Our commitment to European data protection standards
The General Data Protection Regulation (GDPR) is a comprehensive data protection law that governs how organisations collect, process, and protect personal data of individuals in the European Union. Although Tundra-orbit is based in Australia, we are committed to upholding GDPR principles for all users, regardless of their location.
When you interact with our website or services, Tundra-orbit acts as the data controller, determining the purposes and means of processing your personal data. We are responsible for ensuring that your data is processed lawfully, fairly, and transparently.
We process personal data under the following lawful bases as defined by GDPR:
If you are located in the European Economic Area, you have the following rights regarding your personal data:
You have the right to request a copy of the personal data we hold about you, along with information about how we process it.
You have the right to request correction of any inaccurate personal data we hold about you, and to have incomplete data completed.
You have the right to request deletion of your personal data in certain circumstances, such as when the data is no longer necessary for the purposes for which it was collected.
You have the right to request that we limit the processing of your personal data in certain circumstances, such as when you contest the accuracy of the data.
You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit that data to another controller.
You have the right to object to processing of your personal data based on legitimate interests or for direct marketing purposes.
You have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects, subject to certain exceptions.
As an Australian company, transfers of personal data from the EEA to our systems may constitute international data transfers. We ensure that such transfers are conducted in compliance with GDPR requirements through appropriate safeguards, including Standard Contractual Clauses approved by the European Commission.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. Where the breach is likely to result in a high risk, we will also notify affected individuals without undue delay.
For enquiries related to GDPR compliance or to exercise your data protection rights, please contact us at [email protected]. We will respond to your request within one month, as required by GDPR.
If you are located in the EEA and believe that we have not adequately addressed your data protection concerns, you have the right to lodge a complaint with your local data protection supervisory authority.
We may update this GDPR compliance statement periodically to reflect changes in our practices or legal requirements. Any significant changes will be communicated through our website.