← All legal documents · Privacy Policy · Children's Privacy Notice

Balance — New Zealand Country Annex

Effective date: 28 June 2026 Last updated: 28 June 2026

Owner: , Director, BabaYaga Program, TOO — Privacy Officer and Designated Child Safety Officer for every New Zealand resident covered by this Annex; the privacy officer under s 201 of the Privacy Act 2020 (NZ); the designated contact point for the Office of the Privacy Commissioner (Te Mana Mātāpono Matatapu) ("OPC NZ"), the Department of Internal Affairs — Digital Safety Group, NetSafe, the Commerce Commission, and the Office of Film and Literature Classification ("OFLC") under their respective intake protocols. Reviewed: at least once a year, by 9 June. Re-opened immediately on (a) any amendment to the Privacy Act 2020 (NZ) ("Privacy Act") — in force from 1 December 2020 and replacing the Privacy Act 1993 (NZ) — including any amendment to the 13 Information Privacy Principles ("IPPs") at s 22, to the cross-border-disclosure regime at IPP 12 + s 22 + the Privacy (Cross-border Information) Regulations if and when prescribed under s 214, or to Part 6 (Notifiable Privacy Breaches scheme — ss 112–119); (b) any prescribed regulation under s 214 of the Privacy Act 2020 designating a "prescribed country" for the purposes of IPP 12(1)(f); (c) any code of practice issued by the Privacy Commissioner under ss 32–46 of the Privacy Act 2020; (d) any decision of the Human Rights Review Tribunal under Part 5 of the Privacy Act 2020 (ss 88–104); (e) any Order / compliance notice / access direction / prosecution by the Privacy Commissioner under Privacy Act ss 79–87, 99, 105, 211, 212, 213; (f) any judgment of the High Court of New Zealand / Court of Appeal of New Zealand / Supreme Court of New Zealand that materially affects the privacy-related tort of intrusion upon seclusion (recognised in C v Holland [2012] NZHC 2155) or the privacy-related tort of publication of private facts (recognised in Hosking v Runting [2004] NZCA 34 / [2005] 1 NZLR 1) or that materially changes the interpretation of any IPP; (g) any amendment to the Harmful Digital Communications Act 2015 (NZ) ("HDCA"); (h) any amendment to the Films, Videos, and Publications Classification Act 1993 (NZ) ("FVPCA") or its associated Films, Videos, and Publications Classification (Interim Restriction Orders) Amendment Act 2021 + Films, Videos, and Publications Classification (Urgent Interim Classification of Publications and Prevention of Online Harm) Amendment Act 2021; (i) any amendment to the Crimes Act 1961 (NZ) in particular ss 124, 124A, 131, 131A, 131B, 132, 134, 144A (extraterritorial child sex offences), 144C, 216H–216N (intimate visual recordings); (j) any amendment to the Unsolicited Electronic Messages Act 2007 (NZ) ("UEM Act") or its associated regulations; (k) any amendment to the Search and Surveillance Act 2012 (NZ) ("SSA"), the Telecommunications (Interception Capability and Security) Act 2013 (NZ) ("TICSA"), or the Customs and Excise Act 2018 (NZ); (l) any amendment to the Consumer Guarantees Act 1993 (NZ) ("CGA"), the Fair Trading Act 1986 (NZ) ("FTA"), or the Credit Contracts and Consumer Finance Act 2003 (NZ); (m) any amendment to the Oranga Tamariki Act 1989 (NZ) (formerly the Children, Young Persons, and Their Families Act 1989) or to the Children's Act 2014 (NZ); (n) the European Commission rescinding or modifying Commission Implementing Decision 2013/65/EU of 19 December 2012 — on the adequate protection of personal data by New Zealand (the New Zealand EU adequacy decision, in force at the Effective date); (o) New Zealand's accession to the Council of Europe Convention 108 or Convention 108+ (not in force at the Effective date — New Zealand has been invited to accede but has not formally acceded); (p) any amendment to a sub-processor's New Zealand data-handling posture under our sub-processor register; (q) the bringing into force of any post-Effective-date New Zealand regulation governing automated processing or related techniques (covered by the deliberate-silence carve-out in § 2 of this Annex). Classification: Public legal annex. This document is published at Privacy Policy alongside the global Privacy Policy (H1) and at Children's Privacy Notice alongside the Children's Privacy Notice (H2), and is incorporated by reference into both. It is one of the country annexes that travel with the global documents under the "global policy + per-country annex" architecture documented in our internal compliance plan § 6.3.

This Annex discharges the country-annex obligations referenced in:

This Annex is the canonical New Zealand-resident extension of the global Privacy Policy and Children's Privacy Notice. Where this Annex grants a New Zealand resident a right that the global Policy does not, this Annex governs. Where the global Policy grants a New Zealand resident a right that this Annex does not, the global Policy governs. The two are read together.

This Annex is drafted in English. New Zealand's official languages are te reo Māori, English, and New Zealand Sign Language (Māori Language Act 2016 (NZ); New Zealand Sign Language Act 2006 (NZ); English by convention and constitutional inheritance). Te reo Māori translation is queued for the Phase-2 locale rollout per our internal compliance tracker, consistent with the Privacy Commissioner's obligation under Privacy Act 2020 s 7(1)(b) to take account of cultural perspectives of Māori in the exercise of the Commissioner's functions and powers. Where this Annex is read by a Māori-speaking resident of Aotearoa New Zealand and a discrepancy arises between the English and the queued te reo Māori versions once published, the resident may choose the operative language.


1. Scope and applicability

This Annex applies to every Balance user (parent or kid) whose country of residence is Aotearoa New Zealand ("New Zealand" or "Aotearoa NZ"), including:

We determine country of residence at install/sign-up time by (a) the country and region the parent self-declares in the in-app onboarding flow, (b) the IP-geolocation read at sign-up (which we discard immediately after the residence decision — our internal data-flow map § 2.1 stores no IP after the authentication request closes), and (c) the Play Store account locale that Google Play passes to us at install. The residence determination is reviewable at any time by the parent at Settings → Account → Region.

Where any of the three signals identifies New Zealand as the country of residence, this Annex applies, even if the other signals are non-New-Zealand. The most-protective-for-the-data-subject reading is the controlling reading per our internal compliance plan § 6.3.

