HomeAboutServicesWebsite CopywritingWebsite Copy AuditContent Writing & SEOBrand Messaging & VoiceEmail & Launch CopyProcessBlogContactBook a free call
Legal · 9 min read

Privacy policy

What I collect, why I collect it, who else can see it, how long I keep it and how to make me delete it — written to be read rather than to be survived.

Last updated Effective 1 September 2026 Governed by New Zealand law
Your data, plainly

The short version

A plain-English summary. It is not a substitute for the detail below, but if you read only one part, read this one.

  • I collect only what you type into a form or send me by email. Nothing is bought, scraped or inferred.
  • This site sets no cookies and runs no third-party trackers or analytics.
  • Your details are never sold, rented or shared for marketing — by anyone, at any price.
  • Enquiries that go nowhere are deleted after 12 months. Tax records are kept 7 years because the law says so.
  • You can ask to see, correct or delete what I hold, any time, free, and I answer within 20 working days.

Who I am, and how to reach me

This website and the copywriting services described on it are operated by Kristen Rive-Thomson, trading as The Riveting Copywriter, a sole trader based in Aotearoa New Zealand. For the purposes of the New Zealand Privacy Act 2020 I am the agency that holds your information; for the purposes of the UK and EU GDPR, where those laws apply to you, I am the data controller.

Trading nameThe Riveting Copywriter
OperatorKristen Rive-Thomson, sole trader
LocationAotearoa New Zealand (clients worldwide)
Privacy contact[email protected]
Response timeOne business day for questions; 20 working days for formal requests

There is no separate privacy officer, no ticketing system and no outsourced team. Your email arrives directly with me, and I answer it.

What information I collect

Everything below is information you choose to hand over. This site does not fingerprint your device, buy data about you from anyone, or enrich what you submit with third-party profiles.

Where it comes fromWhat is collectedWhether it is required
Contact form Name, email address, website URL (optional), the service you selected, budget range (optional), your message, and the fact that you ticked the consent box Name, email, service and message are required. The rest is optional and the form works without it.
Newsletter form Email address only Required, obviously. Nothing else is asked for or stored.
Email you send me Whatever you write, plus your email address and any attachments Entirely up to you.
Discovery and project calls Notes I type during the call. Calls are recorded only if you agree first, in the call, out loud. Recording is always optional and refusing changes nothing about the service.
Client projects Business details, brand materials, analytics access, and — where you arrange them — interviews with your own customers Necessary to do the work you have engaged me for.
Invoicing Billing name, business address, email, GST or VAT number where relevant Required by tax law once you become a client.
Your browser (locally only) Your light/dark theme choice, and a short summary of your last enquiry Stored on your device, never transmitted. See the cookie policy.

Information about other people

During a project you may give me access to your customers — for interviews or review mining — or share documents that contain third-party personal information. In that arrangement you remain the controller of that information and I act on your instructions as a processor. I use it only to write your copy, never contact those people again afterwards, and delete my copies at the end of the project unless you ask me to keep them for a follow-up phase.

What I deliberately do not collect

  • No advertising cookies, pixels or trackers. There is no Meta pixel, no LinkedIn Insight tag, no Google Ads remarketing on this site.
  • No third-party analytics by default. This site currently runs no analytics at all. If that ever changes, the change appears in the log at the bottom of this page before it goes live.
  • No embedded fonts, scripts or media from other companies. Every font and library is served from this domain, so no third party learns that you visited.
  • No sensitive information. I never ask for health data, ethnicity, political or religious views, sexual orientation, biometric data, government identifiers, or card numbers. Please don’t put any of it in the message field.
  • No purchased lists. Nobody is added to the newsletter without asking for it themselves.

Why I use it, and my legal basis

Under the Privacy Act 2020 I collect only what is necessary for a lawful purpose connected with my business. Where the GDPR applies, each purpose also needs a legal basis. Here is both, laid out honestly.

