hazy-crag is committed to protecting the personal data of all individuals, including those residing in the European Economic Area (EEA). This page outlines how we comply with the General Data Protection Regulation (GDPR).
Data Controller
hazy-crag acts as the data controller for personal information collected through our website and services. We determine the purposes and means of processing personal data.
Legal Basis for Processing
We process personal data under the following legal bases:
- Contractual necessity: Processing required to fulfil our service agreement with you
- Consent: Where you have given explicit consent for specific processing activities
- Legitimate interests: Where processing is necessary for our legitimate business interests, provided these do not override your rights
- Legal obligation: Where processing is required to comply with applicable laws
Your Rights Under GDPR
If you are located in the EEA, you have the following rights regarding your personal data:
Right of Access
You have the right to request a copy of the personal data we hold about you, along with information about how we use it.
Right to Rectification
You have the right to request correction of any inaccurate personal data we hold about you.
Right to Erasure
You have the right to request deletion of your personal data in certain circumstances, such as when the data is no longer necessary for the purposes for which it was collected.
Right to Restrict Processing
You have the right to request that we limit how we use your personal data in certain circumstances.
Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit it to another controller.
Right to Object
You have the right to object to our processing of your personal data based on legitimate interests or for direct marketing purposes.
Rights Related to Automated Decision-Making
You have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects concerning you.
International Data Transfers
Our instructors are located globally. When we transfer personal data outside the EEA, we ensure appropriate safeguards are in place, such as:
- Standard contractual clauses approved by the European Commission
- Transfers to countries deemed to provide adequate protection
- Other lawful transfer mechanisms
Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected. Specific retention periods depend on the nature of the data and our legal obligations.
Data Security
We implement technical and organisational measures to protect personal data, including encryption, access controls, and regular security assessments.
Data Breach Notification
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and inform affected individuals without undue delay.
Exercising Your Rights
To exercise any of your GDPR rights, please contact us at:
Email: [email protected]
Address: Level 12, 180 George Street, Sydney NSW 2000, Australia
We will respond to your request within one month. In complex cases, this period may be extended by up to two additional months, and we will inform you of any such extension.
Complaints
If you believe we have not handled your personal data appropriately, you have the right to lodge a complaint with a supervisory authority in your country of residence.
Updates to This Notice
We may update this GDPR notice periodically. Any changes will be posted on this page with an updated revision date.