The Privacy Act 2020 has extraterritorial effect under s 4: it applies to "an overseas agency that, in the course of carrying on business in New Zealand", collects or holds personal information. The High Court of New Zealand in Director of Human Rights Proceedings v Christchurch City Council [2018] NZHRRT 21 and the Privacy Commissioner's published guidance confirm that targeting New Zealand-resident consumers from outside New Zealand satisfies the "carrying on business in New Zealand" limb. Balance squarely targets New Zealand residents through Google Play New Zealand, through publication of this Annex at balance.babayagaprogram.com, and through delivery of the parental-control service to New-Zealand-resident parents and kids; the Privacy Act 2020 applies in full.


2. Statutory framework — what applies

The New Zealand personal-information-protection regime is dominated by the Privacy Act 2020 and its 13 Information Privacy Principles ("IPPs"). The Privacy Act 2020 sits at the intersection of: the New Zealand Bill of Rights Act 1990; the customary and common-law privacy torts (intrusion upon seclusion per C v Holland [2012] NZHC 2155; publication of private facts per Hosking v Runting [2004] NZCA 34); the Harmful Digital Communications Act 2015 (NZ); the Films, Videos, and Publications Classification Act 1993 (NZ); the Crimes Act 1961 (NZ); the Oranga Tamariki Act 1989 (NZ); the Care of Children Act 2004 (NZ); the Unsolicited Electronic Messages Act 2007 (NZ); the Consumer Guarantees Act 1993 (NZ); the Fair Trading Act 1986 (NZ); and the Treaty of Waitangi / Te Tiriti o Waitangi read into Privacy Act 2020 s 7(1)(b). New Zealand holds an EU adequacy decision since 2012 — one of only nine non-EU/EEA jurisdictions (and the only South-Pacific jurisdiction) to hold one as of the Effective date.

