Privacy Policy

Privacy Policy Highlights | Privacy Policy | Cross Border Disclosures of Personal Information | Credit Reporting Policy

In this Privacy Policy, the expressions “Michael Hill”, "we", "us" and "our" are a reference to Michael Hill Jeweller Limited and its related companies (as defined by the provisions of the Companies Act 1993).

At Michael Hill, we want your online and in-store experience to be enjoyable and we take care to respect your privacy when you visit our website and our stores. We endeavour to handle your personal information responsibly and to act fairly and honestly with all our customer transactions. We do this gladly because we know that if you have a good experience with us, you will want to visit our website and our stores again... and maybe even tell your friends about us.

This Privacy Policy applies to 'personal information' as that term is defined in the Privacy Act 1993 that we collect about identifiable individuals ("you", "your". We are bound by the New Zealand Privacy Act 1993, which governs the way agencies such as Michael Hill collect, use, keep secure and disclose personal information.

The purpose of this Privacy Policy is to generally inform people of:

  • how and when we collect personal information;
  • how we use and disclose personal information;
  • how we keep personal information secure, accurate and up-to-date;
  • how an individual can request access to and correction of their personal information; and
  • how we will facilitate or resolve a privacy complaint.

If you have any concerns or complaints about the manner in which your personal information has been collected, used or disclosed by us, we have put in place an effective mechanism and procedure for you to contact us so that we can attempt to resolve the issue or complaint. Please see Section 13 (Resolving Privacy Complaints) for further details.

Our privacy officer can be emailed at online@michaelhill.co.nz or written to at GPO Box 2922, Brisbane, Australia 4001. Our privacy officer will then attempt to resolve the issue. We recommend that you keep this information for future reference.

1. What is personal information?

The Privacy Act 1993 defines “personal information” to mean information about an identifiable individual

2. The kinds of personal information collected, used and disclosed by Michael Hill

We will only use or disclose the personal information we collect about you for the purposes for which it was collected, as set out in this Privacy Policy, or as otherwise required or authorised by law, including under the Privacy Act 1993.

At or around the time we collect personal information from you, we will endeavour to tell you how we will use and disclose that specific information.

We set out some common collection, use and disclosure instances in the following table. You authorise us to collect, use and disclose your personal information for the purposes set out in that table.

Purpose
Type of Information Uses Disclosures
Sales and enquiries (online and in-store)
  • Contact information: Such as your name, email address, postal and residential addresses, phone numbers, country of residence (and, if applicable, age).
  • Life-event information: Such as your date of birth and other anniversaries (wedding, birthday, partner’s birthday etc).
  • Product Information: Such as products or services you are interested in or products or services that you have purchased from us or our affiliated partners and organisations.
  • Transactional information: Such as
    • Product details and order summary.
    • Details in relation to your financial institution.
    • Payment card type.
    • Card number.
    • Expiry date.
    • CVV number.
    • Proof of ID (e.g. driver’s licence).
  • In-store security information: Such as in-store CCTV footage, photographs or information used to secure ecommerce transactions.
  • Customer services: Information collected in connection with us recording calls to our customer services department for quality assurance purposes.
    The types of uses we will make of personal information collected for this type of purpose include:

  • Identity verification: if required, the verification of your identity and age.
  • Sales and delivery: the provision of our products and services to you including:
    • Using your personal information in our point-of-sale messaging application “Leadbooks”, in order to contact you regarding products, services or events we think would be of interest to you.
    • Payment processing, including charging, credit card authorisation, verification and debt collection.
    • Checks for financial standing and credit-worthiness.
    • Delivery.
  • After-sale services:
    • Refunds, exchanges, warranty claims or repairs.
    • Uses in connection with purchased Professional Care Plans.
    • Details of current and past products purchased.
    • To provide customer service functions, including handling customer enquiries and complaints.
    • To provide you with product awareness information.
  • Marketing and consumer analytics: using your personal information to:
    • Aggregate with other information we hold about you, and to then use that data for marketing and consumer analytics.
    • Offer you updates, or other content or products and services or events that may be of interest to you.
    • Improve our services (including contacting you about those improvements and asking you to participate in surveys and reviews about our products and services).
    • Marketing and promotional activities by us (including by direct marketing by mail, telemarketing, email, SMS and MMS messages) such as our customer loyalty programs and newsletters.
  • General administrative and security use:
    • To protect Michael Hill stores and websites from security threats, theft, fraud, burglary or other criminal activities.
    • The administration and management of Michael Hill.
    • The maintenance and development of our products and services, business systems and infrastructure.
    • In connection with the sale of any part of Michael Hill’s business or a company owned by a Michael Hill entity.
    • To provide customer services to customers and for quality assurance purpose when calls are made to our customer services department
    The types of disclosures we will make of personal information collected for the type of purposes listed include, without limitation, to:

