ReFix
Privacy Policy
This policy explains how Deal Busters Limited trading as REFiX collects, holds, uses and discloses personal information under the Privacy Act 2020 and the current information privacy principles (IPPs).
Effective: 15 August 2026 • Last reviewed: 15 August 2026
Purpose and scope
This policy explains how Deal Busters Limited trading as REFiX collects, holds, uses and discloses personal information under the Privacy Act 2020 and the current information privacy principles (IPPs). It applies when you visit our website, make an enquiry, seek regulated financial advice, apply for lending or another product through REFiX, provide supporting documents, or when we collect your information indirectly in connection with those activities. This policy is a compliance draft for legal and compliance review. It does not by itself establish that every operational process is complete, and it is not a substitute for collection-point notices, contracts, retention schedules, breach procedures or staff training.
Who we are and how to contact us
Deal Busters Limited trading as REFiX is the agency that collects and holds personal information for the activities covered by this policy.
- Registered address: 13 Durham Heights, Flagstaff, Hamilton 3210, New Zealand
- Client office: 327 Te Rapa Road, Hamilton 3200, New Zealand
- Privacy Officer: Bhavin Desai
- Email: bhavin@refix.co.nz
- Telephone: 021 233 0244 Website: REFiX website
Personal information we collect
We collect only personal information that is reasonably necessary for a lawful purpose connected with our functions or activities. Depending on your dealings with us, this may include:
- Identity and contact information: name, date of birth, address, email address, telephone number and related identifiers.
- Financial information: financial position and goals, income, expenses, assets, liabilities and supporting records.
- Applications and products: enquiries, applications, product preferences, terms, outcomes and servicing information.
- Identity-verification information: identity documents, verification results and information used to confirm identity.
- Credit information: credit reports, credit history, repayment information and relevant credit- assessment material.
- Employment information: employer details, role, income and employment history.
- Communications and advice records: emails, calls, meeting notes, instructions, recommendations, disclosures and other records of our interactions.
- Website, device and cookie information: IP address, device and browser details, pages visited, timestamps, referral information and cookie identifiers.
- Marketing preferences: contact preferences, consents, subscriptions and opt-out records.
- Health information: only where it is relevant to a product or service and we may lawfully collect it.
How we collect information directly
We may collect personal information directly from you through forms, conversations with advisers, email or telephone, website use, document uploads, authorised bank-statement services, and your engagement with us or our advisers. Before collecting information directly, or if that is not practicable as soon as practicable afterwards, we will take reasonable steps to make you aware of the matters required by IPP3. These include:
- that information is being collected and the purpose for which it is being collected
- the intended recipients of the information
- the name and address of the agency collecting and holding it
- any particular law that authorises or requires the collection, if applicable
- whether supplying the information is voluntary or mandatory and the consequences if it is not supplied
- your rights to request access to and correction of your personal information Where a collection is authorised or required by law, the collection-specific notice will name the particular law, explain whether supply is voluntary or mandatory, and describe the consequences of not supplying the information. We will not treat a general reference to law as a substitute for that notice.
Information collected from other sources
Where authorised by you or permitted by law, we may collect personal information from:
- NZ Financial Services Group Limited (NZFSG) and related entities
- credit reporters
- banks and bank-statement providers acting with appropriate authority
- employers and referees
- lenders and other product providers
- identity-verification providers
- your authorised representatives
- lawful public sources
- other sources you authorise or that the law permits us to use Under IPP3A, we will take reasonable steps to notify you as soon as reasonably practicable after collecting personal information from another source, unless you have already received the required notice or another statutory exception applies. An IPP3A notice will address the fact and circumstances of collection, the purpose, intended recipients, the name and address of the collecting and holding agency, any applicable legal authority, whether supply is voluntary or mandatory and the consequences of non-supply, and your access and correction rights. Where appropriate, REFiX will retain evidence that notice was given, that prior notice covered the collection, or that a statutory exception applied.
Why we collect and use personal information
We collect and use personal information for specific, lawful purposes, including to:
- respond to enquiries and communicate with you
- understand and assess your circumstances, needs and goals
- provide and document financial advice
- identify suitable lending or other products
- prepare, submit, manage and support applications
- verify identity, information and supporting documents
- communicate with lenders, product providers and other authorised participants
- meet legal, licensing, audit, assurance and record-keeping duties
- manage service quality, enquiries, complaints and disputes
- prevent, detect and respond to fraud, misuse and security risks
- administer our relationship and business operations
- send marketing where permitted by law We generally use information for the purpose for which it was obtained, a directly related purpose, or another purpose permitted by the Privacy Act 2020. A materially new purpose requires an appropriate lawful basis and notice or authorisation where required.
NZFSG collection, holding and oversight
REFiX is a member of NZ Financial Services Group Limited (NZFSG). We share information with NZFSG for monitoring, oversight, assurance, audit, compliance and service-support functions connected with regulated financial advice, including oversight arrangements relevant to the Financial Markets Conduct Act 2013. Information shared for these functions may include identity and contact information, advice records, application information, communications and sensitive financial information. NZFSG is an agency that may collect and hold this information. Because this oversight arrangement is part of REFiX's NZFSG membership, necessary sharing with NZFSG is a condition of REFiX providing regulated financial-advice services. Sharing is limited to information reasonably necessary for those functions; this statement does not mean that the Financial Markets Conduct Act 2013 authorises every disclosure. For NZFSG's own privacy practices, contact information and access or correction process, see the NZFSG privacy policy.