Instrument Short cite What it does Balance's posture
New Zealand Bill of Rights Act 1990 (NZ) NZBORA — s 21 (right to be secure against unreasonable search or seizure); s 14 (freedom of expression); s 19 (freedom from discrimination); s 28 (other rights and freedoms not affected — including the unenumerated right to privacy as recognised by the Hosking v Runting line of authority) The principal human-rights instrument. NZBORA is not entrenched and is interpreted as a guide to the construction of other statutes; s 6 requires that, where a statute is open to two interpretations, the rights-consistent interpretation is preferred. Applies as the constitutional / human-rights layer. Treatment in §§ 3, 6, 13 below.
Privacy Act 2020 (NZ) Privacy Act — in force 1 December 2020, replacing the Privacy Act 1993 (NZ). Substantive sections: s 3 purpose; s 4 (overseas agencies — extraterritorial application limb); s 5 (Act binds the Crown); s 6 (agency definition); s 7 (Privacy Commissioner's functions including s 7(1)(b) duty to take account of cultural perspectives of Māori); s 8 (privacy officer of an agency); s 22 (13 Information Privacy Principles — IPP 1 purpose of collection; IPP 2 source of personal information; IPP 3 collection of information from individual; IPP 4 manner of collection; IPP 5 storage and security; IPP 6 access; IPP 7 correction; IPP 8 accuracy of personal information; IPP 9 retention; IPP 10 use limits; IPP 11 disclosure limits; IPP 12 disclosure of personal information outside New Zealandcross-border disclosure; IPP 13 unique identifiers); ss 23–31 (codes of practice); ss 32–55 (privacy codes that are in force at the Effective date — Health Information Privacy Code 2020; Credit Reporting Privacy Code 2020; Telecommunications Information Privacy Code 2020; Justice Sector Unique Identifier Code 2020; Civil Defence National Emergencies (Information Sharing) Code 2020; Superannuation Schemes Unique Identifier Code 2020); ss 56–67 (information matching programmes); ss 68–77 (access and correction); s 75 (response to access requests — 20 working days); ss 78–87 (Privacy Commissioner's powers — investigation, compliance notice, access direction); ss 88–104 (Part 5 — proceedings before the Human Rights Review Tribunal); ss 105–111 (Privacy Commissioner's powers to make decisions and orders); ss 112–119 (Part 6 — Notifiable Privacy Breaches scheme — in force since 1 December 2020 as part of the Act's commencement; s 112 notifiable-breach definition serious-harm test; s 114 OPC notification "as soon as practicable"; s 115 affected-individual notification "as soon as practicable"; s 117 carve-outs; s 118 offence to fail to notify — up to NZ$10,000 fine); ss 120–123 (information privacy principles relating to law enforcement); ss 124–168 (further functions and powers of the Privacy Commissioner); ss 169–212 (general — including s 211 offence + s 213 criminal liability of officers + s 214 prescribed countries Order in Council under IPP 12(1)(f)); s 215 (regulations). The principal statute. Applies in full to Balance as an "overseas agency carrying on business in New Zealand" (s 4). Treatment in §§ 3, 4, 6, 7, 8, 11, 13 below.
Privacy Regulations At the Effective date, no Order in Council has been made under s 214 of the Privacy Act 2020 prescribing a "prescribed country" for the purposes of IPP 12(1)(f). The European Commission's adequacy decision (Commission Implementing Decision 2013/65/EU) is recognised by New Zealand as a substantively-equivalent regime via the Privacy Act IPP 12(1)(a) "comparable safeguards" route. The cross-border-disclosure regulation layer. Applies as the operational layer for IPP 12.
Privacy Commissioner Codes of Practice The Privacy Commissioner's binding codes — Health Information Privacy Code 2020; Credit Reporting Privacy Code 2020; Telecommunications Information Privacy Code 2020; Justice Sector Unique Identifier Code 2020; Civil Defence National Emergencies (Information Sharing) Code 2020; Superannuation Schemes Unique Identifier Code 2020. Sets binding interpretive layer for specific sectors. Not engaged — Balance is not a health agency, credit reporter, telecommunications agency, justice-sector agency, civil-defence agency, or superannuation scheme. Applies as a context-setting fact.
OPC NZ Guidance The Privacy Commissioner's published guidance — Privacy Trust Mark, AskUs Knowledge Base, Guidance for Agencies, the Notifiable Privacy Breach Self-Assessment Tool, the Cross-Border Disclosure Decision-Making Tool, the Children and Young Persons Privacy guidance, the Te Tiriti o Waitangi and Privacy guidance, the body of OPC NZ casenotes and Commissioner's Reports published at https://www.privacy.org.nz/. Sets the OPC NZ's binding interpretive layer on the Privacy Act 2020 + IPPs. Applies. Balance's posture is operationalised consistently with the OPC NZ's published guidance — in particular the Children and Young Persons Privacy guidance and the Cross-Border Disclosure Decision-Making Tool.
Harmful Digital Communications Act 2015 (NZ) HDCA — establishes the civil-enforcement regime and the criminal offence of causing harm by posting digital communication (s 22). Defines 10 communication principles at s 6. Designates an Approved Agency under s 8 — NetSafe (operating as Netsafe / Te Pataka Tukatuka) is the approved agency. Civil enforcement at the District Court (ss 12–21). Criminal offence at s 22 — up to 2 years imprisonment + up to NZ$50,000 fine (individuals) / NZ$200,000 (body corporate). The principal online-harms statute. Applies primarily to communications made by individuals; online content hosts (s 4) have a safe-harbour at s 24 conditional on a notice-and-takedown response. Balance is not an "online content host" within s 4 — Balance does not provide a service that enables a person to make digital communications available to other persons in a public-facing sense; the proof-media payload is end-to-end-encrypted and is delivered only to the kid's paired parent device(s). The s 24 safe-harbour mechanism does not engage Balance directly because there is no public-facing surface to which the notice-and-takedown machinery applies. Applies as a context-setting fact. Cross-reference in Child Safety Standards § 8 + § 14 below.
Films, Videos, and Publications Classification Act 1993 (NZ) FVPCA — establishes the Office of Film and Literature Classification ("OFLC") and the Chief Censor; criminalises possession and distribution of objectionable publications under s 124 + ss 131–131B + s 132 + s 134 + s 144A. The Films, Videos, and Publications Classification (Urgent Interim Classification of Publications and Prevention of Online Harm) Amendment Act 2021 added an urgent interim classification power + takedown notice power at s 119(2). The Films, Videos, and Publications Classification (Interim Restriction Orders) Amendment Act 2021 added interim restriction orders. The Chief Censor is the principal NZ authority on CSAM classification. Sets the CSAM / objectionable-publications classification and criminalisation regime. The Department of Internal Affairs — Digital Safety Group is the principal enforcement agency for online CSAM offences (cross-reference Crimes Act 1961). Applies. Cross-reference in Child Safety Standards § 8 + § 14 below.
Crimes Act 1961 (NZ) Crimes Act — s 124 (distribution of obscene matter); s 124A (indecent communication with young person under 16); s 131 (sexual conduct with dependent family member under 18); s 131A (sexual conduct with consent induced by coercive use of authority); s 131B (meeting young person under 16 following sexual grooming); s 132 (sexual conduct with child under 12); s 134 (sexual conduct with young person under 16); s 144A (sexual conduct with children and young people outside New Zealand — extraterritorial child sex offences); s 144C (organising or promoting child sex tours); ss 216H–216N (intimate visual recordings); s 252 (accessing computer system without authorisation); s 249 (accessing computer system for dishonest purpose). The principal NZ criminal statute for CSAE, online-grooming, and intimate-image offences. Applies. Cross-reference in Child Safety Standards § 8.1 + § 14 below.
Unsolicited Electronic Messages Act 2007 (NZ) UEM Act — regulates the sending of commercial electronic messages ("CEMs") to or from a New Zealand-link computer. Requires consent (express or inferred), identification of the sender, and a functional unsubscribe facility. Enforced by the Department of Internal Affairs — Anti-Spam Compliance Unit. Civil pecuniary penalties up to NZ$200,000 for an individual / NZ$500,000 for a body corporate (s 45). Regulates commercial electronic messages. Applies. Balance does not send commercial electronic messages to New Zealand residents; the only email Balance sends is transactional (account creation, password reset, subscription receipts, security alerts, parent-action notifications). Treatment in § 12.3 below.
Search and Surveillance Act 2012 (NZ) SSA — the principal lawful-search-and-surveillance statute. Sets the procedural rules for search warrants, surveillance device warrants, residual warrants, and the production order regime at ss 71–78. The lawful-access framework for criminal investigations. Applies. Treatment in § 13 below.
Telecommunications (Interception Capability and Security) Act 2013 (NZ) TICSA — the telecommunications lawful-intercept and network-security regime. Applies to network operators (s 3) — Balance is not a network operator. The lawful-intercept framework for telecommunications. Not engaged directly. Applies as a context-setting fact.
Customs and Excise Act 2018 (NZ) Customs Act — Part 4 + Part 6 — applies to seizure of objectionable publications at the border. The border-seizure regime for objectionable publications including CSAM. Applies as a context-setting fact.
Oranga Tamariki Act 1989 (NZ) Oranga Tamariki Act — formerly the Children, Young Persons, and Their Families Act 1989; renamed by the Children, Young Persons, and Their Families (Oranga Tamariki) Legislation Act 2017. Establishes the Ministry for Children — Oranga Tamariki + the framework for children's-and-young-persons' welfare, care, and protection. Definitionschild is under 14; young person is 14 to under 18 (s 2). Best-interest principle at ss 4–5. The principal child-welfare statute. Applies. Treatment in § 5 + § 14 below.
Children's Act 2014 (NZ) Children's Act — establishes the Children's Commissioner (now the Ministry for Children — Oranga Tamariki + the Children's and Young People's Commission); requires children's worker safety checks; requires children's-agency child protection policies. Sets the child-safeguarding policy and personnel-screening framework for "children's services". Applies as a context-setting fact (Balance is not a "children's service" within the s 6 sense — Balance does not employ "children's workers" who are face-to-face with NZ children).
Care of Children Act 2004 (NZ) Care of Children Act — establishes the doctrine of guardianship (s 15 — care for the child + contribute to the child's intellectual, emotional, physical, social, cultural, and other personal development); guardianship is the NZ statutory equivalent of parental authority / patria potestas. The Act applies until age 18 (s 26 — guardianship continues until age 18). The principal NZ parental-authority statute. Applies as the doctrinal anchor for the parent's consent on behalf of the kid. Treatment in § 7 below.
Consumer Guarantees Act 1993 (NZ) CGA — implies into every consumer-services contract the guarantees of: s 28 (reasonable care and skill); s 29 (fitness for particular purpose); s 30 (reasonable time for supply); s 31 (reasonable price). Non-excludable (s 43); collective consumer rights in s 43A; remedies of repair / replacement / refund per ss 32–39. The principal NZ consumer-services-protection statute. Applies in full. Treatment in § 16 below.
Fair Trading Act 1986 (NZ) FTA — s 9 (misleading or deceptive conduct in trade); s 10 (false or misleading representations in connection with goods); s 11 (false or misleading representations in connection with services); s 13 (false or misleading representations about price or value); s 26A (unfair contract terms in standard form consumer contracts; void to the extent of unfairness); ss 36–43 (consumer information standards and product safety standards). Enforced by the Commerce Commission. The principal NZ fair-trading statute. Applies in full. Treatment in § 16 below.
Credit Contracts and Consumer Finance Act 2003 (NZ) CCCFA Applies only to credit contracts. Not engaged — Balance does not provide credit. Applies as a context-setting fact.
EU adequacy Commission Implementing Decision 2013/65/EU of 19 December 2012on the adequate protection of personal data by New Zealand under (then-)Directive 95/46/EC Art 25(6), now GDPR Art 45(9) — in force at the Effective date. New Zealand is one of only nine non-EU/EEA jurisdictions to hold an EU adequacy decision; the decision recognises that the level of protection of personal data ensured by New Zealand is essentially equivalent to the level guaranteed within the EU under the GDPR. Allows the bidirectional flow of personal data between the EU/EEA and New Zealand without supplementary transfer instruments. Cross-reference in EU / EEA annex § 8 — the EU/EEA Annex confirms that EU/EEA residents' data may flow to New Zealand under the 2013/65/EU adequacy decision. Applies as a context-setting fact (Balance's backend is in the US, not in NZ — see § 9 below — so the EU adequacy is relevant only in the alternative).
Convention 108 / Convention 108+ Not applicable. New Zealand has been invited to accede to the Council of Europe Convention 108 but has not formally acceded at the Effective date. Applies as a context-setting fact. The Council-of-Europe layer is not engaged for the NZ-resident flows.
Te Tiriti o Waitangi / Treaty of Waitangi The foundational document of the partnership between the Crown and Māori (signed 6 February 1840). Article 2 / Te Tuarua guarantees Māori tino rangatiratanga (full chieftainship / self-determination) over their taonga (treasured possessions), which the Waitangi Tribunal in Wai 262 (Ko Aotearoa Tēnei) found to include personal information of Māori. Privacy Act 2020 s 7(1)(b) requires the Privacy Commissioner to take account of cultural perspectives of Māori in the exercise of the Commissioner's functions and powers. The constitutional partnership document. Applies as the constitutional partnership layer. Balance honors te Tiriti's principles in respect of Māori personal information by: (i) commitment to the te reo Māori translation queued in Phase 2; (ii) recognition of taonga status of Māori personal information; (iii) consultation with the OPC NZ's Māori Reference Group on any matter the Commissioner refers under s 7(1)(b).

