Information on this site is advertising in nature

Last updated: January 2024

1. Introduction

bold-works is committed to protecting the personal data of all individuals, including those located in the European Economic Area (EEA). This page outlines how we comply with the General Data Protection Regulation (GDPR) and explains your rights under this regulation.

While our business is based in Australia, we recognise that some visitors to our website or users of our services may be subject to GDPR protections. We extend these protections to all users regardless of location.

2. Data Controller

bold-works acts as the data controller for personal information collected through our website and services. This means we determine the purposes and means of processing your personal data.

Contact details for data protection enquiries:

bold-works
47 Harbour Street
Sydney, NSW 2000
Australia

Email: [email protected]

3. Lawful Basis for Processing

We process personal data only when we have a lawful basis to do so. The lawful bases we rely on include:

  • Consent: Where you have given clear consent for us to process your personal data for a specific purpose.
  • Contract: Where processing is necessary for a contract we have with you, or because you have asked us to take specific steps before entering into a contract.
  • Legal obligation: Where processing is necessary for us to comply with the law.
  • Legitimate interests: Where processing is necessary for our legitimate interests or the legitimate interests of a third party, unless there is a good reason to protect your personal data which overrides those legitimate interests.

4. Your Rights Under GDPR

If you are located in the EEA, or if we otherwise extend these rights to you, you have the following rights regarding your personal data:

4.1 Right to Access

You have the right to request a copy of the personal information we hold about you. We will provide this information free of charge within one month of your request.

4.2 Right to Rectification

You have the right to request that we correct any inaccurate personal data we hold about you, and to have incomplete data completed.

4.3 Right to Erasure

You have the right to request that we delete your personal data in certain circumstances, such as when the data is no longer necessary for the purpose for which it was collected.

4.4 Right to Restrict Processing

You have the right to request that we restrict the processing of your personal data in certain circumstances, such as when you contest the accuracy of the data.

4.5 Right to Data Portability

You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller.

4.6 Right to Object

You have the right to object to the processing of your personal data in certain circumstances, including processing for direct marketing purposes.

4.7 Rights Related to Automated Decision Making

You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you.

5. How to Exercise Your Rights

To exercise any of your rights, please contact us using the details provided above. We will respond to your request within one month. In some cases, we may need to verify your identity before processing your request.

There is no fee for exercising your rights, except where requests are manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse to act on the request.

6. Data Transfers

As our business is located in Australia, personal data collected from individuals in the EEA may be transferred to and processed in Australia. Australia has been recognised by the European Commission as providing an adequate level of data protection.

Where we transfer data to third parties in countries that have not been deemed adequate, we ensure appropriate safeguards are in place, such as standard contractual clauses approved by the European Commission.

7. Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy any legal, accounting, or reporting requirements. The retention period may vary depending on the context of the processing and our legal obligations.

8. Security Measures

We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:

  • Encryption of data in transit
  • Regular security assessments
  • Access controls and authentication
  • Staff training on data protection
  • Secure disposal of data when no longer needed

9. Data Breach Notification

In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay. We will also notify the relevant supervisory authority within 72 hours of becoming aware of the breach, where required.

10. Children's Data

Our services are not directed at children under 16 years of age. We do not knowingly collect personal data from children under 16. If we become aware that we have collected such data, we will take steps to delete it promptly.

11. Right to Lodge a Complaint

If you are located in the EEA and believe that your data protection rights have been violated, you have the right to lodge a complaint with a supervisory authority in the EU Member State of your habitual residence, place of work, or place of the alleged infringement.

12. Changes to This Information

We may update this GDPR compliance information from time to time. Any changes will be posted on this page with an updated revision date.

13. Contact Us

For any questions or concerns regarding GDPR compliance or to exercise your data protection rights, please contact us at:

bold-works
47 Harbour Street
Sydney, NSW 2000
Australia

Email: [email protected]