Information on this site is advertising in nature.

Last Updated: January 2024

ginglgastr respects the privacy rights of individuals in the European Union and European Economic Area. This page outlines how we comply with the General Data Protection Regulation (GDPR) when processing personal data of EU/EEA residents.

Data Controller

ginglgastr acts as the data controller for personal information collected through our website and services. For data protection enquiries, contact us at [email protected].

Legal Bases for Processing

We process personal data under the following legal bases:

  • Consent: When you voluntarily submit information through our forms or subscribe to communications
  • Contractual Necessity: When processing is required to fulfil our service obligations
  • Legitimate Interests: For website analytics and service improvement, balanced against your privacy rights
  • Legal Obligation: When required to comply with applicable laws

Your Rights Under GDPR

As a data subject, you have the following rights:

Right of Access

You may request a copy of the personal data we hold about you.

Right to Rectification

You may request correction of inaccurate or incomplete personal data.

Right to Erasure

You may request deletion of your personal data where there is no compelling reason for continued processing.

Right to Restrict Processing

You may request that we limit how we use your data in certain circumstances.

Right to Data Portability

You may request your data in a structured, commonly used format for transfer to another service.

Right to Object

You may object to processing based on legitimate interests, including direct marketing.

Rights Related to Automated Decision-Making

We do not use automated decision-making processes that significantly affect you.

Exercising Your Rights

To exercise any of these rights, please contact us at [email protected]. We will respond to valid requests within one month. There is no fee for most requests, though we may charge a reasonable fee for manifestly unfounded or excessive requests.

International Data Transfers

When we transfer personal data outside the EU/EEA, we ensure appropriate safeguards are in place, such as standard contractual clauses approved by the European Commission.

Data Retention

We retain personal data only as long as necessary for the purposes collected, or as required by law. Retention periods vary based on the nature of the data and our legal obligations.

Data Security

We implement technical and organisational measures appropriate to the risk, including:

  • Encryption of data in transit
  • Access controls and authentication
  • Regular security assessments
  • Staff training on data protection

Data Breach Notification

In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours where feasible. Where the breach poses a high risk, we will also notify affected individuals directly.

Supervisory Authority

If you are unsatisfied with our handling of your data, you have the right to lodge a complaint with your local data protection supervisory authority.

Contact

For GDPR-related enquiries:

Email: [email protected]
Address: Level 12, 225 George Street, Sydney NSW 2000, Australia