(Any prospective New Zealand regulation governing automated processing, algorithmic decisions, or related techniques — including any post-Effective-date OPC NZ guidance in that area, any Algorithm Charter for Aotearoa New Zealand (the Department of Internal Affairs + Stats NZ voluntary charter, applies only to government agencies and is voluntary), any future AI Bill before the New Zealand Parliament, and any successor regulation — is intentionally omitted from this Annex on the principle that this Annex makes no affirmative or negative statement about whether Balance does or does not process personal data using techniques within the scope of any such New Zealand regulation. Balance's substantive product posture is described elsewhere in the policy bundle and is the controlling reference; this Annex's silence on the topic is deliberate and is not to be read as an implicit statement either way.)


3. Supervisory authorities

3.1 OPC NZ — Office of the Privacy Commissioner / Te Mana Mātāpono Matatapu

The principal supervisory authority is the Office of the Privacy Commissioner (Te Mana Mātāpono Matatapu) ("OPC NZ"), established under the Privacy Act 1993 (continuing in office under the Privacy Act 2020). The OPC NZ is led by the Privacy Commissioner — an Officer of Parliament appointed by the Governor-General on the recommendation of the House of Representatives.

Field Value
Name Office of the Privacy Commissioner / Te Mana Mātāpono Matatapu (OPC NZ)
Headquarters PO Box 10094, The Terrace, Wellington 6143 + Level 8, 109–111 Featherston Street, Wellington 6011
Auckland office PO Box 466, Shortland Street, Auckland 1140 + Level 8, 21 Queen Street, Auckland 1010
Website https://www.privacy.org.nz/
Complaint channel OPC NZ online complaint form at https://www.privacy.org.nz/your-rights/making-a-complaint/online-complaint-form/, by mail to the Wellington or Auckland office, or by phone at 0800 803 909 (toll-free within New Zealand)
Breach-notification channel OPC NZ online Notifiable Privacy Breach form per Privacy Act 2020 s 114 at https://privacybreach.privacy.org.nz/ (the NotifyUs portal)
Privacy Commissioner At the Effective date — Michael Webster (or successor as published at the OPC NZ website)

The OPC NZ is the first-line forum for any Privacy-Act-grounded complaint from any New Zealand resident. A New Zealand resident may petition the OPC NZ without first raising the matter with Balance. We accept all DSAR / privacy enquiries at (named individual: , in his capacity as the privacy officer under Privacy Act 2020 s 201) and respond within the Privacy Act 2020 timelines (see § 6 below).

A New Zealand resident may also pursue private remedies against Balance via Part 5 of the Privacy Act 2020 (proceedings before the Human Rights Review Tribunal); via the common-law privacy torts (intrusion upon seclusion per C v Holland + publication of private facts per Hosking v Runting); via the ordinary District / High Courts; or via the criminal route under the Crimes Act 1961 or Privacy Act 2020 s 211 / s 213 where criminal offences are engaged.

