Information on this site is advertising in nature

Overview

The General Data Protection Regulation (GDPR) is a comprehensive data protection law that governs how organisations collect, process, and protect personal data of individuals in the European Union. Although Tundra-orbit is based in Australia, we are committed to upholding GDPR principles for all users, regardless of their location.

Our Role as Data Controller

When you interact with our website or services, Tundra-orbit acts as the data controller, determining the purposes and means of processing your personal data. We are responsible for ensuring that your data is processed lawfully, fairly, and transparently.

Lawful Bases for Processing

We process personal data under the following lawful bases as defined by GDPR:

Your Rights Under GDPR

If you are located in the European Economic Area, you have the following rights regarding your personal data:

Right of Access

You have the right to request a copy of the personal data we hold about you, along with information about how we process it.

Right to Rectification

You have the right to request correction of any inaccurate personal data we hold about you, and to have incomplete data completed.

Right to Erasure

You have the right to request deletion of your personal data in certain circumstances, such as when the data is no longer necessary for the purposes for which it was collected.

Right to Restrict Processing

You have the right to request that we limit the processing of your personal data in certain circumstances, such as when you contest the accuracy of the data.

Right to Data Portability

You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit that data to another controller.

Right to Object

You have the right to object to processing of your personal data based on legitimate interests or for direct marketing purposes.

Rights Related to Automated Decision-Making

You have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects, subject to certain exceptions.

International Data Transfers

As an Australian company, transfers of personal data from the EEA to our systems may constitute international data transfers. We ensure that such transfers are conducted in compliance with GDPR requirements through appropriate safeguards, including Standard Contractual Clauses approved by the European Commission.

Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. Where the breach is likely to result in a high risk, we will also notify affected individuals without undue delay.

Data Protection Officer

For enquiries related to GDPR compliance or to exercise your data protection rights, please contact us at [email protected]. We will respond to your request within one month, as required by GDPR.

Supervisory Authority

If you are located in the EEA and believe that we have not adequately addressed your data protection concerns, you have the right to lodge a complaint with your local data protection supervisory authority.

Updates to This Policy

We may update this GDPR compliance statement periodically to reflect changes in our practices or legal requirements. Any significant changes will be communicated through our website.