Privacy Policy
Kizmazz Pty Ltd
Last updated: 18 August 2026
Kizmazz Pty Ltd respects your privacy and is committed to protecting the personal information entrusted to us.
This Privacy Policy explains how we collect, hold, use and disclose personal information in connection with services provided to customers in New Zealand, how we protect that information, and how you may request access to or correction of your information or make a privacy complaint.
This policy applies to Kizmazz Pty Ltd and the businesses and trading names through which we provide services to New Zealand customers, including Fiji Island Holidays, Fiji Bride and Forever Fiji, where applicable, together with our websites and associated travel services.
In this Privacy Policy, Kizmazz, we, us or our means Kizmazz Pty Ltd.
In providing services to people in New Zealand, we handle personal information in accordance with the Privacy Act 2020, the Information Privacy Principles and other applicable New Zealand laws.
Kizmazz Pty Ltd is an Australian company. Some of our business administration and information systems are therefore operated from or located in Australia.
Because we arrange international travel, providing our services will also commonly require information to be provided to travel suppliers outside New Zealand, particularly in Fiji.
Depending on your dealings with us, the personal information we may collect includes:
- your name and title;
- residential or postal address;
- telephone number and email address;
- date of birth and age where required for travel arrangements;
- passport details, nationality and other identification information where required;
- details of other people travelling with you;
- departure point, travel dates and destination;
- flight, accommodation, transfer, cruise, tour, wedding, activity and other travel arrangements;
- frequent flyer or loyalty details where you choose to provide them;
- travel preferences and special requests;
- booking history;
- quotations, itineraries and booking documentation;
- correspondence and communications with us;
- transaction and payment records, excluding retained credit or debit card details;
- refunds, cancellations, credits, disputes and claims;
- emergency contact information;
- information supplied through enquiry forms, competitions, promotions or surveys;
- information supplied by a travel agent, family member, group organiser or another person arranging travel on your behalf; and
- technical information associated with the use of our websites and electronic communications, such as IP address, browser and device information, cookies and website activity.
We seek to collect personal information only for lawful purposes connected with our business and where the collection is necessary for that purpose or otherwise permitted by law.
Travel arrangements may sometimes require us to collect information relating to:
- health or medical requirements;
- disability or accessibility requirements;
- allergies;
- dietary requirements;
- mobility or assistance requirements; or
- other matters necessary to safely or appropriately arrange the travel services requested.
We seek to collect only information reasonably required to arrange the relevant travel services or assistance.
You do not need to provide information that is not relevant to your travel arrangements.
We generally collect personal information directly from you when you:
- make a travel enquiry;
- request a quotation;
- make a booking;
- amend or manage an existing booking;
- communicate with us by telephone, email, website enquiry form or other electronic means;
- make a payment;
- subscribe to marketing communications;
- enter a competition or promotion;
- provide feedback;
- make a complaint; or
- otherwise deal with us.
When collecting information directly from you, we will provide the information required by New Zealand privacy law where applicable.
Travel arrangements frequently involve information being supplied to us by someone other than the person the information relates to.
We may receive your personal information from:
- a spouse or partner;
- a parent or guardian;
- another passenger;
- a family member;
- a group organiser;
- a travel agent or representative acting for you;
- your employer or organisation where relevant;
- airlines;
- hotels and resorts;
- tour, transfer and activity providers;
- cruise operators;
- destination management companies;
- travel wholesalers;
- payment providers;
- insurers or assistance providers;
- technology and booking providers; and
- other sources where collection is authorised or permitted by law.
Where Information Privacy Principle 3A requires us to notify you that we have collected your personal information from another source, we will take reasonable steps to provide the information required by the Privacy Act 2020 unless an applicable exception applies.
If you provide us with personal information about another person, you should ensure that you are authorised to do so and, where appropriate, make that person aware that their information has been supplied to us.
