iSPARX™ Privacy Policy

Effective date: 1 September 2026

iSPARX™ respects the privacy, dignity and data sovereignty of the people and communities who interact with our work.

This Privacy Policy explains how iSPARX™ collects, holds, uses, discloses and protects personal information across our websites, AR+IQ platform, applications, immersive experiences, AI systems and related services.

Our approach is based on privacy by design. We seek to collect only the information required to provide an experience or service.

Our privacy practices are informed by:

  • the Privacy Act 2020 (New Zealand) and its Information Privacy Principles;

  • the Privacy Act 1988 (Cth) (Australia) and the Australian Privacy Principles, where applicable;

  • applicable privacy and data protection requirements in other jurisdictions in which we operate; and

  • kaupapa Māori principles relating to sovereignty, integrity, responsibility and collective interests.

Where different laws apply to a particular service, project or individual, we will seek to meet the applicable legal requirements.

1. Who we are

iSPARX™ is the trading identity used for our immersive media, spatial computing and digital technology activities.

Our work includes AR+IQ, a modular spatial computing platform combining augmented reality, artificial intelligence, geospatial technologies, 3D media and real-time digital interaction.

This Privacy Policy applies to personal information handled through iSPARX™ services, including:

  • websites;

  • AR+IQ and associated platform services;

  • mobile and spatial applications;

  • augmented reality experiences;

  • AI agents and interfaces;

  • content management systems;

  • developer services and APIs;

  • events and installations;

  • research and co-creation activities;

  • partner deployments;

  • customer and supplier relationships; and

  • other digital products and services operated by us.

A specific application, project or partner deployment may provide an additional privacy notice where its information practices differ from this general policy.

2. Our principles

Legal compliance is the minimum standard for our approach to privacy.

Our work is also informed by kaupapa Māori values.

Tino Rangatiratanga

People, communities and knowledge holders should retain meaningful authority over their information, identity, knowledge and digital representation.

Mana

Information should be handled in ways that respect the dignity, reputation and interests of the people and communities it relates to.

Ngākau Pono

We aim to act honestly and transparently when collecting, using and managing information.

Whai Oranga o te Taiao

We consider the social, cultural, ecological and technological effects of the digital systems we create.

These principles inform the design of AR+IQ and our wider approach to ethical technology.

3. What is personal information?

Personal information is information or an opinion about an identified or reasonably identifiable individual, or information about an identifiable individual as defined under applicable privacy law.

Depending on the service being used, this may include:

  • name;

  • email address;

  • telephone number;

  • account details;

  • authentication information;

  • correspondence;

  • transaction information;

  • application usage;

  • device information;

  • technical and diagnostic information;

  • location or geospatial information;

  • interaction history;

  • photographs;

  • video;

  • audio or voice input;

  • text supplied to an AI system;

  • preferences;

  • survey and research responses; and

  • content voluntarily provided to an experience.

Some information may be considered sensitive information under applicable law and may require additional safeguards.

We seek to avoid collecting identifying or sensitive information where it is not necessary.

4. How we collect information

We may collect personal information when a person:

  • visits our websites;

  • creates an account;

  • uses an iSPARX™ or AR+IQ application;

  • interacts with an AR experience;

  • interacts with an AI agent;

  • submits a form;

  • contacts us;

  • subscribes to communications;

  • participates in research;

  • attends an event or installation;

  • participates in a survey;

  • purchases a product or service;

  • contributes content; or

  • otherwise chooses to provide information to us.

Where appropriate, we will explain what information is being collected and why.

We aim to make privacy information clear, accessible and appropriate to the context in which information is collected.

5. Information received from another organisation

Where practicable, we prefer to collect personal information directly from the person concerned.

However, AR+IQ may operate within partner, institutional or client environments. Information may therefore sometimes be received from another organisation, authorised integration or data source.

Under New Zealand’s Privacy Act 2020, Information Privacy Principle 3A applies to certain indirect collections of personal information from 1 May 2026.

Where IPP 3A applies, we will take reasonable steps to ensure that the individual is informed about the collection as soon as reasonably practicable, unless an exception under the Privacy Act applies.

This may include informing the individual:

  • that information has been collected;

  • why it was collected;

  • who will receive it;

  • who collected and holds it;

  • whether collection is required by law; and

  • how they can access or request correction of their information.

