Your data protection rights under the General Data Protection Regulation
stone-ocelot is committed to protecting the privacy and security of your personal data. We comply with applicable data protection laws, including the General Data Protection Regulation (GDPR) for individuals in the European Economic Area and similar regulations globally.
stone-ocelot is the data controller responsible for your personal data. This means we determine the purposes and means of processing your personal data.
Contact details:
stone-ocelot
45 Garden Lane
North Sydney, NSW 2060
Australia
Email: [email protected]
If you are located in the European Economic Area, you have the following data protection rights:
You have the right to request a copy of the personal data we hold about you. We will provide this information free of charge within one month of receiving your request.
You have the right to request that we correct any inaccurate personal data we hold about you and to have any incomplete personal data completed.
You have the right to request that we delete your personal data in certain circumstances, including when the data is no longer necessary for the purpose for which it was collected or when you withdraw consent.
You have the right to request that we restrict the processing of your personal data in certain circumstances, such as when you contest the accuracy of your data or when you object to processing.
You have the right to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format. You can also request that we transmit this data directly to another controller where technically feasible.
You have the right to object to the processing of your personal data in certain circumstances, including processing for direct marketing purposes or where processing is based on legitimate interests.
Where we rely on consent to process your personal data, you have the right to withdraw that consent at any time. This will not affect the lawfulness of processing carried out before you withdrew your consent.
You have the right to lodge a complaint with a supervisory authority if you believe that our processing of your personal data infringes data protection laws.
We process personal data on the following legal bases:
If we transfer your personal data outside the European Economic Area, we will ensure that appropriate safeguards are in place to protect your data. These safeguards may include standard contractual clauses approved by the European Commission or transfer to countries that have been deemed to provide an adequate level of protection.
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy legal, accounting, or reporting requirements. The specific retention period depends on the nature of the data and the purposes for which it is processed.
We implement appropriate technical and organisational measures to protect personal data against unauthorised or unlawful processing, accidental loss, destruction, or damage. These measures include encryption, access controls, and regular security assessments.
To exercise any of your data protection rights, please contact us using the details provided above. We may need to verify your identity before processing your request. We will respond to your request within one month, though this period may be extended by two further months for complex requests.
There is no fee for exercising your rights in most cases. However, we may charge a reasonable fee if your request is clearly unfounded, repetitive, or excessive, or we may refuse to comply with your request in these circumstances.
We may update this GDPR compliance notice from time to time. Any changes will be posted on this page with an updated revision date. We encourage you to review this notice periodically.