GDPR Compliance
Your data protection rights under GDPR
Introduction
Although Sleek Weave is based in Australia, we recognize and respect the data protection rights of individuals in the European Union under the General Data Protection Regulation (GDPR). This page explains how we comply with GDPR principles when processing personal data of EU residents.
Legal Basis for Processing
We process personal data only when we have a legal basis to do so. Our legal bases include:
- Consent: You have given clear consent for us to process your personal data for specific purposes
- Contract: Processing is necessary for a contract we have with you, or because you have asked us to take specific steps before entering into a contract
- Legal Obligation: Processing is necessary for us to comply with the law
- Legitimate Interests: Processing is necessary for our legitimate interests or the legitimate interests of a third party, provided those interests are not overridden by your rights and interests
Your Rights Under GDPR
If you are an EU resident, you have the following rights regarding your personal data:
Right to Access
You have the right to request copies of your personal data. We may charge a reasonable fee for this service if your request is clearly unfounded or excessive.
Right to Rectification
You have the right to request that we correct any information you believe is inaccurate or complete information you believe is incomplete.
Right to Erasure
You have the right to request that we erase your personal data, under certain conditions, including when:
- The personal data is no longer necessary for the purpose we collected it
- You withdraw your consent
- You object to the processing and there are no overriding legitimate grounds
- The personal data has been unlawfully processed
Right to Restrict Processing
You have the right to request that we restrict the processing of your personal data, under certain conditions.
Right to Object to Processing
You have the right to object to our processing of your personal data, under certain conditions, including processing for direct marketing purposes.
Right to Data Portability
You have the right to request that we transfer the data we have collected to another organization, or directly to you, under certain conditions.
Right to Withdraw Consent
Where we rely on consent as the legal basis for processing, you have the right to withdraw your consent at any time. This will not affect the lawfulness of processing based on consent before its withdrawal.
Data Protection Officer
For GDPR-related inquiries, you may contact our Data Protection Officer:
Email: [email protected]
How We Protect Your Data
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- Encryption of personal data in transit and at rest
- Regular security assessments and audits
- Access controls and authentication procedures
- Staff training on data protection and security
- Secure backup and disaster recovery procedures
International Data Transfers
When we transfer personal data from the EU to countries outside the European Economic Area, we ensure appropriate safeguards are in place, such as:
- Standard contractual clauses approved by the European Commission
- Adequacy decisions by the European Commission
- Binding corporate rules
Data Breach Notification
In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the relevant supervisory authority within 72 hours of becoming aware of the breach, where feasible.
Automated Decision-Making
We do not use your personal data for automated decision-making, including profiling, that produces legal effects or similarly significantly affects you.
Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including:
- Service delivery and customer support
- Compliance with legal, tax, and regulatory requirements
- Resolution of disputes and enforcement of agreements
Third-Party Processors
We carefully select third-party processors and ensure they provide sufficient guarantees to implement appropriate technical and organizational measures to meet GDPR requirements. We enter into data processing agreements with all processors that handle personal data on our behalf.
Children's Data
Our services are not directed at children under 16 years of age. We do not knowingly collect or process personal data from children. If we become aware that we have collected data from a child, we will take steps to delete it promptly.
Marketing Communications
We will only send you marketing communications if you have given us consent to do so. You can withdraw your consent at any time by:
- Clicking the unsubscribe link in any marketing email
- Contacting us at [email protected]
Exercising Your Rights
To exercise any of your GDPR rights, please contact us:
Email: [email protected]
Address: Level 12, 180 Lonsdale Street, Melbourne VIC 3000, Australia
We will respond to your request within one month. If your request is complex or we have received multiple requests, we may extend this period by two additional months, in which case we will inform you.
Right to Lodge a Complaint
If you believe we have not handled your personal data in accordance with GDPR, you have the right to lodge a complaint with a supervisory authority in the EU member state where you live, work, or where the alleged infringement occurred.
Updates to This Policy
We may update this GDPR compliance statement from time to time. Any changes will be posted on this page with an updated revision date. We encourage you to review this page periodically.
Contact Information
For any questions about our GDPR compliance or data protection practices:
Email: [email protected]
Data Protection Officer: [email protected]