Think Blue Tree · Your information matters

Privacy Policy

Effective date: 18 September 2026

This policy explains what personal information Think Blue Tree collects, why we collect it, how we use and protect it, and the choices and rights available to you. It covers our website, coaching, workplace services, workshops and digital tools.

Think Blue Tree is the trading name of Think Blue Tree Limited, a New Zealand company. The Privacy Officer is Patrick Timm.

Our approach in brief. Personal information shared in coaching is treated as confidential, subject to the limits explained below. If your employer funds your sessions, funding does not give your employer automatic access to your session discussions or notes. We may, however, share limited booking or attendance information under the funding arrangement where properly disclosed and authorised.
01 · Overview

Who we are and what this policy covers

Think Blue Tree Limited (trading as Think Blue Tree, referred to as “we”, “us” and “our”) provides mental health coaching, couples coaching, workplace-funded individual wellbeing support, workplace training, workshops and related digital resources. Services may be delivered in person or online.

This policy applies when you visit thinkbluetree.com, use our related tools and applications (including tbt-app.com), make an enquiry, book or attend a session, participate in training or workshops, subscribe to communications or otherwise interact with us. A separate consent form, workplace agreement or service-specific notice may provide more detailed information for a particular service. We read those documents together with this policy.

We handle personal information under applicable New Zealand privacy law, including the Privacy Act 2020 and, where applicable to the information and services concerned, the Health Information Privacy Code 2020. Additional obligations may apply when we serve people in other jurisdictions.

02 · Collection

Information we collect

What we collect depends on how you interact with Think Blue Tree. It can include:

  • Identity and contact: names, date of birth, email address, phone number, location, emergency contact details and, where relevant, parent or guardian and referring person details.
  • Enquiries and bookings: messages, appointment types and times, booking history, cancellations, attendance, preferences and correspondence.
  • Coaching information: intake and consent responses; your goals and concerns; mental wellbeing and personal history; information about health, diagnoses, medication or other support where relevant; questionnaires, assessments, session notes, and information you choose to share during sessions.
  • Couples coaching: information supplied separately by each partner, relationship concerns, shared goals and notes relating to joint sessions.
  • Workplace services: employer or organisation name, eligibility details, approved-name lists where provided, booking and attendance records, funding arrangements, invoices and relevant communications.
  • Workshops: registration details, payment and attendance information, feedback, questionnaire responses and photographs or recordings where separately agreed.
  • Payment and administration: invoices, payments, refunds, bank-transfer references and transaction records. Card details are handled by the payment provider rather than stored directly by us.
  • Website and app activity: device and browser details, IP address, pages visited, interactions, cookie or advertising identifiers and, for app accounts, name, email address and last login or usage activity.

We primarily collect information directly from you. We may also receive limited information from an employer funding your sessions, a person arranging a booking, a partner or a referring professional. Where information is collected from another source, we will take the steps reasonably required to inform you about that collection unless an applicable exception applies. We ask that people referring or arranging support do not send sensitive details unnecessarily.

You may choose not to provide some information. However, information needed to verify eligibility, arrange payment, identify suitable services or provide support may be necessary for us to proceed. We will explain where information is required and where it is optional.

03 · Purpose

How and why we use information

We use personal information for purposes connected with providing and running our services, including to:

  • respond to enquiries and explain available services;
  • assess whether a service is suitable, obtain consent and deliver individual or couples coaching;
  • maintain accurate intake, session and administrative records;
  • book appointments, send confirmations and reminders, communicate changes and follow up about services;
  • verify workplace-funded eligibility, manage session allowances and administer funding;
  • organise workshops, process registrations and receive feedback;
  • issue invoices, process payments and meet accounting, tax and legal obligations;
  • operate, protect and improve our websites and digital tools, understand website use and measure advertising effectiveness;
  • send optional marketing communications where you have subscribed or otherwise authorised them; and
  • respond to requests, complaints, safety concerns, privacy incidents and legal obligations.

