GDPR Compliance
Our Commitment to Data Protection
Sydney Barbershop is committed to protecting the privacy and security of your personal data. This page outlines how we comply with the General Data Protection Regulation (GDPR) and similar data protection laws.
While we are based in Australia, we respect the data protection rights of all our visitors and customers, including those from the European Union.
Data Controller
Sydney Barbershop is the data controller for personal information collected through this website. Our contact details are:
Sydney Barbershop
142 Crown Street
Surry Hills, NSW 2010
Australia
Email: [email protected]
Your Rights Under GDPR
If you are a resident of the European Economic Area (EEA), you have certain data protection rights. Sydney Barbershop aims to take reasonable steps to allow you to correct, amend, delete, or limit the use of your Personal Data. You have the following rights:
- Right to Access: You have the right to request copies of your personal data.
- Right to Rectification: You have the right to request that we correct any information you believe is inaccurate or complete information you believe is incomplete.
- Right to Erasure: You have the right to request that we erase your personal data, under certain conditions.
- Right to Restrict Processing: You have the right to request that we restrict the processing of your personal data, under certain conditions.
- Right to Object to Processing: You have the right to object to our processing of your personal data, under certain conditions.
- Right to Data Portability: You have the right to request that we transfer the data that we have collected to another organisation, or directly to you, under certain conditions.
Legal Basis for Processing
We process personal data on the following legal bases:
- Consent: Where you have given clear consent for us to process your personal data for a specific purpose.
- Contract: Where processing is necessary for the performance of a contract with you (such as processing a booking request).
- Legitimate Interests: Where processing is necessary for our legitimate interests or the legitimate interests of a third party, unless there is a good reason to protect your personal data which overrides those legitimate interests.
- Legal Obligation: Where we need to comply with a legal obligation.
Data Retention
We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.
To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure, the purposes for which we process your personal data, and whether we can achieve those purposes through other means.
Data Security
We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used, or accessed in an unauthorised way, altered, or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors, and other third parties who have a business need to know.
International Transfers
As we are based in Australia, any personal data you provide may be transferred to and processed in Australia. By providing your personal data, you consent to this transfer. We take steps to ensure that your data is treated securely and in accordance with this policy.
Exercising Your Rights
If you wish to exercise any of the rights set out above, please contact us at [email protected].
You will not have to pay a fee to access your personal data or to exercise any of the other rights. However, we may charge a reasonable fee if your request is clearly unfounded, repetitive, or excessive. Alternatively, we may refuse to comply with your request in these circumstances.
We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data. This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it.
Right to Lodge a Complaint
If you are unhappy with how we have processed your personal data, you have the right to lodge a complaint with a supervisory authority. In Australia, this is the Office of the Australian Information Commissioner (OAIC). In the EU, you may contact your local data protection authority.
Changes to This Policy
We may update this GDPR compliance information from time to time. We encourage you to review this page periodically for the latest information on our data protection practices.
Last updated: September 2024