  • Third party service providers utilised in connection with our point-of-sale messaging application “Leadbooks”.
  • Service providers (including IT service providers).
  • Related companies of Michael Hill (including related entities in New Zealand, Australia, Canada and the United States of America).
  • Third parties connected with the sales and after sales process including, payment platform providers, financial institutions, credit service providers and credit reporters.
  • Third parties connected with the sales process including, on our behalf and any third party providers who provide us with ecommerce services, or who assist us in providing our products and services to you.
  • Third parties connected with the marketing process including, messaging service providers, marketing list providers or other third parties who assist us in providing our products and services to you.
  • Third parties in connection with the sale of any part of Michael Hill’s business or a company owned by a Michael Hill entity.
  • We also make other disclosures as authorised by you or as required or authorised by law.
Credit services
  • Contact and identifying information:
    • Your name.
    • Address, previous address, time spent at current address and previous address.
    • Date of birth.
    • Relationship status.
    • Email address.
    • Contact numbers.
    • Residential status (rent, board, home owner etc).
    • Number of dependants (spouse, children, etc).
    • Details of required primary identification information (such as a current New Zealand drivers licence, passport, birth certificate, etc).
    • Details of required secondary identification information (such as a utility bill, rates etc).
    • Alternative Contact (name, address and phone number).
  • Credit information: Personal credit information relating to your financial standing, credit and credit worthiness, including, but not limited to:
    • Employment status and details (including time worked and industry).
    • Financial details (bank account details, personal assets, weekly income, share of living expenses, mortgage and loan payments, number of credit/store cards, balance and limits of store/credit cards).
    • Requested credit limit.
  • Credit reporting:
    • The processing of any application and the consideration of your credit information.
    • The processing of any payments, refunds or exchanges.
    • For full details relating to uses of personal information in relation to any credit services which are offered via Michael Hill, please refer to our Credit Reporting Policy.
  • Marketing: In addition, we may also use this type of personal information for marketing purposes (including direct marketing) and:
    • To aggregate with other information we hold about you, and to then use that data for marketing and consumer analytics.
    • Offer you updates, or other content or products and services that may be of interest to you.
    • Improve our services (including contacting you about those improvements and asking you to participate in surveys about our products and services).
    • Marketing and promotional activities by us (including by direct mail, telemarketing, email, SMS and MMS messages) such as our customer loyalty programs and newsletters.
  • General administrative and security use:
    • To protect Michael Hill stores and websites from security threats, theft, fraud, burglary or other criminal activities.
    • The administration and management of Michael Hill.
    • The maintenance and development of our products and services, business systems and infrastructure.
    • In connection with the sale of any part of Michael Hill’s business or a company owned by a Michael Hill entity.
In summary, we may disclose this type of personal information to:
  • The third party credit provider who is providing (or may provide) credit services to you, the details of which are set out in our Credit Reporting Policy.
  • Credit reporting agencies and credit providers, the details of which are set out in our Credit Reporting Policy.
  • Our contractors and agents, including but not limited to third party providers who undertake our bill and/or credit services on our behalf and any third party providers who provide us with ecommerce services, or who assist us in providing our products and services to you.
  • Offshore and New Zealand service providers (including IT service providers), if any.
  • To third parties in connection with the sale of any part of Michael Hill’s business or a company owned by a Michael Hill entity.
  • Related companies of Michael Hill (including related entities in New Zealand, Australia, Canada and the United States of America).
  • As required or authorised by law.
  • For full details relating to disclosures of personal information in relation to any credit services which are offered via Michael Hill, please refer to our Credit Reporting Policy.
Marketing services which includes social media
  • Contact information: Such as your name, email address, current postal and residential addresses, phone numbers, country of residence (and, if applicable, age).
  • Life-event information: Such as your date of birth, anniversaries (wedding, birthday, partner’s birthdays etc).
  • Product and service interests: Such as:
    • Products or services you are interested in.
    • Products or services that you have purchased.
    • Aggregated information provided by services such as Google Analytics and Remarketing.
  • Social media activity: Including “likes”, comments posted, any of your oppositions or feedback, photos posted or uploaded and other information pertaining to your social media activities which concern, or relate, to Michael Hill.
  • Events: including your attendance at any event and participation in any competitions or promotions, photos taken or any reviews or product preferences provided by you.
  • Digital device information: Information which identifies your digital devices, such as the media access control address (or MAC address) of your mobile phone or other digital devices.
  • General marketing and consumer analytics: using your personal information to:
    • Aggregate with other information and to then use it for marketing and consumer analytics.
    • Offer you updates, or other content or products and services that may be of interest to you.
    • Improve our services (including contacting you about those improvements and asking you to participate in surveys or reviews about our products and services).
    • Marketing and promotional activities by us (including by direct mail, telemarketing, email, SMS and MMS messages) such as our customer loyalty programs and newsletters.
    • In connection with the sale of any part of Michael Hill’s business or company.
  • Online accounts or social media: If you create an account with Michael Hill, attend an event run or facilitated by Michael Hill (or its agents) or participate in our social media platforms (such as Facebook, Twitter, Google+, YouTube, Instagram) and you provide us your personal information, we may use it for:
    • Drawing and contacting winners.
    • Adding entrants to marketing database.
    • Responding to social media messages.
    • Customer service related contact.
    • Fulfilling social media platform rules.
    • Passport details required for prizes with travel.
  • Identity verification: if required, the verification of your identity and age.
  • Location-based and device-based marketing: we may use information we collect about your geographical location and digital devices (such as your device MAC address) to send you marketing communications.
We may disclose your personal information to:
  • Our third party partners, such as magazines, media companies who assist us with a competition or promotion.
  • Third parties in connection with the sale of any part of Michael Hill’s business or a company owned by a Michael Hill entity.
  • Service providers (including IT service providers).
  • Third party service providers utilised in connection with our point-of-sale messaging application “Leadbooks”.
  • Third parties in connection with the sale of any part of Michael Hill’s business or a company owned by a Michael Hill entity.
  • Third parties connected with the marketing process including, messaging service providers, marketing list providers or other third parties who assist us in providing our products and services to you.
  • We may also make other disclosures as authorised by you or as required or authorised by law.
Human resources
  • Contact information: Such name, e-mail address, current postal and residential address, phone numbers, country of residence, next of kin contact details.
  • Employee record information
  • Identifying information: Such as your photo, passport and residency details, date of birth.
  • CV, resume or candidacy related information: Such as the details provided in your resume or CV, your eligibility to work in New Zealand, your education, previous employment details, professional memberships or trade qualifications.
  • Tax, superannuation and payroll information: Such as your IRD Number, Superannuation details and financial institution details.