Partner access to information does not automatically give iSPARX™ permission to use that information for unrelated purposes.

6. AR+IQ spatial and location information

AR+IQ creates experiences that connect digital information with physical places.

Some experiences may therefore require spatial or location information.

Technologies may include:

  • GPS;

  • geospatial coordinates;

  • ARKit;

  • ARCore;

  • LiDAR;

  • spatial anchors;

  • device positioning;

  • visual positioning;

  • environment mapping; and

  • related spatial-computing technologies.

We seek to collect location information only when required for a defined experience or function.

The ability to determine a user’s location does not mean that a permanent location history must be created.

Where practical, location information should be processed for the immediate experience without creating an unnecessary permanent record of a person’s movements.

Where persistent location information is required, this should be disclosed through the relevant application or project privacy notice.

7. Cameras, AR and spatial mapping

Some iSPARX™ applications use cameras, depth sensors, facial tracking or spatial mapping technologies to position digital content within physical environments.

This can include technologies such as ARKit, ARCore, LiDAR, TrueDepth or equivalent systems.

Using these technologies does not necessarily mean that iSPARX™ receives or stores camera or sensor information.

Where information is processed locally on a device solely to enable an AR function, we seek not to retain that information unless retention is required for a clearly identified purpose.

We do not use facial or biometric information for unrelated surveillance or identification merely because the technology makes this technically possible.

Where biometric or sensitive information is collected, additional legal and consent requirements may apply.

8. Artificial intelligence

AR+IQ uses custom multi-model AI systems to create contextual and adaptive digital experiences.

Depending on the implementation, an AI interaction may process:

  • text;

  • voice;

  • images;

  • location;

  • spatial context;

  • selected application content;

  • interaction history; and

  • authorised organisational knowledge.

We apply data minimisation principles to AI interactions.

Personal information collected for one purpose should not automatically become training material, behavioural profiling data or input into an unrelated AI system.

Where third-party AI infrastructure is used, information may be processed by a service provider acting on our behalf.

We assess these relationships according to applicable privacy, security and cross-border disclosure requirements.

Where an AI function materially changes how personal information is processed, additional notice should be provided within the relevant experience.

9. How we use information

We may use personal information to:

  • provide requested products and services;

  • operate AR+IQ experiences;

  • authenticate users;

  • deliver spatial functionality;

  • provide AI interactions;

  • personalise an experience where appropriate;

  • manage customer and partner relationships;

  • process transactions;

  • provide technical support;

  • maintain security;

  • diagnose faults;

  • prevent misuse;

  • measure service performance;

  • conduct authorised research;

  • communicate with users;

  • meet contractual requirements; and

  • comply with legal obligations.

We do not treat the availability of information as permission to use it for any purpose.

10. Analytics and telemetry

AR+IQ may collect technical and engagement information to understand whether an experience is functioning effectively.

This may include:

  • session information;

  • device type;

  • application performance;

  • crashes and errors;

  • feature usage;

  • interaction events;

  • aggregate engagement;

  • spatial interactions; and

  • approximate or experience-specific location information.

Where practical, analytics should be aggregated, anonymised, de-identified or pseudonymised.

Our objective is to understand systems and experiences without unnecessarily identifying individuals.

11. Automated personalisation

Some AR+IQ experiences may adapt according to a person’s interaction, context, location or preferences.

Automated personalisation should be:

  • relevant to the experience;

  • proportionate to its purpose;

  • understandable where it materially affects an individual;

  • subject to appropriate safeguards; and

  • based on the minimum information reasonably required.

Where automated systems could significantly affect an individual, we will consider whether human review or additional transparency is appropriate.

12. Sharing information

iSPARX™ does not sell personal information.

We may disclose personal information where reasonably necessary to:

  • provide a requested service;

  • operate technical infrastructure;

  • provide cloud or AI services;

  • work with an authorised project partner;

  • process a transaction;

  • obtain professional services;

  • protect our systems or users;

  • investigate security incidents;

  • comply with contractual requirements; or

  • comply with applicable law.

We seek to provide service providers and partners only with the information reasonably required for their role.

Where another organisation independently determines how it handles personal information, that organisation’s own privacy policy may also apply.

13. Australia

Some iSPARX™ activities and services operate in Australia.

