Information on this site is advertising in nature.

GDPR Information

Information for visitors from the European Union and European Economic Area.

Last updated: July 2024

Our Commitment to GDPR Compliance

jolly-sprout is committed to protecting the privacy and rights of all website visitors, including those from the European Union and European Economic Area. This page provides information specific to the General Data Protection Regulation (GDPR) requirements.

This information supplements our Privacy Policy and should be read in conjunction with it.

Data Controller

For the purposes of GDPR, jolly-sprout is the data controller for personal information collected through this website. Our contact details are:

jolly-sprout
Level 8, 210 Collins Street
Melbourne VIC 3000
Australia

Email: [email protected]

Legal Basis for Processing

Under GDPR, we process personal data based on the following legal grounds:

  • Consent (Article 6(1)(a)): When you provide explicit consent, such as subscribing to communications or submitting an enquiry form.
  • Contract (Article 6(1)(b)): When processing is necessary to perform a contract with you or to take steps at your request before entering a contract.
  • Legitimate Interests (Article 6(1)(f)): When processing is necessary for our legitimate business interests, provided these do not override your fundamental rights and freedoms.
  • Legal Obligation (Article 6(1)(c)): When we are required to process data to comply with legal obligations.

Your Rights Under GDPR

If you are located in the EU or EEA, you have the following rights regarding your personal data:

Right of Access (Article 15)

You have the right to request a copy of the personal data we hold about you and information about how we process it.

Right to Rectification (Article 16)

You can request correction of inaccurate personal data or completion of incomplete data.

Right to Erasure (Article 17)

Also known as the "right to be forgotten," you can request deletion of your personal data in certain circumstances, such as when the data is no longer necessary for the purposes for which it was collected.

Right to Restriction (Article 18)

You can request that we limit the processing of your personal data in certain situations, such as when you contest the accuracy of the data.

Right to Data Portability (Article 20)

You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit it to another controller where technically feasible.

Right to Object (Article 21)

You can object to processing based on legitimate interests or for direct marketing purposes.

Rights Related to Automated Decision-Making (Article 22)

You have the right not to be subject to decisions based solely on automated processing that significantly affect you. We do not currently use automated decision-making processes.

Exercising Your Rights

To exercise any of these rights, please contact us using the details above. We will respond to your request within one month. This period may be extended by two further months where necessary, taking into account the complexity and number of requests.

We may need to verify your identity before processing your request. There is generally no fee for exercising your rights, though we may charge a reasonable fee for manifestly unfounded or excessive requests.

International Data Transfers

As jolly-sprout is based in Australia, your personal data may be transferred outside the EU/EEA. When we transfer data internationally, we ensure appropriate safeguards are in place, which may include:

  • Standard Contractual Clauses approved by the European Commission
  • Adequacy decisions where applicable
  • Other appropriate safeguards as permitted under GDPR

Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law. When determining retention periods, we consider:

  • The nature and sensitivity of the data
  • The purposes for which we process the data
  • Applicable legal and regulatory requirements
  • Legitimate business needs

Data Security

We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:

  • Encryption of personal data where appropriate
  • Regular security assessments
  • Access controls and authentication measures
  • Staff training on data protection

Data Breach Notification

In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly.

Complaints

If you believe we have not handled your personal data appropriately, you have the right to lodge a complaint with a supervisory authority in your country of residence. We encourage you to contact us first so we can address your concerns directly.

Updates to This Information

We may update this GDPR information periodically. The revised version will be posted on this page with an updated effective date.