  • Background check information: Information obtained from you or third parties to perform background checks. In order to perform background checks we may require the following types of information from you:
  • Birth certificate, passport or citizenship certificate.
  • Address over last 5 years.
  • Driver’s licence details.
  • Land rate or water rates or other type of utility bill.
  • Credit or debit card details.
  • If applicable, marriage certificate or civil union certificate.
  • We may perform the following types of background checks:
  • Bankruptcy and directorship search and company checks
  • Criminal history.
  • Social media activity.
  • Medical or health information which you voluntarily provide to us (we do not require you to provide this information unless it is related to an incident which has occurred during the course of your employment).
  • Performance related information: Including information and metrics collected by Michael Hill systems in the course of the employee or contractor’s engagement with Michael Hill.
  • Information collected from referees
  • Security information: Such as CCTV security.
  • Background checks: Utilising the information collected for the purpose of assessing candidate suitability for role, including by obtaining:
    • Verification of your identity and age.
    • Criminal history background checks including publically available information including Facebook, Twitter, Instagram, YouTube.
    • Confirmation of eligibility to work in New Zealand.
    • Confirmation of education and qualifications.
    • Confirmation of previous employment.
    • Consideration regarding sick leave.
  • Administration and performance monitoring use: Utilising the information collected for the purpose of:
    • Dealings related to the employer/employee relationship or the contractor/principal relationship (as the case may be).
    • Use of such information whether or not the employment or contractor relationship is prospective, current or past.
    • To facilitate any purchase of any products and associated discounts.
    • Use of such information to monitor systems, performance and time usage and internet usage.
  • General administrative and security use:
    • To protect Michael Hill stores, systems and websites from security threats, fraud, theft, burglary or other criminal activities.
    • The use of your personal information collected in the administration and management of Michael Hill.
    • In connection with the sale of any part of Michael Hill’s business or a company owned by a Michael Hill entity.
We may disclose your personal information to:
  • Superannuation – your superannuation provider.
  • Inland Revenue Department (IRD).
  • Accident Compensation Corporation (ACC).
  • Third party referees provided by you in connection with an application made to Michael Hill.
  • Service providers (including IT service providers), if any.
  • Recruitment agents used in connection with your application with us.
  • Third parties in connection with the sale of any part of Michael Hill’s business or a company owned by a Michael Hill entity.
  • Third party parties in connection with obtaining any background checks, pre-employment screening (including without limitation psychometric services) or loss prevention consultation and implementation programs.
  • Financial institutions for payroll purposes.
  • As required or authorised by law.

