← Back to Medifest

Privacy Notice

Simranjit Singh Bhinder — last updated 2026

1. Who we are

Simranjit Singh Bhinder, trading as Medifest, is the data controller for the personal data described in this notice. We decide why and how your data is processed when you use medifest.co.nz and the Medifest app.

2. What we collect and why

  • Account data (name or display name, email, login credentials): to create and secure your account. Legal basis: performance of our contract with you.
  • Wellbeing content you create (session history, favourites, presets, mood check-ins, gratitude and journal entries, manifestations, reminders): to provide the Service and sync it across your devices. Legal basis: contract performance.
  • Community data (profile visibility choices, friend connections, direct messages, shared sessions): to run the social features you opt into. Legal basis: contract performance.
  • Usage and device data (pages viewed, feature usage, device type, browser, IP address, error logs): to keep the Service secure, diagnose faults and improve the product. Legal basis: our legitimate interests in security and product improvement.
  • Support messages: to answer your questions. Legal basis: legitimate interests / contract performance.
  • Marketing emails, where you opt in: legal basis is your consent, withdrawable at any time.

Card and billing details are collected and processed by Paddle, not by us — we never see or store your full payment details.

3. Who we share data with

  • Service providers / subprocessors: hosting, database and authentication, email delivery, error monitoring and analytics providers acting on our instructions.
  • Paddle.com, our Merchant of Record, for the sale of memberships, subscription management, payments, invoicing and tax compliance.
  • AI providers where you use assistant or generated-content features, limited to the prompt content needed to produce a response.
  • Professional advisers (legal, accounting) and authorities where required by law.

We do not sell your personal data.

4. International transfers

Our providers may process data outside New Zealand, including in Australia, the United States and the EEA. Where required, transfers are protected by appropriate safeguards such as standard contractual clauses or adequacy decisions.

5. Retention

We keep account and content data for as long as your account is active. If you delete your account we delete or anonymise your personal data within 90 days, except records we must keep for legal, tax or fraud prevention purposes (typically up to 7 years for transaction records).

6. Your rights

Under the New Zealand Privacy Act 2020 you have the right to access and correct your personal information. If the UK or EU GDPR applies to you, you also have rights to erasure, restriction, portability, objection, and to withdraw consent, plus the right to complain to your supervisory authority (in New Zealand, the Office of the Privacy Commissioner). We respond to requests within one month. Most data can be viewed, edited or deleted directly in the app.

7. Security

We use appropriate technical and organisational measures including encryption in transit, encrypted storage, row-level access controls, least-privilege service credentials and audit logging. No system is perfectly secure, but we take protecting your practice seriously.

8. Cookies and local storage

We use essential cookies and browser storage to keep you signed in and to remember preferences such as your chosen soundscape and volume. Any analytics storage is used only to understand aggregate feature usage. You can clear or block storage in your browser settings, though sign-in will not work without essential cookies. We do not use advertising cookies.

9. Contact

Simranjit Singh Bhinder, Auckland, New Zealand. For privacy requests, email Support@medifest.co.nz. See also our Terms & Conditions and Refund Policy.