Privacy Policy
Last Updated: November 9, 2025
Introduction
Aawhina ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application (the "App").
Information We Collect
Information You Provide
- Account Information: Team key, username, password
- Support Data: Information you provide about those you are supporting - such as notes, documentation, and files you create or upload
- Communications: Messages, emails, and other communications sent through the App
- Profile Information: Name, role, contact details
Automatically Collected Information
- Device Information: Device type, operating system, unique device identifiers
- Usage Data: App features used, time spent in the App, interaction patterns
- Push Notification Tokens: Firebase Cloud Messaging tokens for sending notifications
- Log Data: Error logs, performance data, crash reports
Camera and Media
- Photos: When you use the camera feature to attach photos to cases or messages
- Files: Documents and media you choose to upload
How We Use Your Information
We use your information to:
- Provide and maintain the App's functionality
- Facilitate the support that you provide through your organisation, and empower team collaboration
- Send push notifications for important updates
- Enable real-time messaging and communication
- Store and manage support files and documentation
- Authenticate users and maintain security
- Improve and optimise the App
- Respond to technical support requests
- Comply with legal obligations
Data Storage and Security
Encryption
- All data is encrypted in transit using TLS/SSL
- Sensitive data is encrypted at rest
- Authentication tokens are securely stored
Data Ownership
Your organisation retains full ownership of all case data, support information, and content created in the App. Aawhina acts solely as a data processor.
Access Control
- Aawhina team members do not have access to your organisation's support data or information
- Data is isolated per organisation using secure multi-tenant architecture
- Role-based access controls ensure users only see authorised information
Infrastructure
- Data is hosted on secure cloud infrastructure
- We undertake regular security audits and updates
- We do automated backups and disaster recovery
Data Sharing and Disclosure
We do not sell, rent, or trade your personal information.
We may share information only in the following circumstances:
Within Your Organisation
- Team members with appropriate permissions can access shared support information
- Communications are visible to authorised users within your organisation, according to their role
Service Providers
- Cloud hosting providers
- Push notification services (Firebase Cloud Messaging)
- Email delivery services (for email functionality)
These providers are bound by strict confidentiality agreements and only process data on our behalf.
Legal Requirements
We may disclose information if required by law, court order, or to:
- Comply with legal processes
- Protect rights, property, or safety
- Prevent fraud or security issues
Push Notifications
The App uses Firebase Cloud Messaging to send push notifications:
- Notifications alert you to new messages, support updates, and important events
- You can disable notifications in your device settings
- We store notification tokens securely and only use them for App notifications
Your Rights
You have the right to:
- Access: Request a copy of your personal data
- Correction: Update or correct inaccurate information
- Deletion: Request deletion of your personal data (subject to legal retention requirements)
- Export: Download your organisation's data
- Opt-out: Disable push notifications or certain features
To exercise these rights, contact your organisation's administrator or email [email protected].
Data Retention
- Active Data: Retained while your organisation's subscription is active
- Account Deletion: Data is permanently deleted within 90 days of account closure
- Legal Requirements: Some data may be retained longer to comply with legal obligations
- Backups: Backup copies are automatically deleted according to our retention schedule
Children's Privacy
The App is not intended for children under 13 years of age. We do not knowingly collect information from children. If you believe a child has provided information to us, please contact us immediately.
International Data Transfers
If you access the App from outside New Zealand, your data may be transferred to and processed in New Zealand or other countries where our service providers operate. We ensure appropriate safeguards are in place for such transfers.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of changes by:
- Posting the new Privacy Policy in the App
- Updating the "Last Updated" date
- Sending an in-app notification for significant changes
Continued use of the App after changes constitutes acceptance of the updated policy.
Third-Party Services
The App integrates with:
- Firebase Cloud Messaging: For push notifications (Privacy Policy)
- AWS: For cloud hosting (Privacy Policy)
These services have their own privacy policies governing their use of information.
Contact Us
If you have questions about this Privacy Policy or our privacy practices:
Aawhina Support
Email: [email protected]
Website: aawhina.com
Privacy Email: [email protected]
Address: Aawhina Team, Waihāpai, Strandon Professional Centre, 17 Nobs Line, New Plymouth, 4310, Aotearoa New Zealand
Compliance
This Privacy Policy complies with:
- New Zealand Privacy Act 2020
- General Data Protection Regulation (GDPR) principles
- Google Play Store requirements
- Apple App Store guidelines