Last updated: January 2024

Our Commitment to GDPR

spring-puffin is committed to ensuring the security and protection of the personal information that we process, and to providing a compliant and consistent approach to data protection. We recognise our obligations under the General Data Protection Regulation (GDPR) and are committed to processing data in accordance with its principles.

Lawful Basis for Processing

We process personal data under the following lawful bases:

Your Rights Under GDPR

As a data subject, you have the following rights:

Right to Access

You have the right to request a copy of the personal information we hold about you and information about how we process it.

Right to Rectification

You have the right to request correction of any inaccurate or incomplete personal data we hold about you.

Right to Erasure

You have the right to request deletion of your personal data where there is no compelling reason for its continued processing.

Right to Restrict Processing

You have the right to request that we restrict the processing of your personal data in certain circumstances.

Right to Data Portability

You have the right to receive your personal data in a structured, commonly used, and machine-readable format.

Right to Object

You have the right to object to processing of your personal data in certain circumstances, including for direct marketing purposes.

Rights Related to Automated Decision-Making

You have the right not to be subject to decisions based solely on automated processing, including profiling, that produce legal effects or similarly significantly affect you.

Exercising Your Rights

To exercise any of your rights, please contact us using the details below. We will respond to your request within one month. In some cases, we may need to extend this period by up to two months, in which case we will inform you.

We may need to verify your identity before processing your request. We will not charge a fee for processing your request unless it is manifestly unfounded or excessive.

Data Protection Officer

For any queries regarding data protection or to exercise your rights, please contact our data protection representative at:

Email: [email protected]
Address: 42 Harbour View Drive, Sydney NSW 2000, Australia

International Transfers

Where we transfer personal data outside the European Economic Area, we ensure appropriate safeguards are in place to protect your data, including standard contractual clauses approved by the European Commission.

Data Breach Notification

In the event of a data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly.

Complaints

If you believe that your data protection rights have been violated, you have the right to lodge a complaint with a supervisory authority. For EU residents, this would be the data protection authority in your country of residence.

Changes to This Policy

We may update this GDPR policy from time to time. Any changes will be posted on this page with an updated revision date.