Our commitment to protecting your data rights
Last updated: October 2024
Cozy-vine is committed to complying with the General Data Protection Regulation (GDPR) for users located in the European Economic Area (EEA). This page explains how we handle personal data in accordance with GDPR requirements.
Cozy-vine acts as the data controller for personal information collected through our website and services. We determine the purposes and means of processing your personal data.
Contact details:
Cozy-vine
Level 8, 123 Collins Street
Melbourne VIC 3000
Australia
Email: [email protected]
We process personal data under the following legal bases:
If you are located in the EEA, you have the following rights regarding your personal data:
You have the right to request a copy of the personal data we hold about you and information about how we process it.
You have the right to request correction of inaccurate personal data or completion of incomplete data.
You have the right to request deletion of your personal data in certain circumstances, such as when the data is no longer necessary for the purpose it was collected.
You have the right to request that we restrict the processing of your personal data in certain circumstances, such as when you contest the accuracy of the data.
You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit it to another controller.
You have the right to object to processing of your personal data based on legitimate interests or for direct marketing purposes.
Where processing is based on consent, you have the right to withdraw that consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
To exercise any of these rights, please contact us using the details provided above. We will respond to your request within one month. In some cases, we may need to verify your identity before processing your request.
There is no fee for exercising your rights, although we may charge a reasonable fee for unfounded or excessive requests.
As an Australian-based company, we may transfer your personal data outside the EEA. When we do so, we ensure appropriate safeguards are in place, such as standard contractual clauses approved by the European Commission or transfers to countries with adequate data protection laws.
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, unless a longer retention period is required by law. When personal data is no longer needed, we securely delete or anonymise it.
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including encryption, access controls, and regular security assessments.
In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay. We will also notify the relevant supervisory authority within 72 hours of becoming aware of the breach where required.
Our services are not directed at individuals under 16 years of age. We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child, we will take steps to delete that information.
If you are not satisfied with how we handle your personal data, you have the right to lodge a complaint with a supervisory authority. For EEA residents, this would be the data protection authority in your country of residence.
We may update this GDPR compliance notice from time to time. We will post any changes on this page with an updated revision date.