Your rights under the General Data Protection Regulation
Last Updated: January 2024
Hazy Reef is committed to protecting the personal data of all users, including those in the European Economic Area (EEA). This page outlines how we comply with the General Data Protection Regulation (GDPR) and explains your rights under this regulation.
Hazy Reef acts as the data controller for personal information collected through our website and services. Our contact details are:
Hazy Reef
42 Marine Parade
Port Douglas, QLD 4877
Australia
Email: [email protected]
We process personal data under the following legal bases:
If you are located in the EEA, you have the following rights regarding your personal data:
You have the right to request copies of your personal data. We may charge a small fee for this service if requests are excessive or repetitive.
You have the right to request that we correct any information you believe is inaccurate or complete information you believe is incomplete.
You have the right to request that we erase your personal data under certain conditions, such as when the data is no longer necessary for the purpose it was collected.
You have the right to request that we restrict the processing of your personal data under certain conditions, such as when you contest the accuracy of the data.
You have the right to object to our processing of your personal data under certain conditions, particularly for direct marketing purposes.
You have the right to request that we transfer the data we have collected to another organisation, or directly to you, under certain conditions.
Where we rely on your consent to process your personal data, you have the right to withdraw that consent at any time. This will not affect the lawfulness of processing based on consent before its withdrawal.
As we are based in Australia, your personal data may be transferred to and processed in a country outside the EEA. When we transfer data outside the EEA, we ensure appropriate safeguards are in place to protect your data, including:
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law. Criteria used to determine retention periods include:
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
To exercise any of your rights under GDPR, please contact us at [email protected]. We will respond to your request within one month. If your request is complex or we receive a high volume of requests, we may extend this period by up to two additional months, in which case we will inform you.
If you believe we have not handled your personal data properly, you have the right to lodge a complaint with a supervisory authority. For EEA residents, this would be the data protection authority in your country of residence.
We may update this GDPR information from time to time. Any changes will be posted on this page with an updated revision date.