GDPR Compliance
Information for European Union residents
Our Commitment to GDPR
Although Fern-spark is based in Australia, we are committed to protecting the personal data of all individuals, including those residing in the European Union (EU) and European Economic Area (EEA). This page outlines how we comply with the General Data Protection Regulation (GDPR) when processing personal data of EU/EEA residents.
Data Controller
For the purposes of the GDPR, Fern-spark acts as the data controller for personal data collected through our website and services. Our contact details are:
Fern-spark
Level 4, 127 Creek Street
Brisbane QLD 4000
Australia
Email: [email protected]
Legal Basis for Processing
Under the GDPR, we process personal data only when we have a valid legal basis. The legal bases we rely on include:
- Consent: Where you have given clear consent for us to process your personal data for a specific purpose.
- Contract: Where processing is necessary to perform a contract with you or to take steps at your request before entering into a contract.
- Legal Obligation: Where processing is necessary to comply with a legal obligation.
- Legitimate Interests: Where processing is necessary for our legitimate interests or those of a third party, provided your rights do not override those interests.
Your Rights Under GDPR
If you are a resident of the EU or EEA, you have the following rights regarding your personal data:
Right of Access
You have the right to request a copy of the personal data we hold about you and information about how we process it.
Right to Rectification
You have the right to request that we correct any inaccurate personal data or complete any incomplete data we hold about you.
Right to Erasure
You have the right to request that we delete your personal data in certain circumstances, such as when the data is no longer necessary for the purpose for which it was collected.
Right to Restrict Processing
You have the right to request that we restrict the processing of your personal data in certain circumstances, such as when you contest the accuracy of the data.
Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit it to another controller.
Right to Object
You have the right to object to the processing of your personal data in certain circumstances, including processing for direct marketing purposes.
Rights Related to Automated Decision-Making
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects or similarly significantly affects you.
Exercising Your Rights
To exercise any of these rights, please contact us at [email protected]. We will respond to your request within one month of receiving it. In some cases, we may need to verify your identity before processing your request.
If your request is complex or you have made multiple requests, we may extend the response period by up to two additional months. We will inform you of any such extension within one month of receiving your request.
International Data Transfers
As we are based in Australia, any personal data you provide to us will be transferred to and processed in Australia. Australia is not considered to have an adequacy decision from the European Commission. We take appropriate safeguards to ensure your personal data is protected in accordance with GDPR requirements when transferred internationally.
Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy legal, accounting, or reporting requirements. When determining retention periods, we consider the amount, nature, and sensitivity of the data, the potential risk of harm from unauthorised use or disclosure, and applicable legal requirements.
Data Security
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including encryption, access controls, and regular security assessments. In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority and, where required, affected individuals without undue delay.
Complaints
If you believe we have not handled your personal data in accordance with the GDPR, you have the right to lodge a complaint with a supervisory authority in the EU Member State of your habitual residence, place of work, or place of the alleged infringement. We would, however, appreciate the opportunity to address your concerns before you contact a supervisory authority, so please contact us in the first instance.
Updates to This Information
We may update this GDPR compliance information from time to time. Any changes will be posted on this page with an updated revision date. We encourage you to review this page periodically for the latest information on our GDPR compliance practices.