Privacy Statement
Effective date: 13 September 2026
Mangrove respects your privacy and is committed to handling personal information carefully and transparently. This statement explains how Mangrove collects, uses, stores and shares personal information when you visit www.mangrove.co.nz, contact us, subscribe to communications, or work with us.
In this statement, Mangrove, we, us and our mean the business trading as Mangrove, NZBN 9429053561169.
1. What information we collect
Depending on how you interact with us, we may collect:
- your name, job title, organisation and contact details
- information you provide through our website forms, emails, calls, meetings, surveys or other communications
- information about your business, its people, systems, processes, customers and suppliers where this is relevant to an enquiry or engagement
- billing, transaction and payment information
- records of our communications and work with you
- website and device information, such as your IP address, browser type, pages viewed, referral source and cookie or analytics data; and
- information available from public sources, referrals, business directories, professional networks, service providers, or people within your organisation
If you provide us with personal information about another person, you must have a lawful basis to do so and, where required, have told them that their information may be provided to us.
2. Why we collect and use it
We may use personal information to:
- respond to enquiries and assess whether Mangrove can help
- prepare proposals, statements of work and service agreements
- provide operational, financial, systems, implementation, advisory and fractional leadership services
- manage client relationships, projects, support requests, billing and administration
- configure or work within systems where a client has authorised us to do so
- improve our services, website, processes and customer experience
- send useful service information, insights or marketing communications where you have agreed to receive them or where the law otherwise permits
- protect our systems, detect misuse and manage legal, security and business risks; and
- comply with legal, regulatory, tax and professional obligations
Where information is requested from you, providing it is generally voluntary. However, if you do not provide information we reasonably need, we may be unable to respond fully, prepare a proposal, or provide the relevant services.
3. Client information and access to business systems
Our work may require access to information held in a client's systems. This can include personal information relating to the client's staff, customers, suppliers or other contacts. When Mangrove processes that information on a client's instructions, the client remains responsible for deciding why and how the information is collected and used. We will:
- access and use it only as reasonably required to provide the agreed services
- follow the client's reasonable privacy and security instructions
- limit access to people and providers who need it for the work; and
- take reasonable steps to protect it from loss, misuse or unauthorised access
Clients should avoid giving Mangrove access to information that is not needed for the engagement and should use secure access methods rather than sending passwords or other credentials by email.
4. Artificial intelligence and automation tools
Mangrove may use reputable artificial intelligence and automation tools to support research, analysis, drafting, documentation or service delivery. We will apply reasonable human oversight and will not knowingly use client confidential information or personal information in a public AI tool where that use would be inconsistent with the purpose for which the information was provided, our confidentiality obligations, or applicable privacy law.
5. When we share information
We may share personal information where reasonably necessary with:
- contractors or specialist advisers helping us provide the services
- technology, hosting, CRM, communications, accounting, analytics, automation and cloud-service providers
- a client's authorised staff, advisers or technology providers
- professional advisers, insurers, debt-recovery providers or prospective purchasers of our business; and
- regulators, courts, law-enforcement agencies or other parties where required or permitted by law
We do not sell personal information.
Some service providers may store or process information outside New Zealand. Where personal information is disclosed overseas, we will take reasonable steps to ensure the disclosure is permitted by the Privacy Act 2020 and that appropriate safeguards apply.
6. Cookies, analytics and marketing
Our website may use cookies and similar technologies to operate the site, remember preferences, understand how people use it and measure the effectiveness of our communications or marketing.
You can manage cookies through your browser and, where available, our website cookie controls. Blocking some cookies may affect how the website functions. You can unsubscribe from marketing emails at any time using the unsubscribe link in the email or by contacting us. We may still send service or administrative messages that are necessary for an existing relationship.
7. Storage, security and retention
We use reasonable technical and organisational safeguards appropriate to the nature of the information we hold. These may include controlled access, multi-factor authentication, secure cloud services, device security and contractual confidentiality requirements.
No method of storage or transmission is completely secure. If a privacy breach occurs, we will assess and respond to it in accordance with the Privacy Act 2020, including notifying affected people and the Office of the Privacy Commissioner where required.
We retain personal information only for as long as reasonably necessary for the purposes for which it was collected, including service delivery, relationship management, legal, tax, insurance and record-keeping requirements. We will then securely delete, anonymise or return it where practicable.
8. Accessing or correcting your information
You may ask for access to personal information we hold about you, or ask us to correct it. We may need to verify your identity before responding. In limited circumstances, the Privacy Act 2020 permits us to withhold information.
To make a privacy request or raise a concern, use the contact form at www.mangrove.co.nz/contact and mark your message for the attention of the Privacy Officer.
If we cannot resolve your concern, you can contact the New Zealand Office of the Privacy Commissioner at www.privacy.org.nz.
9. Changes to this statement
We may update this statement when our practices, services or legal obligations change. The current version will be published on our website with its effective date.
