Who I am, and how to reach me
This website and the copywriting services described on it are operated by Kristen Rive-Thomson, trading as The Riveting Copywriter, a sole trader based in Aotearoa New Zealand. For the purposes of the New Zealand Privacy Act 2020 I am the agency that holds your information; for the purposes of the UK and EU GDPR, where those laws apply to you, I am the data controller.
| Trading name | The Riveting Copywriter |
|---|---|
| Operator | Kristen Rive-Thomson, sole trader |
| Location | Aotearoa New Zealand (clients worldwide) |
| Privacy contact | [email protected] |
| Response time | One business day for questions; 20 working days for formal requests |
There is no separate privacy officer, no ticketing system and no outsourced team. Your email arrives directly with me, and I answer it.
What information I collect
Everything below is information you choose to hand over. This site does not fingerprint your device, buy data about you from anyone, or enrich what you submit with third-party profiles.
| Where it comes from | What is collected | Whether it is required |
|---|---|---|
| Contact form | Name, email address, website URL (optional), the service you selected, budget range (optional), your message, and the fact that you ticked the consent box | Name, email, service and message are required. The rest is optional and the form works without it. |
| Newsletter form | Email address only | Required, obviously. Nothing else is asked for or stored. |
| Email you send me | Whatever you write, plus your email address and any attachments | Entirely up to you. |
| Discovery and project calls | Notes I type during the call. Calls are recorded only if you agree first, in the call, out loud. | Recording is always optional and refusing changes nothing about the service. |
| Client projects | Business details, brand materials, analytics access, and — where you arrange them — interviews with your own customers | Necessary to do the work you have engaged me for. |
| Invoicing | Billing name, business address, email, GST or VAT number where relevant | Required by tax law once you become a client. |
| Your browser (locally only) | Your light/dark theme choice, and a short summary of your last enquiry | Stored on your device, never transmitted. See the cookie policy. |
Information about other people
During a project you may give me access to your customers — for interviews or review mining — or share documents that contain third-party personal information. In that arrangement you remain the controller of that information and I act on your instructions as a processor. I use it only to write your copy, never contact those people again afterwards, and delete my copies at the end of the project unless you ask me to keep them for a follow-up phase.
What I deliberately do not collect
- No advertising cookies, pixels or trackers. There is no Meta pixel, no LinkedIn Insight tag, no Google Ads remarketing on this site.
- No third-party analytics by default. This site currently runs no analytics at all. If that ever changes, the change appears in the log at the bottom of this page before it goes live.
- No embedded fonts, scripts or media from other companies. Every font and library is served from this domain, so no third party learns that you visited.
- No sensitive information. I never ask for health data, ethnicity, political or religious views, sexual orientation, biometric data, government identifiers, or card numbers. Please don’t put any of it in the message field.
- No purchased lists. Nobody is added to the newsletter without asking for it themselves.
Why I use it, and my legal basis
Under the Privacy Act 2020 I collect only what is necessary for a lawful purpose connected with my business. Where the GDPR applies, each purpose also needs a legal basis. Here is both, laid out honestly.
| Purpose | Information used | GDPR legal basis |
|---|---|---|
| Replying to your enquiry and arranging a call | Contact form fields, emails | Steps taken at your request prior to entering a contract (Art. 6(1)(b)) |
| Preparing an accurate, fixed-fee proposal | Service selected, budget range, message | Pre-contractual steps (Art. 6(1)(b)) |
| Delivering the project you engaged me for | Project materials, analytics, interviews | Performance of a contract (Art. 6(1)(b)) |
| Invoicing and keeping tax records | Billing details, invoice history | Legal obligation (Art. 6(1)(c)) — NZ Tax Administration Act |
| Sending the newsletter | Email address | Consent (Art. 6(1)(a)), withdrawable in one click |
| Keeping my own business records and defending claims | Contracts, correspondence | Legitimate interests (Art. 6(1)(f)) |
| Remembering your theme preference | A value in your browser’s local storage | Strictly necessary for a feature you asked for; no consent banner required |
Where I rely on legitimate interests, I have weighed my interest in running a functioning business against your privacy, and limited the data to what a reasonable person would expect a service provider to keep. You can object to that processing at any time using the contact details above.
