General Data Protection Regulation compliance statement
While nimble-glow operates primarily in Australia, we recognize that some visitors to our website may be located in the European Economic Area. This page outlines our commitment to GDPR principles and how we handle personal data in accordance with these standards.
We process personal data based on the following legal grounds:
If you are located in the European Economic Area, you have the following rights regarding your personal data:
You may request confirmation of whether we process your personal data and obtain a copy of that data.
You may request correction of inaccurate personal data or completion of incomplete data.
You may request deletion of your personal data under certain circumstances, including when the data is no longer necessary for its original purpose or when you withdraw consent.
You may request that we limit the processing of your personal data in specific situations, such as when you contest the accuracy of the data.
You may request to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller.
You may object to processing of your personal data based on legitimate interests or for direct marketing purposes.
Where processing is based on consent, you have the right to withdraw that consent at any time without affecting the lawfulness of processing based on consent before withdrawal.
For questions regarding GDPR compliance or to exercise your data subject rights, please contact us at:
Email: [email protected]
Address: 247 Industrial Avenue, Moorabbin VIC 3189, Australia
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including satisfying legal, accounting, or reporting requirements. Retention periods vary depending on the type of data and the purpose of processing.
Our operations are based in Australia. If your data is transferred outside the EEA, we ensure appropriate safeguards are in place to protect your information in accordance with GDPR requirements.
We do not engage in automated decision-making or profiling that produces legal effects or similarly significant impacts on individuals.
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including encryption, access controls, and regular security assessments.
In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, where feasible.
If you believe our processing of your personal data violates GDPR, you have the right to lodge a complaint with a supervisory authority in the EU member state of your habitual residence, place of work, or place of the alleged infringement.
This GDPR compliance statement may be updated to reflect changes in our data processing practices or regulatory requirements. Updates will be posted on this page with a revision date.