PurposeInformation usedGDPR legal basis
Replying to your enquiry and arranging a callContact form fields, emailsSteps taken at your request prior to entering a contract (Art. 6(1)(b))
Preparing an accurate, fixed-fee proposalService selected, budget range, messagePre-contractual steps (Art. 6(1)(b))
Delivering the project you engaged me forProject materials, analytics, interviewsPerformance of a contract (Art. 6(1)(b))
Invoicing and keeping tax recordsBilling details, invoice historyLegal obligation (Art. 6(1)(c)) — NZ Tax Administration Act
Sending the newsletterEmail addressConsent (Art. 6(1)(a)), withdrawable in one click
Keeping my own business records and defending claimsContracts, correspondenceLegitimate interests (Art. 6(1)(f))
Remembering your theme preferenceA value in your browser’s local storageStrictly necessary for a feature you asked for; no consent banner required

Where I rely on legitimate interests, I have weighed my interest in running a functioning business against your privacy, and limited the data to what a reasonable person would expect a service provider to keep. You can object to that processing at any time using the contact details above.

What I will never do with it

Sell it. Rent it. Trade it for a listing. Share it with a data broker or an AI training set. Add you to a newsletter because you sent a project enquiry. Use anything you told me in confidence as a case study without asking you first, by name, in writing.

Who else can see your information

I use a small number of established suppliers to actually run a business. Each one is a processor acting on my instructions, bound by its own contractual and legal obligations, and none of them is permitted to use your information for its own purposes.

SupplierWhat it handlesWhere it processes data
Email and document hostingYour emails, project docs, call notesData centres in Australia, the EU and the United States
Web hosting and CDNServing this site; standard server logs including IP addressRegional edge locations, typically Australia or Singapore for NZ visitors
Newsletter platformSubscriber email addresses, send and open recordsEuropean Union or United States, depending on plan region
Accounting and invoicing softwareBilling details, invoice and payment historyNew Zealand and Australia
Video callingLive calls; recordings only where you agreedUnited States and regional relays
Payment processor / bankPayment settlement. I never see or store full card numbers.New Zealand and the payment network’s own regions

Beyond that list, I disclose information only where the law requires it — a court order, a tax audit, a lawful request from a regulator — or where it is necessary to establish or defend a legal claim. If I ever receive a government request for your information and I am legally permitted to tell you about it, I will.

Server logs deserve a specific mention because they exist on every website whether the owner mentions them or not. My host records IP addresses, timestamps, requested URLs and user agents for security and reliability. I do not use those logs for marketing, do not link them to enquiries, and do not retain them beyond the host’s standard rolling window of roughly 30 days.

Sending information overseas

New Zealand’s Information Privacy Principle 12 means I may only send personal information outside New Zealand where the receiving country has comparable safeguards, or the recipient is contractually bound to protect it to a comparable standard. Because my suppliers are ordinary international SaaS providers, some of your information is processed in Australia, the European Union, the United Kingdom, Singapore and the United States.

For each supplier I rely on one or more of: an adequacy decision, the provider’s standard contractual clauses or international data transfer addendum, and the provider’s published security commitments. If you would like to know which mechanism applies to a specific supplier, ask and I will tell you.

How long I keep it

Nothing is kept “just in case” forever. These are the actual retention periods.

RecordKept forWhy
Enquiries that never became projects12 months from last contactLong enough to pick a conversation back up; short enough not to hoard
Proposals not accepted12 monthsReference for repeat enquiries
Client contracts, invoices and payment records7 yearsRequired by the NZ Tax Administration Act 1994
Project working files and research2 years after final delivery, then deletedSupports the 30-day check-in and later phases
Call recordings (where agreed)90 daysOnly needed while the copy is being written
Interview material involving your customersDeleted at project close unless you ask otherwiseIt is your data, not mine to keep
Newsletter subscriptionUntil you unsubscribe, plus a suppression recordThe suppression record exists so you are never re-added by accident
Server logsAbout 30 days, rollingSecurity and uptime
Browser local storageUntil you clear your browser dataIt lives on your device; I cannot read or delete it

How your information is protected

  • Two-factor authentication on every account that touches client information: email, documents, accounting, newsletter, hosting.
  • Full-disk encryption on every device I work from, with automatic lock and a password manager holding unique credentials for each service.
  • Encryption in transit. This site is served over HTTPS, and all supplier connections use TLS.
  • Least data. I don’t ask for admin access when read-only will do, and I hand analytics access back at the end of a project.
  • No client data on public or shared machines, no working from unsecured shared drives, no USB sticks.
  • Regular deletion. Retention periods above are reviewed and enforced twice a year rather than left to drift.

No system is perfect, and anyone who tells you otherwise is selling something. What I can promise is that the surface area is deliberately small: one person, a short list of suppliers, and no data collected that isn’t needed.

Your rights

Under the Privacy Act 2020 you have the right to access the personal information I hold about you and to request correction of anything inaccurate. If you are in the UK or the EU, the GDPR adds further rights.

