Privacy Policy

Privacy Policy

When you use MB Private Limited (“MBP”) services, you trust us with your personal information. We recognise this is a significant responsibility and are committed to protecting your information. Our obligations are set out in the Privacy Act 2020 (“the Act”).

Personal information is defined in the Act and means information about an identifiable individual.

This Privacy Policy explains how MBP collects, uses, shares, and protects your personal information. We only collect personal information that is reasonably necessary for our business activities and legal obligations, we keep it secure, and we give you rights to access and correct it. If we share information overseas, we ensure it’s protected. If there’s a serious privacy breach, we will let you and the Office of the Privacy Commissioner know.

Collection of information

MBP follows the privacy principles in the Privacy Act 2020 when collecting, using, and storing personal information: https://www.privacy.org.nz/privacy-principles/

We collect personal information from you when you enquire about, apply for or use our products or services. We may also collect personal information about you from our employees, contractors, service providers and prospective clients where required for our business. The information we collect may include your name, contact details, identification information, financial information and other information reasonably required to establish and manage our relationship with you.

If you choose not to provide information we reasonably require, we may be unable to assess an application, provide our products or services, comply with our legal obligations, or continue our relationship with you.

In certain situations, we may collect information from other sources, such as credit reporting agencies, identity verification providers, AML/CFT service providers, technology service providers acting on our behalf, mortgage advisers, employers (where relevant), lawyers, valuers, insurers, publicly available registers, regulatory authorities, referees and fraud prevention databases.

Where you provide us with personal information about another individual (for example, where you are acting as an adviser, lawyer, guarantor, trustee, director, shareholder, beneficiary, attorney, or other authorised representative), or submit an application on behalf of another person or entity, you confirm that you are authorised to provide that information to us and, where required, that the individual has been informed that their personal information may be collected, used, shared and otherwise handled by MBP in accordance with this Privacy Policy.


Use of information

We use your personal information to verify your identity, process applications, deliver services, administer and service your loan or other relationship with us, and comply with legal requirements.

We also use personal information to:

assess applications and make lending decisions;

manage and administer our products and services;

communicate with you about your application, loan, or other relationship with MBP;

detect, prevent, and investigate fraud, financial crime and other unlawful activity;

manage complaints, disputes and customer enquiries;

undertake internal reporting, quality assurance, audit, risk management and compliance activities;

improve our products, services and customer experience; and

meet our regulatory obligations.

For example, we use financial information to assess creditworthiness and manage lending relationships, identification information to verify your identity and meet our AML/CFT obligations, and contact information to communicate with you and provide service updates.

We may also use your personal information to send you information about our products and services, including electronic marketing communications where permitted by law. You may opt out of receiving marketing communications at any time.


Credit reporting

We may obtain credit reports and other credit-related information from credit reporting agencies to assess applications, verify identity, manage credit risk and comply with our legal obligations. We may obtain and disclose credit-related information with credit reporting agencies, including information about your applications, repayment history and defaults, where permitted by law.

AML/CFT

We are required by the Anti-Money Laundering and Countering Financing of Terrorism Act 2009 to collect, verify and retain customer due diligence information. We may also undertake sanctions, politically exposed person (PEP) and other compliance screening.

Data sharing practices

MBP may share personal information with our related entities, technology service providers, service providers, professional advisers, valuers, insurers, credit reporting agencies, identity verification providers, debt collection and recovery agencies (where required), funders, warehouse lenders, trustees, security trustees, investors, auditors, regulatory authorities, and other parties involved in providing, funding, administering or enforcing our products and services.

We may also share your personal information with our related entities, assignees, transferees and other third parties in relation to our products and financing arrangements, including The New Zealand Guardian Trust Company Limited (https://guardiantrust.co.nz), Trustees Executors Limited (https://www.trustees.co.nz) and their related entities.

This may include parties involved in loan funding, participation, assignment, securitisation or other financing arrangements.

When using overseas service providers, MBP will only disclose personal information overseas where permitted under the Act. This may include overseas-based cloud hosting providers and technology service providers who assist us in operating our business and protecting your information.