We do not use sensitive coaching disclosures as material for targeted advertising. We do not sell client session notes or coaching records.

04 · Coaching

Individual coaching and client records

When you engage in individual coaching, we use the information you provide to understand your circumstances, agree on goals, deliver sessions, provide consistent support and keep appropriate records. This may include sensitive personal and health-related information.

Client intake forms and formal session notes are held in our practice-management system, Splose. We are transitioning away from Cliniko, which may continue to hold historical or transitional records while that migration is completed. We do not use Google Workspace to store client session notes or client files, although email correspondence with clients is handled through email services.

Information you share is handled confidentially, with the exceptions and disclosures described in the Confidentiality and disclosure section. With your consent, we may send your GP a brief, general update about how coaching is going, within the scope agreed with you. We do not routinely send detailed session content or session notes to GPs. Any more detailed disclosure would be discussed separately with you unless another lawful basis requires or permits disclosure.

Our coaching service is non-clinical in scope; this does not mean that personal or health-related information you provide receives a lower standard of privacy protection.

05 · Couples

Couples coaching and our no-secrets approach

Couples coaching involves information about two people and their relationship. Each partner may complete an individual intake form, and we may collect information from joint discussions and separate communications.

Important: no-secrets policy. We work with a no-secrets approach in couples coaching. Information relevant to the joint work that one partner shares separately is not automatically treated as a secret to be permanently withheld from the other partner. We may discuss how relevant information is brought into the joint work rather than agreeing to keep material secrets between partners. This approach should be explained and agreed through the couples consent process before work begins.

Our no-secrets approach does not mean either partner has an unrestricted right to receive every message, form, note or other record relating to the other person. Privacy and access requests are assessed in light of each person's rights, the nature of joint records and applicable law. We will consider safety and confidentiality when managing sensitive information.

06 · Young people

Clients aged 16 or 17

We do not accept coaching clients under 16. We occasionally work with 16- and 17-year-olds and obtain parent or guardian consent before commencing services, as well as involving the young person in the consent process.

Parent or guardian consent does not automatically mean that every detail of a young person's discussions will be shared with them. We explain the practical confidentiality arrangements at intake and consider the young person's rights, relevant consent, safety considerations and applicable law when handling any request to disclose information.

07 · Employer-funded support

Workplace and employer-funded individual sessions

An employer or organisation may pay for your sessions through an ongoing workplace support arrangement or a one-off agreement. We may receive your name, organisation, eligibility status or other limited information needed to arrange the service. You may also identify your employer to us directly. We use this information to verify access, manage bookings and session allowances, provide support and administer payment. If an employer supplies information about you, we take reasonable steps to explain that collection to you, its purpose and intended recipients, unless an applicable legal exception applies.

What your employer does not automatically receive. Funding your session does not give your employer access to your intake answers, personal disclosures, session notes, diagnoses, assessment information or the content of your discussions. We do not routinely supply employers with individual coaching progress reports.

Administrative information linked to funding

The information an employer may receive depends on its particular funding agreement. It may include your name or another eligibility identifier, whether an appointment was booked, attended, cancelled or missed, the number of funded sessions used or remaining, relevant booking dates or billing details. We may instead provide aggregated information where that is suitable. We limit identifiable disclosures to what is necessary for the funding arrangement and is properly notified and authorised; this is not permission for an employer to request all of the information listed here.

What you will be told before support begins. Before your first employer-funded session, we will provide or arrange access to information specific to your employer's scheme explaining which details we receive from your employer, exactly which administrative details we may share back, whether those details identify you, why disclosure is needed, who receives them, and how to raise a concern before booking. Any material change to those reporting arrangements will be explained before a new disclosure takes place. You can contact our Privacy Officer if the arrangement is unclear. Some minimum administrative disclosure may be necessary to use employer funding; we will explain this rather than treating all disclosures as automatically agreed to.