RightWhat it means hereWhere it applies
AccessI send you everything I hold about you, in a readable formatNZ + UK/EU
CorrectionI fix it, and note the correction on the recordNZ + UK/EU
ErasureI delete it, except records tax law requires me to keepUK/EU (and honoured for NZ enquiries as a matter of practice)
RestrictionI keep it but stop using it while a dispute is resolvedUK/EU
PortabilityYou get the data you gave me in a machine-readable fileUK/EU
ObjectionYou object to processing based on legitimate interestsUK/EU
Withdraw consentOne click in any newsletter, or one email to meEverywhere

How to exercise them

Email [email protected] with the subject line “Privacy request”. Tell me what you want and, if we have not worked together, enough detail for me to find your record — usually the email address you used. I may ask one clarifying question to confirm it is really you, but I will not demand identity documents for a routine request.

I respond within 20 working days, which is the statutory maximum in New Zealand, and usually much sooner. There is no charge. If a request is genuinely excessive or repetitive I may explain why I am declining, and I will always tell you which provision I am relying on.

Cookies, local storage and tracking

The short version: this site sets no cookies. It stores two small values in your browser’s local storage — your theme preference and a summary of your last enquiry so the thank-you page can greet you by name. Neither is transmitted anywhere and neither can identify you to me.

The cookie policy explains exactly what is stored, how to inspect it yourself, and how to clear it.

Marketing and the newsletter

The Riveting Note is opt-in only. Subscribing takes one deliberate action, every issue carries a working one-click unsubscribe, and unsubscribing takes effect immediately rather than “within 10 days”.

Sending an enquiry does not subscribe you to anything. Becoming a client does not subscribe you either. New Zealand’s Unsolicited Electronic Messages Act 2007 requires consent, sender identification and a functional unsubscribe in commercial electronic messages; all three are honoured, and I apply the same standard to subscribers everywhere regardless of local law.

Automated decisions and artificial intelligence

No decision affecting you is made by an automated system. There is no lead scoring, no algorithmic pricing and no automated profiling. A human — me — reads every enquiry and decides whether to reply and what to quote.

On AI tools specifically, since it is a fair question to ask a writer in 2026: I use them for research, structure checks and phrasing exploration. I do not paste client confidential material, unpublished strategy, customer interview transcripts or personal information about identifiable people into third-party AI tools. Where a client prefers no AI involvement of any kind, that is written into the project agreement and honoured.

Children

These services are sold to businesses and are not directed at children. I do not knowingly collect personal information from anyone under 16. If you believe a child has submitted information through this site, email me and I will delete it promptly.

If something goes wrong

If a privacy breach occurs and it is likely to cause serious harm, New Zealand law requires notification to the Office of the Privacy Commissioner and to affected people as soon as practicable. I will notify you directly, in plain language, and tell you what happened, what information was involved, what I have done about it and what you should do. You will hear it from me rather than from a news story.

Links to other websites

This site links to LinkedIn, Facebook and Instagram, and articles occasionally link to other people’s work. Those sites have their own privacy practices, which I do not control and cannot vouch for. Nothing on my pages loads content from them in the background — a link is only followed when you click it.

Complaints

Come to me first. Most privacy complaints are misunderstandings that take one email to resolve, and I would rather fix it than have you take it elsewhere unhappy.

If you are not satisfied, you can complain to the Office of the Privacy Commissioner in New Zealand. If you are in the United Kingdom you may complain to the Information Commissioner’s Office; if you are in the European Union, to your national supervisory authority. Using this policy does not remove any right you have to complain to a regulator.

Changes to this policy

When this policy changes materially, three things happen: the “last updated” date at the top changes, the change is described in the log below, and — if the change affects how your information is used — anyone on the newsletter list is told in the next issue. Previous versions are kept, and I will send you one on request.

DateWhat changed
22 August 2026Full rewrite: added supplier list, legal-basis table, retention schedule, international transfers, AI-tool position and this change log.
1 August 2026Clarified local-storage use and added the newsletter suppression record.
14 February 2026First version published alongside the rebuilt website.

Questions about this page?

These policies are written by me, not pasted from a generator, and I am happy to explain any part of them. There is no legal department to route you through — the email below reaches me directly.

[email protected]

These policies are written in plain English for clarity. They are not legal advice, and if you are adapting them for your own business you should have a lawyer in your jurisdiction review them first.