Last updated: September 2024

Overview

lotus-trek respects the privacy rights of individuals in the European Union and European Economic Area. This page provides additional information about how we comply with the General Data Protection Regulation (GDPR) when processing personal data of EU residents.

Data Controller

lotus-trek acts as the data controller for personal information collected through this website. Our contact details are:

lotus-trek
Level 12, 88 George Street
Sydney NSW 2000
Australia
[email protected]

Legal Bases for Processing

We process personal data under the following legal bases:

Your Rights Under GDPR

If you are located in the EU or EEA, you have the following rights regarding your personal data:

Right of Access

You can request a copy of the personal data we hold about you and information about how we process it.

Right to Rectification

You can request correction of any inaccurate or incomplete personal data we hold.

Right to Erasure

You can request deletion of your personal data in certain circumstances, such as when the data is no longer necessary for the purposes collected.

Right to Restrict Processing

You can request that we limit how we use your personal data in certain circumstances.

Right to Data Portability

You can request transfer of your personal data to you or a third party in a structured, commonly used format.

Right to Object

You can object to processing based on legitimate interests or for direct marketing purposes.

Right to Withdraw Consent

Where processing is based on consent, you can withdraw that consent at any time without affecting the lawfulness of prior processing.

Exercising Your Rights

To exercise any of these rights, please contact us at [email protected]. We will respond to your request within one month of receipt. We may request additional information to verify your identity before processing your request.

International Data Transfers

As we are located in Australia, personal data collected from EU residents may be transferred outside the EEA. Australia has received an adequacy decision from the European Commission, meaning it is recognised as providing adequate protection for personal data. We implement appropriate safeguards for any transfers to countries without adequacy decisions.

Data Retention

We retain personal data only as long as necessary for the purposes for which it was collected, to comply with legal obligations, resolve disputes and enforce agreements. Specific retention periods vary based on the type of data and purpose of collection.

Automated Decision Making

We do not use automated decision-making or profiling that produces legal effects or similarly significantly affects individuals.

Complaints

If you believe we have not handled your personal data appropriately, you have the right to lodge a complaint with your local data protection authority. In Australia, you may contact the Office of the Australian Information Commissioner.

Updates to This Information

We may update this GDPR information periodically to reflect changes in our practices or legal requirements. We encourage you to review this page regularly.