GDPR Compliance Statement
Data Protection and Privacy Rights
While Juniper-trek operates primarily in Australia, we recognize that individuals from the European Union may access our services. This statement outlines our commitment to complying with the General Data Protection Regulation where applicable.
Legal Basis for Processing
We process personal data only when we have a legal basis to do so. Our legal bases include:
- Consent: You have given clear consent for us to process your personal data for specific purposes
- Contract: Processing is necessary for a contract we have with you, or because you have asked us to take specific steps before entering into a contract
- Legal Obligation: Processing is necessary for us to comply with the law
- Legitimate Interests: Processing is necessary for our legitimate interests or the legitimate interests of a third party, unless there is a good reason to protect your personal data which overrides those legitimate interests
Your Rights Under GDPR
If you are an EU resident, you have the following rights regarding your personal data:
Right to Access
You have the right to request copies of your personal data. We may charge a reasonable fee if your request is clearly unfounded, repetitive, or excessive.
Right to Rectification
You have the right to request that we correct any information you believe is inaccurate or complete information you believe is incomplete.
Right to Erasure
You have the right to request that we erase your personal data, under certain conditions, including when the data is no longer necessary for the purpose it was collected.
Right to Restrict Processing
You have the right to request that we restrict the processing of your personal data, under certain conditions.
Right to Object to Processing
You have the right to object to our processing of your personal data, under certain conditions, particularly for direct marketing purposes.
Right to Data Portability
You have the right to request that we transfer the data we have collected to another organization, or directly to you, under certain conditions.
Right to Withdraw Consent
Where we rely on consent as the legal basis for processing, you have the right to withdraw your consent at any time. This will not affect the lawfulness of processing based on consent before its withdrawal.
Data Processing Activities
Categories of Personal Data
We process the following categories of personal data:
- Identity data including name and contact details
- Professional data including employment history and qualifications
- Technical data including IP address and browser information
- Usage data including how you interact with our website
- Communication data including correspondence and feedback
Data Recipients
We may share your personal data with:
- Potential employers, with your explicit consent
- Service providers who support our business operations
- Legal and regulatory authorities when required by law
International Data Transfers
As we are based in Australia, your personal data may be transferred to and processed in Australia. We ensure that any international transfers of personal data are protected by appropriate safeguards in accordance with GDPR requirements.
Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, or reporting requirements.
To determine the appropriate retention period, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorized use or disclosure, the purposes for which we process the data, and applicable legal requirements.
Automated Decision Making
We do not use automated decision making or profiling in ways that produce legal effects or similarly significantly affect you.
Data Security
We have implemented appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- Encryption of personal data in transit and at rest
- Regular security assessments and updates
- Access controls and authentication procedures
- Staff training on data protection and security
Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the appropriate supervisory authority within 72 hours of becoming aware of the breach. If the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay.
Exercising Your Rights
To exercise any of your GDPR rights, please contact us using the details below. We will respond to your request within one month, though this may be extended by two additional months if your request is complex or we receive multiple requests.
We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data or to exercise any of your other rights.
Supervisory Authority
If you are an EU resident, you have the right to lodge a complaint with your local data protection supervisory authority if you believe we have not complied with applicable data protection laws.
Contact Information
For any questions about this GDPR statement or to exercise your rights, please contact:
Email: [email protected]
Address: Level 8, 343 Little Collins Street, Melbourne VIC 3000, Australia