GDPR Compliance
Last Updated: September 2024
Overview
The General Data Protection Regulation (GDPR) establishes requirements for processing personal data of individuals in the European Union. While we operate primarily in Australia, we recognize the importance of data protection principles and strive to maintain practices aligned with international standards.
Lawful Basis for Processing
We process personal data based on the following lawful grounds:
- Consent: You have given clear consent for processing your personal data for specific purposes
- Contract: Processing is necessary for fulfilling a contract or taking steps before entering into a contract
- Legal Obligation: Processing is necessary to comply with legal requirements
- Legitimate Interests: Processing is necessary for our legitimate business interests, provided these do not override your fundamental rights
Your GDPR Rights
Under GDPR, you have the following rights regarding your personal data:
Right to Access
You can request confirmation of whether we process your personal data and obtain a copy of that data along with information about how it is processed.
Right to Rectification
You can request correction of inaccurate personal data and completion of incomplete data.
Right to Erasure
Under certain circumstances, you can request deletion of your personal data. This right is not absolute and depends on specific conditions outlined in GDPR.
Right to Restriction of Processing
You can request limitation of processing in specific situations, such as when you contest data accuracy or object to processing.
Right to Data Portability
You can request to receive personal data you provided to us in a structured, commonly used format, and to transmit that data to another controller.
Right to Object
You can object to processing based on legitimate interests or for direct marketing purposes.
Rights Related to Automated Decision-Making
You have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects.
Data Protection Officer
For questions about data protection or to exercise your GDPR rights, contact us at [email protected]. We will respond to requests within the timeframes required by GDPR.
Data Processing Activities
We process the following categories of personal data:
- Contact information (name, email address)
- Project inquiry details
- Technical data (IP addresses, browser information, visit patterns)
- Communication records
Data Recipients
Personal data may be shared with service providers who assist with website hosting, email communications, and analytics. These processors are contractually bound to protect data and process it only according to our instructions.
Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected or as required by legal obligations. Retention periods vary depending on data type and processing purpose.
International Transfers
If personal data is transferred outside the European Economic Area, we ensure appropriate safeguards are in place, such as standard contractual clauses or adequacy decisions.
Security Measures
We implement technical and organizational measures to protect personal data against unauthorized access, accidental loss, destruction, or damage. These measures are reviewed and updated regularly.
Data Breach Notification
In the event of a personal data breach that poses risks to individual rights and freedoms, we will notify affected individuals and relevant supervisory authorities as required by GDPR.
Complaints
If you believe we have not handled your personal data properly, you have the right to lodge a complaint with a supervisory authority in your jurisdiction.
Updates to This Statement
We may update this GDPR compliance statement to reflect changes in our practices or legal requirements. The revision date will be updated accordingly.