MBP may share personal information if we sell or assign any of our assets or parts of our business, where you have allowed us to or where we are permitted to do so under the Act.

Where we engage third-party service providers to process personal information on our behalf, we require them to maintain appropriate privacy, confidentiality and security safeguards and only to use the information for the services they provide to us.

Data retention

MBP retains personal information only for as long as necessary to fulfil the purposes for which it was collected, or as required by law. Retention periods are determined based on legal obligations, business needs, and the type of information. For example, residential mortgage application records are retained for a minimum of seven (7) years after the end of the client relationship in accordance with financial services legislation. When personal information is no longer required, it is securely destroyed or permanently de-identified.

Data security measures

MBP implements reasonable technical and organisational measures to protect personal information against loss, unauthorised access, use, modification, disclosure and other misuse. These measures include encryption, access controls, monitoring, regular security audits and secure information disposal processes.

We also ensure data security when working remotely and when using third-party service providers. Where third-party service providers process personal information on our behalf, we require them to implement appropriate privacy, confidentiality and security safeguards.

Only authorised staff have access to personal information on a need-to-know basis.

Client rights and procedures

You have the right to request access to, and correction of, your personal information. You may also request deletion where appropriate, although MBP may be required to retain information to meet legal or regulatory obligations. Requests can be made via mail, phone, or email to our Privacy Officer. If we decline a request to correct personal information, you may ask us to attach a statement of correction. We will acknowledge and respond to requests within the timeframes required by the Act (generally within 20 working days). The contact details for our Privacy Officer are:

Attn: Privacy OfficerPO Box 317, Christchurch 8140

Phone: +64 3 928 1440

Email: admin@mbprivate.nz

If you ask us to delete your personal information, we will consider your request in accordance with applicable legal and regulatory obligations. Where we are required to retain information for statutory, contractual, or operational reasons (e.g., under financial services or anti-money laundering legislation), deletion may not be possible.

Privacy breaches

Privacy breaches can occur in any business that holds personal information. Our breach notification process works as follows:

Contain: Immediately contain the breach and investigate its cause.

Assess: Evaluate the risks associated with the breach.

Notify: If there is a notifiable privacy breach, we will notify affected individuals and the Office of the Privacy Commissioner where required by law.

Prevent: Implement measures to prevent future breaches.

MBP must report any notifiable privacy breaches to the Office of the Privacy Commissioner. A notifiable privacy breach is one that poses a risk of serious harm (e.g., leaked personal information is published online or used to facilitate identity theft). Where a notifiable privacy breach occurs that affects your personal information, we will notify you where required by law.

If you have a complaint

If you have a complaint or concerns about your personal information, please let us know by calling us on +64 3 928 1440 or contacting our Privacy Officer (using the contact details above).

We will acknowledge your complaint, investigate the matter and endeavour to resolve it promptly and fairly in accordance with the Act. We may contact you if we require further information to assist with our investigation. We encourage you to raise any privacy concerns with us first so that we have an opportunity to investigate and resolve them.

If you are not satisfied with the outcome, you may refer your privacy-related complaint to the Office of the Privacy Commissioner:

https://www.privacy.org.nz/your-rights/making-a-complaint-to-the-privacy-commissioner/

Cookies and marketing

Our website may use cookies and analytics technologies to improve functionality, enhance security, remember your preferences, and understand how our website is used so that we can improve our products, services and website experience.

Cookies are small text files that are stored on your device when you visit our website. Most web browsers automatically accept cookies; however, you can manage or disable cookies through your browser settings. Please note that disabling cookies may affect the functionality of parts of our website.

Where permitted by law, we may send you information about our products and services. You may opt out of receiving marketing communications at any time by using the unsubscribe facility included in our electronic communications or by contacting us using the details set out above.

Changes to this policy

We reserve the right to change, amend or modify this Privacy Policy at any time. If there are material changes to our information use and collection practices, we will apply this to information collected on a going forward basis, and we will update this Privacy Policy. The updated version will be posted on our website and will be effective from the day it is posted.

This policy is current as at 21 July 2026.

Discover how we can help you and your clients grow and protect wealth. Talk to us today.