Who we may disclose information to
Where relevant to the purpose for which information was collected, authorised by you, or otherwise permitted by law, we may disclose personal information to:
- prospective and selected lenders or other product providers
- mortgage insurers
- guarantors, trustees and assignees where relevant
- credit reporting and identity-verification agencies
- authorised bank-statement providers
- NZFSG and its service providers
- REFiX contractors and professional advisers
- referral partners, only where authorised or otherwise lawful
- regulators and government agencies where required or permitted
- a purchaser or successor in a legitimate business transaction, subject to appropriate safeguards Each disclosure remains subject to IPP11 or another applicable legal authority. We will limit disclosures to what is reasonably necessary for the relevant purpose or legal basis.
Overseas storage, processing and disclosure
An overseas service provider may store or process information solely as our agent. When it acts only on our behalf and does not use the information for its own purposes, REFiX remains responsible for taking reasonable steps to ensure appropriate safeguards. A disclosure to an overseas person or organisation for that recipient's own purposes is different. Before making such a disclosure, we will establish a basis permitted by IPP12, such as the recipient being subject to the Privacy Act 2020, being protected by comparable privacy law, participating in a binding scheme, or being bound by contractual arrangements that provide comparable safeguards. If we instead rely on your authorisation, we will first expressly warn you that the overseas recipient may not be required to provide comparable safeguards to those in the Privacy Act 2020, and we will obtain specific authorisation for that disclosure. Providers, countries and safeguards may change. Collection-specific information will be supplied where required; this policy does not name arrangements that have not been verified.
Security
We will use reasonable technical and organisational safeguards appropriate to the sensitivity of the financial, identity, credit and other information we hold. These safeguards may include access controls, secure systems, confidentiality obligations for staff and contractors, appropriate transmission methods, vendor management and secure disposal. No internet transmission is completely risk-free, but this does not reduce REFiX's continuing obligations under the Privacy Act 2020 to protect personal information with safeguards that are reasonable in the circumstances.
Accuracy and retention
Before using or disclosing personal information, we will take reasonable steps to ensure it is accurate, up to date, complete, relevant and not misleading, having regard to the purpose for which it will be used or disclosed. We will retain personal information only for as long as it is required for the purposes for which it may lawfully be used and for any verified legal or regulatory retention obligation. When it is no longer required, we will securely delete or de-identify it, subject to lawful exceptions.
Website, cookies and analytics
When you use our website, we may collect IP addresses, device and browser information, pages visited, timestamps, referral information and cookie identifiers. This information may be personal information when it identifies you or can reasonably be linked to you. We may use necessary technologies to operate and secure the website, preference technologies to remember choices, and analytics technologies to understand website use and improve our services. Any collection and use remains subject to this policy and applicable law. You can use browser settings to manage or block some cookies. Doing so may affect website functions, and browser controls may not prevent every form of collection or measurement.
Direct marketing
We will send marketing communications only as permitted by law. Marketing messages will identify the sender and provide a functional way to unsubscribe. We will action valid opt-out requests within the timeframe required by law. Opting out of marketing does not prevent us from sending communications that are necessary to provide services, manage an application, respond to you, or meet legal obligations.
Accessing and correcting personal information
You may ask us to confirm whether we hold personal information about you and request access to or correction of that information. Contact Bhavin Desai, Privacy Officer, at bhavin@refix.co.nz or 021 233 0244. We will handle requests within the statutory timeframes. The Privacy Act 2020 permits information to be withheld in certain circumstances; if a lawful withholding ground applies, we will explain our decision as required by law. If we do not make a requested correction, you may ask us to attach a statement of correction to the information. Any charge by REFiX will be lawful, reasonable and assessed for the particular request; charges are not routine.
Privacy breaches
We will assess suspected privacy breaches promptly. If it is reasonable to believe that a privacy breach has caused, or is likely to cause, serious harm, we will notify the Privacy Commissioner as soon as practicable. We will also notify affected individuals or give public notice as required by the Privacy Act 2020, subject to the statutory exceptions and delay provisions that apply to those notifications.
Questions and complaints
Please first raise any privacy question or complaint with Bhavin Desai, Privacy Officer, at bhavin@refix.co.nz or 021 233 0244. We will review the issue and respond through our internal process. If you are dissatisfied with our response, you may make a complaint to the Office of the Privacy Commissioner. See its complaint guidance.
Changes to this policy
We may update this policy when our practices or legal obligations change. We will publish material changes with a revised effective date. Continued use of our website is not treated as blanket consent to materially different collection, use or disclosure; we will provide additional notice or obtain authorisation where required.
Collection-point notices
This policy does not replace shorter notices that may be required for enquiry forms, fact-find forms, credit-check authorities, bank-statement integrations, document-upload pages, referral workflows and other collection points. Those notices must be consistent with this policy and displayed or communicated at the legally appropriate time. Depending on the collection, they may need to identify the specific purpose, recipients, collecting and holding agencies, applicable legal authority, whether supply is voluntary or mandatory, consequences of non-supply, and access and correction rights. This policy records the governing approach; it does not claim that every collection-point notice or operational implementation has already been completed.