GDPR Compliance
Information about your data protection rights.
Last updated: January 2024
Overview
The General Data Protection Regulation (GDPR) is a European Union regulation that protects the personal data and privacy of individuals. While cove-cipher is based in Australia, we respect the privacy rights of all visitors and have implemented practices consistent with GDPR principles for any visitors from the European Economic Area (EEA).
Data Controller
cove-cipher acts as the data controller for personal information collected through this website. Our contact details are:
Email: [email protected]
Address: 42 Industrial Drive, Alexandria NSW 2015, Australia
Legal Basis for Processing
We process personal data on the following legal bases:
- Consent - When you voluntarily submit information through our forms or accept cookies
- Legitimate Interest - To respond to enquiries and provide requested services
- Contract - To fulfil service bookings and appointments
- Legal Obligation - To comply with applicable laws and regulations
Your Rights Under GDPR
If you are located in the EEA, you have the following rights regarding your personal data:
Right to Access
You have the right to request a copy of the personal data we hold about you. We will provide this information free of charge within one month of your request.
Right to Rectification
You have the right to request that we correct any inaccurate personal data or complete any incomplete data we hold about you.
Right to Erasure
You have the right to request that we delete your personal data in certain circumstances, such as when the data is no longer necessary for the purpose it was collected.
Right to Restrict Processing
You have the right to request that we limit the processing of your personal data in certain circumstances, such as when you contest the accuracy of the data.
Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller.
Right to Object
You have the right to object to the processing of your personal data in certain circumstances, including processing for direct marketing purposes.
Right to Withdraw Consent
Where we rely on your consent to process your personal data, you have the right to withdraw that consent at any time. This will not affect the lawfulness of processing carried out before the withdrawal.
Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law. Typical retention periods include:
- Enquiry data: 2 years from last contact
- Service records: 7 years for legal and warranty purposes
- Marketing preferences: Until consent is withdrawn
International Transfers
As we are based in Australia, personal data collected from EEA visitors may be transferred to and stored in Australia. Australia is not subject to an EU adequacy decision; however, we implement appropriate safeguards to protect your data during such transfers.
Data Security
We implement appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access.
Exercising Your Rights
To exercise any of your GDPR rights, please contact us at:
Email: [email protected]
We will respond to your request within one month. In complex cases, this period may be extended by a further two months, in which case we will inform you of the extension and the reasons for it.
Complaints
If you believe that we have not handled your personal data in accordance with GDPR, you have the right to lodge a complaint with a supervisory authority in the EU member state of your residence, place of work, or place of the alleged infringement.
Updates
We may update this GDPR information from time to time. Any changes will be posted on this page with an updated revision date.