Last updated: January 2024

Our Commitment to GDPR

Although AurenzaTrustPro is an Australian company, we are committed to complying with the General Data Protection Regulation (GDPR) for any personal data we process belonging to individuals in the European Union.

This page supplements our Privacy Policy with additional information specific to GDPR requirements.

Data Controller

AurenzaTrustPro acts as the data controller for personal information collected through our website and service delivery. Our contact details are:

AurenzaTrustPro
Level 18, 123 Collins Street
Melbourne VIC 3000
Australia
Email: [email protected]

Lawful Basis for Processing

We process personal data under one or more of the following lawful bases:

  • Consent: You have given explicit consent for processing for specific purposes (e.g., receiving marketing communications)
  • Contract: Processing is necessary for the performance of a contract with you or to take steps prior to entering a contract
  • Legal Obligation: Processing is necessary to comply with legal requirements
  • Legitimate Interests: Processing is necessary for our legitimate business interests, provided these do not override your fundamental rights

Your Rights Under GDPR

As an EU resident, you have the following rights regarding your personal data:

Right to Access

You have the right to request a copy of the personal data we hold about you and information about how we process it.

Right to Rectification

You have the right to request correction of any inaccurate or incomplete personal data we hold about you.

Right to Erasure

You have the right to request deletion of your personal data in certain circumstances, such as when the data is no longer necessary for the purposes for which it was collected.

Right to Restriction of Processing

You have the right to request that we restrict the processing of your personal data in certain circumstances.

Right to Data Portability

You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller.

Right to Object

You have the right to object to processing of your personal data based on legitimate interests or for direct marketing purposes.

Rights Related to Automated Decision-Making

You have the right not to be subject to decisions based solely on automated processing that produce legal effects concerning you. We do not currently use automated decision-making in our services.

International Data Transfers

As an Australian company, any personal data transferred from the EU will be transferred to Australia. We ensure that appropriate safeguards are in place to protect your data, including:

  • Standard Contractual Clauses approved by the European Commission
  • Encryption of data in transit and at rest
  • Strict access controls and confidentiality agreements

Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable laws. When personal data is no longer needed, we securely delete or anonymise it.

Security Measures

We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:

  • Encryption of personal data
  • Regular testing and evaluation of security measures
  • Staff training on data protection
  • Incident response procedures

Data Breach Notification

In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly.

Exercising Your Rights

To exercise any of your GDPR rights, please contact us at:

Email: [email protected]

We will respond to your request within one month. In complex cases, this may be extended by a further two months, and we will inform you of any such extension.

Complaints

If you believe that your data protection rights have been violated, you have the right to lodge a complaint with a supervisory authority in the EU Member State of your habitual residence, place of work, or place of the alleged infringement.

Updates to This Information

We may update this GDPR information from time to time. Any changes will be posted on this page with an updated revision date.