Sell it. Rent it. Trade it for a listing. Share it with a data broker or an AI training set. Add you to a newsletter because you sent a project enquiry. Use anything you told me in confidence as a case study without asking you first, by name, in writing.
Who else can see your information
I use a small number of established suppliers to actually run a business. Each one is a processor acting on my instructions, bound by its own contractual and legal obligations, and none of them is permitted to use your information for its own purposes.
| Supplier | What it handles | Where it processes data |
|---|---|---|
| Email and document hosting | Your emails, project docs, call notes | Data centres in Australia, the EU and the United States |
| Web hosting and CDN | Serving this site; standard server logs including IP address | Regional edge locations, typically Australia or Singapore for NZ visitors |
| Newsletter platform | Subscriber email addresses, send and open records | European Union or United States, depending on plan region |
| Accounting and invoicing software | Billing details, invoice and payment history | New Zealand and Australia |
| Video calling | Live calls; recordings only where you agreed | United States and regional relays |
| Payment processor / bank | Payment settlement. I never see or store full card numbers. | New Zealand and the payment network’s own regions |
Beyond that list, I disclose information only where the law requires it — a court order, a tax audit, a lawful request from a regulator — or where it is necessary to establish or defend a legal claim. If I ever receive a government request for your information and I am legally permitted to tell you about it, I will.
Server logs deserve a specific mention because they exist on every website whether the owner mentions them or not. My host records IP addresses, timestamps, requested URLs and user agents for security and reliability. I do not use those logs for marketing, do not link them to enquiries, and do not retain them beyond the host’s standard rolling window of roughly 30 days.
Sending information overseas
New Zealand’s Information Privacy Principle 12 means I may only send personal information outside New Zealand where the receiving country has comparable safeguards, or the recipient is contractually bound to protect it to a comparable standard. Because my suppliers are ordinary international SaaS providers, some of your information is processed in Australia, the European Union, the United Kingdom, Singapore and the United States.
For each supplier I rely on one or more of: an adequacy decision, the provider’s standard contractual clauses or international data transfer addendum, and the provider’s published security commitments. If you would like to know which mechanism applies to a specific supplier, ask and I will tell you.
How long I keep it
Nothing is kept “just in case” forever. These are the actual retention periods.
| Record | Kept for | Why |
|---|---|---|
| Enquiries that never became projects | 12 months from last contact | Long enough to pick a conversation back up; short enough not to hoard |
| Proposals not accepted | 12 months | Reference for repeat enquiries |
| Client contracts, invoices and payment records | 7 years | Required by the NZ Tax Administration Act 1994 |
| Project working files and research | 2 years after final delivery, then deleted | Supports the 30-day check-in and later phases |
| Call recordings (where agreed) | 90 days | Only needed while the copy is being written |
| Interview material involving your customers | Deleted at project close unless you ask otherwise | It is your data, not mine to keep |
| Newsletter subscription | Until you unsubscribe, plus a suppression record | The suppression record exists so you are never re-added by accident |
| Server logs | About 30 days, rolling | Security and uptime |
| Browser local storage | Until you clear your browser data | It lives on your device; I cannot read or delete it |
How your information is protected
- Two-factor authentication on every account that touches client information: email, documents, accounting, newsletter, hosting.
- Full-disk encryption on every device I work from, with automatic lock and a password manager holding unique credentials for each service.
- Encryption in transit. This site is served over HTTPS, and all supplier connections use TLS.
- Least data. I don’t ask for admin access when read-only will do, and I hand analytics access back at the end of a project.
- No client data on public or shared machines, no working from unsecured shared drives, no USB sticks.
- Regular deletion. Retention periods above are reviewed and enforced twice a year rather than left to drift.
No system is perfect, and anyone who tells you otherwise is selling something. What I can promise is that the surface area is deliberately small: one person, a short list of suppliers, and no data collected that isn’t needed.