3.2 Other regulatory bodies

Body Subject matter URL
Department of Internal Affairs — Digital Safety Group (formerly DIA Censorship Compliance Unit) FVPCA enforcement; online CSAM; collaboration with NetSafe + NZ Police + OFLC https://www.dia.govt.nz/Digital-Safety
NetSafe / Te Pataka Tukatuka HDCA approved agency under s 8; INHOPE member; online-harms triage and mediation https://netsafe.org.nz/
Office of Film and Literature Classification (OFLC) Classification of films, videos, and publications; CSAM classification https://www.classificationoffice.govt.nz/
Department of Internal Affairs — Anti-Spam Compliance Unit UEM Act enforcement https://www.dia.govt.nz/Spam
Commerce Commission FTA + CGA enforcement https://comcom.govt.nz/
Ministry for Children — Oranga Tamariki Child welfare under Oranga Tamariki Act https://www.orangatamariki.govt.nz/
NZ Police National Cyber Crime Unit (NCCU) Cybercrime investigation including CSAE https://www.police.govt.nz/
Children's and Young People's Commission (Mana Mokopuna) Children's rights monitoring https://www.manamokopuna.org.nz/

3.3 The privacy officer

Privacy Act 2020 s 201 requires every agency (including overseas agencies that carry on business in New Zealand) to designate one or more individuals as "privacy officers" whose responsibilities are to (a) encourage compliance with the IPPs; (b) deal with requests made to the agency under the Act; (c) work with the Privacy Commissioner in relation to investigations conducted under the Act; (d) ensure the agency's compliance.

The Balance privacy officer is:

The privacy officer's contact details are published in this Annex and in the global Privacy Policy (Privacy Policy § 1).


4. Lawful bases — IPPs + s 22 framework

The Privacy Act 2020 does not use the GDPR "lawful bases" taxonomy. Instead, the IPPs at s 22 set: (i) purpose limits on collection (IPP 1); (ii) collection from the individual (IPP 2 + IPP 3 + IPP 4); (iii) storage and security (IPP 5); (iv) access and correction (IPP 6 + IPP 7); (v) accuracy (IPP 8); (vi) retention (IPP 9); (vii) use and disclosure limits (IPP 10 + IPP 11); (viii) cross-border disclosure (IPP 12); (ix) unique identifiers (IPP 13).

Balance processes personal information of New Zealand residents on the following IPP mapping:

Processing purpose IPP basis Cross-reference
Run the parental-control service the parent signed up for (account creation, family configuration, kid profile, limits, schedules, tasks, earned-time ledger, end-to-end-encrypted proof media) IPP 1 (collection for a lawful purpose connected with the agency's function) + IPP 2 + IPP 3 + IPP 4 (collection from the parent — the individual concerned — by fair and lawful means) + IPP 10 (use limit — for the primary purpose of providing the parental-control service) + IPP 11 (disclosure limit — only to authorised recipients) H1 § 4; H7 PA-01 through PA-08; § 7 of this Annex
Process the kid's personal information IPP 1 + IPP 2 (collection from the kid via the kid app + collection from the parent via the parent app, both with the parent's authorisation under the Care of Children Act 2004 guardianship doctrine) + IPP 3 + IPP 4 + IPP 10 + IPP 11 + OPC NZ Children and Young Persons Privacy guidance on capacity test § 7 of this Annex; our Data Protection Impact Assessment § 6
Deliver operational alerts IPP 10 (primary purpose) H1 § 4; H7 PA-09; M3
Detect, prevent, and respond to security incidents, abuse, fraud, and unauthorised access IPP 5 (storage and security — reasonable security safeguards) + IPP 11(1)(b) (disclosure necessary to maintain the law including for the detection, investigation, or prosecution of any offence) + IPP 11(1)(e) (disclosure to prevent or lessen a serious threat to the life or health of any individual) H7 PA-15; § 13 below
Comply with legal, regulatory, and supervisory obligations IPP 11(1)(d) (disclosure required or authorised by or under any enactment) + IPP 10(1)(d) (use required or authorised by or under any enactment) § 13 below; M1; § 14 below
Process Verifiable Parental Consent for the kid's data IPP 1 + IPP 3 — collection of the parent's information for the primary purpose of obtaining VPC § 7 of this Annex; A-US § 5
Process the parent's billing / subscription data IPP 1 — necessary for the agency's function of providing the subscription service; CGA + FTA overlay in § 16 below H4; § 16 below

Balance does not assign or use a unique identifier in the IPP 13 sense (a number, letter, name, or any other sequence of characters or symbols designed to identify a unique individual that is assigned to the individual to which the unique identifier was first assigned). Balance assigns an internal user ID that is not derived from any government-issued or commonly-used unique identifier. IPP 13 is therefore not engaged.


5. Children's rights overlay

New Zealand does not have a children-specific data-protection statute equivalent to COPPA (US), GDPR Art 8, or Quebec Private Sector Act s 8.1, at the Effective date. The children's regime is built up from (i) the Privacy Act 2020 IPPs read with the OPC NZ's Children and Young Persons Privacy guidance (case-by-case capacity assessment) and the Privacy Commissioner's reference to Gillick / Hewer v Bryant / Marion's Case on capacity; (ii) the Care of Children Act 2004 (NZ) — the guardianship doctrine; (iii) the Oranga Tamariki Act 1989 (NZ) — best-interest principle (ss 4–5) + cooperation routes; (iv) the UN Convention on the Rights of the Child (NZ ratified 6 April 1993, with reservations on Arts 32(1) and 37(c)); (v) NZBORA s 28 + Mana Mokopuna — Children's and Young People's Commission Act 2023.

5.1 Definitions

For the purposes of this Annex:

Balance applies the most-protective reading and obtains Verifiable Parental Consent for every New Zealand kid regardless of age, using the VPC mechanism in United States annex § 5 (email-verified parent account creation + payment-method capture at subscription time + parent's affirmative in-app action of creating the kid profile and pairing the kid's device). The VPC screen for New Zealand residents itemises the categories of personal information being authorised, the purposes for which it is being processed, the third parties to whom it may be disclosed (sub-processors), and the data subject's rights under the Privacy Act 2020.

Balance does not provide a kid-self-serve consent path inside the app. The parent always consents on behalf of the kid; the kid app's UI is designed for the kid to see their own limits, schedules, tasks, and earned-time ledger, and to request changes through the in-app "request change" affordance, which is forwarded to the parent device for the parent's decision. This is the most-protective reading of IPP 1 + IPP 3 + IPP 4 + IPP 10 + the OPC NZ Children and Young Persons Privacy guidance + Care of Children Act 2004 s 15 (guardianship).

