GDPR Compliance
Last Updated: May 11, 2026
General Data Protection Regulation (GDPR)
Vortex Harbor is committed to protecting the privacy and security of your personal data in accordance with the General Data Protection Regulation (GDPR) and other applicable data protection laws.
1. Data Controller
Vortex Harbor is the data controller responsible for your personal data. Our contact details are:
Email: [email protected]
Address: Level 12, 118 Queen Street, Melbourne VIC 3000, Australia
2. Legal Basis for Processing
We process your personal data under the following legal bases:
- Consent: You have given explicit consent for us to process your personal data for specific purposes.
- Contract: Processing is necessary for the performance of a contract with you or to take steps at your request before entering into a contract.
- Legal Obligation: Processing is necessary to comply with legal obligations.
- Legitimate Interests: Processing is necessary for our legitimate interests or those of a third party, provided your interests and fundamental rights do not override those interests.
3. Your Rights Under GDPR
Under the GDPR, you have the following rights:
Right to Access
You have the right to request access to your personal data and obtain information about how we process it.
Right to Rectification
You have the right to request correction of inaccurate or incomplete personal data.
Right to Erasure
You have the right to request deletion of your personal data under certain circumstances.
Right to Restrict Processing
You have the right to request restriction of processing of your personal data under certain circumstances.
Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit it to another controller.
Right to Object
You have the right to object to processing of your personal data based on legitimate interests or for direct marketing purposes.
Right to Withdraw Consent
Where processing is based on consent, you have the right to withdraw your consent at any time.
Right to Lodge a Complaint
You have the right to lodge a complaint with a supervisory authority if you believe your data protection rights have been violated.
4. How to Exercise Your Rights
To exercise any of your rights under GDPR, please contact us at [email protected]. We will respond to your request within one month, though this period may be extended by two additional months where necessary.
5. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including legal, accounting, or reporting requirements. When determining retention periods, we consider:
- The nature and sensitivity of the data
- The purposes for which we process the data
- Legal and regulatory requirements
- Our legitimate business interests
6. Data Security
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- Encryption of personal data
- Regular security assessments
- Access controls and authentication
- Staff training on data protection
- Incident response procedures
7. International Transfers
When we transfer personal data outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, such as:
- Standard contractual clauses approved by the European Commission
- Transfers to countries with adequate data protection levels
- Binding corporate rules
8. Automated Decision-Making
We do not engage in automated decision-making, including profiling, that produces legal effects or similarly significantly affects you.
9. Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you without undue delay and, where feasible, within 72 hours of becoming aware of the breach.
10. Changes to This Policy
We may update this GDPR compliance statement from time to time. We will notify you of any significant changes by posting the updated statement on our website.
11. Contact Information
For any questions or concerns regarding GDPR compliance or to exercise your data protection rights, please contact us:
Email: [email protected]
Address: Level 12, 118 Queen Street, Melbourne VIC 3000, Australia