Our commitment to data protection and your privacy rights
Last updated: January 2024
spring-puffin is committed to ensuring the security and protection of the personal information that we process, and to providing a compliant and consistent approach to data protection. We recognise our obligations under the General Data Protection Regulation (GDPR) and are committed to processing data in accordance with its principles.
We process personal data under the following lawful bases:
As a data subject, you have the following rights:
You have the right to request a copy of the personal information we hold about you and information about how we process it.
You have the right to request correction of any inaccurate or incomplete personal data we hold about you.
You have the right to request deletion of your personal data where there is no compelling reason for its continued processing.
You have the right to request that we restrict the processing of your personal data in certain circumstances.
You have the right to receive your personal data in a structured, commonly used, and machine-readable format.
You have the right to object to processing of your personal data in certain circumstances, including for direct marketing purposes.
You have the right not to be subject to decisions based solely on automated processing, including profiling, that produce legal effects or similarly significantly affect you.
To exercise any of your rights, please contact us using the details below. We will respond to your request within one month. In some cases, we may need to extend this period by up to two months, in which case we will inform you.
We may need to verify your identity before processing your request. We will not charge a fee for processing your request unless it is manifestly unfounded or excessive.
For any queries regarding data protection or to exercise your rights, please contact our data protection representative at:
Email: [email protected]
Address: 42 Harbour View Drive, Sydney NSW 2000, Australia
Where we transfer personal data outside the European Economic Area, we ensure appropriate safeguards are in place to protect your data, including standard contractual clauses approved by the European Commission.
In the event of a data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly.
If you believe that your data protection rights have been violated, you have the right to lodge a complaint with a supervisory authority. For EU residents, this would be the data protection authority in your country of residence.
We may update this GDPR policy from time to time. Any changes will be posted on this page with an updated revision date.