Annelize du Toit

Legal


Privacy notice

Last updated 30 August 2026.

Not yet reviewed by a lawyer

This notice was drafted against the Privacy Act 2020, the Unsolicited Electronic Messages Act 2007, the Australian Privacy Principles and the UK and EU GDPR. It is a working draft and has not been reviewed by a qualified legal adviser. Get it reviewed before the site goes live, particularly the retention periods and the overseas transfer section. Remove this box once that is done.

Who is collecting this

Annelize du Toit, based in Auckland, New Zealand, operating as a speaker, coach and facilitator. For anything in this notice, write tospeaking@annelizedutoit.com.

[TODO: once the trading entity is registered, replace the line above with the registered company name, company number and registered address.]

What is collected, and why

Three things, and only when you choose to send them.

  • Enquiry form. Your name, email, and whatever else you fill in about your event or your situation. Used to reply to you and to prepare a proposal. Lawful basis under the GDPR: steps taken at your request before entering into a contract.
  • Email list. Your email address, plus the date and time you confirmed. Used to send you new writing. Lawful basis: consent, which you give by clicking the link in the confirmation email and can withdraw at any time.
  • Questionnaire. Your answers, name and email. Used to prepare for a conversation with you. Lawful basis: consent.

You are not asked for, and should not send, information about your health, your finances, or anything else you would consider sensitive. If you do, it is treated as confidential and deleted on request.

Email marketing

The list is confirmed opt-in. You give an address, you receive one email asking you to confirm, and nothing further is sent unless you click the link in it. Every email carries a working unsubscribe link and identifies the sender, as required by the Unsolicited Electronic Messages Act 2007. Unsubscribing takes effect immediately.

Cookies and measurement

This site sets no cookies of its own. Visit statistics are collected through Cloudflare Web Analytics, which does not use cookies and does not fingerprint or track individuals across sites.

Google advertising cookies are used to measure which pages lead to an enquiry. These are set to denied by default. Visitors whose browser reports a European timezone are asked before anything is set. Visitors elsewhere can decline at any time by using the browser's own cookie controls, or by writing to the address above.

Who else sees it

  • Cloudflare hosts the site and processes form submissions.
  • Resend sends the email.
  • Google Workspace holds the mailbox the enquiry arrives in.
  • Google Ads receives conversion measurement, where consent allows.

Nothing is sold, rented, or shared for anyone else's marketing. Ever.

Where it goes

These providers operate servers outside New Zealand, including in the United States and the European Union. Where personal information leaves New Zealand it is protected by the providers' contractual commitments, which for EU and UK data include Standard Contractual Clauses.

[TODO: confirm the transfer mechanism in each provider's current data processing agreement before this goes live, and record which version of the Standard Contractual Clauses applies.]

How long it is kept

  • Enquiries: kept for as long as there is an active conversation, then two years, then deleted.
  • Email list: until you unsubscribe.
  • Questionnaire answers: two years, or on request, whichever comes first.

Your rights

Under the Privacy Act 2020 you can ask for a copy of the personal information held about you, and ask for it to be corrected. Under the UK and EU GDPR, if you are in the UK or the EU, you can also ask for it to be deleted, restricted, or provided in a portable format, and you can object to how it is used.

Write to speaking@annelizedutoit.com. Requests are answered within 20 working days under the Privacy Act, and within one month under the GDPR.

If you are unhappy with the response, you can complain to the New Zealand Office of the Privacy Commissioner at privacy.org.nz, or to your own supervisory authority if you are in the UK or the EU.

Security, and what happens if something goes wrong

The site is served over HTTPS. Form submissions are transmitted encrypted. Access to the mailbox is protected by two-factor authentication.

If a privacy breach occurs that is likely to cause serious harm, the Office of the Privacy Commissioner and the people affected are notified, as the Privacy Act 2020 requires. Where the GDPR applies, the relevant supervisory authority is notified within 72 hours.

Changes

Any change is published here with a new date at the top. Material changes affecting people on the email list are sent to that list.