New Zealand Privacy Supplement
- Version
- 1.1
- Effective
- 2024-04-01
- Last updated
- 2026-08-02
- Issuer
- Omni Data Tech Inc. ("Zeus"), 3601 Highway 7 East, Suite 1006, Markham, Ontario, L3R 0M3, Canada
- Audience
- New Zealand data subjects (Account Owners, Authorized Users, Workers, Clients and Link Recipients located in New Zealand).
- Binding mechanism
- NOTICE. This Supplement is part of the Zeus Privacy Policy disclosure set. Like the Privacy Policy, it is expressly not part of any Agreement.
- Precedence
- Tier 5 (jurisdictional privacy supplement). This Supplement supplements — and, solely to the extent mandatory New Zealand law requires, prevails over — the Global Privacy Policy for individuals in New Zealand. It never reduces Zeus's protections under the global core outside that mandatory scope.
1. Application, status and basis of handling
Section 1.1 — Application and non-contractual status
This New Zealand Privacy Supplement (the "Supplement") applies to Personal Information about individuals located in New Zealand that Zeus collects or holds in connection with the Services, and to Zeus's acts and practices as an agency under the Privacy Act 2020 (NZ). This Supplement must be read together with the Zeus Privacy Policy at https://fieldzeus.com/legal/privacy; terms capitalized here have the meanings given in the Privacy Policy and the Defined Terms of the Zeus legal suite. This Supplement and the Privacy Policy are notices, not contracts: they do not form part of any Agreement between Zeus and any Customer, and nothing in them grants contractual rights against Zeus. Creating an account, accessing or using the Services, or providing Personal Information to Zeus constitutes acknowledgment of the Privacy Policy and this Supplement, including as revised from time to time; if you do not agree with the practices they describe, your remedy is to not use, or to stop using, the Services. Where this Supplement and the Privacy Policy differ, this Supplement prevails for individuals in New Zealand only to the extent mandatory New Zealand law requires; in every other respect the global core of the Privacy Policy continues to apply without dilution.
Section 1.2 — Basis of handling in New Zealand; voluntariness
For individuals in New Zealand, and unless this Supplement or the Privacy Policy states otherwise for a specific practice, Zeus does not rely on consent as the basis on which it handles Personal Information; Zeus collects, holds, uses and discloses Personal Information as reasonably necessary for the business purposes and functions described in the Privacy Policy and as authorized by the information privacy principles of the Privacy Act 2020. Accessing or using the Services, or otherwise providing Personal Information to Zeus, constitutes your acknowledgment that your Personal Information will be handled as described in the Privacy Policy and this Supplement. Providing Personal Information to Zeus is voluntary; however, if you choose not to provide it, Zeus may be unable to provide you (or the Customer whose Workspace you use) with some or all of the Services, and some features may be prevented or severely constrained.
Section 1.3 — Roles: agency for Account Data; agent-style handling of End-Customer Data and Worker Data
Zeus is the agency accountable under the Privacy Act 2020 only for Account Data — registration, billing, device and session Telemetry, diagnostics and Zeus website data — and for Personal Information Zeus collects for its own purposes as described in the Privacy Policy. For End-Customer Data and Worker Data — Personal Information about Clients, workers, subcontractors and other individuals that a Customer or its Authorized Users enter into, or cause to be collected through, the Services — Zeus acts solely as a service provider processing that information on the Customer's behalf and on the Customer's instructions, unless otherwise required by law; on the record of the law audit, information Zeus holds in that capacity is held as agent for the Customer, and the Privacy Act treats information held by an agent as held by the principal (s 11). The Customer, not Zeus, decides why and how that information is collected and is responsible for compliance with the privacy laws that apply to it, including giving any notices required at or before collection. If your Personal Information sits in a Customer's Workspace, direct your questions and requests to that Customer (for example, the contracting business you dealt with); Zeus refers such dealings to the relevant Customer as described in §5.
Section 1.4 — Mandatory-law savings; application of the Privacy Act 2020
Nothing in the Privacy Policy or this Supplement excludes, restricts or modifies any right you have, or any obligation Zeus has, under the Privacy Act 2020 or any other New Zealand law that cannot lawfully be excluded, restricted or modified. Nothing in any Zeus document states or implies that only the law of a foreign country governs Zeus's handling of Personal Information about individuals in New Zealand: the Privacy Act 2020 applies to Zeus's acts and practices in respect of that information to the full extent the Act itself provides, including as it applies to overseas agencies carrying on business in New Zealand, regardless of where Zeus is incorporated or where the information is held. Where the Privacy Policy describes a practice, allocation or limitation that mandatory New Zealand law does not permit as to you, that practice applies to you only to the maximum extent the law permits, and otherwise the statutory position applies — without affecting the operation of the global clause for any other person or place.