3. How Michael Hill collects and holds personal information

3.1 Collection generally

As much as possible or unless provided otherwise in this Privacy Policy or a notification, we will collect your personal information directly from you. Most often, this personal information will be collected from you in connection with a purchase you make from us (whether online or in-store). However, we may collect your personal information from other sources in circumstances permitted by the Privacy Act 1993 or as set out in this Privacy Policy.

When you engage in certain activities online or in-store, such as entering a contest or promotion, filling out a survey or sending us feedback, we may ask you to provide certain information. It is completely optional for you to engage in these activities.

Depending upon the reason for requiring the information, some of the information we ask you to provide may be identified as mandatory or voluntary. If you do not provide the mandatory information or any other information we require in order for us to provide our products or services to you, we may be unable to provide our products or services to you in an effective manner, or at all.

3.2 Other collection types

We may also collect personal information about you from other sources, such as competitions and also from third parties. Some examples of these alternative collection events are:

  • (a) trade promotions, competitions and games (whether in-store or online), including those run by us or run by third parties who participate with us;
  • (b) when we collect personal information about you from someone you know, such as someone who buys a gift for you and your personal information is provided in connection with the purchase of that gift;
  • (c) when we use digital devices and applications to automatically collect information about the digital devices you use near our stores or to otherwise interact with us; when we collect personal information about you from a referee provided by you on an application made with us;
  • (d) (d) when we collect personal information about you from a referee provided by you on an application made with us;
  • (e) when we collect personal information about you from credit reporters, in connection with any credit applications made with us or through us as an agent for a third party credit provider;
  • (f) when we collect personal information about you from third parties (including other retailers) as part of a co-promotion that we participate in; or
  • (g) when we collect personal information about you from publically available sources including but not limited to court judgments, directorship and bankruptcy searches, New Zealand Post, White Pages directory, and social media platforms (such as Facebook, Twitter, Google, Instagram etc).

