Last Updated: January 2024

1. Introduction

reef-moose is committed to protecting your personal data and respecting your privacy rights. This page outlines how we comply with the General Data Protection Regulation (GDPR) for visitors from the European Economic Area (EEA) and how we extend similar protections to all our users.

2. Data Controller

reef-moose acts as the data controller for personal information collected through our website and services. This means we determine why and how your personal data is processed.

Contact Details:
reef-moose
47 Harbour View Road
Sydney, NSW 2000
Australia
Email: [email protected]

3. Legal Basis for Processing

We process personal data only when we have a lawful basis to do so. The legal bases we rely on include:

  • Consent: When you have given clear consent for us to process your personal data for a specific purpose (e.g., marketing communications).
  • Contract: When processing is necessary to fulfil a contract with you or to take steps at your request before entering into a contract (e.g., providing pet care services).
  • Legal obligation: When processing is necessary to comply with legal requirements.
  • Legitimate interests: When processing is necessary for our legitimate interests or those of a third party, provided your rights do not override these interests.

4. Your Rights Under GDPR

If you are located in the EEA, you have the following rights regarding your personal data:

Right to Access

You have the right to request copies of your personal data. We may charge a small fee for this service if requests are excessive or unfounded.

Right to Rectification

You have the right to request that we correct any information you believe is inaccurate or complete information you believe is incomplete.

Right to Erasure

You have the right to request that we erase your personal data under certain conditions, such as when the data is no longer necessary for the purpose it was collected.

Right to Restrict Processing

You have the right to request that we restrict the processing of your personal data under certain conditions, such as when you contest the accuracy of the data.

Right to Data Portability

You have the right to request that we transfer the data we have collected to another organisation, or directly to you, under certain conditions.

Right to Object

You have the right to object to our processing of your personal data under certain conditions, including processing for direct marketing purposes.

Rights Related to Automated Decision-Making

You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you.

5. Exercising Your Rights

To exercise any of these rights, please contact us at [email protected] with your request. We will respond within one month of receiving your request. This period may be extended by two further months where necessary, taking into account the complexity and number of requests.

We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data or exercise any of your other rights.

6. International Data Transfers

As reef-moose is based in Australia, your personal data may be transferred to and processed in Australia. When we transfer personal data from the EEA, we ensure appropriate safeguards are in place, such as:

  • Standard contractual clauses approved by the European Commission
  • Ensuring the recipient country has been deemed to provide adequate data protection
  • Obtaining your explicit consent for the transfer

7. Data Retention

We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected. The criteria used to determine retention periods include:

  • The nature and sensitivity of the data
  • The purposes for which we process your data
  • Legal, regulatory, and contractual requirements
  • Our legitimate business interests

8. Data Security

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, or destruction. These measures include:

  • Encryption of data in transit and at rest
  • Regular security assessments
  • Access controls and authentication measures
  • Staff training on data protection

9. Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly.

10. Complaints

If you believe that we have not handled your personal data properly or that we have not complied with your rights under the GDPR, you have the right to lodge a complaint with a supervisory authority.

For EEA residents, this would be the data protection authority in your country of residence. For Australian residents, you may contact the Office of the Australian Information Commissioner (OAIC).

11. Updates to This Page

We may update this GDPR compliance information from time to time. We will post any changes on this page and update the "Last Updated" date at the top.

12. Contact Us

For any questions about our GDPR compliance or to exercise your data protection rights, please contact us:

reef-moose
47 Harbour View Road
Sydney, NSW 2000
Australia
Email: [email protected]