Your data protection rights under the General Data Protection Regulation
storm-rhythm is committed to protecting and respecting your privacy in accordance with the General Data Protection Regulation (GDPR). This page outlines how we comply with GDPR requirements and explains your rights as a data subject.
storm-rhythm is the data controller for personal information collected through this website. We determine the purposes and means of processing your personal data.
Contact details:
Email: [email protected]
Address: Level 8, 350 Collins Street, Melbourne VIC 3000, Australia
We process personal data under the following legal bases:
Under GDPR, you have the following rights regarding your personal data:
You have the right to request a copy of the personal information we hold about you. We will provide this information within one month of receiving your request.
You have the right to request that we correct any inaccurate personal data and complete any incomplete personal data.
You have the right to request that we delete your personal data in certain circumstances, including when the data is no longer necessary for the purpose for which it was collected.
You have the right to request that we restrict the processing of your personal data in certain circumstances, such as when you contest the accuracy of the data.
You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller.
You have the right to object to processing of your personal data in certain circumstances, including processing for direct marketing purposes.
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you.
To exercise any of these rights, please contact us at:
Email: [email protected]
We will respond to your request within one month. In complex cases, this period may be extended by two further months, in which case we will inform you of the extension and the reasons for it.
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected. Specific retention periods depend on the type of data and the purposes for processing. When data is no longer needed, it is securely deleted or anonymised.
If we transfer personal data outside the European Economic Area, we ensure appropriate safeguards are in place to protect your data, such as standard contractual clauses approved by the European Commission.
We implement appropriate technical and organisational measures to protect personal data against unauthorised or unlawful processing, accidental loss, destruction, or damage. These measures are regularly reviewed and updated as necessary.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly.
If you believe that your data protection rights have been violated, you have the right to lodge a complaint with a supervisory authority. In Australia, you can contact the Office of the Australian Information Commissioner (OAIC).
We may update this GDPR compliance information from time to time. Any changes will be posted on this page with an updated revision date.
Last updated: January 2024