Privacy Policy

Effective date: 15/11/17

Responsibility

A. NZForex Limited (CN: 2514293; NZBN: 9429031497541) (trading as “OFX”) a subsidiary of OzForex Limited
(collectively “We”, “Us”) is responsible for, and may collect and hold, all Personal Information you provide to us
and will deal with that information in accordance with the following Privacy Principles. When used in this Policy,
“Personal Information” has the meaning given in the Privacy Act 1993, being in general terms information about
an identifiable individual.

B. We have in place strict procedures to ensure the implementation of our Privacy Principles and to deal with
complaints and enquiries. Our Compliance Manager has overall responsibility for ensuring that our employees,
agents and subsidiaries comply with our Privacy Principles. Our Compliance Manager may be contacted in
relation to any enquiry or complaint at privacy@ofx.com or on TEL: +612 8667 8090.

C. We will not disclose any of your Personal Information to a third party, or a foreign country, unless the recipient
is subject to legislation, or a contract, that safeguards your Personal Information in a manner that is substantially
similar to our Privacy Principles.

D. These Privacy Principles should be read in conjunction with our customer agreement and any other applicable
terms (including Terms of Use). We reserve the right to make changes to this privacy policy, so we encourage
you to review the policy from time to time for the latest information on our privacy practices.

Privacy Principles

Purpose and Intended Recipients
1 We will collect Personal Information such as your name, telephone number, mobile number, date of birth,
address and bank account information only for the purpose of providing our services to you or for any purpose
that is directly incidental to the provision of those services. In the event that we wish to use your Personal
Information for any other purpose, we will identify such purpose and obtain your consent before doing so, unless
the new purpose is required by law. For the avoidance of doubt, purposes that we would regard as being directly
incidental to the provision of our service include credit assessment and debt recovery purposes as well as
information about our services. If you choose to add a recipient on our website, we will ask you for your
recipient’s name, email address, financial information (bank information) and physical address.

2 We are always willing to explain to you the purposes for which your information is being collected. Failure to
provide necessary Personal Information when requested may result in certain services not being available to you
or other consequences as notified at the time of request.

3 We may disclose information about you, including your Personal Information, to our affiliates, employees,
officers and agents for the purposes set out in paragraph 1 above and to our contractors and suppliers to enable
them to assist in the provision of the services to you. If We wish to provide your Personal Information to any other
recipient, we will identify that recipient and obtain your consent before doing so, unless the provision of that
information to that recipient is permitted by law.

Consent

4 We will seek your consent to the use of your Personal Information either expressly or impliedly, depending on
the circumstances and the type of information collected. For example, we will rely on your implied consent when
you give us your name, address, telephone number and other details necessary for us to verify your identity in
accordance with the provisions of the customer agreement you enter into. We will seek your express consent if
the information is of a financial nature or concerns your personal credit.

5 Your consent may also be given by an authorised representative or a person having your power of attorney.

6 You may withdraw your consent at any time, subject to any legal restrictions and subject to any contractual
restrictions you have already entered into with us, and provided that you give us reasonable notice in writing. We
will explain to you the implications of such withdrawal.

7 If you are registered with us, we may from time to time send you information that is relevant to the provision of
our services. If you provide us with electronic contact details, you agree that we may send you commercial
electronic messages (for example, e-mails) for any of the purposes set out in this privacy policy or otherwise
disclosed to you. If, at any time, you do not wish to receive that information, you may by sending us an email opt-
out and request that you are not included in any future mail-outs.

8 There may be circumstances in which we are obliged to collect, use, or disclose certain Personal Information
without your consent as provided for by applicable laws or in case of buying and selling of business assets.
Collecting information relating to the identity of parties transferring money is a mandatory requirement in New
Zealand under the Financial Transactions Reporting Act 1996 and the Anti-Money Laundering and Countering
Financing of Terrorism Act 2009.

Limiting Collection and Retention of Information

9 The amount and type of information collected by us will be limited to that which is necessary to provide our
services.

10 We will make reasonable efforts to inform you if we have collected Personal Information about you from
someone else such as any credit information that may be obtained in the course of obtaining the identity
particulars described above

11 Any Personal Information that you provide to us will, unless otherwise notified, be collected and held by us in
an electronic form on our web server in Sydney Australia. Personal information shall be retained only for as long
as may be necessary for the fulfilment of the purpose for which the information is collected. However, you should
be aware that we are obliged under relevant anti-money laundering and counter-terrorism legislation to retain
information relating to personal identity for 7 years.

12 Subject to any legislative requirements, we will destroy, erase, or make anonymous your Personal Information
when it is no longer required to fulfil the purpose for which it has been collected.

Accuracy

13 We will make reasonable efforts to ensure that your Personal Information is sufficiently accurate, complete,
and up-to- date to minimise the possibility that inappropriate information may be used to make a decision about
you.

14 We will not routinely update your Personal Information, unless such a process is necessary to fulfil the
purposes for which the information was collected. In accordance with the customer agreement, you must notify
us as soon as possible if any of the information you have provided to us has changed.

Safeguards

15 We have in place a range of security safeguards to protect your Personal Information against loss or theft, as
well as unauthorised access, disclosure, copying, use, or modification, regardless of the format in which it is held.

