Privacy

Privacy Policy

KEY2 Real Estate Limited – Privacy Policy

Last updated: August 2026

KEY2 Real Estate Limited (KEY2, we, our, us) recognises the importance of protecting your privacy and personal information.

This Privacy Policy explains how we collect, use, disclose, store and protect personal information in accordance with the Privacy Act 2020, including when we collect information directly from you and when we obtain information about you from other people or organisations.

It also explains how we collect and use personal information to meet our obligations under the Anti-Money Laundering and Countering Financing of Terrorism Act 2009 (AML/CFT Act).

1. What is personal information?

Personal information is information about an identifiable individual.

Depending on your relationship with KEY2, this may include information such as your name, contact details, address, date of birth, identification information, property or transaction information and other information that identifies you or can reasonably be linked to you.

2. What personal information do we collect?

The information we collect depends on your dealings with KEY2 and the services we provide to you.

We may collect:

  • your full name;
  • residential, mailing or other relevant addresses;
  • email address and telephone number;
  • date of birth;
  • occupation, profession or employment information;
  • information about properties you own, wish to purchase, sell or otherwise enquire about;
  • information relating to a property transaction or prospective transaction;
  • financial or transaction-related information where required to provide our services;
  • records of correspondence and communications with us;
  • information you provide through our website, enquiry forms, surveys, promotions or other communications;
  • marketing preferences;
  • website and digital interaction information;
  • identification and verification information required for AML/CFT compliance; and
  • other information reasonably necessary for us to provide our services or meet our legal obligations.

Where AML/CFT requirements apply, we may need to collect additional information as described in the AML/CFT section below.

3. How do we collect your personal information?

Where practicable, we collect personal information directly from you.

This may occur when you:

  • contact or enquire with us;
  • use our website;
  • enquire about a property, house and land package or other service;
  • engage KEY2 to provide real estate or related services;
  • communicate with us by telephone, email, online form or in person;
  • provide documents or information to us;
  • attend an open home or other property-related appointment;
  • enter a competition or promotion;
  • subscribe to marketing or property updates;
  • complete a survey or provide feedback; or
  • undertake customer due diligence or other verification procedures.

We may also collect information about you from other people and organisations where permitted or required by law.

Depending on the circumstances, these may include:

  • your authorised representatives;
  • lawyers, conveyancers, accountants, mortgage advisers, banks and other professionals involved in a transaction;
  • property owners, purchasers, vendors and other people involved in a property transaction;
  • publicly available sources and registers;
  • government agencies and authorities;
  • property and land information sources;
  • credit reporting or electronic verification sources where appropriate;
  • identity verification providers; and
  • AMLHUB Ltd and its approved service providers where AML/CFT checks are required.

Further information about indirect collection for AML/CFT purposes is provided below.

4. Why do we collect and use personal information?

We may collect, hold and use personal information to:

  • provide our real estate and related services;
  • respond to property and service enquiries;
  • communicate with you about properties, listings, developments, house and land packages and services;
  • assist with property transactions;
  • establish and manage our relationship with you;
  • verify your identity and authority to act;
  • maintain and update our records;
  • improve our website, services and customer experience;
  • administer competitions, promotions and surveys;
  • manage complaints and enquiries;
  • undertake business administration and operational activities;
  • send marketing communications where permitted;
  • protect against fraud and unlawful activity;
  • meet AML/CFT requirements;
  • meet our record-keeping, reporting and regulatory obligations; and
  • comply with applicable laws, regulations, court orders and lawful requests from regulators or government authorities.

We will not sell your personal information.

5. Anti-Money Laundering and Countering Financing of Terrorism

KEY2 is required to comply with New Zealand anti-money laundering and countering financing of terrorism laws, including the Anti-Money Laundering and Countering Financing of Terrorism Act 2009 and related regulations.

To meet these obligations, we need to collect and verify information about our customers and, where relevant, other people connected with a customer or transaction.

This may include:

  • beneficial owners;
  • directors and shareholders;
  • partners;
  • trustees, settlors, protectors and beneficiaries;
  • attorneys and authorised representatives;
  • people acting on behalf of customers; and
  • other individuals whose identity, ownership, control, authority, source of funds, source of wealth or relationship to a transaction needs to be checked.

The AML/CFT provisions of this Privacy Policy apply to those individuals as well as our direct customers.

6. Information we may collect for AML/CFT purposes

Depending on the customer, transaction and level of risk, AML/CFT information may include:

Identity and contact information

  • full name;
  • date of birth;
  • residential, registered office or other relevant address;
  • telephone number and email address;
  • nationality, citizenship, residency or tax residency information where relevant;
  • relationship to a customer or transaction; and
  • role, authority, ownership, control or beneficial ownership information.

