Information on this site is advertising in nature

Our Commitment to GDPR

heath-whale is committed to protecting the personal data of individuals located in the European Economic Area (EEA) and ensuring compliance with the General Data Protection Regulation (GDPR). This page outlines how we handle personal data in accordance with GDPR requirements and explains your rights as a data subject.

Data Controller

heath-whale acts as the data controller for personal information collected through our website and services. As the data controller, we determine the purposes and means of processing your personal data and are responsible for ensuring that processing activities comply with applicable data protection laws.

Contact details:

heath-whale
Suite 412, Media Tower
88 Collins Street
Melbourne, VIC 3000
Australia

Email: [email protected]

Lawful Basis for Processing

We process personal data only when we have a valid legal basis to do so. The lawful bases we rely upon include:

  • Consent: When you have given clear consent for us to process your personal data for a specific purpose, such as subscribing to our newsletter.
  • Contract: When processing is necessary to perform a contract with you or take steps at your request before entering into a contract, such as providing training services you have booked.
  • Legitimate Interests: When processing is necessary for our legitimate business interests, provided these interests do not override your fundamental rights and freedoms.
  • Legal Obligation: When processing is necessary to comply with a legal obligation to which we are subject.

Your Rights Under GDPR

As a data subject under GDPR, you have the following rights regarding your personal data:

Right to Access

You have the right to request a copy of the personal data we hold about you, along with information about how we process it. We will provide this information free of charge within one month of receiving your request.

Right to Rectification

You have the right to request that we correct any inaccurate personal data we hold about you, or complete any incomplete data.

Right to Erasure

Also known as the "right to be forgotten," you may request that we delete your personal data in certain circumstances, such as when the data is no longer necessary for the purposes for which it was collected, or when you withdraw consent.

Right to Restrict Processing

You have the right to request that we restrict the processing of your personal data in certain circumstances, such as when you contest the accuracy of the data or when you have objected to processing based on legitimate interests.

Right to Data Portability

Where processing is based on consent or contract and carried out by automated means, you have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller.

Right to Object

You have the right to object to processing of your personal data based on legitimate interests or for direct marketing purposes. Upon receiving an objection, we will cease processing unless we can demonstrate compelling legitimate grounds that override your interests.

Rights Related to Automated Decision-Making

You have the right not to be subject to decisions based solely on automated processing, including profiling, which produce legal effects or similarly significantly affect you. We do not currently engage in automated decision-making of this nature.

International Data Transfers

As heath-whale is based in Australia, personal data collected from individuals in the EEA may be transferred to and processed in Australia. Australia is not currently recognised by the European Commission as providing an adequate level of data protection.

Where we transfer personal data outside the EEA, we ensure appropriate safeguards are in place, such as:

  • Standard contractual clauses approved by the European Commission
  • Binding corporate rules where applicable
  • Other legally recognised transfer mechanisms

Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy legal, accounting, or reporting requirements. When determining retention periods, we consider the nature and sensitivity of the data, the purposes of processing, and applicable legal requirements.

Data Security

We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:

  • Encryption of personal data where appropriate
  • Regular testing and evaluation of security measures
  • Staff training on data protection and security
  • Access controls limiting who can access personal data

Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly.

Exercising Your Rights

To exercise any of your rights under GDPR, please contact us at [email protected]. We will respond to your request within one month. In complex cases or where we receive a large number of requests, this period may be extended by up to two additional months, in which case we will inform you of the extension and the reasons for it.

We may ask you to verify your identity before processing your request to ensure that personal data is not disclosed to any person who has no right to receive it.

Complaints

If you are not satisfied with how we handle your personal data or respond to your requests, you have the right to lodge a complaint with a supervisory authority in the EU member state of your habitual residence, place of work, or place of the alleged infringement.

Updates to This Information

We may update this GDPR information from time to time to reflect changes in our practices or applicable laws. We will notify you of any significant changes by posting the updated information on this page.