Overview
The General Data Protection Regulation (GDPR) is a European Union regulation that governs the processing of personal data of individuals within the EU and EEA. Although Hollow Wren Environmental Consulting is based in Australia, we are committed to protecting the privacy of all our clients and website visitors, including those in the European Union.
This page explains how we comply with GDPR requirements when processing personal data of EU residents.
Data Controller
For the purposes of the GDPR, the data controller is:
Hollow Wren Environmental ConsultingLevel 3, 42 Greenway Circuit
Brisbane, QLD 4000
Australia
Email: [email protected]
Legal Basis for Processing
We process personal data under the following legal bases as defined by the GDPR:
- Consent: Where you have given clear consent for us to process your personal data for a specific purpose
- Contract: Where processing is necessary for the performance of a contract with you or to take steps at your request before entering into a contract
- Legal obligation: Where processing is necessary to comply with a legal obligation
- Legitimate interests: Where processing is necessary for our legitimate interests or those of a third party, provided your rights do not override those interests
Your Rights Under GDPR
If you are a resident of the European Union, you have the following rights regarding your personal data:
Right of Access
You have the right to request a copy of the personal data we hold about you. We will provide this information free of charge within one month of your request.
Right to Rectification
You have the right to request that we correct any inaccurate personal data we hold about you without undue delay.
Right to Erasure
You have the right to request that we delete your personal data in certain circumstances, including when the data is no longer necessary for the purposes for which it was collected, or when you withdraw consent.
Right to Restrict Processing
You have the right to request that we restrict the processing of your personal data in certain circumstances, such as when you contest the accuracy of the data or object to processing.
Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller without hindrance.
Right to Object
You have the right to object to the processing of your personal data where we are relying on legitimate interests as our legal basis, or where processing is for direct marketing purposes.
Rights Related to Automated Decision-Making
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you. We do not currently use automated decision-making processes.
International Data Transfers
As an Australian company, personal data you provide to us may be transferred to and stored in Australia. Australia is not subject to an adequacy decision by the European Commission. However, we implement appropriate safeguards to ensure your personal data remains protected in accordance with GDPR requirements, including:
- Standard contractual clauses approved by the European Commission
- Ensuring any third-party service providers maintain adequate data protection measures
- Implementing technical and organisational security measures
Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable laws. When determining retention periods, we consider:
- The nature and sensitivity of the data
- The purposes for which we process the data
- Applicable legal requirements
- Our legitimate business interests
Data Security
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
- Encryption of data in transit and at rest where appropriate
- Access controls limiting who can view personal data
- Regular security assessments and updates
- Staff training on data protection
Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. If the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly.
Exercising Your Rights
To exercise any of your rights under the GDPR, or if you have any questions about how we process your personal data, please contact us at:
Email: [email protected]
We will respond to your request within one month. If your request is complex or we receive multiple requests, we may extend this period by a further two months, but we will inform you of any extension within the initial one-month period.
Complaints
If you believe that we have not complied with your data protection rights, you have the right to lodge a complaint with a supervisory authority. If you are in the EU, you can contact the supervisory authority in the EU member state of your habitual residence, place of work, or place of the alleged infringement.
Updates to This Notice
We may update this GDPR compliance notice from time to time. Any changes will be posted on this page with an updated revision date.
Last updated: January 2024