GDPR Compliance
Last Updated: January 2024
1. Introduction
bright-marsh respects the privacy of individuals in the European Union and European Economic Area and is committed to compliance with the General Data Protection Regulation (GDPR). This document outlines how we handle personal data of EU/EEA residents in accordance with GDPR requirements.
2. Data Controller
For the purposes of GDPR, bright-marsh acts as the data controller for personal data collected through our website and services. Our contact details are:
bright-marsh
Level 4, 125 Collins Street
Melbourne VIC 3000
Australia
Email: [email protected]
3. Lawful Basis for Processing
We process personal data only when we have a lawful basis to do so. The legal bases we rely on include:
3.1 Consent
Where you have given clear consent for us to process your personal data for specific purposes, such as receiving marketing communications.
3.2 Contract Performance
Where processing is necessary for the performance of a contract with you or to take steps at your request before entering into a contract.
3.3 Legitimate Interests
Where processing is necessary for our legitimate interests or those of a third party, provided these interests do not override your fundamental rights and freedoms.
3.4 Legal Obligation
Where processing is necessary for compliance with a legal obligation to which we are subject.
4. Your Rights Under GDPR
If you are located in the EU/EEA, you have the following rights regarding your personal data:
4.1 Right of Access
You have the right to request a copy of the personal data we hold about you and information about how we process it.
4.2 Right to Rectification
You have the right to request that we correct any personal data that is inaccurate or complete any data that is incomplete.
4.3 Right to Erasure
You have the right to request that we delete your personal data in certain circumstances, such as when the data is no longer necessary for the purposes for which it was collected.
4.4 Right to Restrict Processing
You have the right to request that we restrict the processing of your personal data in certain circumstances, such as when you contest the accuracy of the data.
4.5 Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller.
4.6 Right to Object
You have the right to object to processing of your personal data where we rely on legitimate interests as the legal basis, including processing for direct marketing purposes.
4.7 Rights Related to Automated Decision-Making
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you.
5. International Data Transfers
As we are based in Australia, personal data collected from EU/EEA residents may be transferred to and processed in Australia. We ensure that such transfers comply with GDPR requirements by implementing appropriate safeguards, such as standard contractual clauses approved by the European Commission.
6. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law. We regularly review our data retention practices to ensure compliance with the principle of storage limitation.
7. Data Security
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including measures to protect against unauthorised or unlawful processing and against accidental loss, destruction, or damage.
8. Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority without undue delay and, where feasible, within 72 hours. If the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly.
9. Exercising Your Rights
To exercise any of your rights under GDPR, please contact us using the details provided above. We will respond to your request within one month, although we may extend this period by two months for complex requests. We will not charge a fee for most requests, but may charge a reasonable fee if your request is clearly unfounded or excessive.
10. Complaints
If you are not satisfied with how we handle your personal data or respond to your requests, you have the right to lodge a complaint with your local supervisory authority. A list of EU/EEA supervisory authorities is available at: https://edpb.europa.eu/about-edpb/board/members_en
11. Changes to This Notice
We may update this GDPR compliance notice from time to time. Any changes will be posted on this page with an updated revision date.