Our commitment to protecting your data rights
atoll-path is committed to ensuring the security and protection of the personal information that we process, and to provide a compliant and consistent approach to data protection. The General Data Protection Regulation (GDPR) applies to the processing of personal data of individuals in the European Union, regardless of where the data processor is located.
For the purposes of the GDPR, atoll-path acts as the data controller for personal information collected through our website and services. This means we determine the purposes and means of processing personal data.
We process personal data under the following legal bases:
If you are located in the European Union, you have the following rights regarding your personal data:
Right to Access
You have the right to request a copy of the personal information we hold about you. We will provide this information free of charge within one month of receiving your request.
Right to Rectification
You have the right to request that we correct any personal information you believe is inaccurate. You also have the right to request that we complete information you believe is incomplete.
Right to Erasure
You have the right to request that we erase your personal data under certain conditions, such as when the data is no longer necessary for the purpose for which it was collected or when you withdraw consent.
Right to Restrict Processing
You have the right to request that we restrict the processing of your personal data under certain conditions, such as when you contest the accuracy of the data or when processing is unlawful but you oppose erasure.
Right to Data Portability
You have the right to request that we transfer the data we have collected to another organisation, or directly to you, under certain conditions.
Right to Object
You have the right to object to our processing of your personal data under certain conditions, particularly where we are processing data for direct marketing purposes.
As an Australian company, some of your personal data may be transferred to and stored in locations outside the European Economic Area (EEA). When we transfer personal data outside the EEA, we ensure that appropriate safeguards are in place to protect your information, such as standard contractual clauses approved by the European Commission.
We will retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy any legal, accounting, or reporting requirements. To determine the appropriate retention period, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure, the purposes for which we process the data, and applicable legal requirements.
We have implemented appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. If the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly.
To exercise any of your rights under the GDPR, please contact us using the details below. We may need to verify your identity before processing your request. We will respond to your request within one month, though this period may be extended by two further months where necessary, depending on the complexity of your request.
If you believe that we have not complied with your data protection rights, you have the right to lodge a complaint with a supervisory authority. For EU residents, this would typically be the data protection authority in your country of residence.
For any questions regarding GDPR or to exercise your data protection rights, please contact us at:
Email: [email protected]
Address: Level 4, 127 Creek Street, Brisbane QLD 4000, Australia
Last updated: January 2024