Privacy Policy
Tasman Bay Navigation Systems Limited — Nelson, New Zealand
Contents
1. About this policy
Tasman Bay Navigation Systems Limited ("we", "us", "our") is a New Zealand company providing marine navigation software and applications. We are committed to protecting your personal information in accordance with the Privacy Act 2020 (New Zealand) and, where applicable, the General Data Protection Regulation (GDPR) (EU) 2016/679.
This policy applies to all customers and website visitors worldwide. Where you are located in the European Union or European Economic Area, the additional GDPR provisions marked throughout this document apply to you.
2. Information we collect
When you make a purchase through our website, we collect the following personal information:
Contact details
Your full name, email address, and phone number.
Billing information
Billing address and payment details. Full card numbers are not stored — these are handled securely by our payment provider.
Transaction records
Details of software licences or products purchased and the dates of those transactions.
Technical data
IP address, browser type, and device information collected automatically when you visit our website.
3. How we use your information
We use your personal information only for purposes directly related to providing our products and services, including:
- Processing and fulfilling your orders and delivering software licences.
- Sending purchase confirmations, invoices, and licence keys.
- Providing customer support and responding to your enquiries.
- Managing your account and purchase history.
- Complying with our legal obligations, including tax and accounting requirements.
- Detecting and preventing fraud or misuse of our services.
4. Lawful basis for processing (GDPR)
Under the GDPR, we are required to identify a lawful basis for each way we process your personal data. The table below sets out the purposes for which we process your data and the lawful basis we rely on for each.
| Purpose | Lawful basis |
|---|---|
| Processing your purchase and delivering your licence | Performance of a contract Art. 6(1)(b) GDPR — necessary to fulfil the contract with you. |
| Sending order confirmations and licence keys | Performance of a contract Art. 6(1)(b) GDPR — necessary to fulfil the contract with you. |
| Tax and financial record-keeping | Legal obligation Art. 6(1)(c) GDPR — required by applicable law. |
| Fraud detection and prevention | Legitimate interests Art. 6(1)(f) GDPR — our legitimate interest in protecting our business and customers from fraud. |
| Technical data / website functionality | Legitimate interests Art. 6(1)(f) GDPR — our legitimate interest in maintaining a secure and functional website. |
5. Third-party disclosure
We do not sell, rent, or trade your personal information to any third parties for marketing or commercial purposes. Your information is used solely by Tasman Bay Navigation Systems for the purposes described in this policy.
We may disclose information if required to do so by law, court order, or government authority in New Zealand or, where applicable, in the EU/EEA.
6. International data transfers
We are based in New Zealand. If you are located in the European Union or European Economic Area, your personal data will be transferred to and processed in New Zealand.
GDPR — EU/EEA customers
The European Commission has recognised New Zealand as providing an adequate level of data protection under GDPR Article 45, meaning your data can be lawfully transferred to New Zealand without additional safeguards. You can verify the current adequacy decision status at ec.europa.eu/info/law/law-topic/data-protection.
7. Data storage and security
Your personal information is stored securely on servers protected by industry-standard security measures, including encryption in transit and at rest. We take reasonable steps to protect your information from unauthorised access, loss, misuse, or disclosure.
We retain your personal information for as long as necessary to provide our services and meet our legal obligations — generally no longer than seven years following your last transaction, in line with New Zealand tax and financial record-keeping requirements.
GDPR — EU/EEA customers
Under GDPR Article 5(1)(e), we will not retain your personal data for longer than is necessary for the purposes for which it was collected. Once the retention period has elapsed, your data will be securely deleted or anonymised.
8. Cookies and website tracking
Our website may use cookies and similar technologies to support essential functions such as the shopping cart and secure checkout process. These do not collect personally identifiable information beyond what is required for your transaction.
You may disable cookies in your browser settings, though doing so may affect the functionality of certain parts of the website.
GDPR — EU/EEA customers
We use only technically necessary cookies required for the website to function and to complete your purchase. We do not use analytics, advertising, or tracking cookies. No consent banner is required for strictly necessary cookies under the ePrivacy Directive; however, if we introduce non-essential cookies in future, we will seek your explicit consent first.
9. Your rights
Under the Privacy Act 2020, you have the right to:
- Access the personal information we hold about you.
- Request correction of any personal information that is inaccurate or out of date.
- Request deletion of your personal information, subject to our legal obligations to retain certain records.
- Lodge a complaint with the Office of the Privacy Commissioner if you believe we have breached your privacy rights.
We will respond to all requests within 20 working days as required by New Zealand law.
GDPR — additional rights for EU/EEA customers
If you are located in the EU or EEA, you have the following additional rights under GDPR:
- Right to data portability — receive your personal data in a structured, machine-readable format (Art. 20).
- Right to object — object to processing based on legitimate interests (Art. 21).
- Right to restrict processing — ask us to limit how we use your data in certain circumstances (Art. 18).
- Right to withdraw consent — where processing is based on consent, you may withdraw it at any time without affecting prior processing.
- Right to lodge a complaint — with your local EU supervisory authority. A list of authorities is available at edpb.europa.eu.
To exercise any of these rights, please contact us at the details in Section 12. We will respond within one calendar month as required by GDPR Article 12.
10. Privacy breaches
In the event of a privacy breach that poses a risk of serious harm to any individual, we will notify the Office of the Privacy Commissioner and affected individuals as required under the Privacy Act 2020.
GDPR — EU/EEA customers
Under GDPR Article 33, we will notify the relevant EU supervisory authority of a personal data breach within 72 hours of becoming aware of it, where the breach is likely to result in a risk to your rights and freedoms. Where the risk is high, we will also notify you directly without undue delay (Art. 34).
11. Changes to this policy
We may update this Privacy Policy from time to time. The current version will always be available on our website, and the "last updated" date at the top of this page will reflect any revisions. We encourage you to review this policy periodically.
12. Contact us
If you have any questions about this Privacy Policy, wish to access or correct your information, or have a privacy concern, please contact us:
Tasman Bay Navigation Systems Limited
Nelson, New Zealand
Email: info@expeditionmarine.com
NZ customers: You may contact the Office of the Privacy Commissioner at privacy.org.nz.
EU/EEA customers: You may lodge a complaint with your local data protection authority. Find your authority at edpb.europa.eu.