or for other operational, legal or regulatory reasons. We will always ensure that the current date of the Privacy Policy also known as the “Effective Date” is prominently displayed at the very top of this Privacy Policy, so you know it’s the latest version.

CHOOSING NOT TO PROVIDE PERSONAL DATA

You can choose not to provide us with any personal data. However, if you do this, we will not be able to provide you with any products or services, however, you can continue to use our Site and browse the pages of our Site.

OUR ROLE IN YOUR PRIVACY

If you are a customer, account holder, event attendee, subscriber or just a visitor to our Site, this Privacy Policy will apply to you. 

OUR RESPONSIBILITIES

As we are the providers of the products and services on this Site, we determine how and why your data is processed. We do not sell or rent your details to any third parties. We are committed to protecting your privacy and we want you to know exactly what information is collected and how we use it.

YOUR RESPONSIBILITIES

Please read this Privacy Policy and our Website Terms & Conditions. If you provide us with any data relating to a third party, you confirm that you have the right to authorise us to process that data on your behalf in accordance with this Privacy Policy.

WHEN AND HOW WE COLLECT DATA

From the moment you visit our Site, we are collecting data, sometimes you might provide this data by completing a form or setting up an account, otherwise we might collect the data automatically. 

We may also collect data when:

  • You interact with us on social media;
  • You purchase a gift card for redemption on our Site;
  • You purchase an online course, webinar, program or service;
  • You complete any sign-up forms, landing pages, subscribe to our mailing list or send us an email to any of our nominated emails;
  • You participate in events, competitions, promotions and giveaways or any request for additional data such as customer surveys;
  • You accept our cookies and other tracking technologies on any device you use to interact with us;
  • You submit a delivery form (Art Box); and/or
  • You voluntarily submit your data to us for any reason.

TYPES OF DATA WE MAY COLLECT

  • Contact details (name, address, email, phone number, postal address)
  • Financial Information (credit card when you are making a purchase)
  • Your business name (sometimes)
  • Basic information about your business and its history (sometimes) 
  • Data about the products or services you purchase 
  • Data about your experience with our Site and our products and services
  • Data relating to your circumstances and such other information that is relevant to the products or services we provide to you
  • Data relating to your attendance at seminars or other events held by us (including webinars and podcasts)
  • Data that identifies you (your IP address, login, browser type, time zone, browser plugins, geolocation, what operating system and version) – we do not link this with any personal Data
  • Data on how you use our Site (URL clicks, products and services views, how long you are on our pages and other actions)

USE AND DISCLOSURE OF YOUR DATA

Under data laws, we are only allowed to use your data for specific reasons and where we have the legal basis to do so. 

We will use your data for the purposes it was collected and related purposes that include:

  • Operating our Site 
  • Providing you with products, information and services
  • Customer support
  • Tracking your purchase history
  • Detecting and preventing fraud
  • Improving our Site
  • Making your experience on our Site more efficient and enjoyable
  • Market research e.g. we may contact you for feedback about our products and services
  • Provide you with information about events, other products or services or opportunities that may be of interest
  • Marketing (with your consent)
  • Monitoring your compliance with our Website Terms and Conditions

We may disclose your data for the purposes it was collected and also:

  • As required by law subject to our obligations
  • With your consent
  • Within our business
  • To send you marketing material (with your consent)
  • To process your participation in any promotions and giveaways (including contacting you if you win, displaying your name online and on our social media platforms)
  • Share with third parties to enable us to provide our products and/or services 

GOOGLE ANALYTICS

We use Google Analytics functions. You can find out how your data is collected here and there are instructions here on how to opt-out of Google Analytics data tracking.

Our use of Google Analytics may include but is not limited to display advertising and remarketing. You may see our adverts across the internet, this is due to the use of tracking technologies (cookies) to optimise and serve our adverts based on past visits to our Site as well as groups of individuals based on age, gender, interests and past visits to our site and other sites we use. When you log onto our Site, we, with the help of Google Analytics, use your browsing behaviour to connect this with other data that you previously provided to us in accordance with this privacy policy. Importantly, we do not combine the anonymous information collected through Google Analytics with personally identifiable information.

META INSIGHTS

We use Facebook and Instagram Insights to track your interaction with our pages, this will allow us to track usage and improve the performance of our page. We will use Facebook Analytics to better measure, track and understand customer user experience to enable us to improve our products and services that we offer. You can check out Facebook’s privacy policy here, and if you want to opt out of seeing ads on Facebook based on information we have received, you can control this in your ad preferences here.

COOKIES

Our Site uses cookies and similar technologies to provide certain functionality to our Site and  helps us improve the use experience. “Cookies” are data files that are placed on your device or computer and often include an anonymous unique identifier. Cookies can also be used to analyse traffic and for advertising and marketing purposes. They do not harm your systems and the HELP function in your browser will tell you how to restrict or block the cookies on your individual device.  For more information about cookies, visit http://www.allaboutcookies.org

TURNING OFF COOKIES

You can turn off cookies by activating the setting in your browser that allows you to do this. You can also delete cookies through your browser settings. If you do decide to turn off cookies, you can continue to use the Site, however, certain services may not work as effectively.

MARKETING

We will always let you know before we collect any data from you what the intended use is and if we intend to use it for marketing and if third parties are involved we will obtain your consent (which you can withdraw at any time).