We may collect, hold and use personal information to:
- respond to enquiries;
- prepare quotations, proposals and itineraries;
- recommend travel products and services;
- make and administer bookings;
- amend or cancel bookings;
- communicate with travel suppliers;
- arrange flights, accommodation, transfers, tours, cruises, activities, weddings and other travel services;
- issue booking confirmations and travel documentation;
- arrange requested special requirements;
- process payments, refunds and credits;
- communicate important information concerning your travel;
- provide assistance before, during or after travel;
- manage travel disruptions;
- administer cancellations, complaints, disputes and claims;
- help prevent fraud and unauthorised transactions;
- maintain booking, financial and compliance records;
- administer our business;
- undertake reporting, auditing, training and quality assurance;
- improve our services, systems and websites;
- communicate with you about products and offers where permitted by law;
- comply with legal, taxation, accounting and regulatory requirements; and
- protect our rights and the rights, safety and interests of our customers, staff and suppliers.
We will only use personal information for the purpose for which it was obtained or for another purpose permitted under the Privacy Act 2020 or other applicable law.
Travel arrangements frequently involve more than one passenger.
A person making an enquiry or booking may provide us with personal information about family members, children, travelling companions or other members of a group.
Where you are the primary contact for a booking, we may communicate with you about arrangements affecting the passengers included in that booking.
We may also communicate with another passenger, parent or guardian, group organiser, authorised representative or travel agent where reasonably necessary to administer the booking.
We take reasonable steps to avoid disclosing information unrelated to the booking or information we have reason to believe should not be disclosed to another passenger or booking contact.
Many family travel bookings include children.
Information about children may be provided to us by a parent, guardian or another person authorised to arrange their travel.
We only seek information about children that is reasonably required for their travel arrangements, which may include:
- name;
- date of birth or age;
- passport information where required;
- dietary requirements;
- medical or accessibility requirements; and
- other information relevant to the services being arranged.
We may disclose personal information where permitted by law and reasonably necessary to provide, administer or support the travel arrangements requested, including to:
- airlines;
- hotels and resorts;
- transfer and transport operators;
- cruise operators;
- tour and activity providers;
- wedding and event suppliers;
- travel wholesalers;
- destination management companies;
- travel agents and authorised representatives;
- insurance and assistance providers where applicable;
- payment processors and financial service providers;
- booking and reservation technology providers;
- information technology, cloud, hosting, communications and cybersecurity providers;
- professional advisers including accountants, auditors and lawyers;
- contractors and service providers assisting with our business operations;
- government, immigration, customs, border, security, regulatory and law-enforcement authorities where required or authorised by law; and
- another entity involved in a genuine sale, restructure or transfer of all or part of our business, subject to applicable legal requirements.
We do not sell personal information to advertisers or data brokers.
Our services inherently involve international travel and overseas service providers.
Personal information may therefore be disclosed outside New Zealand, particularly to recipients in:
- Australia;
- Fiji;
- countries through which you travel;
- countries in which your airline, accommodation or other travel provider operates; and
- other countries relevant to the particular services you ask us to arrange.
Kizmazz Pty Ltd operates from Australia and some business administration and technology used to provide services to New Zealand customers may be operated from or located in Australia.
Where you book travel in Fiji, relevant passenger information may need to be provided to airlines, hotels, resorts, transfer operators, cruise operators, tour providers, wedding suppliers and other businesses in Fiji.
We handle overseas disclosures in accordance with the Privacy Act 2020, including Information Privacy Principle 12 where applicable.
Depending on the circumstances and the legal basis for disclosure, this may include ensuring appropriate privacy safeguards apply to the overseas recipient, using contractual protections, obtaining express authorisation where appropriate, or relying on another basis permitted by New Zealand privacy law.
Information stored or processed by a service provider acting on our behalf may be treated differently from a disclosure to an overseas third party depending on the circumstances and applicable law.
Payments may be processed through authorised third-party payment service providers.
Kizmazz Pty Ltd does not store or retain customers’ credit or debit card details.
Where you enter card details into a third-party payment platform, those card details are collected and processed by the payment service provider under its own security and privacy arrangements.
We may retain transaction information necessary for our accounting and booking records, such as the amount paid, payment date, transaction reference and payment status. This does not include retaining your full credit or debit card details.
Payment card information is handled through payment processes designed to operate in accordance with applicable payment card security requirements, including the Payment Card Industry Data Security Standard (PCI DSS), where applicable.
You should not send credit or debit card details to us by email or through other unsecured communication methods.