2. Who we are; accountability and contacts (IPP3 name and address)
Section 2.1 — Identity, New Zealand-usable address and privacy contact
The agency collecting and holding the Personal Information described in this Supplement is Omni Data Tech Inc., of 3601 Highway 7 East, Suite 1006, Markham, Ontario, L3R 0M3, Canada. Privacy questions, access, correction and complaint communications for New Zealand should be directed to [email protected] (postal route: 3601 Highway 7 East, Suite 1006, Markham, Ontario, L3R 0M3, Canada). The current version of this Supplement and the Privacy Policy are published at https://fieldzeus.com/legal.
3. Collection notice (IPP3) and indirect collection (IPP3A)
Section 3.1 — What Zeus collects in New Zealand and how
The kinds of Personal Information Zeus collects and holds, how it is collected, and the purposes of collection, holding, use and disclosure are described in §3–§5 of the Privacy Policy. For New Zealand users these practices are, in summary and as verified product fact: account registration and billing details; first-party device and session Telemetry (raw events retained 30 days, aggregate rollups 365 days); diagnostic and error data; job, client, quoting, invoicing and payment-record content entered by Customers; photos and their metadata; snapshot-only Location Data limited to the six disclosed purposes (photo-tag fallback, clock-in/out snapshots, optional GPS at signing, address geocoding, map-tile requests, and the location recorded against a receipt or expense where that capture switch is on — no background or continuous tracking); electronic-signature evidence records; workforce records entered by Customers about their own personnel (time entries and their approval state, crew membership, recorded absences and the reason given for them, and skill, certification, licence or insurance records); and receipts processed by Zeus's own self-hosted OCR (no third-party OCR vendor). Zeus does not sell Personal Information, use third-party advertising networks or ad cookies, perform data enrichment, or pull credit reports.
Section 3.2 — Indirect collection through Customers
Much of the Personal Information in the Services about Clients and workers is collected indirectly: a Customer (for example, a contracting business you engaged) enters it, uploads it, or causes it to be collected through job records, photos, documents, signatures and payment records. The Customer is responsible for having told you, and for having any authority it needs, before putting your Personal Information into the Services, and for giving you the notices its own privacy obligations require. If you did not deal with Zeus directly, the Customer is your first point of contact for questions about why your information was collected.
Section 3.3 — IPP3A notification for indirectly collected information (in force since 1 May 2026)
Since 1 May 2026, IPP3A of the Privacy Act 2020 requires an agency that collects Personal Information about an individual from someone other than that individual to take reasonable steps, as soon as reasonably practicable, to make the individual aware of prescribed matters (including the name and address of the collecting and holding agencies, any authorising law, and access and correction rights), subject to statutory exceptions.
4. Offshore disclosure, holding and cross-border processing (IPP12)
Section 4.1 — Offshore holding; likely recipients and countries
All Zeus production data is held offshore from New Zealand: Zeus is likely to disclose Personal Information to, and hold it with, overseas recipients — its hosting, infrastructure, email-delivery, geocoding and other service providers — located in the United States, Canada, and Europe, and in any other location where Zeus or its service providers maintain facilities as reasonably necessary for the proper performance and delivery of the Services. As a statement of current practice (and not a warranty — see §4.4): Zeus's primary object storage is pinned to an Eastern North America region; database and application infrastructure are operated from North America; transactional and document-delivery email is dispatched via a United States provider; street addresses for New Zealand jobs may be sent to third-party geocoding services, and the current fallback for New Zealand addresses is the public geocoding service operated on OpenStreetMap Foundation infrastructure (a public, shared service — Zeus does not commit to any single or exclusive geocoding provider); map tiles are requested by your device directly from the OpenStreetMap tile servers; and traffic to and from the Services traverses a global content-delivery edge, which processes traffic at the data centre closest to you.
Section 4.2 — Your acknowledgment of offshore processing
By using the Services or submitting Personal Information — and this applies expressly to users located in New Zealand — you consent to, and acknowledge, the transfer, storage and processing of your information in the United States, Canada and any other country in which Zeus or its service providers maintain facilities. The laws of those countries may not be as protective of Personal Information as the laws of New Zealand, and information held there may be subject to lawful access by the governments, courts, law-enforcement and regulatory agencies of those countries. If you do not want your Personal Information transferred, stored or processed as this section describes, you should not use the Services; continued use constitutes your ongoing acknowledgment of these transfers.
