GDPR Compliance
Our commitment to data protection and your rights
Introduction
Mountain Quest is committed to protecting the personal data and privacy of all individuals, including those in the European Union. This page outlines our compliance with the General Data Protection Regulation (GDPR) and your rights under this regulation.
Data Controller
Mountain Quest is the data controller responsible for your personal data. Our contact details are:
Mountain Quest
Level 12, 347 Kent Street
Sydney NSW 2000
Australia
Email: [email protected]
Legal Basis for Processing
We process your personal data based on the following legal grounds:
- Consent: You have given clear consent for us to process your personal data for specific purposes
- Contract: Processing is necessary for a contract we have with you
- Legal Obligation: Processing is necessary to comply with the law
- Legitimate Interests: Processing is necessary for our legitimate interests or those of a third party
Your GDPR Rights
Under the GDPR, you have the following rights:
Right to Access
You have the right to request copies of your personal data. We may charge a small fee for this service.
Right to Rectification
You have the right to request that we correct any information you believe is inaccurate or complete information you believe is incomplete.
Right to Erasure
You have the right to request that we erase your personal data, under certain conditions.
Right to Restrict Processing
You have the right to request that we restrict the processing of your personal data, under certain conditions.
Right to Object to Processing
You have the right to object to our processing of your personal data, under certain conditions.
Right to Data Portability
You have the right to request that we transfer the data we have collected to another organization, or directly to you, under certain conditions.
Exercising Your Rights
To exercise any of your GDPR rights, please contact us at [email protected]. We will respond to your request within one month.
Data Protection Officer
For questions regarding data protection or to exercise your rights, you may contact our Data Protection Officer at [email protected].
Complaints
If you believe we have not complied with GDPR requirements, you have the right to lodge a complaint with your local supervisory authority.
Data Security
We have implemented appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- Encryption of personal data
- Regular security assessments
- Access controls and authentication
- Employee training on data protection
- Incident response procedures
Data Breach Notification
In the event of a personal data breach, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, where feasible. If the breach is likely to result in a high risk to your rights and freedoms, we will also notify you without undue delay.
International Data Transfers
If we transfer your personal data outside the European Economic Area, we will ensure that appropriate safeguards are in place, such as:
- Standard contractual clauses approved by the European Commission
- Adequacy decisions
- Binding corporate rules
Automated Decision-Making
We do not use automated decision-making or profiling that produces legal effects or similarly significantly affects you.
Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including any legal, accounting, or reporting requirements.
Changes to This Policy
We may update this GDPR compliance statement from time to time. We will notify you of any significant changes by posting the new statement on this page.
Contact Us
For any questions about our GDPR compliance or to exercise your rights, please contact us at [email protected].