Effective Date: May 1, 2026 | Last Updated: April 30, 2026
FoundHer is committed to protecting your personal information in accordance with the Privacy Act 2020, the Privacy Amendment Act 2025, and other applicable laws. This Privacy Policy explains how we collect, use, store, share, and protect your information when you use our services or visit our website.
FoundHer is operated by financial adviser Sarah Curley, who also acts as the Privacy Officer for the business. If you have any questions or concerns about this policy, please contact us at [email protected].
We collect personal information necessary to provide our financial advice services and operate our business. The information we collect includes:
When you engage with FoundHer, you provide information directly through meetings, phone calls, online forms, or email correspondence. This may include:
We may collect personal information about you from third-party sources, including:
Important: When we collect personal information about you from a third party (rather than directly from you), we will notify you as soon as reasonably practicable. We will tell you what information we collected, where we got it from, why we collected it, and your rights to access and correct that information. This notification requirement is part of the Privacy Amendment Act 2025, effective May 1, 2026 (Information Privacy Principle 3A).
There are limited exceptions to this notification requirement, including when:
When you visit foundher.co.nz, we automatically collect certain technical information about your visit using cookies and third-party analytics and advertising tools. This is explained in detail in Section 3 below (Cookies and Tracking Technologies).
We use your personal information only for lawful and relevant purposes related to our financial advice services. These purposes include:
We will not use your personal information for any purpose other than the reason it was collected, unless you consent or the Privacy Act 2020 permits disclosure (for example, to prevent or lessen a serious threat to public health or safety).
When you visit foundher.co.nz, we use cookies and third-party tracking technologies to understand how visitors interact with our website, improve user experience, develop our content strategy, and deliver targeted advertising. This section explains what tools we use, what data is collected, and how you can control these technologies.
Cookies are small text files stored on your device (computer, phone, or tablet) when you visit a website. They help websites remember information about your visit, such as your preferences or browsing behaviour. Cookies can be:
FoundHer uses the following third-party tracking and analytics tools on foundher.co.nz:
Provider: Google LLC
Purpose: To analyse website traffic, understand user behaviour, measure website performance, improve content strategy, and optimise advertising campaigns (including Google Ads)
Data Collected: IP address (anonymised), browser type and version, device type (desktop, mobile, tablet), operating system, pages visited, time spent on each page, links clicked, referring website, geolocation data (country, region, city), session duration, and browsing behaviour
Cookie Type: First-party and third-party persistent cookies
Retention Period: Google Analytics cookies are retained for up to 24 months
Data Sharing: Data is shared with Google as a third-party processor. Google processes this data on our behalf to provide analytics and advertising services.
Cross-Border Transfer: Google Analytics transfers data to servers in the United States and other jurisdictions. Google has implemented contractual protections and participates in recognised data transfer frameworks to safeguard your data.
Learn More: How Google uses information from sites or apps that use our services
Provider: Meta Platforms, Inc. (Facebook)
Purpose: To measure the effectiveness of advertising campaigns, track conversions (for example, form submissions or bookings), build custom audiences for targeted advertising on Facebook and Instagram, and enable remarketing to website visitors
Data Collected: IP address, browser type, device identifiers, pages visited, buttons clicked, forms submitted, referring website, and browsing behaviour
Cookie Type: Third-party persistent cookies
Retention Period: Meta Pixel cookies are retained for up to 90 days
Data Sharing: Data is shared with Meta as a third-party processor. Meta processes this data to provide advertising, remarketing, and analytics services.
Cross-Border Transfer: Meta Pixel transfers data to servers in the United States and other jurisdictions. Meta has implemented contractual protections to safeguard your data.
Provider: Google LLC
Purpose: To manage and deploy tracking codes (such as Google Analytics and Meta Pixel) on our website without modifying the website code directly
Data Collected: Google Tag Manager itself does not collect personal data. It is a container that deploys other tracking tools (like Google Analytics and Meta Pixel), which then collect data as described above.
Cookie Type: First-party cookies (used to coordinate the deployment of other tracking tools)
We use cookies and tracking technologies based on the following legal grounds:
You have full control over cookies and tracking technologies. You can opt out or manage your preferences at any time:
Google Analytics: Install the Google Analytics Opt-out Browser Add-on to prevent your data from being used by Google Analytics across all websites.
Meta Pixel (Facebook/Instagram Ads): Manage your advertising preferences at Facebook Ad Preferences to control how Meta uses your data for targeted advertising.
Most web browsers allow you to control cookies through their settings. You can:
For instructions on how to manage cookies in your browser, visit:
Important: Blocking or deleting cookies may affect your ability to use certain features of our website. Essential cookies required for basic website functionality will continue to operate, but analytics and advertising cookies will be blocked.
We only share your personal information when necessary to provide our services, when required by law, or with your explicit consent. We do not sell or trade your personal information to any other company or person.
We may share your information with:
When we share information internationally, we ensure the recipient has equivalent data protection standards. This includes using contractual protections and verifying participation in recognised data transfer frameworks.