Our websites may use cookies and similar technologies to enable website functionality, remember preferences, understand website usage, measure traffic and performance, improve our websites and services, measure advertising and marketing performance, provide relevant advertising or content and identify technical or security issues.
Information collected through these technologies may include IP address, browser type, device type, referring website, pages viewed, time spent on pages and approximate location information.
You can generally control or disable cookies through your browser or device settings, although doing so may affect some website functionality.
For more information, please see our Cookies Policy.
Where permitted by law, we may use personal information to send information about travel products, destinations, special offers and services that may be of interest to you.
Marketing communications may be sent by email, SMS, telephone, post or other permitted electronic means.
You may opt out at any time by using the unsubscribe facility contained in an electronic communication or by contacting us.
Opting out of marketing will not prevent us from sending communications reasonably necessary to respond to an enquiry or administer an existing quotation or booking.
You are not required to subscribe to marketing communications in order to receive our travel services.
We may use technology, including artificial intelligence-assisted systems, to support business activities such as travel research, quotation preparation, document preparation, administration, information analysis, quality assurance, customer service support, internal business processes and improving the efficiency and consistency of our services.
The use of such technology does not remove our responsibility for complying with our obligations under the Privacy Act 2020.
Where personal information is handled using technology-assisted systems, it remains subject to our privacy, security and confidentiality requirements.
We take reasonable safeguards to protect personal information from:
- loss;
- unauthorised access;
- unauthorised use;
- unauthorised modification;
- unauthorised disclosure; and
- other misuse.
Information may be held electronically or, where appropriate, in physical records.
Our information systems may include cloud-based services and systems operated by contracted technology providers.
Depending on the circumstances, safeguards may include user access controls, authentication requirements, staff access restrictions, system and security monitoring, cybersecurity protections, staff policies and procedures, secure cloud and information technology services and contractual arrangements with relevant service providers.
No electronic system or method of transmission can be guaranteed to be completely secure.
We maintain processes for identifying, assessing, managing and responding to suspected privacy and information security incidents.
Where a privacy breach has caused or is likely to cause serious harm and notification is required under the Privacy Act 2020, we will notify the Office of the Privacy Commissioner and affected individuals as required by law.
We may also take steps to contain, investigate and remediate an incident and reduce the risk of further harm.
We retain personal information only for as long as we have a lawful purpose for retaining it, including:
- providing and administering travel services;
- maintaining booking and business records;
- financial and taxation requirements;
- legal and regulatory requirements;
- responding to disputes, complaints and claims; and
- other legitimate business purposes.
Some information may therefore be retained after your travel has been completed.
When information is no longer required for a lawful purpose, we will take reasonable steps concerning its secure disposal or anonymisation as appropriate.
Credit and debit card details are not retained by Kizmazz.
You have the right to request access to personal information about you that we hold, subject to the Privacy Act 2020.
We may need to verify your identity before releasing information.
We will respond within the timeframes and in the manner required by New Zealand privacy law.
There may be circumstances in which the Privacy Act permits us to withhold some information. Where applicable, we will explain our decision and the rights available to you.
You may request correction of personal information we hold about you if you believe it is incorrect.
If we do not make the correction requested, you may have the right to provide a statement of the correction sought to be attached to the information.
We encourage you to tell us promptly if your contact information, passport details or other information relevant to an existing booking changes.
If you believe we have not handled your personal information appropriately, please contact our Privacy Officer.
Please provide sufficient information to enable us to understand and investigate your concern.
We will investigate privacy complaints and respond as soon as reasonably practicable.
We would appreciate the opportunity to resolve your concern directly.
If you are not satisfied with our response, you may make a complaint to the Office of the Privacy Commissioner of New Zealand.
For privacy enquiries, requests for access or correction, or privacy complaints relating to our New Zealand services, please contact:
Privacy Officer
Kizmazz Pty Ltd
Email:
privacyofficer@fijiislands.com.au
New Zealand telephone:
0800 485 632
We may update this Privacy Policy from time to time to reflect changes in our business, services, technology, privacy and security practices or applicable legal requirements.
The current version will be published on our website and will display the date on which it was last updated.
