Legal
Privacy Policy
Effective date: 27 August 2026.
New Zealand Motel Standards™ (NZMS™) respects privacy and is committed to handling personal and business information carefully, lawfully and professionally.
This policy explains what information NZMS™ collects, why it is collected, how it may be used or disclosed, and how a person may request access, correction or a change to optional communication or publication consent.
Who We Are
New Zealand Motel Standards Limited is a New Zealand-founded independent standards, certification, improvement and professional-membership organisation supporting confidence and visible standards within the motel and accommodation sector.
NZMS™ is not a government agency, statutory authority or regulator.
Privacy Officer: Susie Barber, Founder & Chief Executive Officer. Privacy enquiries may be directed to nzms@consultant.com.
Information We Collect
NZMS™ may collect information supplied through:
- Founding Motel Programme and certification applications;
- NZMS™ Membership applications, acceptance, activation and renewal;
- Guest Confidence Reviews and self-assessment forms;
- contact, support and feedback forms;
- uploaded documents, images and supporting evidence;
- payment, invoice and reconciliation records;
- public verification and optional directory consent;
- correspondence, meetings and professional relationships;
- administrative, governance, complaint and review processes.
This may include names, contact details, professional roles, motel or organisation details, location, application responses, uploaded evidence, assessment and review records, payment references, consent records, member or certificate numbers, communication history and other information reasonably required for the relevant NZMS™ purpose.
Why We Collect and Use Information
Information may be used to:
- receive, secure and assess applications;
- administer certification, membership and professional services;
- request or verify information and payment;
- issue decisions, certificates, member numbers and controlled credentials where authorised;
- operate applicant, verification, support and internal administration systems;
- communicate about an enquiry, application, service, payment, activation, renewal or governance matter;
- maintain accurate public certification or membership verification records where consent and approval exist;
- prevent abuse, duplication, unauthorised access and misleading credential use;
- improve NZMS™ resources, systems, standards and service quality;
- meet legal, accounting, security and recordkeeping responsibilities.
Applicant Access and Acceptance Links
Applicants may receive a secure access token or time-limited acceptance link. These links are personal to the relevant application and must be kept confidential. NZMS™ may use one-way hashes, expiry controls and limited security records to protect these facilities.
A person who loses access should contact NZMS™ using the identity and email information recorded in the application so that appropriate verification can occur.
Uploaded Photos and Evidence
Uploaded photos, documents and supporting material are used for the relevant assessment, review or governance purpose. Private application evidence and internal review material are not published unless an appropriate authority, consent and publication decision have been recorded.
Certification, Membership and Public Verification
Only an approved, current and intentionally published certification or membership record appears in the corresponding public verification facility. An application, payment, approval in principle or internal review record is not public verification.
Public certification records may include the motel name, level, certificate number, issue and review dates and current status. Public membership verification may include the approved member name, organisation, category, member number, issue and expiry dates and current status.
Member Directory inclusion is optional and requires separate consent. Withdrawing optional directory consent does not automatically cancel membership.
Payments and Financial Records
Payment-card information is not collected through the NZMS™ membership application form or stored in the membership application record. Approved applicants receive a separate controlled payment instruction or approved payment route.
NZMS™ may retain the payment reference, amount, currency, date, GST treatment, counterparty, related application or service reference and reconciliation notes required for administration and accounting. Financial evidence is accessible only to authorised personnel who require it.
How We Store and Protect Information
NZMS™ takes reasonable technical and organisational steps to protect information from unauthorised access, misuse, loss, disclosure or alteration. Administrative records are restricted to authorised users and sensitive actions are supported by role, approval, audit, token, expiry or duplicate-prevention controls where appropriate.
No online system can be guaranteed completely secure. A person should not send unnecessary sensitive information through ordinary email or public forms.
Third-Party Service Providers and Overseas Processing
NZMS™ may use trusted providers for hosting, databases, email delivery, security verification, file storage, payment processing, accounting, analytics and controlled AI-assisted administration.
Providers may process or store information outside New Zealand. NZMS™ seeks to disclose only information reasonably required for the service and to use appropriate contractual, technical and organisational safeguards.
External legal-AI or generative-AI providers must not receive live NZMS™ confidential, privileged or personal information unless an approved privacy impact assessment, vendor and contractual review, data-processing configuration and human-governance controls are in place for that exact use.
NZMS™ does not sell personal information.
AI-Assisted Administration and Human Oversight
NZMS™ may use controlled AI-assisted tools to organise work, identify missing administrative actions, prepare draft communications, prioritise business prospects using approved business-level information and produce aggregate management summaries.
AI-assisted tools do not make final certification, membership, complaint, appeal, privacy, legal, credential, payment-confirmation or public-publication decisions. Those decisions remain subject to authorised human review, with Susie Barber retaining Founder oversight and escalation authority.
NZMS™ seeks to minimise personal information supplied to AI-assisted tools. Confidential assessment evidence, access tokens, payment-card information, health information and other sensitive material must not be included unless a separately approved and documented process expressly permits it.
AI output is treated as support material rather than a legal opinion or final decision. Material legal, privacy, investment, contractual and certification decisions remain subject to authorised human review and, where appropriate, qualified professional advice.
Business Outreach and Indirect Collection
NZMS™ may record publicly available or lawfully supplied business contact information for relevant professional relationships and carefully controlled one-to-one communications. The source, business purpose, consent or authority, privacy-notification position and Do Not Contact status must be assessed before contact is approved.
A person may ask where information came from, request correction or ask NZMS™ to stop promotional contact. Public availability does not automatically make every communication appropriate.
Electronic Communications and Opt-Outs
NZMS™ sends transactional communications reasonably required to administer an enquiry, application, requested service, payment, certification, membership, support matter or renewal.
Promotional electronic messages must identify NZMS™, provide current contact information and include a clear unsubscribe facility where required. An unsubscribe or Do Not Contact request is recorded in the controlled suppression system. Essential transactional communication may still be sent where necessary for an active relationship or legal obligation.
Privacy Impact and Incident Response
New AI, outreach and personal-information processes should be assessed through the NZMS™ governance system before broader activation. Suspected privacy or security incidents are escalated for human assessment, containment, recording and any notification required by law.
Retention
NZMS™ retains information only for as long as reasonably required for the application, review, certification, membership, service, accounting, governance, security, dispute or legal purpose. Information may then be securely deleted or de-identified where appropriate.
Access, Correction and Consent Changes
A person may request access to or correction of personal information held by NZMS™. A person may also withdraw optional directory or promotional consent, subject to information that NZMS™ must retain or use for an active transaction, legal obligation, dispute or security record.
Privacy Breaches
If NZMS™ becomes aware of a privacy breach that may cause serious harm, it will take appropriate steps under applicable New Zealand privacy obligations.
Updates
NZMS™ may update this policy as systems, services or legal obligations change. The current version will be published on this website.
Contact
For privacy enquiries, access or correction requests, optional consent changes or concerns about a communication, email nzms@consultant.com or use the NZMS™ Support Desk.