Our Commitment to Data Protection
Although rascecical is based in Australia, we are committed to protecting the privacy and data rights of all our visitors, including those from the European Economic Area (EEA) and the United Kingdom. We adhere to the principles of the General Data Protection Regulation (GDPR) as a matter of best practice.
Data Controller
rascecical acts as the data controller for personal information collected through this website. Our contact details are:
rascecical
142 Collins Street
Melbourne, VIC 3000
Australia
Email: [email protected]
Legal Basis for Processing
Under the GDPR, we process personal data based on one or more of the following legal grounds:
Consent
Where you have provided explicit consent for us to process your data for specific purposes. You may withdraw consent at any time by contacting us.
Contract Performance
Where processing is necessary to fulfil a contract with you or to take steps at your request before entering into a contract (such as booking an appointment).
Legitimate Interests
Where we have a legitimate business interest that does not override your fundamental rights and freedoms. This includes improving our services and understanding how our website is used.
Legal Obligations
Where we are required to process data to comply with legal requirements.
Your Rights Under GDPR
If you are located in the EEA or UK, you have the following rights regarding your personal data:
Right of Access
You have the right to request a copy of the personal data we hold about you. We will provide this information free of charge within one month of your request.
Right to Rectification
You have the right to request correction of any inaccurate or incomplete personal data we hold about you.
Right to Erasure (Right to be Forgotten)
You have the right to request deletion of your personal data in certain circumstances, including when:
- The data is no longer necessary for its original purpose
- You withdraw consent and there is no other legal basis for processing
- You object to processing and there are no overriding legitimate grounds
- The data has been unlawfully processed
Right to Restriction of Processing
You have the right to request that we restrict processing of your personal data in certain circumstances, such as when you contest the accuracy of the data.
Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller.
Right to Object
You have the right to object to processing of your personal data based on legitimate interests or for direct marketing purposes.
Rights Related to Automated Decision-Making
You have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects. We do not currently use automated decision-making processes.
Exercising Your Rights
To exercise any of these rights, please contact us at [email protected]. We will respond to your request within one month. In complex cases, we may extend this period by up to two months, but we will inform you of any extension within the first month.
We may request proof of identity before processing your request to ensure the security of your data.
Data Transfers
As we are based in Australia, your data may be transferred to and processed in Australia. Australia has been recognised by the European Commission as providing an adequate level of data protection. We also implement appropriate safeguards to protect data transferred internationally.
Data Retention
We retain personal data only for as long as necessary for the purposes for which it was collected. Retention periods depend on:
- The nature of the data and the purposes for processing
- Legal and regulatory requirements
- The need to establish, exercise, or defend legal claims
When data is no longer required, we securely delete or anonymise it.
Data Security
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, or destruction. These measures include:
- Encryption of data in transit
- Secure storage systems
- Access controls and authentication
- Regular security assessments
- Staff training on data protection
Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. If the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay.
Supervisory Authority
If you are located in the EEA or UK and believe that we have not complied with data protection laws, you have the right to lodge a complaint with your local data protection supervisory authority.
Updates to This Notice
We may update this GDPR notice from time to time. Any changes will be posted on this page with an updated revision date.
Contact Us
For any questions about this GDPR notice or our data protection practices, please contact us:
Email: [email protected]
Address: 142 Collins Street, Melbourne, VIC 3000, Australia