You can change your mind about marketing material at any time by opting out by:

  • Emailing us at hello@pinotandpicasso.nz, with the subject line ‘unsubscribe me’; or
  • Clicking ‘unsubscribe’ at the bottom of any emails we send to you. 

LINKS TO OTHER SITES

During our Events or on our Site and social media channels may have links to other sites operated by third parties. Unless we expressly tell you otherwise, we do not in any way endorse, control or approve of, nor are we responsible for, the content on those websites. It’s up to you to decide if those websites and their content are suitable and appropriate for you. We also encourage you to review the terms and conditions and privacy policy of any third party sites. 

YOUR RIGHTS

You can exercise the following rights in relation to your privacy at any time by contacting us at hello@pinotandpicasso.nz.

ACCESSING INFORMATION WE HOLD ABOUT YOU

We will provide you with the information within 30 days of your request, unless doing so would adversely affect the rights and freedoms of others (e.g. another person’s confidentiality or intellectual property rights). We will tell you if we can’t comply with your request and why.

INACCURATE INFORMATION (right of rectification)

You can contact us to ask us to correct any information we hold about you that you believe is inaccurate.

OBJECTIONS TO USING DATA FOR PROFILING OR AUTOMATED DECISIONS

We may use your data to determine what products and services are relevant to you (e.g. tailoring our emails based on your behaviour). Otherwise, the only circumstances in which we will use this data is to provide our products and services to you.

THE RIGHT TO BE FORGOTTEN

You have the right to request for your data to be erased. This means we have to delete all information that we hold about you, except to the extent of any information we are required to hold due to our legal obligations.

MAKING A COMPLAINT

If you have any complaints regarding how your data is handled, please contact us at hello@pinotandpicasso.nz.  If you are not satisfied with our response to your complaint you may seek a review by contacting the New Zealand Office of the Privacy Commissioner (OPC).

SECURITY OF THE DATA WE COLLECT

We realise that our customers trust us to protect their data and whilst we cannot guarantee the security of any information you transmit to us, or receive from us, we take that task seriously and maintain reasonable and appropriate physical, electronic and procedural safeguards to help protect your data from misuse, interference, modification, disclosure or loss.

This includes the following:

  • Password access to accounts;
  • Storing electronic data with reputable third party storage providers who have appropriate security protections;
  • Limit access to personal information to employees who need to know and who have specific authorisation to access such information; 
  • Using payment providers who are PCI DSS compliant;
  • We do not store your payment details.

WHERE WE STORE DATA

We use service providers based in New Zealand, Australia, United Kingdom, United States of America, Singapore and India. If we transfer personal data outside of New Zealand, we will ensure that your privacy rights are adequately protected by ensuring these service providers have the same or similar measures in place to protect data shared. 

HOW LONG WE STORE DATA FOR

We will keep your data for as long as we need it, and this period will also depend on your interactions with us. If you have made a purchase with us, we will keep a record of your purchase for the period necessary for invoicing and tax purposes. When we no longer need to keep your information, we will delete it permanently or anonymise data that is no longer necessary.

THIRD PARTIES WHO ACCESS YOUR DATA

We share data with third parties in the following circumstances:

  • Other companies in our group of companies, as necessary to operate our Site
  • Our suppliers and service providers working for us e.g. payment processors
  • Our professional and legal advisors
  • Third parties engaged in fraud prevention and detection
  • Law enforcement or other government authorities
  • Share with third parties who enable us to provide our products and services which may include:
    • payment processors such as Stripe, PayPal, Xero, Woocommerce who may process your payment for any products and services bought from us;
    • Social media and analytics such as Facebook, Instagram and Google Adwords for purpose of custom audience generation and the development of targeting criteria;
    • Other third parties such as Klaviyo, Formstack, Monday.com, Typeform etc for processing and holding Data that enables us to ensure you are kept informed of all course information, logins and marketing material, offers, promotions, newsletters, blogs and video training.
  • Where we have your consent to do so or otherwise where we are legally permitted to do so.

PAYMENT SECURITY

All of our real-time credit card authorisations are handled by secure third party gateway providers and these are secured by the highest level of security. 

The following measures are taken to protect your data:

  • Payments are fully automated with an immediate response.
  • Your complete credit card number cannot be viewed by us or any outside party.
  • All transaction data is encrypted for storage within our third party gateway suppliers bank-grade data centre, further protecting your credit card data.
  • Our third party gateway provider is an authorised third party processor for all the major New Zealand banks.
  • Our third party gateway provider will at no time touch your funds, all monies are directly transferred from your credit card to the merchant account held by us.

We use third-party gateway providers that are widely respected for providing secure and reliable online payment solutions. We have chosen to deal with the best so you can feel safe that your personal information is kept safe and secure at all times. While we attempt to protect the information in our possession, no security system is perfect, and we cannot promise that information about you will remain secure in all circumstances.

The Payment Card Industry Data Security Standard (PCI DSS) is an information security standard for all organisations that handle branded credit cards from major card schemes. PCI DSS is a standard mandated by the card brands like Visa, Mastercard, American Express and Discover and is managed by the PCI Security Standards Council.

PCI-DSS requirements help ensure the secure handling of credit card information through our Site and the service providers.

AGE OF MAJORITY

By using this site, you warrant that you are at least the age of majority in your State or Province of residence. Our Site should not be used by anyone under the age of majority, and we do not knowingly collect data from anyone under the age of majority.

GOVERNING LAW

This Privacy Policy and your use of this Site is governed in all respects by the laws of New Zealand.