GDPR Compliance
Information for European Union residents regarding data protection.
Last Updated: January 2024
Our Commitment to GDPR
While azure-petal is based in Australia, we are committed to complying with the General Data Protection Regulation (GDPR) for any personal data we process relating to individuals in the European Union.
Data Controller
For the purposes of GDPR, azure-petal acts as the data controller for personal information collected through our website and services. Our contact details are:
azure-petal
42 Industrial Drive
Smithfield NSW 2164
Australia
Email: [email protected]
Legal Basis for Processing
We process personal data under the following legal bases:
- Consent: Where you have given clear consent for us to process your personal data for specific purposes
- Contractual Necessity: Where processing is necessary to fulfil a contract with you or take steps at your request before entering a contract
- Legitimate Interests: Where processing is necessary for our legitimate business interests, provided these do not override your fundamental rights
- Legal Obligation: Where processing is necessary to comply with applicable laws
Your Rights Under GDPR
If you are an EU resident, you have the following rights:
Right to Access
You have the right to request a copy of the personal data we hold about you.
Right to Rectification
You have the right to request correction of any inaccurate or incomplete personal data.
Right to Erasure
You have the right to request deletion of your personal data under certain circumstances, including when the data is no longer necessary for the purposes for which it was collected.
Right to Restrict Processing
You have the right to request restriction of processing of your personal data under certain circumstances.
Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit it to another controller.
Right to Object
You have the right to object to processing of your personal data in certain circumstances, including processing for direct marketing purposes.
Rights Related to Automated Decision-Making
You have the right not to be subject to decisions based solely on automated processing that produce legal effects concerning you.
International Data Transfers
As we are based in Australia, any personal data you provide may be transferred to and processed in Australia. Australia has been recognised by the European Commission as providing an adequate level of data protection. Where we transfer data to other countries, we ensure appropriate safeguards are in place.
Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, unless a longer retention period is required by law. When determining retention periods, we consider:
- The nature and sensitivity of the data
- The purposes for which it was collected
- Legal requirements for retention
- The potential risk of harm from unauthorised use
Data Security
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
- Encryption of data in transit
- Access controls and authentication procedures
- Regular security assessments
- Staff training on data protection
Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly.
Exercising Your Rights
To exercise any of your rights under GDPR, please contact us at [email protected]. We will respond to your request within one month of receipt. In complex cases, this period may be extended by a further two months, and we will inform you of any such extension.
Complaints
If you believe we have not handled your personal data properly, you have the right to lodge a complaint with your local data protection authority. We would, however, appreciate the opportunity to address your concerns directly before you approach the supervisory authority.
Updates to This Policy
We may update this GDPR information from time to time. Any significant changes will be communicated through our website.