Your rights
Under the Privacy Act 2020 you have the right to access the personal information I hold about you and to request correction of anything inaccurate. If you are in the UK or the EU, the GDPR adds further rights.
| Right | What it means here | Where it applies |
|---|---|---|
| Access | I send you everything I hold about you, in a readable format | NZ + UK/EU |
| Correction | I fix it, and note the correction on the record | NZ + UK/EU |
| Erasure | I delete it, except records tax law requires me to keep | UK/EU (and honoured for NZ enquiries as a matter of practice) |
| Restriction | I keep it but stop using it while a dispute is resolved | UK/EU |
| Portability | You get the data you gave me in a machine-readable file | UK/EU |
| Objection | You object to processing based on legitimate interests | UK/EU |
| Withdraw consent | One click in any newsletter, or one email to me | Everywhere |
How to exercise them
Email [email protected] with the subject line “Privacy request”. Tell me what you want and, if we have not worked together, enough detail for me to find your record — usually the email address you used. I may ask one clarifying question to confirm it is really you, but I will not demand identity documents for a routine request.
I respond within 20 working days, which is the statutory maximum in New Zealand, and usually much sooner. There is no charge. If a request is genuinely excessive or repetitive I may explain why I am declining, and I will always tell you which provision I am relying on.
Cookies, local storage and tracking
The short version: this site sets no cookies. It stores two small values in your browser’s local storage — your theme preference and a summary of your last enquiry so the thank-you page can greet you by name. Neither is transmitted anywhere and neither can identify you to me.
The cookie policy explains exactly what is stored, how to inspect it yourself, and how to clear it.
Marketing and the newsletter
The Riveting Note is opt-in only. Subscribing takes one deliberate action, every issue carries a working one-click unsubscribe, and unsubscribing takes effect immediately rather than “within 10 days”.
Sending an enquiry does not subscribe you to anything. Becoming a client does not subscribe you either. New Zealand’s Unsolicited Electronic Messages Act 2007 requires consent, sender identification and a functional unsubscribe in commercial electronic messages; all three are honoured, and I apply the same standard to subscribers everywhere regardless of local law.
Automated decisions and artificial intelligence
No decision affecting you is made by an automated system. There is no lead scoring, no algorithmic pricing and no automated profiling. A human — me — reads every enquiry and decides whether to reply and what to quote.
On AI tools specifically, since it is a fair question to ask a writer in 2026: I use them for research, structure checks and phrasing exploration. I do not paste client confidential material, unpublished strategy, customer interview transcripts or personal information about identifiable people into third-party AI tools. Where a client prefers no AI involvement of any kind, that is written into the project agreement and honoured.
Children
These services are sold to businesses and are not directed at children. I do not knowingly collect personal information from anyone under 16. If you believe a child has submitted information through this site, email me and I will delete it promptly.
If something goes wrong
If a privacy breach occurs and it is likely to cause serious harm, New Zealand law requires notification to the Office of the Privacy Commissioner and to affected people as soon as practicable. I will notify you directly, in plain language, and tell you what happened, what information was involved, what I have done about it and what you should do. You will hear it from me rather than from a news story.
Links to other websites
This site links to LinkedIn, Facebook and Instagram, and articles occasionally link to other people’s work. Those sites have their own privacy practices, which I do not control and cannot vouch for. Nothing on my pages loads content from them in the background — a link is only followed when you click it.
Complaints
Come to me first. Most privacy complaints are misunderstandings that take one email to resolve, and I would rather fix it than have you take it elsewhere unhappy.
If you are not satisfied, you can complain to the Office of the Privacy Commissioner in New Zealand. If you are in the United Kingdom you may complain to the Information Commissioner’s Office; if you are in the European Union, to your national supervisory authority. Using this policy does not remove any right you have to complain to a regulator.
Changes to this policy
When this policy changes materially, three things happen: the “last updated” date at the top changes, the change is described in the log below, and — if the change affects how your information is used — anyone on the newsletter list is told in the next issue. Previous versions are kept, and I will send you one on request.
| Date | What changed |
|---|---|
| 22 August 2026 | Full rewrite: added supplier list, legal-basis table, retention schedule, international transfers, AI-tool position and this change log. |
| 1 August 2026 | Clarified local-storage use and added the newsletter suppression record. |
| 14 February 2026 | First version published alongside the rebuilt website. |