Session content and other reporting

We do not provide identifiable session content or individual progress reports to an employer merely because the employer pays. An individual progress summary or other substantive personal report would be considered separately and would ordinarily require your specific, informed consent covering what will be shared and with whom, unless another lawful basis applies. We do not share identifiable workshop feedback with an employer without appropriate permission or another lawful basis. Any aggregated reporting is considered for identification risks, particularly with small teams.

Details of a particular arrangement may also appear in the employer's agreement, an employee access/privacy notice or individual consent documents. Where those documents describe a specific administrative reporting arrangement, we will explain it to the employee rather than relying on this general policy alone.

08 · Groups

Workshops, group training and events

We collect registration details, attendance information, payment information and feedback as needed to organise and evaluate workshops and workplace training. Feedback and workshop or workplace form submissions may be stored in our WordPress systems and may also be sent to our email account.

Participation in a group is different from a private individual session: other participants may hear what you choose to share. We encourage respect for privacy but cannot guarantee the conduct of every participant outside the session.

We may take photographs or make recordings in some workshops only with appropriate permission. We do not share individually identifiable workshop feedback with an employer without permission or another lawful basis. Where findings are reported to an organisation, we aim to present them in a way that does not identify individuals, and we consider the risk of identification in small groups.

09 · Website

Website visits, forms, cookies and advertising

Our website collects information you submit through contact, enquiry, newsletter, booking, payment, event and feedback forms. General enquiries are delivered to our email account; workshop, feedback and workplace submissions may also be held within WordPress. If you enter information in an embedded booking or payment tool, the relevant service provider may collect and process that information as described below.

Our website uses Google Analytics, Microsoft Clarity, Meta Pixel and Google Ads tracking. These technologies may use cookies, pixels, scripts and similar identifiers to collect or infer details such as IP address, device and browser information, pages visited, referring websites, clicks and other interactions. Depending on provider settings, this information may be used for website analytics, advertising conversion measurement and attribution, and personalised or retargeted advertising.

Microsoft Clarity: interaction replays and heatmaps

Microsoft Clarity helps us understand how visitors use the website. It can produce session replays of website interactions, including page views, mouse movements, clicks and scrolling, and heatmaps showing patterns of interaction. These are reconstructions of website activity, not audio or video recordings of coaching sessions. They may involve page content, technical identifiers and interaction data. Microsoft Clarity provides masking for input fields and other content, but masking does not mean that every potentially identifying detail, page element or URL is automatically excluded. We do not use Clarity to intentionally collect the substance of your coaching disclosures. Please avoid putting sensitive coaching details into general website enquiry forms, and contact us if you have concerns about website tracking.

Current cookie controls: We do not currently operate a website cookie-consent banner. You can manage or block cookies through your browser and use available privacy or advertising settings provided by the relevant third parties. Blocking cookies may affect some website functionality. Browser settings are not necessarily a substitute for consent where applicable law requires it, and some tracking methods do not rely on cookies alone.

For more information about providers' processing and available controls, see Google's Privacy Policy, Microsoft's Privacy Statement and Meta's Privacy Policy.

Please avoid including highly sensitive coaching information in general website enquiry forms or public comments. We may redirect sensitive enquiries into our intake process where appropriate. Links to external websites are governed by those organisations' own privacy practices.

10 · Digital tools

Think Blue Tree apps and digital resources

Our digital resources may include tools hosted separately from our main website, including tbt-app.com. Where you have an app account, the administration system stores your name, email address and information about when you last logged in or used the app. These details help us manage access and understand whether the app is being used.

Content you enter while using app exercises and tools is stored locally on your device rather than centrally in our administrator database, according to the current app configuration. We do not ordinarily have access to the content of your locally stored exercise responses through the admin dashboard. Local information may be lost if you clear browser or app storage, uninstall the app or change devices. The app's authentication and hosting providers may separately process technical and account data needed to provide the service.

If a particular tool introduces a feature that stores exercise content on a server or changes how personal information is handled, that feature will need an updated notice before use.

