⚠️ DRAFT — pending review by New Zealand privacy counsel against the Privacy Act 2020 and the Health Information Privacy Code 2020. Items marked in red require completion before this policy takes effect.
BannedBands Privacy Policy
Effective date: [DATE] · Last updated: 4 July 2026
1. Who we are
BannedBands is developed and operated by Xclusion Systems International Limited (NZBN 9429047666214), 9 Kitchener Road, Takapuna, Auckland 0622, New Zealand ("we", "us"). We are the agency responsible for personal information collected through the BannedBands wristband, companion app, and website under the Privacy Act 2020.
Privacy contact: [privacy@xclusion.nz once live] · +64 22 658 1315
2. Our privacy-by-design commitments
No biometric data. We do not collect, process, or store facial images for recognition, fingerprints, or any other biometric identifiers. Venue identification uses your enrolment photo shown to trained staff — it is never processed by automated recognition systems.
No continuous tracking. The wristband contains no GPS. It is dormant by default and interacts only with beacons inside venues you have chosen to be excluded from.
Consent-based. Enrolment is voluntary. Every data-sharing feature (such as the Alert Person feature) is individually opt-in.
3. Information we collect
Enrolment information: name, date of birth, contact details, enrolment photograph, chosen exclusion venues and duration, wristband serial number.
Wristband data: band serial number, battery status, tamper/integrity status, and presence events (timestamped detections at participating venues you are excluded from). The band broadcasts only a serial number — it carries no personal information.
Companion app data: check-in records, mood tracker entries, recovery milestones (days clean, money saved), support contacts you nominate, and in-app messages with counsellors [confirm counsellor messaging data flow].
Website data: contact form submissions and standard server logs. [Complete cookies/analytics section once analytics tooling is confirmed.]
Mood, recovery, and counselling information may constitute health information under the Health Information Privacy Code 2020 and is handled with corresponding safeguards.
4. How we use it
Operating the self-exclusion service: detecting presence at excluded venues and notifying venue staff so your exclusion can be honoured.
Integrity monitoring: confirming the band is intact via check-ins.
Recovery support: powering the dashboard, mood tracking, and MARCiA's adaptive check-in frequency. MARCiA's outputs are recommendations reviewed by people; no solely automated decision produces an enforcement outcome against you. [Confirm this holds in production.]
Safety: connecting you to crisis support when you request it.
Research: producing anonymised, aggregated insights on breach patterns and intervention effectiveness. Anonymised data cannot be linked back to you. [Legal review: confirm anonymisation standard.]
5. Who we share it with
Participating venues: your name, enrolment photo, and exclusion status — only when your band is detected at a venue you are excluded from, and only to staff responsible for honouring your exclusion.
Your nominated support person: only the specific items you have individually consented to share (for example, streak milestones), which you can revoke at any time.
Counsellors and treatment providers: only where you have engaged them through the app.
Regulators: where required by law, or under future integration with the national self-exclusion register [subject to regulations due under the Online Casino Gambling Act 2026 — update when made].
Service providers: hosting and infrastructure providers under contractual confidentiality. [List providers and locations.]
We do not sell personal information. We do not share it with advertisers.
6. Overseas storage
[Complete once hosting is confirmed. If data is stored outside New Zealand, identify the country and the IPP 12 safeguard relied upon — e.g., comparable safeguards or contractual protections.]
7. Security
Data is encrypted in transit and at rest [confirm], access is restricted on a need-to-know basis, and wristbands broadcast serial numbers only — identity resolution happens server-side. [Legal/technical review: describe actual controls accurately; do not overstate.]
8. Retention
We keep enrolment and enforcement records for the duration of your exclusion plus [X years — align with venue/regulatory record-keeping obligations], then delete or anonymise them. App wellbeing data is deleted [X months] after account closure on request.
9. Your rights
Under the Privacy Act 2020 you may request access to, and correction of, your personal information at any time by contacting us at the details above. We will respond within 20 working days. Withdrawing from the programme: [describe process — note any venue/regulatory notice obligations before deactivation].
10. Complaints
Contact us first at the privacy contact above. If unresolved, you may complain to the Office of the Privacy Commissioner: privacy.org.nz · 0800 803 909.
11. Children
BannedBands is available only to people of legal gambling age (18+ for Class 4 venues; 20+ for casinos in New Zealand). We do not knowingly collect information from minors.
12. Changes
We will post updates here and notify enrolled users of material changes through the app.
13. Māori data sovereignty — development commitment
DEVELOPMENT STATUS — The commitments below are proposed safeguards and co-design questions, not a claim of Māori endorsement, legal compliance, or implemented Māori governance.
Any future pilot that may involve Māori data, whānau, hapū, iwi, or collective interests will require qualified Māori-led co-design and governance before data is collected or used. Individual consent is important but does not, by itself, resolve collective interests, authority, tikanga, benefit-sharing, or appropriate data stewardship.
Purpose limitation and minimisation: collect only what is necessary for an agreed recovery-support or exclusion-support purpose; do not repurpose identifiable data for unrelated research, profiling, advertising, or enforcement without a separately agreed basis.
Transparency and control: participants and governance partners should be told where information is stored, who can access it, how long it is retained, and how correction, withdrawal, and deletion work. Proposed pilot controls include role-based access, access logs, documented retention schedules, and auditable deletion requests.
Strict venue boundary: venue staff should receive only the minimum exclusion-related information required to honour an exclusion event. Wellbeing, mood, counselling, recovery-journal, and other support data must not be provided to venues as part of the proposed design.
Auditability and human oversight: access, sharing, changes, and deletion should be reviewable; any MARCiA or analytics use should remain within the agreed purpose and be subject to human review.