Last Updated: January 2024
Magenta Moor is committed to complying with the General Data Protection Regulation (GDPR) and other applicable data protection laws. This page outlines how we protect your personal data and your rights under GDPR when you interact with our services.
For the purposes of GDPR, the data controller is:
Magenta Moor
Level 4, 87 Greenway Drive
Sydney, NSW 2000
Australia
Email: [email protected]
We process your personal data based on the following legal grounds:
As a data subject, you have the following rights:
Right of Access: You have the right to request a copy of the personal data we hold about you and information about how we process it.
Right to Rectification: You have the right to request that we correct any inaccurate personal data or complete any incomplete data we hold about you.
Right to Erasure: Also known as the "right to be forgotten," you have the right to request that we delete your personal data in certain circumstances.
Right to Restriction: You have the right to request that we restrict the processing of your personal data in certain circumstances.
Right to Data Portability: You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller.
Right to Object: You have the right to object to processing of your personal data where we are relying on legitimate interests or where processing is for direct marketing purposes.
Rights Related to Automated Decision-Making: You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you.
To exercise any of your rights under GDPR, please contact us at:
Email: [email protected]
We will respond to your request within one month of receipt. In certain circumstances, we may extend this period by up to two months, in which case we will inform you of the extension and the reasons for it.
We may need to verify your identity before processing your request. If your request is manifestly unfounded or excessive, we may charge a reasonable fee or refuse to act on the request.
We may transfer your personal data to countries outside the European Economic Area (EEA). When we do so, we ensure that appropriate safeguards are in place to protect your data, such as:
We retain your personal data only for as long as necessary for the purposes for which it was collected. The retention period depends on the nature of the information and the purposes for processing. When determining retention periods, we consider:
We have implemented appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. If the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly.
If you believe that we have not complied with GDPR or other applicable data protection laws, you have the right to lodge a complaint with a supervisory authority. In Australia, you may contact the Office of the Australian Information Commissioner (OAIC). If you are in the EU, you may contact the supervisory authority in your member state.
We may update this GDPR compliance notice from time to time. Any changes will be posted on this page with an updated revision date. We encourage you to review this page periodically.