Last Updated: January 2024
lagoon-vertex is committed to protecting the personal data of all visitors, including those located in the European Economic Area (EEA). This page provides information about how we comply with the General Data Protection Regulation (GDPR) and your rights under this regulation.
What is GDPR?
The General Data Protection Regulation (GDPR) is a comprehensive data protection law that came into effect on 25 May 2018. It provides individuals in the European Union and European Economic Area with enhanced rights regarding how their personal data is collected, stored, and used.
Data Controller
For the purposes of GDPR, lagoon-vertex is the data controller responsible for your personal data. Our contact details are:
lagoon-vertex
45 King William Street
Adelaide SA 5000
Australia
Email: [email protected]
Legal Basis for Processing
We process your personal data on the following legal bases:
Consent
When you submit an enquiry form or subscribe to our communications, you provide consent for us to process your data for these specific purposes. You may withdraw consent at any time by contacting us.
Contractual Necessity
When you book a tour with us, we process your data as necessary to fulfil our contractual obligations, including arranging travel services, communicating booking details, and processing payments.
Legitimate Interests
We may process data for our legitimate business interests, such as improving our services, analysing website usage, and protecting against fraud. We balance these interests against your rights and freedoms.
Legal Obligation
We may process your data to comply with legal requirements, such as tax reporting, consumer protection laws, and responding to lawful requests from authorities.
Your Rights Under GDPR
If you are located in the EEA, you have the following rights regarding your personal data:
Right of Access
You have the right to request a copy of the personal data we hold about you. We will provide this information free of charge within one month of your request.
Right to Rectification
You have the right to request correction of any inaccurate or incomplete personal data we hold about you.
Right to Erasure
Also known as the "right to be forgotten," you can request that we delete your personal data in certain circumstances, such as when the data is no longer necessary for the purpose it was collected, or you withdraw consent.
Right to Restriction of Processing
You can request that we restrict the processing of your personal data in certain situations, such as while we verify the accuracy of disputed data or determine whether our legitimate interests override your rights.
Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit that data to another controller.
Right to Object
You have the right to object to processing of your personal data based on legitimate interests or for direct marketing purposes.
Rights Related to Automated Decision-Making
You have the right not to be subject to decisions based solely on automated processing that significantly affect you. We do not currently use automated decision-making processes.
International Data Transfers
As we are based in Australia, your personal data may be transferred to and processed in Australia, which is outside the EEA. Australia is not subject to an adequacy decision by the European Commission.
When we transfer data internationally, we implement appropriate safeguards to protect your data, including:
- Standard contractual clauses approved by the European Commission
- Ensuring third-party recipients maintain adequate data protection standards
- Obtaining your explicit consent for specific transfers where appropriate
Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected. Retention periods vary depending on the type of data:
- Enquiry data: 3 years from last contact
- Booking records: 7 years for legal and tax purposes
- Marketing preferences: Until you withdraw consent
- Website analytics: 26 months
Data Security
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
- Encryption of data in transit using SSL/TLS
- Access controls limiting data access to authorised personnel
- Regular security assessments and updates
- Staff training on data protection practices
Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours. If the breach is likely to result in high risk to your rights, we will also notify you directly.
Exercising Your Rights
To exercise any of your GDPR rights, please contact us using the details above. To help us process your request efficiently, please:
- Clearly state which right you wish to exercise
- Provide sufficient information to verify your identity
- Include any relevant details about the data concerned
We will respond to your request within one month. In complex cases, we may extend this period by up to two additional months, and we will inform you if this is necessary.
Complaints
If you believe we have not handled your personal data correctly, you have the right to lodge a complaint with a supervisory authority. For EU residents, this would typically be the data protection authority in your country of residence. You may also contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
Updates to This Information
We may update this GDPR information from time to time. We will notify you of significant changes through our website or direct communication where appropriate.