Privacy Policy

We know that how we collect, use, disclose and protect your information is important to you, and we value your trust. That is why protecting your information and being clear about what we do with it is a vital part of our relationship with you.

This Privacy Policy applies to all our products and services and describes how we comply with the New Zealand Privacy Act 2020 (the Privacy Act) in managing personal information.

Consent to Privacy Policy

Please note that when you contact us through our website or social media pages, you agree to this Privacy Policy. If you do not agree with this Privacy Policy, please do not contact us through any of our digital platforms.

Who we are

Total Life is the trading name of Financial Services South Limited.

We, us, or our means Financial Services South Limited trading as Total Life.

Some financial advice services under the Total Life brand are provided by authorised bodies operating under our financial advice provider licence. Authorised bodies are separate businesses, but they adopt this Privacy Policy when they provide services to you under the Total Life brand.

You and your means our clients and other individuals who engage with us directly or indirectly.

Personal Information is defined in the Privacy Act as information about an identifiable individual (a natural person as opposed to a company or other legal entity).

We collect personal information in connection with our services. In some cases, the law requires us to make reasonable enquiries to ensure our services, including our financial advice, are suitable for you. It is important you provide accurate and complete information to us.

Types of personal information we collect

The types of personal information we collect will vary depending on the nature of your dealings with us, and we only collect personal information that is necessary. Where reasonable and practicable, we will collect your personal information directly from you and inform you that we are collecting it.

Generally, the types of personal information we collect, and hold include:

 

    • Your name, contact details (such as email address, phone number, and residential address), and date of birth.

    • Identification and verification information (for example, copies or details from identity documents and other checks we may carry out).

    • Information about your employment and income, assets and liabilities, spending, and other financial circumstances relevant to the financial advice services you request.

    • Information about your financial goals, needs, priorities, and risk profile (including your attitude to risk and investment timeframe, where relevant).

    • Information about products you hold or have held (for example, insurance policies, KiwiSaver and other investments, loans, or superannuation), including policy/account numbers and benefit details where relevant.

    • Information about your health or medical history only where it is relevant to the advice or product you request (for example, for insurance underwriting), and only to the extent permitted by law.

    • Records of our interactions with you (for example, meeting notes, emails, calls, and documents we prepare such as a Statement of Advice or Record of Advice).

How we collect personal information

We mainly collect personal information directly from you, for example:

 

    • Over the telephone or a video call (such as over Microsoft Teams, Zoom or Skype) e.g., when you contact our team.

    • When you email or write to us.

    • When you participate in a marketing campaign, competition, or promotion (or a similar event) administered by us or an authorised body.

If it is not obvious that we are collecting personal information from you, we will do our best to make it clear to you so that you are always aware when information is being collected.

We may also collect personal information about you from other sources, including:

 

    • Our authorised bodies and referral partners (where applicable).

    • Product providers and related parties (for example, insurers, banks, investment managers, KiwiSaver providers, and superannuation schemes) and their administrators.

    • Platforms, custodians, and registry/administration providers (where applicable).

    • Your employer, accountant, lawyer, trustee, or other people you have authorised (for example, a family member), and referees where relevant.

    • Credit reporting agencies and identity/verification service providers (where relevant and permitted by law).

    • Publicly available sources (for example, publicly available registers or information available online).

Sometimes we need to confirm or update information about you from the third parties listed above (for example, credit reporting agencies, identity service providers, or publicly available sources). When this happens, we will take reasonable steps to let you know we have collected information from someone else and why (either at the time we ask for your authority, or within a reasonable timeframe afterwards), unless an exception applies under the Privacy Act.