Section 4.3 — IPP12 cross-border disclosure position
Zeus's IPP12 position for disclosures of Personal Information to foreign persons or entities that are not Zeus's agents is the comparable-safeguards route: Zeus relies on contractual mechanisms with the recipient intended to require safeguards comparable to those in the Privacy Act 2020. Zeus does not represent that any particular foreign law provides comparable protection. Use of Zeus and its subprocessors as agents (storage and processing on Zeus's or the Customer's behalf) is, on the record of the law audit, analyzed under s 11 rather than as an IPP12 disclosure; the offshore holding itself is disclosed in §4.1.
Section 4.4 — No data-residency warranty; relocation
Zeus states its storage locations as current practice only and MAKES NO WARRANTY THAT ANY SPECIFIC HOSTING OR STORAGE LOCATION WILL MEET YOUR DATA-RESIDENCY REQUIREMENTS OR PREFERENCES. Without limiting the foregoing, content-delivery edge processing, backups and disaster-recovery copies, diagnostics, and support access may each occur outside any stated primary region, and traffic is processed at the edge data centre closest to the requesting device. Zeus may relocate data between facilities, regions or providers at any time, subject to §4.3's mandatory-law route once settled and to the savings clause in §1.4.
5. Access, correction and your other rights (IPP6 and IPP7; Part 4)
Section 5.1 — Rights framework and routing
You have the rights that applicable law provides — including, under the Privacy Act 2020, the right to confirmation of whether Zeus holds Personal Information about you and to access it (IPP6), and the right to request correction of it (IPP7) — and those rights are not absolute: they are subject to the exceptions, conditions and timeframes the Act itself sets. If your Personal Information was entered into the Services by or for a Customer (End-Customer Data or Worker Data), please direct your request to that Customer, as this may expedite its completion — under the Privacy Act, information Zeus holds solely as the Customer's agent is treated as held by that Customer; Zeus refers such requests to the relevant Customer and provides reasonable assistance to that Customer, as appropriate and as required by applicable law.
Section 5.2 — Identity verification
Before actioning any request, Zeus may require you to prove you are who you say you are: Zeus may request up to three pieces of personal information to compare against its records, may ask for copies of relevant identity documents, and may take additional steps where fraud is suspected; failure to verify may result in denial of the request. Requests made through an agent or representative require the agent's written permission from you and your direct identity verification with Zeus, failing which the request may be denied; and where records also contain Personal Information about other people, Zeus may redact or withhold that information.
Section 5.3 — Response, refusal grounds, timeline and charges
Zeus responds to access and correction requests as soon as reasonably practicable, and in any case within the time limits the Privacy Act 2020 prescribes (for a decision on an IPP6 access request, no later than 20 working days after receipt, subject to the Act's extension grounds); Zeus may decline to process requests that are manifestly unfounded or excessive, unreasonably repetitive, frivolous or vexatious, require disproportionate technical effort, jeopardise the privacy of others, are extremely impractical, or for which access is not otherwise required by law — in each case only where and to the extent the Privacy Act permits refusal. There is no charge for making a request or for correction; where the Privacy Act permits a private-sector agency to charge for giving access, any such charge will be reasonable; and where Zeus refuses a request, Zeus will give you the reasons and the available complaint mechanisms except to the extent it would be unreasonable to do so — and if Zeus declines to correct information, you may request that a statement of the correction sought but not made be attached to the information, as the Act provides.
Section 5.4 — Deletion, retention carve-outs and communications you cannot opt out of
Where you ask Zeus to delete Personal Information it holds in its own right, deletion is two-phase: deactivation followed by a later purge run as soon as reasonably practicable, with no fixed purge timeline promised; the account purge window is as soon as reasonably practicable, and the retention schedule published in the Data Retention and Deletion Policy applies. Zeus may decline to delete, in whole or in part, Personal Information that Zeus (or its service providers) is required or permitted to retain — including append-only audit and financial records that survive purge by design, backups pending scheduled rotation, records needed to complete transactions, maintain security and integrity, comply with legal obligations, or for internal uses lawfully compatible with the context in which you provided the information. If any processing does rest on your consent, withdrawing it does not affect processing that is required or permitted by law, and may result in your inability to continue using some or all of the Services. You may not opt out of administrative and transactional communications — such as security notices, service messages, and messages confirming or actioning your own requests.
