Information for visitors from the European Economic Area
This page provides additional information for visitors and clients from the European Economic Area (EEA) regarding how grove-cypress processes personal data in compliance with the General Data Protection Regulation (GDPR).
grove-cypress acts as the data controller for personal information collected through this website and in the course of providing consulting services. Our contact details are:
grove-cypress
Level 12, 88 Walker Street
North Sydney NSW 2060
Australia
Email: [email protected]
We process personal data on the following legal bases:
If you are located in the EEA, you have the following rights regarding your personal data:
You have the right to request a copy of the personal data we hold about you, along with information about how we process it.
You have the right to request correction of any inaccurate or incomplete personal data we hold about you.
You have the right to request deletion of your personal data in certain circumstances, such as when the data is no longer necessary for the purposes for which it was collected.
You have the right to request that we restrict the processing of your personal data in certain circumstances, such as while we verify the accuracy of data you have challenged.
You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit it to another controller, where technically feasible.
You have the right to object to processing of your personal data based on legitimate interests or for direct marketing purposes.
Where processing is based on consent, you have the right to withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing prior to withdrawal.
As an Australian organisation, personal data collected from EEA residents may be transferred to and processed in Australia. Australia has been recognised by the European Commission as providing an adequate level of protection for personal data. We also implement appropriate safeguards where required to ensure your data remains protected in accordance with GDPR requirements.
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, after which it is securely deleted or anonymised. The specific retention period depends on the nature of the data and the purpose of processing.
We do not engage in automated decision-making, including profiling, that produces legal effects or similarly significantly affects individuals.
To exercise any of your rights under GDPR, please contact us using the details provided above. We will respond to your request within one month of receipt. In certain circumstances, we may extend this period by up to two months, in which case we will inform you of the extension and the reasons for it.
If you believe that we have not handled your personal data in accordance with GDPR, you have the right to lodge a complaint with a supervisory authority in the EEA member state of your habitual residence, place of work, or place of the alleged infringement.
Last updated: September 2024