Identity documents and verification information

We may collect copies or details of:

  • passports;
  • driver licences;
  • birth certificates;
  • certificates of incorporation;
  • trust deeds;
  • company records;
  • authority documents; and
  • other identification or verification documents.

This may include document numbers, issuing authorities, issue and expiry dates and records showing how your identity or authority was verified.

Electronic identity verification and biometric information

Where electronic identity verification is used, you may be asked to provide a live selfie, video or similar liveness check so that your identity can be matched to your identification document and to help prevent impersonation or fraud.

This may involve the collection and processing of facial images, liveness results, facial matching results and associated verification information by an identity verification provider.

If you cannot or do not wish to complete a liveness or facial matching check, please contact us to discuss whether an alternative verification method is available.

Screening and risk information

We may collect or generate information concerning:

  • politically exposed person (PEP) status;
  • sanctions and watchlist screening;
  • adverse media screening;
  • geographic and country risk;
  • transaction risk;
  • customer and service risk; and
  • other factors relevant to our AML/CFT risk assessment.

Source of funds and source of wealth

Where required, we may request information or documents explaining the source of funds and/or source of wealth.

This may include:

  • bank statements;
  • sale and purchase agreements;
  • loan or mortgage documentation;
  • inheritance documents;
  • trust, company or partnership records;
  • payslips or employment records;
  • accounting, tax or financial statements;
  • gift declarations;
  • evidence relating to savings, investments, business income or asset sales; and
  • other information reasonably required to establish the source of funds or wealth.

Transaction and relationship information

We may also collect:

  • information about the nature and purpose of a business relationship or transaction;
  • property, transaction and settlement information;
  • information about related parties; and
  • records of AML/CFT checks, communications, assessments, decisions and reviews.

7. Where we obtain AML/CFT information

We may collect AML/CFT information directly from you when you engage with us or provide information or documents as part of customer due diligence.

We may also collect information indirectly from other people, organisations and sources.

These may include:

  • the customer or prospective customer and their representatives;
  • beneficial owners, directors, shareholders, partners, trustees, settlors, beneficiaries, attorneys and authorised representatives;
  • lawyers, conveyancers, accountants, mortgage advisers, banks, financial institutions and other professional advisers involved in a transaction;
  • the New Zealand Companies Office;
  • the New Zealand Business Number (NZBN) register;
  • LINZ and property information sources;
  • other relevant public registers;
  • identity and electronic verification providers;
  • address verification providers;
  • credit reporting and electronic verification sources where used for identity or address verification;
  • sanctions, PEP, watchlist and adverse media screening providers;
  • government-issued identity document verification sources;
  • publicly available websites, media and public records; and
  • AMLHUB Ltd and its approved sub-processors, acting on our behalf.

We collect information from these sources because AML/CFT checks can require us to verify information independently and to obtain information about people other than the direct customer.

If we cannot collect or verify information required under the AML/CFT Act, we may not be able to act for you, continue acting for you or proceed with a transaction or service.

8. AMLHUB and AML/CFT service providers

KEY2 uses AMLHUB Ltd to assist us with the collection, verification, screening, management, record-keeping and storage of AML/CFT information.

AMLHUB acts on KEY2's behalf and may use approved sub-processors to provide parts of its AML/CFT services, including:

  • identity verification;
  • biometric and liveness checks;
  • address verification;
  • sanctions, PEP, watchlist and adverse media screening;
  • hosting and storage;
  • security;
  • technical support; and
  • system monitoring.

Information about AMLHUB's current sub-processors is available through AMLHUB's website.

AMLHUB is our AML services provider and is not KEY2's privacy contact. Questions or requests concerning personal information held for KEY2 should be directed to KEY2 using the contact details at the end of this policy.

9. Overseas storage and processing of AML/CFT information

AML/CFT information processed through AMLHUB is stored in Australia.

Some AMLHUB service providers or sub-processors may process or access information from other countries, including the United States and European Union.

Where personal information is stored, processed or accessed outside New Zealand, appropriate steps will be taken in accordance with applicable New Zealand privacy requirements to protect that information.

10. Who may we disclose personal information to?

Where reasonably necessary for the purposes described in this policy, we may disclose personal information to:

  • our employees and contractors;
  • professional advisers including lawyers, accountants and consultants;
  • IT, website, hosting, database, communications and other technology providers;
  • marketing and communications service providers;
  • parties involved in a property transaction;
  • service providers assisting us to deliver our services;
  • AMLHUB Ltd;
  • identity verification and AML/CFT screening providers;
  • auditors and insurers;
  • regulators, supervisors, courts, government agencies, law enforcement bodies and other authorities where required or permitted by law; and
  • another organisation or person where you have authorised us to disclose the information.

