Last updated: January 2024
dawn-sable is committed to protecting the privacy and security of personal data in accordance with the General Data Protection Regulation (GDPR). This page outlines how we handle personal data of individuals in the European Economic Area (EEA) and the rights available to them.
For the purposes of the GDPR, dawn-sable acts as the data controller for personal data collected through our website and service enquiries.
Contact details:
dawn-sable
Level 4, 127 York Street
Sydney NSW 2000
Australia
Email: [email protected]
We process personal data on the following legal bases:
If you are located in the EEA, you have the following rights regarding your personal data:
You have the right to request a copy of the personal data we hold about you and information about how we process it.
You have the right to request that we correct any inaccurate personal data or complete any incomplete personal data.
You have the right to request that we delete your personal data in certain circumstances, such as when the data is no longer necessary for the purposes for which it was collected.
You have the right to request that we restrict the processing of your personal data in certain circumstances, such as when you contest the accuracy of the data.
You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit it to another controller.
You have the right to object to processing of your personal data based on legitimate interests or for direct marketing purposes.
You have the right not to be subject to decisions based solely on automated processing, including profiling, which produce legal effects or significantly affect you.
To exercise any of these rights, please contact us at [email protected]. We will respond to your request within one month of receipt. In certain circumstances, we may extend this period by two further months, in which case we will inform you of the extension and the reasons for it.
We may request specific information from you to help us confirm your identity and ensure your right to access the information or exercise other rights.
As we are based in Australia, personal data collected from individuals in the EEA may be transferred to and processed in Australia. Australia has not received an adequacy decision from the European Commission. To ensure appropriate safeguards for such transfers, we rely on:
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected. When determining retention periods, we consider the amount, nature, and sensitivity of the data, the potential risk of harm from unauthorised use or disclosure, and applicable legal requirements.
We implement appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures include encryption, access controls, and regular security assessments.
If you believe that we have not complied with your data protection rights, you have the right to lodge a complaint with a supervisory authority. If you are in the EEA, you can lodge a complaint with the supervisory authority in your country of residence, place of work, or place of the alleged infringement.
We may update this GDPR compliance notice from time to time. Any changes will be posted on this page with an updated revision date.