When we collect information about you from someone else

Indirect source Types of personal information Purpose of collection
Your employer (where relevant) Contact details and other information relevant to the services you have asked us to provide. To contact you and provide services (for example, to help assess needs and implement financial products where your employer is involved).
People you have authorised (for example, a family member), and your accountant, lawyer, trustee, or other advisers (where relevant) Contact details, identity/verification information, and information relevant to your financial circumstances and needs. To provide financial advice services you request and to implement or administer products and services on your behalf.
Financial product providers and related parties (for example, insurers, banks, investment managers, KiwiSaver providers, and superannuation schemes) and their administrators Information about products you hold or have held, application/underwriting information, policy/account information, and claims information (where applicable), plus related contact/identity details. To help you apply for, maintain, change, or claim on financial products, and to support the advice we provide.
Platforms, custodians, and registry/administration providers (where applicable) Account/holding information, transactions, balances, and related contact/identity details. To implement, administer, and review investments/superannuation, and to provide any agreed ongoing service.
Identity verification and customer due diligence providers (including AML/CFT service providers, where applicable) Identity document details and verification results, and related information necessary to complete verification checks. To verify your identity and meet applicable legal and regulatory obligations (including AML/CFT obligations, where they apply).
Credit reporting agencies (where relevant and permitted by law) Credit-related information and identity matching information relevant to a check. To complete checks relevant to the services you request (for example, where lending is involved), and to manage risk and prevent fraud/unlawful conduct.
Publicly available sources (for example, publicly available registers or information available online) Information that is publicly available (for example, company/director or property-related information where relevant). To verify information you provide, to help us provide services you request, and to meet legal or regulatory obligations where relevant.

Your obligations when you provide personal information about someone else

You must not provide us with personal information about another individual (for example, a partner, dependant, trustee, or other third party) unless you are authorised to do so. If you provide us with personal information about another individual, before doing so you must:

 

    • tell that individual you will be providing their information to us and that we will handle it in accordance with this Privacy Policy;

    • provide that individual with a copy of (or refer them to) this Privacy Policy; and

    • confirm you are authorised to provide that individual’s information to us.

If you have not done this, you must tell us before you provide any third-party information.

Your obligations when we provide you with someone else’s personal information

If we give you, or provide you access to, the personal information of another person, you must only use it:

 

    • for the purposes we have agreed with you; and

    • in compliance with applicable privacy laws (including the Privacy Act 2020).

Online device information and cookies

If you are visiting us through our website or social media pages, then we may collect information about your use and experience on these by using cookies. Cookies are small pieces of information stored on your hard drive or on your mobile browser. They can record information about your visit to the site, allowing it to remember you the next time you visit and provide a more meaningful experience.

The cookies we send to your computer, mobile phone or other device cannot read your hard drive, obtain any information from your browser, or command your device to perform any action. When you interact with us through our website or social media pages, the information collected through the cookies may include:

 

    • The date and time of visits.

    • Website page (or pages) viewed.

    • The website from which you accessed the internet and our website or other digital platform.

    • How you navigate through the website and interact with pages (including any fields completed in forms and applications completed, where applicable).

 

    • Information about your location.

    • Information about the device used to visit our digital platform; and

    • IP address (or addresses), and the type of web browser used.

We will not ask you to supply personal information publicly over Facebook or any other social media platform that we use. Sometimes we may invite you to send your details to us through a private message, for example, to answer a question. You may also be invited to share your personal information through secure channels to participate in other activities, such as competitions, but we would require your express consent prior to us including you in such activities.

Purpose of collection and use of personal information

Any personal information you provide to us may be used to:

 

    • Provide you with financial advice services you request, including collecting information to understand your needs and objectives, preparing and presenting advice, and providing any agreed ongoing service.

    • Verify your identity and meet our obligations under applicable laws and regulations (for example, Anti-Money Laundering and Countering Financing of Terrorism requirements, where they apply).

    • Assess your financial position and other circumstances relevant to the advice (for example, reviewing information you provide such as bank statements, existing policy or account information, and budgets).

    • Research and compare products and make recommendations that we believe are suitable for you.

    • Help you apply for, maintain, change, or claim on financial products (for example, insurance, investments, KiwiSaver, or lending), including communicating with product providers and administrators on your behalf.

    • Communicate with you, respond to your requests, and provide information about our services.

    • Manage and improve our business operations, systems, and service delivery (including quality assurance, training, and record keeping).

    • Prevent and manage fraud, unlawful conduct, and other risks.

    • Facilitate internal and external dispute resolution and complaints handling.

