Tasman Bay Navigation Systems

Last updated: June 2025

Privacy Policy

Tasman Bay Navigation Systems Limited — Nelson, New Zealand

NZ Privacy Act 2020 GDPR (EU/EEA)

Contents

  1. About this policy
  2. Information we collect
  3. How we use your information
  4. Lawful basis for processing (GDPR)
  5. Third-party disclosure
  6. International data transfers
  7. Data storage and security
  8. Cookies and website tracking
  9. Your rights
  10. Privacy breaches
  11. Changes to this policy
  12. Contact us

1. About this policy

Tasman Bay Navigation Systems Limited ("we", "us", "our") is a New Zealand company providing marine navigation software and applications. We are committed to protecting your personal information in accordance with the Privacy Act 2020 (New Zealand) and, where applicable, the General Data Protection Regulation (GDPR) (EU) 2016/679.

This policy applies to all customers and website visitors worldwide. Where you are located in the European Union or European Economic Area, the additional GDPR provisions marked throughout this document apply to you.

2. Information we collect

When you make a purchase through our website, we collect the following personal information:

Contact details

Your full name, email address, and phone number.

Billing information

Billing address and payment details. Full card numbers are not stored — these are handled securely by our payment provider.

Transaction records

Details of software licences or products purchased and the dates of those transactions.

Technical data

IP address, browser type, and device information collected automatically when you visit our website.

3. How we use your information

We use your personal information only for purposes directly related to providing our products and services, including:

4. Lawful basis for processing (GDPR)

Under the GDPR, we are required to identify a lawful basis for each way we process your personal data. The table below sets out the purposes for which we process your data and the lawful basis we rely on for each.

Purpose Lawful basis
Processing your purchase and delivering your licence Performance of a contract
Art. 6(1)(b) GDPR — necessary to fulfil the contract with you.
Sending order confirmations and licence keys Performance of a contract
Art. 6(1)(b) GDPR — necessary to fulfil the contract with you.
Tax and financial record-keeping Legal obligation
Art. 6(1)(c) GDPR — required by applicable law.
Fraud detection and prevention Legitimate interests
Art. 6(1)(f) GDPR — our legitimate interest in protecting our business and customers from fraud.
Technical data / website functionality Legitimate interests
Art. 6(1)(f) GDPR — our legitimate interest in maintaining a secure and functional website.

5. Third-party disclosure

We do not sell, rent, or trade your personal information to any third parties for marketing or commercial purposes. Your information is used solely by Tasman Bay Navigation Systems for the purposes described in this policy.

We may disclose information if required to do so by law, court order, or government authority in New Zealand or, where applicable, in the EU/EEA.

6. International data transfers

We are based in New Zealand. If you are located in the European Union or European Economic Area, your personal data will be transferred to and processed in New Zealand.

GDPR — EU/EEA customers

The European Commission has recognised New Zealand as providing an adequate level of data protection under GDPR Article 45, meaning your data can be lawfully transferred to New Zealand without additional safeguards. You can verify the current adequacy decision status at ec.europa.eu/info/law/law-topic/data-protection.

7. Data storage and security

Your personal information is stored securely on servers protected by industry-standard security measures, including encryption in transit and at rest. We take reasonable steps to protect your information from unauthorised access, loss, misuse, or disclosure.

We retain your personal information for as long as necessary to provide our services and meet our legal obligations — generally no longer than seven years following your last transaction, in line with New Zealand tax and financial record-keeping requirements.

GDPR — EU/EEA customers

Under GDPR Article 5(1)(e), we will not retain your personal data for longer than is necessary for the purposes for which it was collected. Once the retention period has elapsed, your data will be securely deleted or anonymised.

8. Cookies and website tracking

Our website may use cookies and similar technologies to support essential functions such as the shopping cart and secure checkout process. These do not collect personally identifiable information beyond what is required for your transaction.

You may disable cookies in your browser settings, though doing so may affect the functionality of certain parts of the website.

GDPR — EU/EEA customers

We use only technically necessary cookies required for the website to function and to complete your purchase. We do not use analytics, advertising, or tracking cookies. No consent banner is required for strictly necessary cookies under the ePrivacy Directive; however, if we introduce non-essential cookies in future, we will seek your explicit consent first.

9. Your rights

Under the Privacy Act 2020, you have the right to:

We will respond to all requests within 20 working days as required by New Zealand law.

GDPR — additional rights for EU/EEA customers

If you are located in the EU or EEA, you have the following additional rights under GDPR:

  • Right to data portability — receive your personal data in a structured, machine-readable format (Art. 20).
  • Right to object — object to processing based on legitimate interests (Art. 21).
  • Right to restrict processing — ask us to limit how we use your data in certain circumstances (Art. 18).
  • Right to withdraw consent — where processing is based on consent, you may withdraw it at any time without affecting prior processing.
  • Right to lodge a complaint — with your local EU supervisory authority. A list of authorities is available at edpb.europa.eu.

To exercise any of these rights, please contact us at the details in Section 12. We will respond within one calendar month as required by GDPR Article 12.

10. Privacy breaches

In the event of a privacy breach that poses a risk of serious harm to any individual, we will notify the Office of the Privacy Commissioner and affected individuals as required under the Privacy Act 2020.

GDPR — EU/EEA customers

Under GDPR Article 33, we will notify the relevant EU supervisory authority of a personal data breach within 72 hours of becoming aware of it, where the breach is likely to result in a risk to your rights and freedoms. Where the risk is high, we will also notify you directly without undue delay (Art. 34).

11. Changes to this policy

We may update this Privacy Policy from time to time. The current version will always be available on our website, and the "last updated" date at the top of this page will reflect any revisions. We encourage you to review this policy periodically.

12. Contact us

If you have any questions about this Privacy Policy, wish to access or correct your information, or have a privacy concern, please contact us:

Tasman Bay Navigation Systems Limited

Nelson, New Zealand

Email: info@expeditionmarine.com

NZ customers: You may contact the Office of the Privacy Commissioner at privacy.org.nz.

EU/EEA customers: You may lodge a complaint with your local data protection authority. Find your authority at edpb.europa.eu.