Your data protection rights under the General Data Protection Regulation
Aurora Echo respects the rights of individuals located in the European Economic Area (EEA) and is committed to complying with the General Data Protection Regulation (GDPR). This page outlines your rights and how we protect your personal data.
Aurora Echo acts as the data controller for personal information collected through our website and services. We determine the purposes and means of processing your personal data.
Contact details:
Aurora Echo
Level 12, 88 Collins Street
Melbourne VIC 3000
Australia
Email: [email protected]
If you are located in the EEA, you have the following rights concerning your personal data:
You have the right to request copies of your personal data held by us. We may charge a reasonable fee for additional copies or manifestly unfounded requests.
You have the right to request that we correct any information you believe is inaccurate or complete information you believe is incomplete.
You have the right to request that we erase your personal data under certain conditions, including when the data is no longer necessary for its original purpose or when you withdraw consent.
You have the right to request that we restrict the processing of your personal data under certain conditions, such as when you contest the accuracy of the data.
You have the right to object to our processing of your personal data under certain conditions, particularly when processing is based on legitimate interests or for direct marketing purposes.
You have the right to request that we transfer the data we have collected to another organisation, or directly to you, under certain conditions.
Where we rely on your consent to process your personal data, you have the right to withdraw that consent at any time. This will not affect the lawfulness of processing based on consent before withdrawal.
We only process your personal data when we have a valid legal basis to do so. Our legal bases include:
As we are based in Australia, your personal data may be transferred to and processed in Australia. When transferring data from the EEA, we ensure appropriate safeguards are in place, such as standard contractual clauses approved by the European Commission, to protect your data.
While not legally required to appoint a Data Protection Officer, we have designated a privacy lead who can be contacted for any data protection matters at [email protected].
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected. Our standard retention period for enquiry data is three years from your last interaction with us, unless a longer retention period is required by law.
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
To exercise any of your rights, please contact us at [email protected]. We will respond to your request within one month. If your request is complex or we receive numerous requests, we may extend this period by up to two months, in which case we will inform you.
If you believe we have not handled your personal data properly, you have the right to lodge a complaint with a supervisory authority. For EEA residents, this would be the data protection authority in your country of residence.
We may update this GDPR compliance information from time to time. Any changes will be posted on this page with an updated date.