GDPR Compliance
Your data protection rights under the General Data Protection Regulation
Our Commitment to GDPR
Storm Chant is committed to protecting the personal data of individuals located in the European Economic Area (EEA) in accordance with the General Data Protection Regulation (GDPR). This page outlines your rights and our responsibilities under GDPR.
Legal Basis for Processing
We process your personal data under the following legal bases:
- Consent: When you have given clear consent for us to process your personal data for specific purposes
- Contract: When processing is necessary for the performance of a contract with you
- Legal obligation: When we must process your data to comply with the law
- Legitimate interests: When processing is necessary for our legitimate interests or those of a third party, provided your rights do not override those interests
Your Rights Under GDPR
Right to Access
You have the right to request copies of your personal data. We may charge a reasonable fee if your request is clearly unfounded or excessive.
Right to Rectification
You have the right to request that we correct any information you believe is inaccurate or complete information you believe is incomplete.
Right to Erasure
You have the right to request that we erase your personal data under certain conditions, including when the data is no longer necessary for the purposes for which it was collected.
Right to Restrict Processing
You have the right to request that we restrict the processing of your personal data under certain conditions.
Right to Object
You have the right to object to our processing of your personal data under certain conditions, particularly for direct marketing purposes.
Right to Data Portability
You have the right to request that we transfer the data we have collected to another organisation, or directly to you, under certain conditions.
Right to Withdraw Consent
Where we rely on consent as the legal basis for processing, you have the right to withdraw your consent at any time.
How We Protect Your Data
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
- Encryption of personal data in transit and at rest
- Regular security assessments and updates
- Access controls and authentication procedures
- Staff training on data protection and security
- Incident response and breach notification procedures
Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including any legal, accounting, or reporting requirements. When determining retention periods, we consider:
- The nature and sensitivity of the data
- The purposes for which we process the data
- Legal and regulatory requirements
- Whether we can achieve those purposes through other means
International Data Transfers
If we transfer your personal data outside the EEA, we ensure appropriate safeguards are in place, such as:
- Standard contractual clauses approved by the European Commission
- Transfers to countries with adequacy decisions
- Other legally approved transfer mechanisms
Data Breach Notification
In the event of a data breach that is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay, in accordance with GDPR requirements.
Automated Decision-Making
We do not engage in automated decision-making or profiling that produces legal effects or similarly significantly affects you.
Exercising Your Rights
To exercise any of your rights under GDPR, please contact us at:
Email: [email protected]
Subject line: GDPR Request
We will respond to your request within one month. In complex cases, we may extend this period by two additional months, and we will inform you of any such extension.
Complaints
If you believe we have not handled your personal data in accordance with GDPR, you have the right to lodge a complaint with a supervisory authority in the EEA country where you live, work, or where the alleged infringement occurred.
Contact Our Data Protection Officer
For questions specifically related to data protection and GDPR compliance, you may contact our data protection representative:
Email: [email protected]
Address: Level 3, 127 Collins Street, Melbourne VIC 3000, Australia