5.4 No advertising directed at children

Balance does not display advertising to any user (parent or kid), does not allow any third party to display advertising in Balance, and does not build a behavioural-advertising profile of any user. This is consistent with: (i) the OPC NZ's interpretive position on direct marketing to children; (ii) the Advertising Standards Authority Children and Young People's Code (the ASA Children's Code); (iii) NZBORA s 14 freedom of expression read with NZ's CRC Art 17 obligations on protection from harmful media. Cross-references: the Play Console Data Safety form § 2 (Contains ads: No); the Play Console Child Safety Standards declaration § 3 ATTESTATION-D.

5.5 Cooperation routes

The principal NZ child-protection bodies are: (i) the Ministry for Children — Oranga Tamariki — the principal child-welfare agency; (ii) NZ Police National Cyber Crime Unit (NCCU) — the principal law-enforcement node for online CSAE; (iii) Department of Internal Affairs — Digital Safety Group — the principal enforcement agency for online CSAM under FVPCA + Crimes Act; (iv) NetSafe / Te Pataka Tukatuka — the HDCA approved agency + INHOPE member; (v) OFLC — the classification authority; (vi) the Children's and Young People's Commission (Mana Mokopuna) — children's-rights monitoring; (vii) Kidsline — NZ's helpline for children up to age 18; (viii) Youthline — NZ's helpline for young people. Balance cooperates with each on incidents involving NZ kids — see § 14 below.


6. Privacy Act 2020 rights catalogue

6.1 The rights catalogue

A New Zealand resident has the following rights under the Privacy Act 2020 + IPPs as in force at the Effective date.

6.2 Timeline

Where the request would be vexatious or where one of the withholding grounds at ss 49–53 applies (national security; maintenance of the law; protection of trade secrets; legal professional privilege; etc.), Balance may refuse to act on the request; the requestor is told the reason and informed of the right to complain to the OPC NZ.

6.3 Identity verification

Where there is reasonable doubt about the identity of the natural person making the request, Balance may request additional information necessary to confirm the identity. The identity-verification protocol uses the parent's existing authentication credential. Out-of-band identity verification is requested only as a last resort, only for the parent, and only for the categories of personal information that require a higher assurance of identity.

6.4 No cost

The exercise of the IPP 6 access right is free of charge (Privacy Act 2020 s 66(2) — agencies may charge a reasonable fee only in limited circumstances; Balance does not charge in practice).

6.5 Language

A request may be submitted in English or te reo Māori. The OPC NZ accepts complaints in both official languages.


7. Children's data — IPPs + OPC NZ Children and Young Persons Privacy + Care of Children Act 2004

Balance processes personal information of New Zealand kids under the following layered framework:

For Balance:

A parent may revoke consent at any time at Settings → Family → [kid name] → "Delete this kid" (or by email to ). Revocation triggers the cascade documented in Data Retention & Deletion Policy § 7. Revocation does not affect the lawfulness of processing carried out before the revocation.


8. International data transfers from New Zealand — IPP 12

The controller (BabaYaga Program, TOO) is established in Kazakhstan. The backend (Emergent Labs Inc.) is hosted in the United States. Proof-media storage (Google Cloud Storage) is in the United States. Push (Firebase Cloud Messaging), sign-in (Google Sign-In), and billing (Google Play Billing) are operated by Google LLC and dispatched from the United States. Transactional email (Resend) is dispatched from the United States. Accordingly, every New Zealand resident's personal information leaves New Zealand at the point of being uploaded to the Balance backend.

8.1 The New Zealand-to-US transfer mechanism — IPP 12

IPP 12 governs cross-border disclosure. An agency may disclose personal information to a foreign person or entity only if at least one of the following applies (Privacy Act 2020 s 22 — IPP 12(1)(a)–(f)):

Balance relies on the following stack to satisfy IPP 12 for the New Zealand → US transfer:

8.2 The EU-to-NZ axis (incoming transfers) — EU adequacy decision

Commission Implementing Decision 2013/65/EU of 19 December 2012 finds that New Zealand provides an adequate level of protection for personal data. Cross-reference in EU / EEA annex § 8 — the EU/EEA Annex confirms that EU/EEA residents' data may flow to New Zealand under the 2013/65/EU adequacy decision.

For Balance, the EU adequacy is relevant only in respect of any EU/EEA-resident data that transits through (or is processed in) New Zealand — which is not part of Balance's current data-flow architecture (Balance's backend is in the United States, not in New Zealand). The EU adequacy is therefore a context-setting fact, not a transfer mechanism for the Balance flows.

8.3 The NZ-to-KZ axis (controller administrative access)

The controller's personnel in Kazakhstan have administrative access to the US-hosted backend for operational purposes. Because Kazakhstan is a third country and Kazakhstan is not on the OPC NZ's recognised "comparable safeguards" list (because no country has been prescribed under s 214 at the Effective date), the NZ-KZ axis is covered by the IPP 12(1)(b) enforceable-contract route + IPP 12(1)(f) parent's express authorisation. The transfer-impact analysis for the KZ leg is in our international-transfer pack § 7.


9. Data residency for New Zealand residents

Question Answer
Where is the backend hosted? United States. Emergent Labs Inc. (Delaware) on US infrastructure.
Where is the MongoDB database located? United States.
Where is the proof-media storage located? United States — Google Cloud Storage us multi-region.
Where are push notifications dispatched from? United States — Firebase Cloud Messaging.
Is any New Zealand resident's personal information held in New Zealand? No. Every New Zealand resident's personal information is held in the United States. The IPP 12 transfer mechanism in § 8 above is the legal basis for the transfer.
Where is the controller? Kazakhstan (BabaYaga Program, TOO). The controller has administrative access to the US-hosted backend via written processor agreements.
Is there a New Zealand establishment? No. Balance has no permanent establishment in New Zealand. The Privacy Act 2020 s 4 extraterritorial reach (overseas agency carrying on business in NZ) is the basis for Balance's Privacy Act compliance.
Where is the supervisory authority? New Zealand — OPC NZ + the regulatory bodies in § 3.2 above.

The decision to centralise on a US-only backend is documented in our internal compliance plan § 6. New Zealand does not impose a comprehensive data-localisation mandate on parental-control services at the Effective date, with the exception of certain sector-specific regimes (e.g., the Health Information Privacy Code 2020 under the Privacy Act 2020 — health-information handling; not applicable to Balance because Balance does not collect health information).