    • Comply with our legal and regulatory obligations (including obligations that apply to financial advice providers and, where applicable, financial advisers providing services through Total Life or its authorised bodies) and respond to requests from regulators and other authorities.

    • Market products and services provided by Total Life and third parties where you have authorised us to do so or where otherwise permitted by law.

We may also be required to retain and disclose personal information to regulators and similar bodies where required or authorised by law (see “Disclosure of your personal information” below).

Storage and protection of your personal information

We may electronically record and store personal information which we collect from you. When we do so, we will take all reasonable steps to keep it secure and prevent unauthorised disclosure.

However, we cannot promise that your personal information will not be accessed by an unauthorised person (e.g., a hacker) or that unauthorised disclosures will not occur. If we provide you with any passwords or other security devices, it is important that you keep these confidential and do not allow them to be used by any other person. You should notify us immediately if the security of your password or security device is breached, this will help prevent the unauthorised disclosure of your personal information.

Some information we hold about you will be stored in paper files, but most of your information will be stored electronically on our servers or in the cloud, by cloud service providers – see “Cloud-based service providers” below.

We use a range of physical and electronic security measures to protect the security of the personal information we hold, including:

 

    • Access to information systems is controlled through identity and access management.

    • Our buildings are secured with a combination of locks, monitored alarms and cameras to prevent unauthorised access.

    • Employees are bound by internal information security policies and are required to keep information secure. Employees are required to complete training in information security and privacy.

    • When we send information overseas or use service providers to process or store information, we put arrangements in place to protect your information.

    • We regularly monitor and review our compliance (and our service providers’ compliance) with internal policies and industry best practice.

    • We have a data governance policy that governs how we manage our information and records to make sure we destroy any information that is outdated, irrelevant or unnecessary.

Cloud-based service providers

We use third party service providers to store and process most of the information we collect. We use cloud service providers located in New Zealand and Australia. We ensure that our cloud-based service providers are subject to appropriate security and information handling arrangements and that the information stored or processed by them remains subject to confidentiality obligations.

Use of AI tools

We may use AI-enabled tools to help our team work efficiently (for example, Microsoft Copilot and Marloo). These tools may be used for tasks such as drafting and improving documents, summarising notes, and assisting with administrative work. Where we use AI tools, we take reasonable steps to protect your personal information, including limiting access to authorised staff, using approved providers, and applying human review for important outputs (such as advice documents). We do not intentionally enter more personal information than is necessary for the task being performed.

Timeframes for keeping personal information

We take reasonable steps to destroy or permanently de-identify any personal information as soon as practicable after the date of which it has no legal or regulatory purpose, or we have no legitimate business purpose with it. We are required to hold personal information for at least seven years by the Companies Act 1993, the Anti-Money Laundering and Countering Financing of Terrorism Act 2009 and other New Zealand laws. After this time, provided that the personal information is no longer relevant to any product or service we are providing you, we will take reasonable steps to safely destroy or de-identify any personal information.

We have a data governance policy that governs how we manage our information and records to enable us to destroy any information that is outdated, irrelevant or no longer necessary.

If there is a privacy breach

We work hard to keep your personal information safe. However, despite applying strict security measures and following industry standards to protect your personal information, there is still a possibility that our security could be breached. If we experience a privacy breach, we will respond to minimise harm.

If we consider the breach has caused, or is likely to cause serious harm, we will notify the Privacy Commissioner.

We may notify any customers affected by the breach or put a notice on our website advising customers of the breach.

If you think a privacy breach has occurred, please contact us as soon as possible.

Disclosure of your personal information

We may disclose your personal information to others for the following purposes:

 

    • Where it is necessary to enable us to achieve the purpose that we collected the information for.

    • When we are required or authorised by law or where we have a public duty to do so.

    • When you have expressly consented to the disclosure, or your consent can be reasonably inferred from the circumstances; or

    • When we are permitted to disclose information under the Privacy Act.

Parties we may disclose your information to

We may disclose your personal information to the following types of organisations and people:

 

    • Our staff and authorised bodies who provide services under the Total Life brand (including, where applicable, financial advisers engaged by those authorised bodies).

