GDPR Compliance
Your data protection rights
Our Commitment to Data Protection
arc-gleam is committed to protecting the personal data of all individuals, including those covered by the General Data Protection Regulation (GDPR). This page outlines our compliance measures and your rights under data protection legislation.
Data Controller
arc-gleam acts as the data controller for personal information collected through this website. We determine the purposes and means of processing your personal data in accordance with applicable laws.
Lawful Basis for Processing
We process personal data under the following lawful bases:
- Consent: Where you have given clear consent for us to process your personal data for specific purposes
- Contract: Where processing is necessary for a contract we have with you or to take steps at your request before entering into a contract
- Legitimate Interests: Where processing is necessary for our legitimate interests or those of a third party, provided your rights do not override these interests
- Legal Obligation: Where processing is necessary to comply with legal requirements
Your Rights Under GDPR
If you are located in the European Economic Area or if GDPR applies to you, you have the following rights:
Right of Access
You have the right to request a copy of the personal data we hold about you. We will provide this information within one month of your request.
Right to Rectification
You can request that we correct any inaccurate personal data or complete any incomplete data we hold about you.
Right to Erasure
You have the right to request deletion of your personal data in certain circumstances, such as when the data is no longer necessary for its original purpose.
Right to Restrict Processing
You can ask us to limit how we use your personal data in certain situations, such as when you contest the accuracy of the data.
Right to Data Portability
Where processing is based on consent or contract and carried out by automated means, you have the right to receive your personal data in a structured, commonly used format.
Right to Object
You have the right to object to processing based on legitimate interests, direct marketing, or processing for research purposes.
Rights Related to Automated Decision Making
You have the right not to be subject to decisions based solely on automated processing that produce legal effects or similarly significant effects. We do not currently engage in such automated decision making.
International Data Transfers
We primarily process data within Australia. Where data is transferred outside Australia or the EEA, we ensure appropriate safeguards are in place to protect your data in accordance with GDPR requirements.
Data Breach Procedures
We have procedures in place to detect, report, and investigate personal data breaches. Where a breach is likely to result in a high risk to your rights, we will notify you without undue delay.
Exercising Your Rights
To exercise any of these rights, please contact us using the details below. We may need to verify your identity before processing your request. We will respond to valid requests within one month, though this may be extended for complex requests.
Complaints
If you believe your data protection rights have been violated, you have the right to lodge a complaint with the relevant supervisory authority. In Australia, this is the Office of the Australian Information Commissioner (OAIC).
Contact for Data Protection Queries
For any questions regarding GDPR or your data protection rights:
arc-gleam
15 Harbour Street
Sydney NSW 2000
Australia
[email protected]