We are committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR) and applicable Australian privacy laws.
We process your personal data under the following legal bases:
If you are located in the European Economic Area, you have the following rights:
You have the right to request access to the personal data we hold about you. We will provide a copy of your data in a commonly used electronic format.
You can request correction of inaccurate or incomplete personal data we hold about you.
You have the right to request deletion of your personal data under certain circumstances, including when the data is no longer necessary for the purposes for which it was collected.
You can request that we restrict processing of your personal data in specific situations, such as when you contest the accuracy of the data.
You have the right to receive your personal data in a structured, commonly used, and machine-readable format and transmit it to another controller.
You can object to processing of your personal data based on legitimate interests or for direct marketing purposes.
Where processing is based on your consent, you have the right to withdraw that consent at any time.
For questions regarding GDPR compliance or to exercise your rights, please contact our data protection team at [email protected] with "GDPR Request" in the subject line.
Your personal data is primarily processed and stored in Australia. If data is transferred outside Australia or the EEA, we ensure appropriate safeguards are in place to protect your information.
We do not use automated decision-making or profiling that produces legal effects or similarly significantly affects you.
You have the right to lodge a complaint with a supervisory authority if you believe our processing of your personal data violates applicable data protection laws.
In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the relevant supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach.
Last updated: July 2024