Controller and contact
The data controller is Whrexxonphakronx, 1 Wellesley Street West, Auckland CBD, Auckland 1010, New Zealand. Email assist@whrexxonphakronx.world, phone +64 21 038 3066. For a structured overview of our legal identity, see our transparency & advertising disclosure page.
Personal data we process
We may process: identifiers (name, email, phone if you provide it); message content you send through forms; technical data such as IP address, user agent, and referring URL; cookie identifiers and preference flags stored in your browser; and correspondence records when you email us.
Purposes and legal bases
We process data to respond to enquiries (contract steps or legitimate interests in communicating with prospective clients); to operate and secure the website (legitimate interests); to comply with tax or regulatory obligations (legal obligation); and, where you give opt-in consent, to measure site performance and deliver marketing communications. If we use online advertising (including platforms such as Google Ads), measurement and conversion data may be processed in line with your cookie choices and the relevant platform’s terms; we do not use such data to infer sensitive health conditions for targeting.
Retention
Contact form submissions are kept for twenty-four months unless a longer period is required for accounting, taxation, or dispute resolution. Server and security logs are retained on a rolling basis, typically not exceeding twelve months unless an incident investigation requires an extension. Marketing consents are refreshed periodically or removed when you unsubscribe.
Recipients and processors
We use infrastructure and communications providers who host the site, transmit email, or provide analytics under written agreements. They may only process data on documented instructions and must assist us with security and compliance obligations.
International transfers
If personal data is transferred outside New Zealand or the EEA, we implement safeguards such as standard contractual clauses, adequacy decisions, or supplementary measures where required by the GDPR or NZ Privacy Act 2020.
Security measures
We apply access controls, transport encryption where supported, patching, and confidentiality commitments for staff and contractors. We review vendors and configurations when the risk profile changes.
Your rights
Subject to applicable law, you may request access, rectification, erasure, restriction, objection, or portability. You may withdraw consent for optional processing without affecting lawful processing that occurred beforehand. You may lodge a complaint with the Office of the Privacy Commissioner (New Zealand) or your local supervisory authority in the EU/UK.
Children
The site is not directed at children under sixteen. We do not knowingly collect their personal data; if you believe we have, contact us so we can delete it.
Automated decision-making
We do not use fully automated decisions that produce legal or similarly significant effects solely based on profiling.
Changes
We may update this policy and adjust the “last updated” reference in the hero section when changes are material. Continued use after notice constitutes acceptance where permitted by law.