Information on this site is advertising in nature.

GDPR Compliance

Our commitment to protecting your data rights

Last Updated: January 2024

Introduction

fjord-cypress is committed to ensuring compliance with the General Data Protection Regulation (GDPR) and protecting the privacy rights of all individuals whose data we process, regardless of their location.

Data Controller Information

For the purposes of data protection legislation, the data controller is:

fjord-cypress
Level 12, 88 Collins Street
Melbourne VIC 3000
Australia
Email: [email protected]

Your Rights Under GDPR

If you are located in the European Economic Area (EEA) or the United Kingdom, you have the following rights regarding your personal data:

Right to Access

You have the right to request a copy of the personal data we hold about you. This is commonly known as a "data subject access request." We will provide this information free of charge within one month of receiving your request.

Right to Rectification

You have the right to request correction of any inaccurate personal data we hold about you, and to have incomplete data completed.

Right to Erasure

You have the right to request deletion of your personal data in certain circumstances, including:

Right to Restriction of Processing

You have the right to request restriction of processing of your personal data in certain circumstances, such as when you contest the accuracy of the data or object to processing.

Right to Data Portability

You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller where technically feasible.

Right to Object

You have the right to object to processing of your personal data based on legitimate interests, including profiling. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests.

Rights Related to Automated Decision Making

You have the right not to be subject to decisions based solely on automated processing, including profiling, which produce legal effects or similarly significantly affect you.

Legal Basis for Processing

We process personal data only when we have a valid legal basis to do so. Our legal bases for processing include:

International Data Transfers

As an Australian-based company, your data may be transferred to and stored in Australia, which is outside the EEA. When we transfer data internationally, we ensure appropriate safeguards are in place, including:

Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, to comply with legal obligations, to resolve disputes, and to enforce our agreements. When data is no longer needed, we securely delete or anonymise it.

Data Security

We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:

Data Breach Notification

In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. If the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly.

Exercising Your Rights

To exercise any of your rights under GDPR, please contact us at:

Email: [email protected]

We will respond to your request within one month. In complex cases or where we receive a high volume of requests, we may extend this period by up to two additional months, and will inform you if this is necessary.

Right to Lodge a Complaint

If you are not satisfied with how we handle your personal data or respond to your requests, you have the right to lodge a complaint with a supervisory authority. If you are in the EEA, you can contact your local data protection authority.

Changes to This Information

We may update this GDPR compliance information from time to time. Any changes will be posted on this page with an updated revision date.

This information is provided to explain our approach to GDPR compliance. It should be read in conjunction with our Privacy Policy, which provides additional details about our data processing practices.