10. Sub-processors touching New Zealand-resident data

Sub-processor Role Location of processing NZ transfer paperwork
Emergent Labs Inc. (Delaware, USA) — using MongoDB Atlas (MongoDB, Inc., US) for the production database; relationship governed by Emergent ToS (22 Dec 2025) + Privacy Policy (28 May 2026) as the GDPR Art 28(3) "other legal act" (no standalone DPA available outside Enterprise per Emergent final position 2026-06-10; full handling in our internal vendor-handling plan); MongoDB Atlas Customer DPA + EU SCCs Module 2 + UK IDTA Addendum at https://www.mongodb.com/legal/dpa cover the storage layer Hosts the FastAPI backend + MongoDB cluster United States IPP 12(1)(b) enforceable contract with comparable-safeguards clauses + IPP 12(1)(f) parent's express authorisation on file per our international-transfer pack § 6; E2EE supplementary measure for proof media.
Google LLC — Google Cloud Storage (USA) Stores end-to-end-encrypted proof-media ciphertext United States (us multi-region) IPP 12(1)(b) enforceable contract (Google Cloud Data Processing Addendum) + IPP 12(1)(f) parent's express authorisation; ciphertext-only handling.
Google LLC via Google Cloud (USA) Periodic (daily) backups of our operational database United States (us multi-region) IPP 12(1)(b) enforceable contract (Google Cloud Data Processing Addendum) + IPP 12(1)(f) parent's express authorisation; the backup archive holds the operational data we hold about the resident (account, family, kid profile, usage totals, tasks, earned-time ledger, device identifiers, push tokens), other than the items that never reach our backend in readable form (the kid's proof media and the media-encryption keys); retained on a 30-day rolling window, then automatically deleted.
Google LLC — Firebase Cloud Messaging Delivers push notifications to NZ kid + parent devices United States IPP 12(1)(b) enforceable contract + IPP 12(1)(f) parent's express authorisation; push body deliberately free of sensitive content (cross-reference: the just-in-time permission disclosures).
Google LLC — Google Sign-In Authenticates parent Google identity (when used) United States IPP 12(1)(b) + IPP 12(1)(f) as above.
Google LLC — Google Play Billing Processes subscription purchases United States IPP 12(1)(b) + IPP 12(1)(f) + Google Play Developer Distribution Agreement.
Resend, Inc. (San Francisco, CA, USA) Delivers transactional email to NZ parent users United States IPP 12(1)(b) enforceable contract + IPP 12(1)(f) parent's express authorisation.

Every sub-processor is bound by a written data-processing agreement that forbids processing of any data we transmit for any purpose other than performing the service we engaged them for, and that incorporates the security and confidentiality controls in our Records of Processing Activities (Article 30) § 7 + IPP 5 (storage and security). The full sub-processor list, with each row's processor-agreement status, is at our sub-processor register.


11. Breach notification — Privacy Act 2020 Part 6 (Notifiable Privacy Breaches scheme)

Privacy Act 2020 Part 6 (ss 112–119) sets the breach-notification regime — in force since 1 December 2020 with the Act's commencement:

Audience Trigger Deadline Channel
OPC NZ A notifiable privacy breach has occurred — defined at Privacy Act 2020 s 112 as a privacy breach that it is reasonable to believe has caused serious harm to an affected individual or individuals or is likely to do so (the "serious harm" test at s 113 — assessed against any action taken to reduce the risk of harm; the sensitivity of the information; the nature of the harm; etc.). As soon as practicable after the agency becomes aware that a notifiable privacy breach has occurred (Privacy Act 2020 s 114). Balance internal anchor: 72 hours (consistent with the GDPR Art 33 benchmark; faster than the Privacy Act "as soon as practicable" floor). OPC NZ online NotifyUs portal at https://privacybreach.privacy.org.nz/
Affected individuals Same trigger as the OPC NZ notification. As soon as practicable after the agency becomes aware of the breach (Privacy Act 2020 s 115). Balance internal anchor: 72 hours. Direct email to the affected parent on file; in-app banner where the parent is logged in; out-of-app contact via the public-website incident page if email is no longer deliverable. The notification is in English (te reo Māori on request).
CSAE-specific An incident with a CSAE component. Per § 14 below + the internal runbook (M1). DIA Digital Safety Group + NZ Police NCCU + OFLC + NetSafe.

The internal breach-decision SLA is at our breach-notification runbook § 5.4 + § 9: preliminary classification within one business day, fuller assessment within seven days, OPC NZ notification within the 72-hour Balance internal anchor, affected-individual notification at the same point unless the s 116 carve-outs (delay in notification permitted where the delay is in the interests of the public; where there is reasonable apprehension that notification would prejudice law enforcement; where notification would risk further harm) apply.

11.1 Minimum content of the OPC NZ NotifyUs notification (Privacy Act 2020 s 116)

The OPC NZ notification states: - the name of the agency and the privacy officer contact (, named individual: ); - a description of the breach; - when the breach occurred and when it was discovered; - the personal information that was the subject of the breach; - the affected individuals (or the categories of affected individuals if not yet identified); - the steps the agency has taken or is taking to mitigate; - whether the agency has notified or intends to notify the affected individuals; - any other matters the Commissioner may require.

The English-language template lives in our breach-notification runbook § 8.1.

11.2 Offence to fail to notify (Privacy Act 2020 s 118)

A failure to notify the Privacy Commissioner of a notifiable privacy breach without reasonable excuse is an offence punishable on summary conviction by a fine not exceeding NZ$10,000 (Privacy Act 2020 s 118).


12. Cookies, spam, and electronic direct marketing

New Zealand does not have a dedicated ePrivacy / cookies statute. The substantive position on cookies and electronic direct marketing is derived from: (i) IPP 1 + IPP 3 + IPP 4 + IPP 10 + IPP 11 for any cookie that processes personal information; (ii) the OPC NZ's published guidance on online cookies and tracking technologies; (iii) the Unsolicited Electronic Messages Act 2007 (NZ) for commercial electronic messages; (iv) FTA s 9 misleading-or-deceptive-conduct for any cookie practice that misleads consumers; (v) ASA Codes.

12.1 In-app — strictly-necessary storage only

The Balance app (parent and kid) does not deploy any cookie-equivalent storage that is not strictly necessary for the service. The strictly-necessary storage Balance uses (authentication tokens in Android SecureStore; the device-pairing key wrap; the kid app's earned-time cache) is operationally necessary and is covered by the parent's sign-up consent.

