General Data Protection Regulation (GDPR)
While fern-flow operates primarily in Australia, we respect the data protection rights of all individuals, including those in the European Union. This page outlines our GDPR compliance measures.
Legal Basis for Processing
We process your personal data based on the following legal grounds:
- Consent: You have given clear consent for us to process your personal data for specific purposes
- Contract: Processing is necessary for a contract we have with you
- Legal obligation: Processing is necessary for compliance with legal obligations
- Legitimate interests: Processing is necessary for our legitimate business interests
Your GDPR Rights
Under GDPR, you have the following rights regarding your personal data:
- Right to access: Request copies of your personal data
- Right to rectification: Request correction of inaccurate data
- Right to erasure: Request deletion of your data under certain conditions
- Right to restrict processing: Request limitation on how we use your data
- Right to data portability: Request transfer of your data to another service
- Right to object: Object to processing of your data under certain circumstances
- Rights related to automated decision-making: Not be subject to automated decisions with significant effects
Data Protection Measures
We implement appropriate technical and organizational measures to ensure data security, including:
- Encryption of data in transit and at rest
- Regular security assessments and updates
- Access controls and authentication procedures
- Staff training on data protection practices
- Incident response procedures for data breaches
Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by law. When data is no longer needed, it is securely deleted or anonymized.
International Data Transfers
If we transfer your data outside of your jurisdiction, we ensure appropriate safeguards are in place, such as:
- Standard contractual clauses approved by relevant authorities
- Adequacy decisions recognizing sufficient data protection levels
- Other legally approved transfer mechanisms
Data Breach Notification
In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify affected individuals and relevant supervisory authorities within 72 hours of becoming aware of the breach.
Children's Data
We do not knowingly collect or process personal data from individuals under 16 years of age without parental consent.
Exercising Your Rights
To exercise any of your GDPR rights, please contact us at [email protected]. We will respond to your request within one month. There is no charge for most requests, but we may charge a reasonable fee for excessive or repetitive requests.
Complaints
If you believe we have not handled your data properly, you have the right to lodge a complaint with:
- The Office of the Australian Information Commissioner (OAIC) in Australia
- Your local data protection authority if you are in the EU
Contact Information
For questions about our GDPR compliance or to exercise your rights, contact us at [email protected]