    • Product providers and related parties (for example, insurers, banks, investment managers, KiwiSaver providers, superannuation schemes) and their administrators, underwriting or claims assessors.

    • Platforms, custodians, registry/administration providers, and payment providers (where applicable).

    • Outsourced service providers who assist us to operate our business and provide services (for example, IT/hosting providers, cloud service providers, client relationship management systems, identity verification providers, and document management providers).

    • Professional advisers and assurance providers (for example, auditors, external compliance reviewers, and our lawyers and accountants).

    • Our external dispute resolution service.

    • Regulators and other New Zealand authorities (for example, the Financial Markets Authority) where required or authorised.

    • Any organisation or person we consider assigning or transferring any of our rights under any agreement with you.

    • Any referral partner or other third party you have agreed we may share your information with.

If we do not need to share your information with a third party to provide products and services to you, we will not pass on your information to them without your consent. Under no circumstances will we sell or receive payment for disclosing your personal information.

Sending your information overseas

In the normal course of business, we may disclose your personal information outside New Zealand, including to overseas service providers who help us operate our business (for example, cloud and IT providers).

Where we do this, we will take reasonable steps to ensure your information is protected in a way that, overall, provides comparable safeguards to those in New Zealand. This may include contractual protections and other measures appropriate to the nature of the information and the overseas recipient.

Privacy and information protection standards vary between countries. If we need to send your personal information to a country with lower standards than New Zealand, we will take appropriate measures to protect your personal information.

Right to access, and correct personal information

You have the right to request access to, or correction of, your personal information. You can do so by contacting us at:

Total Life

Phone: 03 2111 460

E-mail: admin@totallife.co.nz

Postal Address: PO Box 149, Invercargill 9840

When you contact us with such a request, we will take steps to update your personal information, provide you with access to your personal information and/or otherwise address your query within a reasonable period after we receive your request. To protect the security of your personal information, you may be required to provide identification before we update or provide you with access to your personal information.

There is no fee for requesting that your personal information is corrected or for us to make corrections. In processing your request for access to your personal information, a reasonable cost may be charged. This charge covers such things as locating the information and supplying it to you.

There are some circumstances in which we are not required to give you access to your personal information. If we refuse to give you access or to correct your personal information, we will let you know our reasons, except if the law prevents us from doing so.

If we refuse your request to correct your personal information, you also have the right to request that a statement be associated with your personal information noting that you disagree with its accuracy. If we refuse your request to access or correct your personal information, we will also provide you with information on how you can complain about the refusal.

What happens if you do not provide us with your information?

If you do not provide information we have requested, this may affect the services we can provide to you. Please ask us if you are unsure what information is important and how this might affect you.

Changes to this Privacy Policy

We review this Privacy Policy periodically to keep it current and available on our website. Any changes to the Privacy Policy apply to all information collected before and after the publication date. If the changes are significant, we may advise you directly. You may also obtain a copy of the latest version by contacting us.

Privacy Policy queries and concerns

If you are concerned about how your personal information is being handled or if you feel that we have compromised your privacy in some way, please contact our Head of Compliance at:

Total Life

Phone: 03 2111 460

E-mail: lana.paterson@totallife.co.nz

Postal Address: PO Box 149, Invercargill 9840

We will acknowledge your complaint promptly. We will let you know if we need any further information from you to investigate your complaint. We aim to resolve complaints as quickly as possible.

If you are not satisfied with our response to any privacy related concern you may lodge a complaint on the Privacy Office website:  www.privacy.org.nz or send a complaint form to the Privacy Commissioner at:

Office of the Privacy Commissioner

Postal Address: PO Box 10094, Wellington 6143, New Zealand

Fax: (04) 474 7595

Phone: (0800) 803 909

E-mail: enquiries@privacy.org.nz

Website: www.privacy.org.nz

Start Application

Fill out the form below, and we will be in touch shortly.
Contact Information

Mortgage Assessment

Fill out the form below, and we will be in touch shortly.
Contact Information