Our commitment to protecting your data rights
Last updated: September 2024
Ruby-storm is committed to ensuring the protection of personal data in accordance with the General Data Protection Regulation (GDPR) and applicable Australian privacy legislation. While we are an Australian company, we recognise the importance of GDPR principles for our clients and contacts who may be located in the European Economic Area (EEA).
We process personal data under one or more of the following legal bases:
Under GDPR, individuals in the EEA have the following rights regarding their personal data:
You have the right to request a copy of the personal data we hold about you and to verify that we are processing it lawfully.
You have the right to request correction of any inaccurate personal data we hold about you, or to have incomplete data completed.
You have the right to request deletion of your personal data where there is no compelling reason for its continued processing. This right is not absolute and may be subject to legal obligations requiring us to retain certain data.
You have the right to request restriction of processing of your personal data in certain circumstances, such as when you contest the accuracy of the data or object to its processing.
You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit it to another controller where technically feasible.
You have the right to object to processing of your personal data based on legitimate interests or for direct marketing purposes.
You have the right not to be subject to decisions based solely on automated processing, including profiling, that produce legal effects or similarly significantly affect you.
We implement appropriate technical and organisational measures to protect personal data against unauthorised or unlawful processing and against accidental loss, destruction, or damage. These measures include:
We retain personal data only for as long as necessary for the purposes for which it was collected, or as required by law. When personal data is no longer needed, we securely delete or anonymise it.
As an Australian company, any transfer of personal data from the EEA to Australia is conducted in accordance with appropriate safeguards. Australia has been recognised by the European Commission as providing an adequate level of data protection.
In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals, we will notify the relevant supervisory authority without undue delay and, where feasible, within 72 hours. Where the breach is likely to result in a high risk, we will also notify affected individuals.
To exercise any of your data protection rights, please contact us using the details below. We will respond to your request within one month, though this period may be extended by a further two months for complex requests. We may need to verify your identity before processing your request.
If you believe that your data protection rights have been violated, you have the right to lodge a complaint with a supervisory authority. For individuals in the EEA, this would typically be the data protection authority in your country of residence. In Australia, complaints may be made to the Office of the Australian Information Commissioner.
For any questions regarding GDPR compliance or to exercise your data rights, please contact us at:
Email: [email protected]
Address: Level 12, 345 George Street, Sydney NSW 2000, Australia
The information provided on this website is for general guidance only and should not be considered professional security advice. Results may vary based on individual circumstances. We recommend consulting with qualified security professionals before implementing any security measures. Ruby-storm does not guarantee specific outcomes from our services.