Privacy Policy
Effective date: 30 July 2026
1. About this policy
Digital Discovery Limited trading as Dynamic HSE respects your privacy and is committed to handling personal information in accordance with the Privacy Act 2020.
This policy explains how we collect, use, store, disclose and protect personal information.
It applies to our:
- websites;
- online academy;
- courses and assessments;
- certificates;
- purchases and enrolments;
- course-interest forms;
- communications; and
- related services.
2. Who we are
The agency responsible for the information covered by this policy is:
Digital Discovery Limited trading as Dynamic HSE
Auckland, New Zealand
Privacy contact: Privacy Officer
Email: [email protected]
3. Information we may collect
Depending on how you interact with us, we may collect:
- your name;
- email address and telephone number;
- organisation, employer and job information;
- account and login information;
- enrolment and course-assignment information;
- course progress;
- assessment answers, results and attempts;
- certificate and completion information;
- purchase, transaction and invoice information;
- refund and payment-dispute information;
- support requests and communications;
- feedback and complaints;
- course-interest selections and anticipated learner numbers;
- marketing preferences;
- IP address, browser, device and approximate location information;
- website and platform activity;
- cookie and analytics information; and
- any other information you choose to provide.
We do not ordinarily receive or store complete payment-card information. Card details are handled by the applicable payment provider.
4. How we collect information
We may collect personal information:
- directly from you;
- from an employer, purchaser or organisation enrolling you in training;
- when you create an account;
- when you purchase, access or complete training;
- when you complete an assessment;
- when you submit a Formly or other online form;
- when you contact us;
- through our websites, academy, cookies and analytics tools;
- from payment and service providers; or
- where collection is otherwise authorised or permitted by law.
5. Information collected from employers and other sources
An employer, purchaser or organisation may provide us with learner information so that training can be assigned and administered.
Where we collect personal information about you from someone else, we will take reasonable steps to ensure that you are informed of the matters required by Information Privacy Principle 3A, unless:
- you have already been made aware of those matters;
- the organisation providing the information has given the required notice on our behalf; or
- another lawful exception applies.
The information provided may include your name, email address, organisation, assigned course and training requirements.
6. Why we use personal information
We may use personal information to:
- create and administer accounts;
- process purchases and payments;
- enrol learners;
- deliver courses and assessments;
- record course progress and results;
- issue and verify certificates;
- communicate with learners and purchasers;
- provide technical and customer support;
- respond to course-interest registrations;
- manage refunds, disputes and complaints;
- maintain the security and integrity of our systems;
- prevent fraud, account sharing and misuse;
- improve our websites, training and services;
- analyse demand for future courses;
- meet legal, accounting, insurance and recordkeeping requirements;
- establish, exercise or defend legal claims; and
- send marketing communications where permitted.
We will not use personal information for a materially different purpose unless that use is authorised by law or we obtain any consent that is required.
7. Organisation access to learner information
Where an employer or organisation purchases, assigns or administers training, we may provide that organisation with information including:
- whether a learner has activated an account;
- enrolment status;
- course progress;
- assessment status and result;
- completion date; and
- certificate information.
Learners should contact their employer or purchasing organisation if they have questions about how that organisation uses training records supplied to it.
8. Service providers and disclosures
We may provide personal information to service providers that assist us with:
- learning management;
- websites and hosting;
- forms and surveys;
- email and communications;
- cloud storage;
- spreadsheets and reporting;
- payment processing;
- accounting;
- analytics;
- cybersecurity;
- professional advice; and
- other business operations.
These providers may include Klasio, Formly, Google Workspace and the payment provider used at checkout.
We may also disclose information:
- to an organisation that purchased or assigned the training;
- to our accountants, insurers, lawyers and other professional advisers;
- where required or permitted by law;
- to protect the rights, safety or property of Dynamic HSE or another person;
- in connection with a proposed or completed sale, restructure or transfer of the business; or
- with your authorisation.
We do not sell personal information.
9. Overseas storage and disclosure
Some service providers may store or process personal information outside New Zealand.
Where a provider processes information on our behalf as our agent, we will take reasonable steps to select and manage an appropriate provider.
Where Information Privacy Principle 12 applies to an overseas disclosure, we will rely on an authorised basis for that disclosure. This may include being satisfied on reasonable grounds that:
- the recipient is subject to the New Zealand Privacy Act;
- the recipient is subject to comparable privacy safeguards;
- the recipient has agreed to provide comparable safeguards; or
- you have expressly authorised the disclosure after receiving any required information.
10. Marketing communications
We may send you information about courses, services or promotions where:
- you have consented;
- consent can reasonably be inferred from the circumstances; or
- sending the communication is otherwise permitted by law.
Commercial electronic messages will identify Dynamic HSE and include a functional method of unsubscribing.
You may withdraw consent at any time by:
- using the unsubscribe function in the message; or
- contacting [email protected].
Unsubscribing from marketing does not prevent us from sending necessary account, purchase, course, certificate, security or service communications.
11. Cookies and analytics
Our websites and academy may use cookies and similar technologies to:
- enable accounts and platform functions;
- maintain security;
- remember preferences;
- understand website and course use;
- measure performance; and
- improve our services.
Some cookies may be provided by third-party platforms or analytics providers.
You can control cookies through your browser. Disabling cookies may affect website or course functionality.
12. Security
We take reasonable technical and organisational steps to protect personal information against:
- loss;
- unauthorised access;
- misuse;
- alteration;
- disclosure; and
- destruction.
These measures may include access controls, account authentication, reputable service providers, backups and security monitoring.
No online system can guarantee absolute security.
13. Privacy breaches
If a privacy breach has caused, or is likely to cause, serious harm, we will notify the Office of the Privacy Commissioner and affected individuals as required by the Privacy Act 2020.
14. Retention
We retain personal information only for as long as reasonably required for:
- course administration;
- completion and certificate verification;
- purchaser and learner support;
- legal, accounting, tax and insurance requirements;
- security and fraud prevention; and
- resolving complaints or disputes.
Course completion and certificate information may be retained after course access expires so that completion can be verified.
When information is no longer reasonably required, we will take reasonable steps to delete, anonymise or securely dispose of it.
15. Access and correction
You may ask us to:
- confirm whether we hold personal information about you;
- provide access to that information; or
- correct information that is inaccurate or incomplete.
Send requests to:
Privacy Officer
Email: [email protected]
We may ask you to verify your identity before processing a request.
Where we do not make a requested correction, you may ask us to attach a statement of correction to the information.
16. Complaints
Contact us if you have a privacy concern.
Privacy Officer
Email: [email protected]
We will investigate and respond within a reasonable period.
You may also complain to the New Zealand Office of the Privacy Commissioner.
17. Third-party websites
Our websites and courses may contain links to third-party websites and resources.
Dynamic HSE is not responsible for the privacy practices, security or content of an independent third-party website.
18. Changes to this policy
We may update this policy to reflect changes to our services, providers, practices or legal obligations.
The current version will be published with its effective date.
