GDPR Information
Your data protection rights under the General Data Protection Regulation
Last Updated: January 2024
Introduction
beam-fortress is committed to protecting and respecting your privacy in compliance with the General Data Protection Regulation (GDPR). This page provides information about your rights under GDPR and how we handle personal data of individuals located in the European Economic Area (EEA) and the United Kingdom.
Although we are based in Australia, we extend GDPR-level protections to all users where applicable.
Data Controller
For the purposes of GDPR, beam-fortress is the data controller responsible for your personal data. Our contact details are:
beam-fortress
47 Harbour View Road
Sydney, NSW 2000
Australia
Email: [email protected]
Legal Basis for Processing
We process your personal data on the following legal bases:
- Consent: Where you have given clear consent for us to process your personal data for specific purposes.
- Contract: Where processing is necessary for the performance of a contract with you or to take steps at your request before entering into a contract.
- Legal Obligation: Where processing is necessary for compliance with a legal obligation to which we are subject.
- Legitimate Interests: Where processing is necessary for our legitimate interests or those of a third party, provided those interests are not overridden by your rights and interests.
Your Rights Under GDPR
If you are located in the EEA or UK, you have the following rights regarding your personal data:
Right to Access
You have the right to request a copy of the personal data we hold about you. We will provide this information free of charge, typically within one month of your request.
Right to Rectification
You have the right to request that we correct any inaccurate personal data we hold about you. You also have the right to have incomplete data completed.
Right to Erasure
You have the right to request that we delete your personal data in certain circumstances, including when the data is no longer necessary for the purpose for which it was collected, or when you withdraw consent.
Right to Restriction of Processing
You have the right to request that we restrict the processing of your personal data in certain circumstances, such as when you contest the accuracy of the data or object to our processing.
Right to Data Portability
You have the right to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format. You also have the right to request that we transmit this data to another controller where technically feasible.
Right to Object
You have the right to object to the processing of your personal data based on legitimate interests or for direct marketing purposes. We will cease processing unless we have compelling legitimate grounds.
Rights Related to Automated Decision Making
You have the right not to be subject to decisions based solely on automated processing, including profiling, which produce legal effects or similarly significant effects. We do not currently use automated decision-making processes.
Exercising Your Rights
To exercise any of your GDPR rights, please contact us using the contact details provided above. We will respond to your request within one month. In certain circumstances, we may extend this period by two months, in which case we will inform you.
We may request specific information from you to confirm your identity before processing your request. This is a security measure to ensure personal data is not disclosed to unauthorised persons.
International Data Transfers
As we are based in Australia, your data may be transferred to and processed in Australia. Australia has been granted adequacy status by the European Commission, meaning personal data can be transferred from the EEA to Australia without additional safeguards. We also implement appropriate technical and organisational measures to protect your data.
Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy legal, accounting, or reporting requirements. When determining retention periods, we consider the amount, nature, and sensitivity of the data, the potential risk of harm from unauthorised use or disclosure, and applicable legal requirements.
Security Measures
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
- Encryption of personal data where appropriate
- Regular security assessments
- Staff training on data protection
- Access controls to limit who can access personal data
Complaints
If you are not satisfied with our response to your privacy concerns, you have the right to lodge a complaint with a supervisory authority. For EEA residents, this is typically the data protection authority in your country of residence. For UK residents, this is the Information Commissioner's Office (ICO).
Changes to This Notice
We may update this GDPR information from time to time. Any changes will be posted on this page with an updated revision date. We encourage you to review this page periodically.
Contact Us
For any questions about this GDPR information or to exercise your rights, please contact us at:
beam-fortress
47 Harbour View Road
Sydney, NSW 2000
Australia
Email: [email protected]