Where the Privacy Act 1988 (Cth) applies to an iSPARX™ entity, service or activity, we will handle personal information consistently with the applicable requirements of that Act and the Australian Privacy Principles (APPs).

These principles address matters including:

  • open and transparent management of personal information;

  • anonymity and pseudonymity where practicable;

  • collection of solicited information;

  • unsolicited information;

  • notification of collection;

  • use and disclosure;

  • direct marketing;

  • cross-border disclosure;

  • adoption and disclosure of government identifiers;

  • information quality;

  • security;

  • access; and

  • correction.

Sensitive information may be subject to additional requirements.

Individuals in Australia may also have rights to complain to the Office of the Australian Information Commissioner (OAIC) where applicable.

14. Cross-border information

Digital infrastructure does not always operate within national borders.

iSPARX™ and AR+IQ may use cloud, AI, analytics, communications or infrastructure providers operating outside New Zealand or Australia.

Before disclosing personal information overseas, we consider the applicable requirements governing cross-border disclosure.

For New Zealand information, this includes Information Privacy Principle 12 of the Privacy Act 2020.

For Australian information subject to the Australian Privacy Principles, this includes applicable requirements concerning cross-border disclosure, including APP 8.

Where required, we will take reasonable steps to ensure appropriate safeguards exist before information is disclosed overseas.

Where informed authorisation or consent is relied upon, we will provide relevant information before seeking it.

15. Data sovereignty and cultural information

Some iSPARX™ projects involve Māori, Indigenous, community or culturally significant knowledge.

Compliance with general privacy legislation does not necessarily resolve questions of cultural authority or collective rights.

Where a project involves mātauranga Māori, whakapapa, cultural narratives, taonga, Indigenous knowledge or culturally sensitive information, we seek to establish appropriate governance with relevant knowledge holders.

Depending on the project, this may include agreed controls over:

  • collection;

  • access;

  • attribution;

  • storage;

  • location of storage;

  • publication;

  • AI processing;

  • reuse;

  • commercialisation;

  • modification;

  • removal; and

  • return of material.

Our objective is to support meaningful data and creative sovereignty rather than treating cultural knowledge simply as another digital asset.

16. Security

We take reasonable technical and organisational steps to protect personal information from:

  • misuse;

  • interference;

  • loss;

  • unauthorised access;

  • unauthorised modification; and

  • unauthorised disclosure.

Controls may include:

  • encryption;

  • secure authentication;

  • access controls;

  • role-based permissions;

  • secure cloud infrastructure;

  • monitoring;

  • software updates;

  • vulnerability management;

  • confidentiality requirements; and

  • incident-response procedures.

Security measures are selected according to the nature and sensitivity of the information and the risks associated with the service.

No internet-connected system can guarantee absolute security.

17. Retention and deletion

We do not intend to retain personal information indefinitely.

Information should be retained only for as long as it is reasonably required for its lawful purpose, contractual requirements, security needs or applicable legal obligations.

When personal information is no longer required, we will take reasonable steps to:

  • delete it;

  • destroy it securely;

  • anonymise it; or

  • otherwise prevent it from being associated with an identifiable individual.

Different information may have different retention periods.

18. Access and correction

Individuals may have legal rights to access personal information held about them and request correction of inaccurate information.

For information governed by the New Zealand Privacy Act 2020, requests will be handled according to the access and correction requirements of that Act.

For information governed by the Australian Privacy Act 1988, requests will be handled according to the applicable Australian Privacy Principles.

We may need to verify a person’s identity before providing access.

Some information may lawfully be withheld in circumstances permitted by applicable legislation.

19. Privacy and data breaches

A privacy or data breach may involve accidental or unauthorised:

  • access;

  • disclosure;

  • loss;

  • alteration;

  • destruction; or

  • misuse of personal information.

We maintain procedures to identify, contain, assess and respond to privacy incidents.

Where a breach meets the notification threshold under the Privacy Act 2020 (New Zealand), we will notify affected individuals and the New Zealand Office of the Privacy Commissioner as required.

Where Australia’s Notifiable Data Breaches scheme applies, we will assess the incident and notify affected individuals and the Australian Information Commissioner where required.

Our response process may include:

  1. containing the incident;

  2. identifying affected information;

  3. assessing potential harm;

  4. mitigating that harm;

  5. determining legal notification requirements; and

  6. reviewing systems and procedures to reduce the risk of recurrence.

