Your data protection rights under the General Data Protection Regulation
At calm-craft, we are committed to protecting the privacy and security of your personal data. This page outlines our compliance with the General Data Protection Regulation (GDPR) and explains the rights available to individuals in the European Economic Area (EEA) and other jurisdictions with similar data protection laws.
calm-craft acts as the data controller for personal information collected through our website and services. This means we determine the purposes and means of processing your personal data. We are responsible for ensuring that your data is processed lawfully, fairly, and transparently.
We process personal data only when we have a valid legal basis to do so. The legal bases we rely on include:
The GDPR provides individuals with several rights regarding their personal data:
You have the right to request a copy of the personal data we hold about you. We will provide this information within one month of receiving your request, along with details about how we use your data.
If you believe any personal data we hold about you is inaccurate or incomplete, you have the right to request that we correct or complete it.
Also known as the "right to be forgotten," you can request that we delete your personal data in certain circumstances, such as when the data is no longer necessary for the purpose it was collected.
You have the right to request that we limit the processing of your personal data in certain circumstances, such as when you contest the accuracy of the data or object to our processing.
Where technically feasible, you can request to receive your personal data in a structured, commonly used, and machine-readable format, or have it transmitted directly to another controller.
You have the right to object to the processing of your personal data based on legitimate interests or for direct marketing purposes. We will stop processing unless we can demonstrate compelling legitimate grounds.
You have the right not to be subject to decisions based solely on automated processing, including profiling, which produce legal effects or similarly significantly affect you.
To exercise any of these rights, please contact our Data Protection Officer using the contact details provided below. We may ask you to verify your identity before processing your request. We will respond to your request within one month, although this period may be extended by two further months for complex requests.
As an Australian company, we may transfer personal data outside the EEA. When we do so, we ensure appropriate safeguards are in place, such as standard contractual clauses approved by the European Commission or reliance on adequacy decisions.
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable laws. Our retention periods are based on business needs and legal requirements, and we regularly review our data holdings to ensure compliance.
We implement appropriate technical and organisational measures to protect personal data against unauthorised or unlawful processing, accidental loss, destruction, or damage. These measures include encryption, access controls, and regular security assessments.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. Where the breach is likely to result in a high risk, we will also notify affected individuals without undue delay.
If you are not satisfied with how we handle your personal data or respond to your requests, you have the right to lodge a complaint with a supervisory authority. For individuals in the EEA, this is typically the data protection authority in your country of residence.
For questions about GDPR compliance or to exercise your rights, please contact our Data Protection Officer:
Email: [email protected]
Address: Level 4, 127 Creek Street, Brisbane QLD 4000, Australia
Last updated: January 2024