11 · Third parties

Service providers, data hosting and overseas processing

We use external providers to operate our business. The services involved can include:

  • Splose and Cliniko: practice management, booking, forms and client records, with Cliniko being phased out.
  • Stripe and banking providers: payment processing, transaction records and bank transfers. We do not store full payment-card details ourselves.
  • Google Workspace and Google Meet: business email, communication and online meetings; client session files and formal session notes are not stored in Google Workspace.
  • Heidi: consent-based session recording and AI-assisted documentation, described in the next section.
  • WordPress and website hosting services: website operation, submitted forms and related records.
  • MailerLite and Brevo: relevant email distribution or technical email functions.
  • Supabase and app hosting or authentication services: account administration and technical operation of our digital tools.
  • Google, Microsoft and Meta: website measurement and advertising technologies as described above.

These providers receive or process only the categories of information involved in the services we use them for. Their systems may store or process information in New Zealand or overseas. We do not represent that all information is kept exclusively in New Zealand, and the locations and subcontractors used by providers can change.

Where we disclose personal information to an overseas recipient, we consider applicable New Zealand cross-border privacy requirements. Where a provider processes or stores information on our behalf, we remain responsible for taking appropriate steps regarding the arrangement. Providers may have their own policies and lawful retention obligations, including for transactions and security logs.

We do not sell personal coaching records to third parties. We may change service providers from time to time and will update this policy when a material change affects how personal information is handled.

12 · Recording and AI

Heidi, audio recordings and AI-assisted notes

We may offer the use of Heidi to assist with session documentation, but only with your consent. Where offered, you may instead consent to audio recording without AI-assisted documentation. Recording is not a condition of receiving coaching unless we have separately explained and agreed to a specific requirement.

We ask permission before making a session recording or using Heidi. We explain the option being proposed and respect your decision if you do not consent. We ordinarily delete temporary Heidi content and locally held audio files within approximately one to two days, after completing the relevant documentation. This is our usual practice rather than a guarantee that every copy, backup or provider-held record is immediately erased; provider-specific retention and deletion settings may differ.

Relevant session notes created from a recording may be retained in Splose as part of your client record. Deleting a temporary recording does not delete the formal session note. Any recording, photographs or other material proposed for a separate purpose would require appropriate permission.

13 · Confidentiality

When information may be shared

We treat information disclosed during coaching as confidential. We may use or disclose personal information with your consent, where necessary to operate our services through the providers identified in this policy, or where required or permitted by applicable law.

GP communication and professional supervision

With your consent, we may provide your GP with a general, non-detailed update about your coaching, within the scope agreed with you. We do not routinely provide session notes or detailed discussion content. A request for more specific information is considered separately and ordinarily requires your agreement, unless disclosure has another lawful basis.

We also undertake professional supervision to support our work. When discussing a case in supervision, we do not use client names and minimise or remove other identifying details as far as possible. Because circumstances can sometimes be recognisable even without a name, we do not claim that removing a name guarantees complete anonymity. If identifiable disclosure is ever proposed beyond this usual approach, we consider consent or another lawful basis before proceeding.

Other circumstances

Other examples of disclosure can include:

  • limited employer-funded administrative information, where properly notified and authorised as described in the workplace section;
  • a lawful court order or another binding legal requirement;
  • an appropriate response to a serious threat to someone's life, health or safety where the legal conditions for disclosure are met; and
  • investigating and responding to fraud, privacy incidents or other matters where there is a lawful basis.

We consider each situation individually and seek to disclose no more than reasonably necessary. Confidentiality is not absolute; we explain relevant limits during intake and consent. Information about a partner, family member or other third party may also be protected by that person's privacy rights.

14 · Communication

Email, text messages and optional marketing

We contact people by email, SMS, telephone and, for online appointments, Google Meet. Booking confirmations, reminders, invoices and other communications needed to provide a booked service are administrative messages, not automatically marketing messages. Messages may reveal that you have interacted with Think Blue Tree, so please tell us if you have a particular communication or contact-safety concern.