3.3 Notification of collection

If we collect details about you from someone else, we will, whenever reasonably possible, make you aware that we have done this and why, unless special circumstances apply, including as described in clauses 3.3(a) to 3.3(d) below. Generally speaking, we will not tell you when we collect personal information about you in the following circumstances:

  • (a) where personal information is collected from third party credit reporters;
  • (b) where personal information is collected from any credit referee, trade referee or personal referee you have listed on any application form (including any employment application) with Michael Hill;
  • (c) where personal information is collected from publically available sources including but not limited to court judgments, directorship and bankruptcy searches, social media platforms (such as Facebook, Twitter, Google, Instagram etc); or
  • (d) as otherwise required or authorised by law, including under the Privacy Act 1993.

3.4 Unsolicited personal information

In the event we collect personal information from you, or a third party, in circumstances where we have not requested or solicited that information (known as unsolicited information), and it is determined by Michael Hill (in its absolute discretion) that the personal information is not required, we will destroy the information or ensure that the information is modified so that you cannot be identified.

In the event that the unsolicited personal information collected is in relation to potential future employment with Michael Hill, such as your CV, resume or candidacy related information, and it is determined by Michael Hill (in its absolute discretion) that it may consider you for potential future employment, Michael Hill may keep the personal information on its human resource records.

3.5 How we hold your personal information

Once we collect your personal information, we will either hold it securely and store it on infrastructure owned or controlled by us or with a third party service provider who have taken reasonable steps to ensure they comply with the Privacy Act 1993. We provide some more general information on our security measures in Section 11 (Data security and quality).

4. Uses and discloses of personal information

4.1 Use and disclose details

We provide a detailed list at Section 2 of some common uses and disclosures we make regarding your personal information that we collect. You authorise us to collect, use, and disclose your personal information for the purposes set out in section 2.

4.2 Other uses and disclosures

We may also use or disclose your personal information without seeking your additional authorisation:

  • (a) in connection with any of the purposes identified in Section 2 or for a purpose directly related to any of the purposes identified in Section 2;
  • (b) if we reasonably believe that the use or disclosure is necessary to lessen or prevent a serious or imminent threat to an individual’s life, health or safety or to lessen or prevent a threat to public health or safety;
  • (c) if we have reason to suspect that unlawful activity has been, or is being, engaged in; or
  • (d) if it is required or authorised by law, including under the Privacy Act 1993.

4.3 Use and disclosure procedures

In the event we propose to use or disclose such personal information other than for reasons set out in the above table at Section 2 , or at clause 4.2, or as otherwise outlined in this Privacy Policy, we will first notify you and seek your authorisation prior to such disclosure or use.

Your personal information is disclosed to the organisations or parties referred to in the table at Section 2 only in relation to the products or services we provide to you or for a purpose permitted by this Privacy Policy.

We take such steps as are reasonable to ensure that these organisations or parties are aware of the provisions of this Privacy Policy in relation to your personal information.

4.4 Communications opt-outs

If you have received marketing communications (i.e. comercial electronic messages) from us and you no longer wish to receive those sorts of communications, you should contact us via the details set out at the top of this document and we will ensure the relevant marketing communication ceases. Any other use or disclosure we make of your personal information will only be as required or authorised by law or as permitted by this Privacy Policy or otherwise with your consent.

5. Direct Marketing

5.1 Express informed consent

You give your express and informed consent to us using your personal information set out in:

  • (a) the “Sales and enquiries (ecommerce and in-store)” row of the table at Section 2 of this document above;
  • (b) the “Credit services” row of the table at Section 2 of this document above; and
  • (c) the “Marketing services which include Social Media” row of the table at Section 2 of this document above,
  • (d) when we collect personal information about you from credit reporting bodies, in connection with any credit applications made with us or through us as an agent for a third party credit provider;

to provide you with information and to tell you about our products, services or events or any other direct marketing activity (including third party products, services, and events) which we consider may be of interest to you, whether by post, email, SMS, MMS, messaging applications and telephone ("Direct Marketing Communications").

5.2 Inferred consent

Without limitation to paragraph 5.1, if we reasonably infer that you consent to receiving Direct Marketing Communications (e.g. not opting out where an opt-out opportunity has been provided to youor based on the transactions or communications you have had with us) then we may also use your personal information for the purpose of sending you Direct Marketing Communications which we consider may be of interest to you.

