Last updated: September 22, 2026
While Dawn Spark operates primarily in New Zealand, we recognize that some of our website visitors may be from the European Union. We are committed to protecting personal data in accordance with the General Data Protection Regulation (GDPR) principles.
We process personal data under the following legal bases:
If you are an EU resident, you have the following rights regarding your personal data:
You have the right to request confirmation of whether we process your personal data and to receive a copy of that data.
You can request correction of inaccurate or incomplete personal data.
You have the right to request deletion of your personal data under certain circumstances, including when the data is no longer necessary for the purposes collected or when you withdraw consent.
You can request that we limit the processing of your personal data in specific situations.
You have the right to receive your personal data in a structured, commonly used format and to transmit that data to another controller.
You can object to processing of your personal data for direct marketing purposes or based on legitimate interests.
You have the right not to be subject to decisions based solely on automated processing that produces legal effects or similarly significant effects.
Your personal data is processed and stored in New Zealand. If you are located in the EU, this constitutes a transfer of data outside the European Economic Area. We ensure appropriate safeguards are in place for such transfers.
For questions about our data protection practices or to exercise your rights, you can contact us at:
Email: [email protected]
Address: 127 Harbour View Road, Wellington 6011, New Zealand
If you are an EU resident and believe that our processing of your personal data violates GDPR, you have the right to lodge a complaint with your local data protection supervisory authority.
We retain personal data only for as long as necessary to fulfill the purposes outlined in our Privacy Policy, typically:
We implement technical and organizational measures to ensure a level of security appropriate to the risk, including:
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you without undue delay and within 72 hours of becoming aware of the breach, as required by GDPR.
We may update this GDPR compliance statement to reflect changes in our practices or legal requirements. We will notify you of significant changes through our website or via email.