Optional newsletters, event announcements and promotional communications are sent where you have opted in, including through an intake form or by asking us verbally to add you. Our promotional emails include an unsubscribe facility. You can also contact us to withdraw your marketing permission. Unsubscribing from marketing does not necessarily stop necessary appointment or service communications.

We may retain relevant email and SMS correspondence as part of business administration or a client record when appropriate. We cannot guarantee the security of ordinary email or SMS end to end.

15 · Protection and timeframes

Security, retention and deletion

Security

We use unique passwords, device password protection and two-factor authentication where available. Client intake information and formal session notes are held in our practice-management platform. We do not maintain paper client files. Temporary handwritten notes are de-identified and notebooks are destroyed when full.

No electronic or communications system is completely risk-free. We consider security incidents when they arise and, where a privacy breach is notifiable under New Zealand law, notify the Privacy Commissioner and affected individuals as required, subject to any applicable exceptions.

How long information is kept

Client coaching records: We retain client records, including intake information and formal session notes, for at least 10 years from the most recent service provided to that client. We may retain information longer if a legal requirement or other justified reason applies. This is our retention policy for coaching records regardless of whether a particular record is legally classified as health information. The Health (Retention of Health Information) Regulations 1996 also prescribe a 10-year minimum for information and providers within their scope.

Financial records: Financial and tax records are generally retained for the legally required period, ordinarily at least seven years.

Enquiries and WordPress submissions: We do not currently have a fixed deletion period for standalone phone, SMS or email enquiries, or for WordPress submissions such as workshop registrations, feedback and workplace forms. These records may remain in relevant communications or website systems while needed for administration, feedback analysis or applicable obligations. Where submitted information becomes part of a client record, the client-record retention policy may apply. We do not currently apply an automatic deletion period to these categories.

Temporary recordings: Heidi content and locally held session audio files are ordinarily deleted within approximately one to two days, as described in the recording section. This does not mean related formal notes or every provider-held backup is deleted at the same time.

Other data, including website logs, marketing records, technical backups and provider-held information, may have different retention periods and settings. When information is no longer required, we take appropriate steps to delete, destroy or de-identify it, subject to applicable requirements and technical constraints.

You may ask us to delete particular information. We will consider your request and explain any applicable retention obligations; there is no unconditional right to immediate deletion of every record.

16 · Your rights

Access, correction, preferences and complaints

You can email patrick@thinkbluetree.com to ask what personal information we hold about you, request access to it, or ask us to correct information you believe is inaccurate or incomplete. You may also contact us by phone or post using the details below. We may need to verify your identity before releasing information. Where records include information about another person, we consider their privacy rights and any lawful grounds for withholding information.

Response time: We will make and communicate a decision on a request for access or correction as soon as reasonably practicable and generally within 20 working days of receiving it, unless a lawful extension applies. If an extension is necessary, we will notify you as required. If we agree to provide information but cannot supply it with our initial decision, we will provide it without undue delay, subject to applicable law.

If we do not agree to a requested correction, you may ask for a statement of correction to be attached to the information where applicable. You may also ask about retention, withdrawal of optional consent, marketing preferences or the handling of information supplied by a third party.

If you have a concern, please contact our Privacy Officer, Patrick Timm, at patrick@thinkbluetree.com, so we can consider it and respond. You can also complain to the Office of the Privacy Commissioner.

17 · Contact

Changes to this policy and how to contact us

We may update this policy as our services, technology or legal obligations change. The effective date at the top identifies the version currently published. Where a change materially affects a particular service or use of information, we will consider whether additional notice or consent is required.

Privacy Officer

Patrick Timm
Think Blue Tree Limited
Trading as Think Blue Tree
PO Box 2625
Wakatipu, Queenstown 9371
New Zealand

Email: patrick@thinkbluetree.com
Phone: 0204 350 250
Online: thinkbluetree.com/contact/

This policy describes Think Blue Tree's information practices and should be read with any relevant intake consent, booking terms, app notice and workplace service agreement.

↑ Back to top