Our commitment to data protection and your privacy rights
Last updated: January 2024
gorge-puma is committed to complying with the General Data Protection Regulation (GDPR) and protecting the personal data of all individuals, including those located in the European Economic Area (EEA). This page outlines our GDPR compliance practices and your rights under this regulation.
gorge-puma acts as the data controller for personal data collected through this website. As data controller, we determine the purposes and means of processing personal data.
Contact details:
gorge-puma
42 Greenway Boulevard
Sydney, NSW 2000
Australia
Email: [email protected]
We process personal data only when we have a lawful basis to do so. The lawful bases we rely on include:
If you are located in the EEA, you have the following rights regarding your personal data:
You have the right to request a copy of the personal data we hold about you, along with information about how we use it.
You have the right to request that we correct any inaccurate or incomplete personal data we hold about you.
You have the right to request that we delete your personal data in certain circumstances, such as when the data is no longer necessary for the purpose for which it was collected.
You have the right to request that we restrict the processing of your personal data in certain circumstances.
You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller.
You have the right to object to the processing of your personal data in certain circumstances, including processing for direct marketing purposes.
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you.
To exercise any of your rights under GDPR, please contact us using the details provided above. We will respond to your request within one month. In certain circumstances, we may extend this period by two further months, in which case we will inform you of the extension and the reasons for it.
We may need to verify your identity before processing your request. If we cannot verify your identity, we may ask for additional information.
As we are based in Australia, personal data collected from individuals in the EEA may be transferred to and processed in Australia. When we transfer personal data outside the EEA, we ensure that appropriate safeguards are in place to protect your data in accordance with GDPR requirements.
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy legal, accounting, or reporting requirements. The retention period may vary depending on the context of the processing and our legal obligations.
We implement appropriate technical and organisational measures to protect personal data against unauthorised or unlawful processing and against accidental loss, destruction, or damage. These measures include encryption, access controls, and regular security assessments.
In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. If the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly.
If you believe that we have not complied with GDPR or your data protection rights, you have the right to lodge a complaint with a supervisory authority. For individuals in the EEA, this would be the data protection authority in your country of residence.
We may update this GDPR compliance notice from time to time. Any changes will be posted on this page with an updated revision date.