Privacy Policy

Privacy Policy for FoodComplify

Last updated: 01/11/2025

Welcome to FoodComplify (“the App”, “the Platform”), owned and operated by FoodComplify (“we”, “us”, “our”).
We are committed to protecting your privacy and ensuring compliance with the New Zealand Privacy Act 2020 and the Information Privacy Principles (IPPs).

This Privacy Policy describes how we collect, use, store, disclose, and protect your personal information when you use FoodComplify’s services, including our website, mobile applications, and software platform.

By accessing or using FoodComplify, you agree to this Privacy Policy.
If you do not agree, please stop using the Platform.

1. Information We Collect

We collect only the information needed to operate the FoodComplify Platform and deliver food-safety and compliance services.

1.1. Personal Information You Provide

  • Name

  • Email address

  • Phone number

  • Job title

  • Organisation

  • Login information

  • Compliance forms, checklists, and assessments

  • Photos and documents submitted (e.g., product recall evidence)

1.2. Business and Operational Information

  • Store/branch details

  • Employee information (uploaded by your administrator)

  • Product data, SKUs, batch codes

  • Inventory and stock details

  • Compliance and audit records

1.3. Automatically Collected Information

  • IP address and device identifiers

  • Browser or app version

  • Log files

  • Usage analytics

  • Authentication logs

  • System error logs

1.4. Third-Party Integration Data

(Used only if you enable integrations within FoodComplify)

  • Identity providers (Google, Microsoft, Clerk, etc.)

  • Cloud storage providers

  • Environmental monitoring hardware (e.g., temperature sensors)

  • Invoicing or financial systems

We access only the minimum required data to enable these integrations.

2. Why We Collect This Information

We use information to:

  • Provide core food compliance and safety features

  • Manage user accounts and authentication

  • Generate compliance reports

  • Maintain audit trails

  • Process product recalls and evidence

  • Improve platform performance and reliability

  • Deliver customer support

  • Detect security issues or fraud

  • Meet legal and regulatory obligations (MPI, FSANZ, record retention)

We do not sell or rent your personal data to third parties.

3. Legal Basis for Processing

FoodComplify processes data under the New Zealand Privacy Act based on:

  • Your consent

  • Performance of a service or contract

  • Compliance with legal requirements

  • Our legitimate business interests (security, platform improvement)

4. Photos, Evidence & Uploaded Documents

Users may upload:

  • Product recall photos

  • Proof of disposal

  • Compliance forms and evidence

  • Operational documents

FoodComplify processes this data solely for:

  • Verification

  • Compliance auditing

  • Credit validation (if applicable)

  • Ensuring accuracy of records

You retain ownership of all content you upload.

5. Data Storage & Security

FoodComplify uses secure cloud hosting and implements:

  • Encryption in transit (HTTPS/TLS 1.2+)

  • Encryption at rest

  • Role-based access control (RBAC)

  • Multi-factor authentication options (if enabled)

  • Access logging and monitoring

  • Regular security reviews and updates

  • Least-privilege internal access controls

No system is completely secure; you acknowledge inherent risks of online services.

6. When We Share Information

FoodComplify may share data with:

6.1. Service Providers

Under contractual confidentiality obligations, for:

  • Cloud hosting

  • Data storage

  • Email/SMS notifications

  • Error monitoring

  • Subscription management and invoicing

  • Analytics

6.2. Legal or Regulatory Authorities

If required:

  • By NZ law

  • For investigations

  • Under court orders

  • To protect rights, prevent harm, or address fraud

6.3. Business Sale or Restructuring

If FoodComplify undergoes a merger or sale, data may be transferred under binding confidentiality protections.

7. International Data Transfers

FoodComplify may store or process data using partners located outside New Zealand.
We ensure these countries or providers offer comparable privacy protections, including:

  • Standard contractual clauses

  • Provider certifications (ISO 27001, SOC2, GDPR compliance)

8. Data Retention

We retain personal information as long as necessary to:

  • Comply with legal and industry food-safety obligations

  • Maintain required record-keeping

  • Support your active subscription

If you request deletion, FoodComplify will comply unless retention is legally required.

9. Your Privacy Rights

You have the right to:

  • Access the personal information we hold about you

  • Request correction of inaccurate data

  • Request deletion (where permitted by law)

  • Withdraw consent (for consent-based processing)

Submit requests to: [Insert your company’s email]

We may require identity verification before responding.

10. Children’s Data

FoodComplify is not intended for children under 16 years of age, and we do not knowingly collect personal information from minors.

11. Cookies & Similar Technologies

We use cookies for:

  • Login/session management

  • Security

  • Analytics

  • Improving user experience

You may disable cookies, but some features may not function.

12. Responsibilities of Organisation Administrators

If you manage an organisation account within FoodComplify:

  • You must ensure all uploaded staff information complies with New Zealand law

  • You must obtain consent from employees where required

  • You are responsible for managing user access and permissions

  • You must ensure your staff use the Platform lawfully

FoodComplify is not liable for misuse of the Platform by your organisation or staff.

13. Limitation of Liability

To the fullest extent permitted by New Zealand law:

  • FoodComplify is not responsible for indirect, consequential, or incidental damages

  • We are not liable for losses resulting from misuse, incorrect data entry, or poor account security practices by your staff

  • We do not guarantee uninterrupted service or error-free performance

  • You use the Platform at your own risk

  • You remain responsible for verifying compliance decisions made using the Platform

14. Updates to This Policy

FoodComplify may update this Privacy Policy from time to time. Material changes will be communicated via email or in-app notification.

Continued use of the Platform constitutes acceptance of updated terms.

15. Contact Us

If you have questions or want to exercise your privacy rights:

FoodComplify
Email: hello@foodcomplify.co.nz