Privacy statement.
How we collect, use, and look after personal information for the people we work with.
How we collect, use, and look after personal information for the people we work with.
We collect personal information only when we need it for genuine engineering business purposes. We handle it fairly, keep it secure, and act in line with the Privacy Act 2020. You can ask to see or correct information we hold about you at any time. If you have a concern, contact our Privacy Officer. Details are in the Complaints section.
This statement explains how Dobbie collects, uses, looks after, and shares personal information when we deal with people outside our team. That includes our clients and the people who work for them, the people we meet on site, our suppliers, people who contact us or use our website, and job applicants.
We have a separate privacy statement for our own employees and contractors. This one is for everyone else we deal with in our engineering work.
We are committed to handling your personal information lawfully, fairly, and openly, in line with the Privacy Act 2020 and its Information Privacy Principles.
We take reasonable steps to make sure the personal information we handle is:
When you give us personal information, please only give us someone else's information if you are authorised to do so, give us only what is reasonably needed, make sure it is accurate and complete, and tell us promptly if anything changes or is wrong. Avoid sending us sensitive personal information we do not need. Contact us promptly if you want to raise a privacy concern or you think information has been lost or accessed by mistake.
This statement applies to personal information we handle about people outside our team, including:
We collect personal information across a range of everyday business situations, including when providing engineering consultancy services, when visiting client or project sites, when responding to enquiries, when administering accounts, when recruiting, when people use our website, and when managing health, safety, and site access.
Examples of the specific situations in which we collect personal information:
Where we can, we collect personal information directly from the person concerned: through meetings, emails, calls, forms, applications, correspondence, site processes, website interactions, and other direct dealings. When we collect information directly from you, the Privacy Act generally requires us to take reasonable steps to tell you why we are collecting it and your rights of access and correction.
We may also collect personal information indirectly, including from clients and the people who work for them, employers or organisations you represent, contractors and other project participants, referees, recruitment agencies, public registers or other publicly available sources, professional advisers, service providers acting on our behalf, and other third parties where we are authorised or the law allows. Where we collect personal information about you indirectly, we take reasonable steps to let you know as required by Information Privacy Principle 3A, unless an exception applies.
The types of personal information we collect depend on the situation. Examples include:
We may use personal information to:
We use approved AI tools to help us deliver our services and run our business, for example to draft, summarise, analyse, organise, and search information. An engineer always reviews AI output before it is used in your work.
Where we use AI in connection with personal information, we apply privacy and security safeguards, confidentiality controls, internal approval and usage controls, and provider or contractual controls where appropriate. We only handle your information through approved AI tools in ways that are consistent with this statement and the law.
Our separate AI Policy explains in detail how we use AI, what information goes into AI tools, what we will not do, where your information goes, and the choices you have, including the right to opt out. Please read the two documents together.
Some of the service providers and systems we use store or process personal information outside New Zealand, including in Australia, the United States, the European Economic Area, and Canada.
Where we disclose personal information to an overseas recipient for that recipient's own purposes, we only do so where the Privacy Act 2020 allows, and we rely on the cross-border safeguards in Information Privacy Principle 12.
If you choose not to give us information we reasonably need, we may not be able to:
We take reasonable steps to protect the personal information we hold against loss, and against unauthorised access, use, change, disclosure, and other misuse. That includes requiring appropriate privacy and security safeguards from the service providers who handle personal information on our behalf.
We keep personal information only for as long as we need it for the purpose we collected it, and for as long as our professional, legal, and insurance obligations require or permit, which for our engineering work includes the period we remain liable for our designs. When we no longer need it, we take reasonable steps to delete, dispose of, or return it. Because we run routine backups across our files, email, and document systems, copies may remain in our secure backup systems for a time and cannot always be fully removed.
Under the Privacy Act 2020, you can ask for access to the readily retrievable personal information we hold about you, and you can ask us to correct it. We may ask you to confirm your identity before we respond, and we will consider and answer your request in line with the Act.
To make an access or correction request, please contact our Privacy Officer using the details below. Please give us enough detail to identify you and the information you want to access or correct.
If you have a privacy concern or complaint, please contact us first so we have the chance to look into it and respond. Please include your name and contact details, details of your concern or complaint, any relevant dates, correspondence, or supporting information, and the outcome you are seeking.
Hamish Bennett, Managing Director
Email: privacy@dobbie.co.nz
Phone: +64 9 446 6285
Post: Privacy Officer, Dobbie Engineers Limited, Unit G02, 246 Khyber Pass Road, Grafton, Auckland 1023
If we cannot resolve your concern, you can complain to the Office of the Privacy Commissioner at privacy.org.nz or 0800 803 909.
When you use our website or digital channels, we may collect technical and usage information such as your device, browser, IP address, access times, pages visited, the contents of online forms, and cookie-related information.
We may use that information to operate and secure our website and digital systems, understand how our site is used, improve performance, content, and user experience, troubleshoot issues, and support analytics and administration.
Our website measurement uses Cloudflare Web Analytics, a cookieless service: it counts page views and enquiry-form submissions in aggregate, without cookies, cross-site tracking, or personal profiles.
Where we link to third-party sites or platforms, those third parties have their own privacy statements and practices, and this statement does not cover them.
We may update this statement from time to time. The most current version is the one we make available through our usual external channels. The revision is shown at the top of this statement.