AML/CFT information may also be shared with identity verification, biometric/liveness, address verification, PEP, sanctions, watchlist and adverse media screening providers where reasonably necessary to complete the required checks.

We do not sell AML/CFT information or use information collected specifically for AML/CFT compliance for unrelated marketing purposes.

11. If you provide information about another person

If you give KEY2 personal information about another person, you should take reasonable steps to ensure that person knows their information has been provided to us and is aware of this Privacy Policy.

This is particularly important where you provide information about:

  • beneficial owners;
  • directors or shareholders;
  • trustees, settlors or beneficiaries;
  • attorneys;
  • authorised representatives;
  • people acting on behalf of a customer; or
  • other people connected with a property transaction.

You should provide that person with a copy of this Privacy Policy or direct them to the Privacy Policy on the KEY2 website.

You must also ensure you have authority to provide their information where authority is required.

If you cannot make the other person aware of this Privacy Policy, please tell us.

12. What happens if you don't provide information?

You are not always required to provide personal information to us.

However, if we cannot collect information reasonably required to provide a service or comply with our legal obligations, we may be unable to:

  • respond fully to an enquiry;
  • provide some or all of our services;
  • act for you;
  • complete required identity or AML/CFT checks;
  • continue acting for you;
  • proceed with a transaction; or
  • complete other requested services.

In some circumstances, we may also be required or permitted to take other steps under applicable law.

13. Direct marketing

Where permitted by law, we may use your contact information to send you information about properties, developments, house and land opportunities, services, news or other information that we think may be relevant to you.

Marketing communications may be sent by email, telephone, SMS or other electronic means.

You may opt out of receiving marketing communications at any time by using the unsubscribe facility included in the communication or by contacting us.

Information collected specifically for AML/CFT purposes is not used for unrelated marketing.

14. Website, cookies and analytics

When you use our website, we may collect information about your use of the site, including:

  • IP address;
  • browser and device information;
  • pages viewed;
  • referring websites or sources;
  • dates and times of visits; and
  • interactions with our website.

Our website may use cookies and similar technologies to operate the website, understand how visitors use it, measure website and marketing performance and improve our services.

Some cookies may be provided by third-party analytics, advertising or technology services.

You can control or disable cookies through your browser settings, although doing so may affect some website functionality.

15. Security

We take reasonable steps to protect personal information against loss, misuse, unauthorised access, disclosure, alteration and destruction.

Depending on the information and systems involved, these measures may include access controls, secure systems, encryption, audit logs, contractual protections, staff procedures and controls over service providers.

While we take reasonable security precautions, information transmitted over the internet cannot be guaranteed to be completely secure.

16. How long do we keep personal information?

We retain personal information only for as long as reasonably required for the purposes for which it was collected and to meet applicable legal, regulatory, contractual, audit, insurance and business record requirements.

For AML/CFT purposes, identity and verification records generally need to be retained for at least five years after the end of the relevant business relationship or completion of the relevant occasional transaction or activity.

We may retain information for longer where required or permitted by law or where reasonably necessary for legal, regulatory, audit, dispute, insurance or compliance purposes.

When information is no longer required, we will take reasonable steps to securely delete, destroy or anonymise it where appropriate.

17. Accessing and correcting your personal information

Under the Privacy Act 2020, you have the right to ask for access to personal information we hold about you and to request correction if you believe it is inaccurate.

To request access to or correction of your information, please contact us using the details below.

There may be circumstances where the law allows or requires us to withhold information or limits what we are permitted to disclose about certain compliance matters. We will respond to requests in accordance with the Privacy Act 2020 and other applicable laws.

18. Privacy breaches

If we become aware of a privacy breach, we will assess and respond to it in accordance with our obligations under the Privacy Act 2020.

Where a privacy breach has caused or is likely to cause serious harm, we will notify the Office of the Privacy Commissioner and affected individuals where required by law.

19. Links to other websites

Our website may contain links to websites operated by third parties.

Those websites have their own privacy practices and policies. KEY2 is not responsible for the privacy practices, security or content of third-party websites.

We encourage you to review the privacy policy of any third-party website you visit.

20. Questions, access requests and privacy complaints

If you have a question about this Privacy Policy, wish to request access to or correction of personal information, or have a concern or complaint about how we have handled your personal information, please contact:

Russell Benshaw
Managing Director
KEY2 Real Estate Limited

Post:
PO Box 305 323
Triton Plaza
Albany 0632
New Zealand

Email: russell@key2.co.nz

We will treat privacy enquiries and complaints appropriately and will endeavour to respond within a reasonable timeframe.

If you are not satisfied with our response to a privacy concern, you may also make a complaint to the New Zealand Office of the Privacy Commissioner.

21. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes to our practices, technology, service providers or legal obligations.

The current version will be published on the KEY2 website and will show the date it was last updated.