Your data protection rights under EU regulation
The General Data Protection Regulation (GDPR) is a regulation in EU law on data protection and privacy. It applies to all organisations that process personal data of individuals residing in the European Union, regardless of where the organisation is located.
Although thicket-dive is based in Australia, we are committed to protecting the privacy of all our clients, including those who may be EU residents or citizens.
For the purposes of the GDPR, thicket-dive acts as the data controller for personal information collected through our website and services. This means we determine the purposes and means of processing your personal data.
Contact details for the data controller:
thicket-dive
Level 14, 123 Collins Street
Melbourne VIC 3000
Australia
Email: [email protected]
Under the GDPR, we must have a valid legal basis to process your personal data. We rely on the following legal bases:
If you are an EU resident, the GDPR provides you with specific rights regarding your personal data:
Right to Access: You have the right to request copies of your personal data. We may charge a small fee for this service.
Right to Rectification: You have the right to request that we correct any information you believe is inaccurate or complete information you believe is incomplete.
Right to Erasure: You have the right to request that we erase your personal data, under certain conditions.
Right to Restrict Processing: You have the right to request that we restrict the processing of your personal data, under certain conditions.
Right to Object to Processing: You have the right to object to our processing of your personal data, under certain conditions.
Right to Data Portability: You have the right to request that we transfer the data that we have collected to another organisation, or directly to you, under certain conditions.
To exercise any of these rights, please contact us using the details provided above. We will respond to your request within one month. If your request is complex or you have made multiple requests, we may extend this period by up to two months, but we will inform you of any extension within one month of receiving your request.
We may ask you to verify your identity before fulfilling your request. This is to ensure that personal data is not disclosed to anyone who has no right to receive it.
As we are based in Australia, any personal data you provide to us may be transferred to and stored in Australia. Australia is not subject to an adequacy decision by the European Commission, but we implement appropriate safeguards to protect your data, including standard contractual clauses where applicable.
We will only retain your personal data for as long as necessary to fulfil the purposes for which we collected it. When determining the appropriate retention period, we consider the amount, nature, and sensitivity of the data, the potential risk of harm from unauthorised use or disclosure, the purposes for which we process your data, and applicable legal requirements.
We have implemented appropriate technical and organisational measures to protect your personal data against unauthorised or unlawful processing and against accidental loss, destruction, or damage. However, no method of transmission over the internet or method of electronic storage is completely secure.
If you are an EU resident and believe that your data protection rights have been violated, you have the right to lodge a complaint with your local data protection supervisory authority. However, we would appreciate the opportunity to address your concerns before you approach the supervisory authority, so please contact us first.
We may update this GDPR information from time to time. We will notify you of any changes by posting the new information on this page and updating the date at the top.