20. Children and young people

Some immersive, cultural and educational experiences may involve children or young people.

We apply particular care when designing these experiences.

We consider:

  • whether collecting the information is necessary;

  • whether the method of collection is fair;

  • whether privacy information is understandable;

  • the age and circumstances of the participant;

  • whether parent, guardian, school or institutional involvement is appropriate; and

  • whether additional safeguards are required.

We do not use children’s information for unrelated behavioural advertising.

21. Research and co-creation

Research, testing and co-creation form part of some iSPARX™ projects.

Where personal information is collected through interviews, research, testing, surveys or co-creation, participants should be informed about:

  • the purpose of the activity;

  • what information is being collected;

  • how it will be used;

  • whether participation is voluntary;

  • who will have access; and

  • how long identifiable information will be retained.

Where identification is unnecessary, we prefer anonymous, aggregated or de-identified research information.

22. Cookies and similar technologies

Our websites and services may use cookies, local storage or similar technologies for:

  • essential functionality;

  • authentication;

  • security;

  • preferences;

  • service performance; and

  • analytics.

We do not assume that every form of tracking is necessary simply because it is technically available.

Where non-essential tracking technologies are used, we will provide appropriate information and controls where required by applicable law.

23. Marketing communications

Where a person has subscribed to communications, we may send information about relevant iSPARX™ projects, products or services.

Recipients may unsubscribe using the mechanism provided in the communication or by contacting us.

Unsubscribing from marketing communications does not prevent us from sending necessary operational, security or contractual messages.

24. Third-party services

Our applications and experiences may integrate with external platforms, services, APIs or websites.

These organisations may independently collect or process information under their own privacy policies.

We encourage users to review the privacy practices of third-party services.

Where a third party processes information on behalf of iSPARX™, we seek appropriate privacy, security and contractual safeguards.

25. Privacy by design

Privacy should be considered before an experience is deployed.

Depending on the nature and scale of a project, our process may include:

  • privacy impact assessment;

  • data minimisation;

  • data-flow mapping;

  • consent and notification design;

  • access controls;

  • retention planning;

  • de-identification;

  • security assessment;

  • AI system assessment;

  • cross-border disclosure assessment;

  • partner governance; and

  • cultural data governance.

AR+IQ is intended to create intelligent environments without requiring unnecessary surveillance of the people using them.

26. Privacy enquiries and complaints

Questions, access requests, correction requests or privacy complaints can be directed to:

Privacy Officer
iSPARX™

Email: info@isparx.group

Website: www.isparx.group

Current company and operational contact details are published on the iSPARX™ website.

We encourage people to contact us first so that we can investigate and respond to a concern.

New Zealand

Individuals may also contact:

Office of the Privacy Commissioner
Aotearoa New Zealand
privacy.org.nz

Australia

Where Australian privacy legislation applies, individuals may also contact:

Office of the Australian Information Commissioner (OAIC)
Australia
oaic.gov.au

27. Changes to this policy

Privacy law, spatial computing and artificial intelligence continue to develop.

We may update this policy when:

  • legislation changes;

  • our products change;

  • new technologies are introduced;

  • our information practices change; or

  • new privacy risks are identified.

Material changes will be published through our website or communicated through the relevant service where appropriate.

The effective date at the beginning of this document identifies the current version.

iSPARX™

Changing the way we interact with the World

Privacy by design.
Data sovereignty by principle.
Technology with responsibility.


International privacy considerations

Footnote: In addition to the New Zealand and Australian privacy frameworks identified in this policy, iSPARX™ considers relevant privacy and data protection requirements in other jurisdictions where our users, partners, clients or services may be located. These include the European Union General Data Protection Regulation (GDPR), applicable United States federal and state privacy laws, and applicable Canadian federal and provincial privacy laws, including PIPEDA where relevant.

Consideration of these frameworks does not mean that every international privacy law applies to every iSPARX™ service or activity. The applicable requirements will depend on factors including jurisdiction, the location of individuals, the nature of the service, how personal information is collected or processed, and the role of iSPARX™ or its partners in that processing.

Where an international privacy law applies, iSPARX™ will seek to meet the relevant requirements in addition to the New Zealand and Australian standards described in this policy.