GDPR Compliance
Our commitment to data protection under the General Data Protection Regulation
Last updated: January 2024
Overview
vale-path is committed to ensuring the protection of personal data in accordance with the General Data Protection Regulation (GDPR). This page outlines our approach to GDPR compliance and the rights available to individuals whose data we process.
Data Controller
vale-path acts as the data controller for personal information collected through this website. We determine the purposes and means of processing personal data and are responsible for ensuring compliance with applicable data protection legislation.
Lawful Basis for Processing
We process personal data on the following lawful bases:
- Consent: Where you have given clear consent for us to process your personal data for a specific purpose
- Contract: Where processing is necessary for the performance of a contract with you
- Legal obligation: Where processing is necessary for compliance with a legal obligation
- Legitimate interests: Where processing is necessary for our legitimate interests, provided these do not override your rights
Your Rights Under GDPR
If you are located in the European Economic Area, you have the following rights:
Right to Access
You have the right to request copies of your personal data. We may charge a small fee for this service in certain circumstances.
Right to Rectification
You have the right to request that we correct any information you believe is inaccurate or complete information you believe is incomplete.
Right to Erasure
You have the right to request that we erase your personal data, under certain conditions. This right is not absolute and may be subject to legal retention requirements.
Right to Restrict Processing
You have the right to request that we restrict the processing of your personal data, under certain conditions.
Right to Object
You have the right to object to our processing of your personal data, under certain conditions, particularly where we rely on legitimate interests.
Right to Data Portability
You have the right to request that we transfer the data we have collected to another organisation, or directly to you, under certain conditions.
Exercising Your Rights
To exercise any of these rights, please contact us using the details below. We will respond to your request within one month of receiving it. If your request is complex, we may extend this period by a further two months, in which case we will inform you.
Data Transfers
When we transfer personal data outside the European Economic Area, we ensure appropriate safeguards are in place, such as standard contractual clauses approved by the European Commission or adequacy decisions.
Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly.
Data Protection Officer
For matters relating to data protection and GDPR compliance, please contact us at:
Email: [email protected]
Address: 47 Industrial Circuit, Dandenong South VIC 3175, Australia
Supervisory Authority
You have the right to lodge a complaint with a supervisory authority if you believe your data protection rights have been violated. In Australia, this is the Office of the Australian Information Commissioner (OAIC).