5.3 Opt-out

If at any time you do not wish to receive any further Direct Marketing Communications from us or others under this Section 5, you may ask us not to send you any further information about products and services and not to disclose your information to other organisations for that purpose. You may do this at any time by using the “unsubscribe” facility included in the Direct Marketing Communication (if any) or by contacting us via the details set out at the top of this document. You agree, pursuant to section 11(2) of the Unsolicited Electronic Messages Act 2007, that the person sending such Direct Marketing Communication need not include a functional unsubscribe facility in that communication.

6. Online Information

6.1 Online information generally

We endeavour to provide clear, complete and up-to-date information online about our business and the products and services we offer. This includes how to get in touch with us. This information helps you to make informed choices.

6.2 Online contracts and ecommerce

We keep records of online contracts, including when we accept one or more of your offer(s) to purchase product or services using our website. Our system also helps you to keep an accurate record so there is no confusion about the contract.

If you have a problem with any of our products or services that you receive from us, our website provides further information about how to make a complaint, obtain redress or pursue dispute resolution. We can be emailed at online@michaelhill.co.nz if there is a problem.

6.3 Collections of personal information via linked websites

This website may offer links to other websites. Those websites may also collect your personal information (including information generated through the use of cookies) when you visit them. We are not responsible for how such third parties collect, use or disclosure your personal information, so it is important to familiarise yourself with their privacy policies before providing them with your personal information.

6.4 Uses and disclosures for cross border shipments

If you engage in electronic commerce on this website (i.e. when you purchase our products or services), please be aware that cross border shipments are subject to opening and inspection by customs authorities. In order to facilitate customs clearance and comply with local laws, we may provide certain order, shipment and product information (such as name and titles) to our international carriers and such information may be communicated by the carriers to customs authorities. Customs authorities require the value of the product item to be stated directly on the package.

6.5 Cookies and IP addresses

If you use our website, we may utilise "cookies" which enable us to monitor traffic patterns, trends and to serve you more efficiently if you revisit a Michael Hill website or store. In most cases, a cookie does not identify you personally but may identify your internet service provider or computer.

We may gather your IP address as part of our business activities and to assist with any operational difficulties or support issues with our services. This information does not identify you personally.

However, in some cases, cookies may enable us to aggregate certain information with other personal information we collect and hold about you. Michael Hill extends the same privacy protection to your personal information, whether gathered via cookies or from other sources, as detailed in this Privacy Policy.

You may be able to set your browser to notify you when you receive a cookie and this will provide you with an opportunity to either accept or reject it in each instance. However, if you disable cookies, you may not be able to access certain areas of our websites or take advantage of the improved web site experience that cookies offer.

7. Google Analytics, Display Advertising and Remarketing

7.1 Persistent cookies

We use persistent cookies to enable basic web traffic analysis using Google Analytics which, for example, shows us which areas of our website are popular against those that are not visited often. This allows us to prioritise our enhancements to our website and increase the productivity of our website. We also use persistent cookies in relation to affiliate marketing with web based traffic through affiliate networks.

7.2 Google features

We may undertake and use the following Google features on our website, Google Analytics, Google Adwords, Remarketing and DoubleClick. These features do not use any identifiable personal information. We do not facilitate the merging of your personal information with any non-personal information unless we notify you and you opt-in to that merger.

Google may include in-ads notice labels to disclose interest-based advertising to you. Third-party vendors and search engines, including Google, will show Michael Hill ads on websites and search-results across the Internet. Michael Hill and third-party vendors, including Google, use first-party cookies (such as the Google Analytics cookie) and third-party cookies (such as the DoubleClick cookie) together to inform, optimise, and serve ads based on an individual's past visits to the Michael Hill websites.

7.3 Google Remarketing

We may also use Google Remarketing with Google Adwords and Google Analytics to display content specific advertisements to visitors that have previously visited our website when those visitors go to other websites that have implemented the Google Display Network.

