Cloud 1st Limited trading as Cloud1st (New Zealand)
Effective date: 24 October 2025
Cloud 1st Limited trading as Cloud1st ("Cloud1st", "we", "us", "our") provides point-of-sale (POS), EFTPOS, payments, and IT services to businesses in New Zealand.
Website: https://cloud1st.co.nz
Email: [email protected]
Phone: +64 27 253 4678
Registered location: Auckland, New Zealand.
Legal entity: Cloud 1st Limited (trading as Cloud1st). Invoices are issued by Cloud 1st Limited.
This Privacy Policy explains how we handle personal information as required by the Privacy Act 2020 and its 13 Information Privacy Principles (IPPs). It also outlines additional disclosures for visitors from other regions (e.g. GDPR/UK GDPR) where applicable.
We collect and process personal information only where it is reasonably necessary for our functions and services, including:
We generally collect personal information directly from you (contact forms, email, phone, meetings, proposals, account portals). We may also collect information from authorised third parties you nominate (e.g. your staff or vendors) or from publicly available sources where appropriate for business contact verification.
We use personal information to:
We will not use personal information for materially different purposes without your knowledge or consent unless permitted by law.
For individuals in the EEA/UK, our lawful bases may include: contract (to provide services), legitimate interests (to operate and secure our services), consent (for marketing/cookies where required), and legal obligation (tax and compliance).
We share personal information only with:
We do not sell personal information.
Our primary operations are in New Zealand. Some service providers may process data in Australia or other countries. Where information is transferred offshore, we take reasonable steps to ensure comparable safeguards (e.g. contractual clauses and security controls). If you require data residency in NZ/Australia only, please tell us and we will discuss available options.
We use reasonable technical and organisational measures appropriate to the risk, including access controls, encryption in transit, least-privilege administration, patching and vendor due diligence. No method is 100% secure; we continually improve our controls.
We keep personal information only for as long as needed for the purposes above and to meet legal/financial record requirements (often 7 years for tax/invoice data). When no longer required, we take reasonable steps to delete or de-identify it.
Under the Privacy Act, you have the right to access and request correction of your personal information. For EEA/UK visitors, additional rights may include deletion, restriction, portability and objection in certain circumstances. To exercise your rights, contact us at [email protected].
We send commercial electronic messages only in compliance with NZ law. You can unsubscribe at any time using the link in our emails or by contacting us.
Where we supply/install CCTV or security systems, you (the customer) are the controller of any recordings captured at your premises. We act as your service provider, processing footage under your instructions. You are responsible for signage and local compliance; we can provide guidance on request.
Our services are for businesses. We do not knowingly collect personal information from children.
If a privacy breach is likely to cause serious harm, we will assess and, where required, notify the Office of the Privacy Commissioner (OPC) and affected individuals.
Our website may link to third-party sites. Their privacy practices are their own; review their policies before providing information.
We may update this policy to reflect changes in law or our services. The updated version will be posted on our website with a new effective date.
Questions or requests: [email protected]
Complaints: contact us first. If unresolved, you may contact the Office of the Privacy Commissioner (OPC) at https://privacy.org.nz.