At FoundHer, we use Artificial Intelligence (AI) tools, including Contented AI and Gamma AI, to assist with meeting summarisation and the drafting of advice documents. These tools enhance our efficiency and help us deliver information to you more clearly.
We prioritise your data security:
For a detailed explanation of our safeguards and our 'Traffic Light' data policy, please see our AI Transparency & Ethics Statement.
We take the security of your personal information seriously and implement appropriate physical and electronic security measures to protect it from unauthorised access, alteration, loss, or destruction.
Your personal information is stored securely, primarily in electronic form using:
Important: While we strive to protect your information, no system is entirely risk-free. We cannot guarantee absolute security, and using the internet to transmit data has inherent risks.
We keep your personal information only as long as necessary for the purposes for which it was collected or as required by law.
You have the following rights under the Privacy Act 2020:
You have the right to request access to the personal information we hold about you. We will respond within a reasonable timeframe (generally within 20 working days).
If you believe your information is incorrect, incomplete, or out of date, you may request a correction. If we do not agree to make the correction, we will add a note to your record stating your requested correction.
You may request that we delete your personal information. However, we may not be able to delete information we are legally required to keep (for example, financial advice records that must be retained for seven years).
If you are visiting from the European Union or European Economic Area, you have additional rights under the General Data Protection Regulation (GDPR):
To exercise any of these rights, please contact our Privacy Officer at [email protected]. We will respond within a reasonable timeframe. There may be a charge for access requests to cover administrative costs, but we will inform you of any fees before processing your request.
If we refuse your request, we will provide reasons and information on how to complain to the Office of the Privacy Commissioner.
In the unlikely event of a privacy breach that is likely to cause you serious harm, we will:
Our services are not directed at individuals under the age of 18. We do not knowingly collect personal information from children. If you believe we have inadvertently collected information from a child, please contact us immediately at [email protected] so we can delete it.
Our website may contain links to third-party websites (for example, product provider websites, regulatory bodies, or external resources). These websites are governed by their own privacy policies. We are not responsible for the privacy practices of third-party websites, and we encourage you to read their privacy policies before providing any personal information.
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will update the 'Last Updated' date at the top of this policy and notify you by:
We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your information.
If you are not satisfied with our response to your privacy concern or complaint, you have the right to contact the Office of the Privacy Commissioner:
Our Commitment to Your Privacy
FoundHer is committed to protecting your personal information in accordance with the
Privacy Act 2020 and other applicable laws. This policy outlines how we collect, use, store,
and share your data.
What We Collect
We collect personal information necessary for our services and business operations. This
includes information you provide directly (like during meetings or calls) and information from
third-party sources (like professional advisers, product providers, IT services, and
custodians). When you visit our website, we may also collect technical data like traffic,
location, cookies, and analytics.
How We Use Your Information
We use your personal information to:
● Provide, manage, and market our services.
● Communicate with you.
● Protect our legal rights.
● Conduct anonymised research.
● Undertake credit checks where needed.
● Comply with legal and regulatory obligations.
Sharing Your Information
We only share your personal information when necessary, as required by law, or with your
explicit consent. This may include sharing with:
● Business partners (IT, accountants, legal).
● Financial product providers.
● Debt collection agencies, if necessary.
● Other entities authorised by law.
● Regulatory bodies, such as the Financial Markets Authority (FMA), if legally required
or requested.
● A qualified locum adviser to ensure service continuity if we are unavailable. They will
be bound by confidentiality and only use your data for that purpose.
If we share information internationally, we ensure the recipient has equivalent data protection
standards.
Your Rights
You have the right to access, correct, or request the deletion of your personal information by
contacting us at [email protected]. We will respond within a reasonable timeframe,
though we may not be able to delete information we are legally required to keep. There may
be a charge for access requests to cover administrative costs. If we refuse a request, we will
provide reasons and information on how to complain.
Data Storage and Protection
We store your personal information securely, primarily electronically with reputable cloud
providers, and implement physical and electronic security measures. While we strive for
security, no system is entirely risk-free. We keep data only as long as necessary or legally
required (seven years for advice-related information)
Use of Technology and Artificial Intelligence
At FoundHer, we use Artificial Intelligence (AI) tools, including Contented AI and Gamma AI, to assist with meeting summarization and the drafting of advice documents. These tools enhance our efficiency and help us deliver information to you more clearly.
We prioritise your data security:
Privacy Protection: We use professional-grade subscriptions that contractually ensure your data is never used to train global AI models.
Data Sanitization: We mask or remove sensitive personal identifiers before data is processed by these tools.
Human Verification: All AI-generated content is reviewed, edited, and validated by a human adviser for accuracy. We do not use AI for financial calculations or core research.
For a detailed explanation of our safeguards and our 'Traffic Light' data policy, please see our publicly available AI Transparency & Ethics Statement.
Privacy Breaches
In the event of a privacy breach likely to cause you serious harm, we will secure the breach,
assess its severity, notify the Privacy Commissioner, and inform you directly where possible.
Internet Use
Using the internet to transmit data has inherent risks. Links to third-party websites from ours
are governed by their own privacy policies.
Contact Us
For any privacy concerns or requests, please contact our Privacy Officer at: Email:
[email protected]