GDPR Compliance Statement

This page outlines our commitment to compliance with the General Data Protection Regulation (GDPR) and explains your rights under this regulation.

Legal basis for processing

We process personal data based on the following legal grounds:

Data subject rights

Under GDPR, you have comprehensive rights regarding your personal data:

Right to access

You can request a copy of all personal data we hold about you. We will provide this information in a structured, commonly used format within 30 days of your request.

Right to rectification

If information we hold about you is inaccurate or incomplete, you have the right to have it corrected or updated.

Right to erasure

Also known as the "right to be forgotten," you can request deletion of your personal data when there is no compelling reason for its continued processing, subject to legal retention requirements.

Right to restrict processing

You can request that we limit how we use your data in certain circumstances, such as while we verify information accuracy or assess legitimate grounds for processing.

Right to data portability

You can request your data in a portable format to transfer to another service provider where technically feasible.

Right to object

You can object to processing based on legitimate interests or for direct marketing purposes. We will cease processing unless we have compelling legitimate grounds that override your interests.

Rights related to automated decision-making

We do not use automated decision-making or profiling that produces legal effects or similarly significant impacts on individuals.

Data retention

We retain personal data only as long as necessary for the purposes outlined in our privacy policy:

International data transfers

Personal data is processed and stored within Australia. If data is transferred internationally, we ensure adequate safeguards are in place through approved mechanisms such as standard contractual clauses or adequacy decisions.

Data protection officer

For questions about data protection practices or to exercise your rights, contact us at info at fern-rhythm.com with "Data Protection" in the subject line.

Supervisory authority

You have the right to lodge a complaint with your local data protection supervisory authority if you believe your data rights have been violated. In Australia, this is the Office of the Australian Information Commissioner (OAIC).

Consent withdrawal

Where we process data based on consent, you may withdraw that consent at any time. This will not affect the lawfulness of processing before withdrawal. To withdraw consent, contact us at info at fern-rhythm.com.

Security measures

We implement appropriate technical and organizational measures to protect personal data, including:

Breach notification

In the event of a data breach that poses a risk to your rights and freedoms, we will notify you and relevant authorities within 72 hours of becoming aware of the breach, as required by GDPR.