Privacy
Last reviewed August 2026.
You can read almost all of this website without telling us anything. We collect personal information in four situations, and nowhere else.
The contact form asks for your first and last name, your email address, an optional phone number, what your message is about, and the message itself. We also store a one-way hash of your IP address and your browser’s user-agent string, purely so we can stop somebody flooding the form; the address itself is never written down.
Your name, email address and a password you choose. Booking requires a verified account because the Trust has to know who attended a session it is funded to deliver.
This is where the health information sits, and every field of it is optional. It may include your preferred name, phone number, date of birth, gender, ethnicity, your type of diabetes, the year you were diagnosed, your general practice, and your National Health Index (NHI) number. You can book a course without filling in any of it.
Which session, how many places, who is coming with you, and anything you tell us about food or access needs so the room is set up properly. After the session we record whether you attended.
We do not use analytics, advertising or tracking cookies of any kind. There is no Google Analytics on this site and no third party is watching you read it.
To answer you, to run the course, and to account for the funding that makes the course free.
The MHT Diabetes Trust is contracted by Health New Zealand – Te Whatu Ora (MidCentral) to deliver diabetes education. Under that contract we report on who we are reaching: how many people attended, in which district, with which type of diabetes, and the ethnicity mix of the group. That reporting is what keeps the service funded and free, and it is why the profile asks what it asks.
What goes to Health New Zealand is counts, not people. We report aggregate demographics — numbers in a table — not names, not email addresses, not NHI numbers, and not anything that identifies you individually.
Your NHI is collected because it is how the health system identifies a person without using their name, and it lets us match our records to a referral if your general practice or hospital team sends you to us. If you would rather not give it, do not — nothing on this site requires it.
Trust staff, and only the ones who need to. Our administrators and the nurse or dietitian teaching your session can see your booking and anything you told us about food or access. Health information in your profile is visible to Trust staff and is never shown to other members, whatever your profile visibility setting says.
We use a small number of suppliers to run the website itself:
Videos on this site do not load from YouTube until you press play, so YouTube receives nothing about you unless you choose to watch one.
We do not sell your information, we do not swap mailing lists, and we will not give your details to anyone else unless you ask us to or the law requires it.
Under the Privacy Act 2020 you can ask to see the personal information we hold about you, and ask us to correct it if it is wrong. You do not need a reason and it does not cost anything.
Email admin@diabetestrust.org.nz or phone 06 357 5992 and say what you would like. We will reply within 20 working days, which is the limit the Act sets.
You can also ask us to delete what we hold. We will do that, with one honest exception: where we are contractually required to keep an attendance record, we will remove everything identifying from it rather than the count itself.
Much of it you can do yourself — signing in and going to your profile lets you see and change everything we hold about you, including removing your NHI or your ethnicity at any time.
If you are not happy with how we have handled your information, you are entitled to complain to the Office of the Privacy Commissioner at privacy.org.nz (opens in a new tab). We would rather you told us first so we can put it right.
Passwords are hashed, never stored in a form anybody can read. The whole site is served over HTTPS. Accounts that can see member information belong to named Trust staff, can have two-factor authentication turned on, and administrative changes are written to an audit log.
No system is perfect. If something does go wrong in a way that could cause you serious harm, we will tell you and the Privacy Commissioner, as the Act requires.
Ask us. Nobody has ever offended us by asking what happens to their information, and we would much rather answer than have you leave a field blank because you were not sure.
Send us a message or phone 06 357 5992.