7.4 Opt-out via Google

As a visitor to our website, you may be able to opt out of Google's use of cookies by visiting Google's Ads Settings and you may be able to opt out of Google’s DoubleClick’s use of cookies by visiting the DoubleClick opt-out page . Alternatively, you may be able to opt out of a third-party vendor's use of cookies by visiting the Network Advertising Initiative opt out page.

8. Credit Information and our Credit Reporting Policy

8.1 Credit information generally

The Credit Reporting Code contains provisions regarding the use and disclosure of credit information, which applies in relation to the provision of both consumer credit and commercial credit.

8.2 Credit information and Michael Hill

When you apply for credit in relation to any products or services you may purchase from Michael Hill, or where you agree to be a guarantor, we may need to (or our credit provider may need to) carry out credit reference checks in relation to you. One of the credit checks will include, but is not limited to, obtaining a credit report about you.

8.3 Consent

To the extent necessary, you give your express voluntary consent to Michael Hill and its credit provider to obtaining credit reports about you from credit reporters. We, or our credit provider, use credit related information for the purposes set out in the “Credit services” section of the table at Section 2 above and our Credit Reporting Policy which includes but is not limited to using the information for our own internal assessment of your credit worthiness.

8.4 Storage and access

To the extent we are required to keep a copy of your application for credit or require credit information for purposes set out in this Privacy Policy, we will store any credit information you provide us, or which we obtain about you, with any other personal information we may hold about you.

You may request to access or correct your credit information in accordance with the provisions of Section 12 and the provisions of our Credit Reporting Policy.

8.5 Complaints

Please see Section 13 and the provisions of our Credit Reporting Policy if you wish to make a complaint in relation to our handling of your credit information.

8.6 Credit providers and credit reports

Our credit service providers obtain credit reports from credit reporters. More information about this is set out in our Credit Reporting Policy (including information about how those credit reporters can be contacted).

8.7 Our Credit Reporting Policy

Please see our Credit Reporting Policy for further information as to the manner in which we collect, use, store and disclosure credit information.

9. Anonymity and pseudo-anonymity

To the extent practicable and reasonable, we will endeavour to provide you with the option of dealing with Michael Hill on an anonymous basis or through the use of a pseudonym. However, there may be circumstances in which it is no longer practicable for Michael Hill to correspond with you in this manner and your personal information may be required in order to provide you with our products and services or to resolve any issue you may have.

10. Cross Border Disclosure

10.1 Cross border disclosures

Any personal information collected and held by Michael Hill may be disclosed to, and held at, a destination outside New Zealand, including but not limited to the jurisdictions set out in our Cross Border Disclosures Table.

Generally speaking this may be because Michael Hill (being part of a global group of organisations) operates in other jurisdictions. Personal information may also be processed by staff or by other third parties operating outside New Zealand who work for us or for one of our suppliers, agents, partners or related companies.

In addition we may utilise overseas IT services (including software, platforms and infrastructure), such as data storage facilities or other IT infrastructure (Cross Border IT Services). In such cases, we may own or control such overseas infrastructure or we may have entered into contractual arrangements with third party service providers to assist Michael Hill with providing our products and services to you.

Notwithstanding paragraph 10.1, as we utilise Cross Border IT Services and platforms which can be accessed from various countries via an Internet connection, it is not always practicable to know where your personal information may be held. If your personal information is stored in this way, disclosures may occur in countries other than those listed in the Cross Border Disclosures Table.

10.2 Provision of informed consent

By providing any of your personal information to Michael Hill, you expressly agree and consent to the disclosure, transfer, storing or processing of your personal information outside of New Zealand. In providing this consent, you understand and acknowledge that countries outside New Zealand do not always have the same privacy protection obligations in relation to personal information as New Zealand. However, we will take steps to require third parties to whom we disclose your personal information to treat your information securely and in accordance with the terms of this Privacy Policy.

10.3 If you do not consent

If you do not agree to the disclosure of your personal information outside New Zealand by Michael Hill, you should not provide any personal information to Michael Hill.

11. Data security and quality

11.1 Michael Hill’s security generally

In this age of internet shopping, we have learned that customers require peace of mind when it comes to the security of using the internet. As set out below, we have taken steps to help ensure your credit card details and other personal information is safe and protected from unauthorised access, use, disclosure, alteration, or destruction. You will appreciate, however, that we cannot guarantee the security of all transmissions or personal information, especially where the Internet is involved.