6. Complaints and the Office of the Privacy Commissioner
Section 6.1 — How to complain; escalation to the regulator
If you believe Zeus has breached the information privacy principles in relation to your Personal Information, you may complain to Zeus at [email protected] (postal route: 3601 Highway 7 East, Suite 1006, Markham, Ontario, L3R 0M3, Canada). Zeus will acknowledge and consider your complaint and respond to you. If you are not satisfied with Zeus's response, you may complain to the Office of the Privacy Commissioner (OPC), online at privacy.org.nz.
7. Privacy breaches (Part 6, ss 112–118)
Section 7.1 — Statutory breach regime; notification posture
Where the Privacy Act 2020's notifiable privacy breach regime (Part 6) applies to Zeus in respect of Personal Information it holds, Zeus will assess suspected notifiable privacy breaches and notify the Privacy Commissioner and affected individuals as and when that regime requires; nothing in any Zeus document limits those statutory duties. For the purposes of Zeus's own notices, a "Security Incident" means confirmed unauthorized access to or disclosure of Personal Information and does not include unsuccessful attempts or activities that do not compromise it (such as failed log-ins, pings, port scans or denial-of-service attacks). Zeus notifies affected Customers without undue delay using the contact details on the Customer's account, and only to the extent applicable law requires; the Customer is solely responsible for keeping those contact details valid and accurate. No notification of, or response to, a Security Incident is an acknowledgment by Zeus of any fault or liability; and incidents not specific to you or your organization may be communicated through Zeus's general status channels.
8. New Zealand-specific practices: retention (IPP9) and changes
Section 8.1 — Retention and disposal (IPP9)
Consistent with IPP9, Zeus retains Personal Information it holds in its own right for the period reasonably required to fulfil the purposes described in the Privacy Policy, unless a longer retention period is required or permitted by law. Retention operates across active and archive systems, and financial and tax records are kept for the statutory periods that apply to them — for example, invoice and financial information is retained for the multi-year periods New Zealand tax law requires — with the schedule published in the Data Retention and Deletion Policy. Backups are excluded from targeted deletion and are destroyed on their own scheduled rotation; where deletion from a backup archive is not immediately possible, the data is securely stored and isolated from further processing until deletion is possible. Complete erasure of every record may not be technically possible, and residual copies may persist; append-only audit and financial records, and documentation evidencing the orderly and accurate processing of data, survive account purge by design. Uninstalling the Zeus mobile application does not delete any data held server-side: Zeus may retain collected data after uninstallation, and the in-app deletion feature (not uninstallation) is the designated channel for deletion requests.
Section 8.2 — Changes to this Supplement
Zeus may revise this Supplement from time to time; the current version, with its effective date and version number, is always available at https://fieldzeus.com/legal. Continued use of the Services after a revision takes effect constitutes acknowledgment of the revised Supplement, as described in §1.1 and in the Privacy Policy's changes section, and subject to the savings clause in §1.4.
Section 8.3 — Workforce data visibility; the employer's monitoring responsibilities
The global workforce-visibility positions of the Privacy Policy (its §3.9 and §10.2) apply unchanged in New Zealand; for transparency to New Zealand workers they are restated here:
Worker Data — time entries and their approval state, clock-in/clock-out location snapshots, photos, assignments and crew membership, recorded absences and the reason given for them, skill and certification records, and activity data about a Customer's personnel — is processed for the business that owns the Workspace: worker time-tracking data, including its optional location component, is made available to the Account Owner and the Workspace's administrators, and location data collected from workers is used exclusively to provide the Services to that business. If you use the Services under a Customer's Workspace as a Member, Helper or other Invited User, your Personal Information and activity within the Workspace may be monitored, processed and analyzed by the Account Owner and its administrators, and content you submit within the Workspace may be accessed, copied and processed by them; you should have no expectation that in-tenant data is private from the business that invited you. The Services maintain an always-on, append-only activity and audit log that users cannot turn off. The Customer (as employer or principal) — not Zeus — is solely responsible for compliance with the employment, workplace-monitoring, surveillance, privacy and consent laws that apply to its use of these features, and must obtain all requisite approvals and authorizations from its personnel for the creation, display, analysis and distribution of the data they generate before enabling them. Worker requests about Worker Data are routed to the employer under §5.1 — under the Privacy Act 2020, Worker Data Zeus holds solely as the Customer's agent is treated as held by that Customer (s 11) — and deletion of workforce records is a matter for the employer as the agency accountable for that data.