Our Commitment to Data Protection
Ocean-grouse is committed to protecting the personal data of all individuals, including those located in the European Economic Area (EEA) and United Kingdom. Although we are based in Australia, we recognise the importance of the General Data Protection Regulation (GDPR) and have implemented measures to ensure compliance when processing data of individuals in these regions.
Data Controller Information
For the purposes of GDPR, ocean-grouse acts as the data controller for personal information collected through this website. Our contact details are:
Ocean-grouse
47 Flinders Lane
Melbourne VIC 3000
Australia
Email: [email protected]
Personal Data We Process
We may collect and process the following categories of personal data:
- Identity data: name, title
- Contact data: email address, postal address
- Technical data: IP address, browser type, device information
- Usage data: information about how you use our website
- Communications data: enquiry content and correspondence
Legal Basis for Processing
We process personal data under the following legal bases as defined by GDPR:
Consent (Article 6(1)(a))
Where you have given clear consent for us to process your personal data for a specific purpose, such as receiving communications about our services.
Contract (Article 6(1)(b))
Where processing is necessary for the performance of a contract with you or to take steps at your request before entering into a contract.
Legitimate Interests (Article 6(1)(f))
Where processing is necessary for our legitimate interests or those of a third party, provided those interests are not overridden by your rights. Our legitimate interests include:
- Improving our website and services
- Ensuring the security of our systems
- Marketing our services to existing clients
Legal Obligation (Article 6(1)(c))
Where processing is necessary to comply with a legal obligation to which we are subject.
Your Rights Under GDPR
If you are located in the EEA or UK, you have the following rights regarding your personal data:
Right of Access (Article 15)
You have the right to obtain confirmation of whether we process your personal data and to receive a copy of that data, along with information about how it is processed.
Right to Rectification (Article 16)
You have the right to request correction of inaccurate personal data or completion of incomplete data.
Right to Erasure (Article 17)
You have the right to request deletion of your personal data in certain circumstances, such as when the data is no longer necessary for the purpose for which it was collected.
Right to Restriction of Processing (Article 18)
You have the right to request restriction of processing in certain circumstances, such as when you contest the accuracy of your data.
Right to Data Portability (Article 20)
You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit it to another controller.
Right to Object (Article 21)
You have the right to object to processing based on legitimate interests or for direct marketing purposes.
Rights Related to Automated Decision Making (Article 22)
You have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects. We do not currently use automated decision-making.
Exercising Your Rights
To exercise any of these rights, please contact us using the details provided above. We will respond to your request within one month. If your request is complex or we receive multiple requests, we may extend this period by up to two additional months, in which case we will inform you of the extension.
We may request specific information to help confirm your identity before processing your request. This is a security measure to ensure personal data is not disclosed to unauthorised persons.
International Data Transfers
As an Australian business, data you provide may be transferred to and stored in Australia. Where we transfer personal data outside the EEA, we ensure appropriate safeguards are in place, such as:
- Transfers to countries with adequate data protection laws
- Standard contractual clauses approved by the European Commission
- Other appropriate safeguards as permitted by GDPR
Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including legal, accounting, or reporting requirements. We apply the following retention periods:
- Enquiry data: 3 years from last contact
- Client records: 7 years from completion of services
- Analytics data: 26 months
Data Security
We have implemented appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures include:
- Encryption of data in transit
- Access controls and authentication
- Regular security assessments
- Staff training on data protection
Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly.
Complaints
If you are not satisfied with how we handle your personal data, you have the right to lodge a complaint with a supervisory authority. For EEA residents, this is typically the data protection authority in your country of residence. For UK residents, this is the Information Commissioner's Office (ICO).
Updates to This Information
We may update this GDPR information from time to time. Any changes will be posted on this page with an updated revision date.
Contact Us
For any questions about our GDPR compliance or to exercise your data protection rights, please contact us:
Ocean-grouse
47 Flinders Lane
Melbourne VIC 3000
Australia
Email: [email protected]