Notwithstanding the above, we will take reasonable steps to:

  • (a) make sure that the personal information we collect, use or disclose is accurate, complete and up to date;
  • (b) protect your personal information from misuse, loss, unauthorised access, modification or disclosure both physically and through computer security methods; and
  • (c) destroy or permanently modify personal information so that you cannot be identified from that information if it is no longer needed for its purpose of collection, or otherwise required to be retained.

We can’t tell you all of the technical details behind our security systems and processes as this may compromise the effectiveness of them.

11.2 Accuracy

The accuracy of personal information depends largely on the information you provide to us, so we recommend that you:

  • (a) let us know if there are any errors in your personal information; and
  • (b) keep us up-to-date with changes to your personal information (such as your name or address).

We provide information about how you can request access to and correct your personal information in Section 12.

12. Access to and correction of your personal information

You are entitled to have access to any personal information relating to you which we hold, except in some exceptional circumstances provided by law (including under the Privacy Act 1993). You are also entitled to request correction of such personal information if the information is inaccurate, out of date, incomplete, irrelevant or misleading.

If you would like to request access to or correction of any personal information we hodl about you, you are able to do so by contacting us via the details set out at the top of this document.

13. Resolving Privacy Complaints

13.1 Complaints generally

We have put in place an effective mechanism and procedure to resolve privacy complaints. We will ensure that all complaints are dealt with in a reasonably appropriate timeframe so that any decision (if any decision is required to be made) is made expeditiously and in a manner that does not compromise the integrity or quality of any such decision.

13.2 Contacting Michael Hill regarding complaints

If you have any concerns or complaints about the manner in which we have collected, used or disclosed and stored your personal information, please contact us by:

- Telephone: 0800 445 590

- Email: online@michaelhill.co.nz

- Post: GPO Box 2922, Brisbane, Australia 4001

Please mark your correspondence to the attention of the Privacy Officer.

13.3 Steps we take to resolve a complaint

In order to resolve a complaint, we:

  • (a) will liaise with you to identify and define the nature and cause of the complaint;
  • (b) may request that you provide the details of the complaint in writing;
  • (c) will keep you informed of the likely time within which we will respond to your complaint; and
  • (d) will inform you of the legislative basis (if any) of our decision in resolving such complaint.

13.4 Register of complaints

We will keep a record of the complaint and any action taken in a register of complaints.

14. Consent, modifications and updates

14.1 Interaction of this Policy with contracts

This Privacy Policy is a compliance document required by law rather than a legal contract between two or more persons. However, certain contracts may incorporate all, or part, of this Privacy Policy into the terms of that contract. In such instances, a Michael Hill company may incorporate the terms of this policy such that:

  • (a) certain sections or paragraphs in this policy are incorporated into that contract, but in such a way that they do not give rise to contractual obligations onto the Michael Hill entity, but do create contractual obligations on the other party to the contract; and
  • (b) the consents provided in this policy become contractual terms provided by the other party to the contract.

14.2 Acknowledgement

By using our website, purchasing a product or service from Michael Hill (whether in store or online) or entering a competition or interacting with us via social media, where you have been provided with a copy of our Privacy Policy or had a copy of our Privacy Policy reasonably available to you, you are acknowledging and agreeing:

  • (a) to provide the consents given by you in this Privacy Policy; and
  • (b) that you have been informed of all of the matters in this Privacy Policy.

14.3 Modifications and updates

We reserve the right to modify our Privacy Policy as our business needs require. We will take reasonable steps to notify you of such changes such as by direct communication or by posting a notice on our website). If you do not agree to our continued use of your personal information due to the changes in our Privacy Policy, please cease providing us with your personal information and contact us via the details set out at the top of this document. Your continued use of the website or provision of any personal information after we post changes to this Privacy Policy will indicate your acknowledgement of the terms of this Privacy Policy as modified.

Last Updated: 06/08/2014