Last Updated: January 2024
orbitunive is committed to protecting the privacy and personal data of all individuals, including those protected under the General Data Protection Regulation (GDPR). This page outlines how we handle personal data in compliance with GDPR requirements.
orbitunive acts as the data controller for personal information collected through our website and services. As data controller, we determine the purposes and means of processing personal data.
Contact Details:
orbitunive
42 Harbour Street
Sydney, NSW 2000
Australia
[email protected]
We process personal data under the following legal bases:
If you are located in the European Economic Area (EEA) or the United Kingdom, you have the following rights regarding your personal data:
You have the right to request a copy of the personal data we hold about you. We will provide this information free of charge within one month of receiving your request.
You have the right to request that we correct any inaccurate personal data we hold about you. You also have the right to have incomplete data completed.
You have the right to request that we delete your personal data in certain circumstances, including when the data is no longer necessary for the purpose for which it was collected.
You have the right to request that we restrict the processing of your personal data in certain circumstances, such as when you contest the accuracy of the data.
You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller.
You have the right to object to the processing of your personal data for direct marketing purposes or when processing is based on legitimate interests.
You have the right not to be subject to decisions based solely on automated processing, including profiling, which produce legal effects concerning you.
To exercise any of your rights, please contact us at [email protected] with your request. We will respond to your request within one month. In complex cases, we may extend this period by up to two additional months, but we will inform you of any such extension within the initial one-month period.
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected. The retention period depends on the nature of the data and the purposes for processing. When data is no longer needed, we securely delete or anonymise it.
As we are based in Australia, personal data collected from individuals in the EEA or UK may be transferred to and processed in Australia. We ensure that appropriate safeguards are in place to protect your data in accordance with GDPR requirements.
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk of processing personal data. This includes measures to protect against unauthorised access, accidental loss, destruction, or damage.
In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay. We will also notify the relevant supervisory authority within 72 hours of becoming aware of a qualifying breach.
If you believe that we have not complied with your data protection rights, you have the right to lodge a complaint with a supervisory authority. In Australia, you can contact the Office of the Australian Information Commissioner (OAIC). If you are in the EEA or UK, you can contact your local data protection authority.
We may update this GDPR compliance notice from time to time. Any changes will be posted on this page with an updated revision date.