The public legal-documents site (balance.babayagaprogram.com) uses only strictly-necessary cookies; no analytics cookies; no advertising cookies; no third-party trackers; no fingerprinting; no embedded social plugins.

12.3 Electronic direct marketing — not sent

Balance does not send commercial electronic messages within the meaning of UEM Act 2007 s 6 to New Zealand residents. The only email Balance sends to NZ parent users is transactional — account creation, password reset, subscription receipts, security alerts, and parent-action notifications, all of which fall outside the UEM Act's "commercial electronic message" definition (which requires the message to promote or solicit the supply of goods or services). If Balance ever introduces a marketing channel, we will comply with UEM Act s 9 (consent — express or inferred), s 10 (sender identification), and s 11 (functional unsubscribe facility).


13. Lawful-access requests and the encryption posture

New Zealand authorities may serve a lawful-access request on Balance via:

The Balance architectural posture interacts with these mechanisms as follows:

The full encryption posture is in our encryption-posture record.


14. CSAE reporting routes — New Zealand / Aotearoa NZ

A New Zealand resident (parent, kid, or third party) who wishes to report a CSAE concern about Balance, about a third party encountered outside Balance, or about a Balance user, may use any of the following routes:

The full CSAE Country Routing Table is in Child Safety Standards § 8.6.


15. Complaint routes (summary)

A New Zealand resident who is dissatisfied with Balance's handling of a privacy enquiry or a child-safety concern may complain to any of the following authorities:

Authority Subject matter Address / URL
Office of the Privacy Commissioner / Te Mana Mātāpono Matatapu (OPC NZ) Privacy Act 2020 + IPPs PO Box 10094, The Terrace, Wellington 6143; https://www.privacy.org.nz/; phone 0800 803 909
NetSafe / Te Pataka Tukatuka HDCA + online-harms triage https://netsafe.org.nz/; phone 0508 638 723
Department of Internal Affairs — Digital Safety Group FVPCA + Crimes Act CSAM https://www.dia.govt.nz/Digital-Safety; phone 0800 257 887
Office of Film and Literature Classification (OFLC) Classification under FVPCA https://www.classificationoffice.govt.nz/
Commerce Commission FTA + CGA enforcement https://comcom.govt.nz/; phone 0800 943 600
DIA Anti-Spam Compliance Unit UEM Act https://www.dia.govt.nz/Spam
Disputes Tribunal of New Zealand Consumer-protection disputes up to NZ$30,000 https://www.disputestribunal.govt.nz/
Human Rights Review Tribunal Privacy Act 2020 Part 5 + Human Rights Act 1993 https://www.justice.govt.nz/tribunals/human-rights/
District Court of New Zealand HDCA civil enforcement + ordinary civil claims https://www.districtcourts.govt.nz/
High Court of New Zealand Common-law privacy torts + judicial review of OPC NZ https://www.courtsofnz.govt.nz/
Children's and Young People's Commission (Mana Mokopuna) Children's-rights complaints https://www.manamokopuna.org.nz/
Ministry for Children — Oranga Tamariki Child-welfare concerns https://www.orangatamariki.govt.nz/; phone 0508 326 459

A New Zealand resident may always first raise the matter with us at (DSAR; named individual: , in his capacity as the privacy officer under Privacy Act 2020 s 201). We will respond within the Privacy Act 2020 timelines. Raising the matter with us first is not a precondition to complaining to the OPC NZ; the OPC NZ accepts complaints directly, though it often refers complainants back to the agency in the first instance.


16. Consumer rights — the CGA + FTA overlay

The Consumer Guarantees Act 1993 (NZ) and the Fair Trading Act 1986 (NZ) apply to Balance's subscription flow as a consumer-services contract — the parent is a consumer within the meaning of CGA s 2 (acquiring services of a kind ordinarily acquired for personal, domestic, or household use). Treatment is implemented in Subscription Terms § 20.

16.1 Consumer guarantees as to services (CGA ss 28–31)

The CGA implies into every consumer-services contract three non-excludable consumer guarantees:

Failure to comply with a consumer guarantee triggers the substantial character analysis at CGA ss 36–38 and a consumer's right to remedy (repair, replacement, refund, or compensation).

16.2 Misleading or deceptive conduct (FTA s 9)

A person must not, in trade, engage in conduct that is misleading or deceptive or is likely to mislead or deceive. The Balance marketing copy at balance.babayagaprogram.com and on the Google Play Store listing is drafted to avoid each FTA s 9 risk.

16.3 False or misleading representations about services (FTA s 11)

A person must not, in trade, make a false or misleading representation about a service. Civil pecuniary penalties up to NZ$200,000 (individual) / NZ$600,000 (body corporate) under FTA s 40A. Criminal penalties under FTA s 40 for knowing offences.

16.4 Unfair contract terms (FTA s 26A)

In a standard form consumer contract, a court may declare a term to be unfair and therefore void to the extent of the unfairness. A term is unfair if it: (a) would cause a significant imbalance in the parties' rights and obligations; (b) is not reasonably necessary to protect the legitimate interests of the party advantaged by it; and (c) would cause detriment (whether financial or otherwise) to a party if it were to be applied or relied on. The 2022 amendment (in force from 16 August 2022) extended the unfair-contract-terms regime to small trade contracts and increased the Commerce Commission's enforcement powers. Civil pecuniary penalties up to NZ$200,000 (individual) / NZ$600,000 (body corporate) under FTA s 40A. The Balance Terms of Service (Terms of Service) are drafted to avoid each FTA s 26A unfair-term risk.

16.5 Forum and choice of law

The Balance Terms of Service preserve the consumer's domicile forum (see Terms of Service § 19); choice-of-law clauses that would displace the CGA or the FTA to the prejudice of the NZ consumer are unenforceable under CGA s 43 (which voids contracting out of the consumer guarantees) and FTA s 5C (which preserves the application of the FTA).

16.6 Disputes Tribunal

The Disputes Tribunal of New Zealand offers a low-cost, no-lawyer-required forum for consumer-protection disputes up to NZ$30,000 (s 10 Disputes Tribunals Act 1988). The Balance subscription value never approaches NZ$30,000.


17. Cross-references


18. Versioning and review

This Annex follows the same strict versioning protocol as the rest of the Phase-1 bundle:


End of New Zealand Country Annex / Whakamutunga o te Tāpiritanga ā-whenua mō Aotearoa.

← Back to Privacy Policy · Children's Privacy Notice