GDPR Information
Last Updated: September 9, 2026
Our Commitment to Data Protection
ravine-orca is committed to protecting and respecting your privacy in accordance with the General Data Protection Regulation (GDPR) and applicable Australian privacy laws. This page outlines how we handle personal data and your rights as a data subject.
Data Controller
ravine-orca acts as the data controller for personal information collected through our website and services. We determine how and why your personal data is processed.
Contact: [email protected]
Legal Basis for Processing
We process personal data based on one or more of the following legal grounds:
- Consent: You have provided clear consent for us to process your personal data for specific purposes
- Contract: Processing is necessary to fulfill a contract with you or take steps at your request before entering into a contract
- Legal Obligation: Processing is necessary to comply with legal requirements
- Legitimate Interests: Processing is necessary for our legitimate business interests, provided these do not override your fundamental rights
Your Data Protection Rights
Under GDPR, you have the following rights regarding your personal data:
- Right of Access: Request copies of your personal data
- Right to Rectification: Request correction of inaccurate or incomplete data
- Right to Erasure: Request deletion of your personal data under certain circumstances
- Right to Restrict Processing: Request limitation on how we use your data
- Right to Data Portability: Request transfer of your data to another organization or directly to you
- Right to Object: Object to processing of your personal data in certain situations
- Rights Related to Automated Decision Making: Protection from decisions based solely on automated processing
How to Exercise Your Rights
To exercise any of your data protection rights, please contact us at [email protected]. We will respond to your request within one month, though this may be extended in complex cases.
You will not be charged for exercising your rights, though we may refuse requests that are manifestly unfounded or excessive.
Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including satisfying legal, accounting, or reporting requirements. When determining retention periods, we consider:
- The nature and sensitivity of the data
- Potential risk of harm from unauthorized use or disclosure
- The purposes for which we process the data
- Whether we can achieve those purposes through other means
- Applicable legal requirements
International Data Transfers
Your personal data may be processed in countries outside your own. When we transfer data internationally, we ensure appropriate safeguards are in place to protect your information in accordance with GDPR requirements.
Data Security
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- Encryption of data in transit and at rest
- Regular security assessments and updates
- Access controls limiting who can view personal data
- Staff training on data protection responsibilities
Data Breach Notification
In the event of a data breach that poses a risk to your rights and freedoms, we will notify you and relevant authorities within 72 hours of becoming aware of the breach, as required by GDPR.
Complaints
If you believe your data protection rights have been violated, you have the right to lodge a complaint with the relevant supervisory authority in your jurisdiction. In Australia, this is the Office of the Australian Information Commissioner (OAIC).
Updates to This Notice
We may update this GDPR information periodically. Changes will be posted on this page with a revised date.