16 The methods of protection may depend on the sensitivity of the information and the format in which it is
contained. Security measures employed by us include:

(i) technological measures including SSL 128-bit encryption for all data transfers over the Internet;
(ii) physical measures such as locked filing cabinets and restricted access to offices; and
(iii) strategic measures such as security clearances and limiting access to a "need-to- know" basis.

17 We ensure that our staff are aware of the importance of maintaining the confidentiality of Personal
Information.

Access

18 Under the Privacy Act 1993, you have rights of access to and correction of Personal Information that we hold.
This can be done by contacting our Privacy Officer at privacy@ofx.com. Without limiting this right, we will upon
request and within 20 working days of any such request allow you access to your Personal Information. The
requested information shall be provided or made available in a form that is generally understandable.

19 In circumstances where you point out to us that any information held by us is inaccurate or incomplete, we will
take appropriate action to amend the information as required and, if necessary, notify any third party of the
correction.

20 There may be circumstances which preclude us from providing access to some or all of your Personal
Information as provided for by applicable laws.

21 We may be prohibited by law from providing you with access to your Personal Information as provided for by
applicable laws.

Availability and changes to this Policy

This Policy is available on the OFX website. We may change this Policy from time to time. If we make any
material changes we will notify you by email (sent to the e-mail address specified in your account) or by means of
a notice on this website prior to the change becoming effective. We encourage you to periodically review this
page for the latest information on our privacy practices.

Complaints

22 We have procedures in place, to receive and respond to, complaints or inquiries about our policies and
practices relating to the handling of Personal Information. For more information, please see our Complaints
Policy on our website.

23 We take all complaints seriously and will investigate all complaints.

Tracking Technologies

We and our marketing partners, affiliates, or analytics or service providers, use technologies such as cookies,
beacons, tags, and scripts, to analyze trends, administer the website, tracking users’ movements around the
website, and to gather demographic information about our user base as a whole. We may receive reports based
on the use of these technologies by these companies on an individual and aggregated basis.

We use Internet technologies like cookies and web beacons to facilitate the services we provide on our websites
and your use of our websites, including for the following reasons.

(i)       To assist us in providing services to you.
(ii)     To allow you to change web pages during your visit without having to re-enter your password.
(iii)      To store your preferences and other information and to track activity on our website.
(iv)      To better understand the effectiveness of our promotional campaigns.
(v)       To determine whether you came to our site from a banner ad or an affiliate website.
(vi)      To deliver Information specific to your interests on additional web sites.
(vii)     To determine whether you've acted on our promotional messages

NOTE: A "cookie" is a text file placed on your computer's hard drive by a web server, which allows for
personalisation of certain aspects of your visit to that website. "Web beacons" are transparent electronic images
placed in the web code that collect non-personal data while visiting a website. Cookies and web beacons can
usually be disabled by changing your browser preferences. Your browser usually has documentation on how to
disable cookies and web beacons. Note that disabling cookies may limit the performance of OFX's websites. If
cookies are disabled, certain features of our websites may not function properly, and you may not be able to
register or use your online account.

We partner with a third party to either display advertising on our website or to manage our advertising on other
sites. Our third party partner may use technologies such as cookies to gather information about your activities on
this website and other sites in order to provide you advertising based upon your browsing activities and interests.
If you wish to not have this information used for the purpose of serving you interest-based ads, you may opt-out
by clicking here. Please note this does not opt you out of being served ads. You will continue to receive generic
ads.

We gather certain information automatically and store it in log files. This information may include Internet protocol
(IP) addresses, browser type, internet service provider (ISP), referring/exit pages, operating system, date/time
stamp, and/or clickstream data.

We do not link this automatically collected data to other information we collect about you.

We use Local Shared Objects, such as Flash cookies, and Local Storage, such as HTML5, to store content
information and preferences. Third parties with whom we partner to provide certain features on our website or to
display advertising based upon your web browsing activity also use Flash cookies or HTML5 to collect and store
information. Various browsers may offer their own management tools for removing HTML5. To manage Flash
cookies, please click
here: http://www.macromedia.com/support/documentation/en/flashplayer/help/settings_manager07.html

Links to Other Sites

Our website may be linked to or from third party websites. These links are provided as a convenience only. We
are not responsible for the content or privacy principles of websites that are linked to or from our website. You are
advised to review the privacy policies of any third party websites you visit.

Social Media Widgets

Our website includes Social Media Features, such as the Facebook Like button, and Widgets, such as the Share
This button or interactive mini-programs that run on our website. These Features may collect your Internet
protocol address, which page you are visiting on our website, and may set a cookie to enable the Feature to
function properly. Social Media Features and Widgets are either hosted by a third party or hosted directly on our
website. Your interactions with these Features are governed by the privacy statement of the company providing
it.

Testimonials

We may display personal testimonials of satisfied customers on our website in addition to other endorsements.
With your consent, we may post your testimonial along with your name. If you wish to update or delete your
testimonial, you can contact us at privacy@ofx.com.

Contact

NZForex Limited
C/- Bell Gully, Level 22, Vero Centre
48 Shortland Street
Auckland 1010
New Zealand
Email: privacy@ofx.com