GDPR Compliance

Information about how we comply with the General Data Protection Regulation.

Last updated: January 2024

Overview

The General Data Protection Regulation (GDPR) is a European Union regulation that governs the collection, storage, and processing of personal data of individuals within the EU and EEA. Although Iris-zone is based in Australia, we are committed to protecting the privacy of all our users, including those from the European Union, and we strive to comply with GDPR principles.

Our Commitment

Iris-zone is committed to:

  • Processing personal data lawfully, fairly, and transparently
  • Collecting data only for specified, explicit, and legitimate purposes
  • Ensuring data is accurate and kept up to date
  • Retaining data only for as long as necessary
  • Implementing appropriate security measures to protect data

Legal Basis for Processing

We process personal data under the following legal bases:

  • Consent: When you submit a booking request or contact us, you consent to our processing of your data
  • Contract: Processing necessary to fulfil our tour services
  • Legitimate Interest: For website analytics and service improvement, where such interests do not override your rights
  • Legal Obligation: When required to comply with applicable laws

Your Rights Under GDPR

If you are located in the European Union or European Economic Area, you have the following rights regarding your personal data:

Right of Access

You have the right to request a copy of the personal data we hold about you. We will provide this information within 30 days of receiving your request.

Right to Rectification

You have the right to request correction of any inaccurate or incomplete personal data we hold about you.

Right to Erasure

Also known as the "right to be forgotten," you may request deletion of your personal data where there is no compelling reason for us to continue processing it.

Right to Restrict Processing

You have the right to request that we restrict the processing of your personal data in certain circumstances.

Right to Data Portability

You have the right to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format.

Right to Object

You have the right to object to the processing of your personal data where we are relying on legitimate interest as our legal basis.

Rights Related to Automated Decision-Making

You have the right not to be subject to decisions based solely on automated processing that produce legal effects concerning you. We do not currently use automated decision-making in our services.

Exercising Your Rights

To exercise any of these rights, please contact us using the details below. We will respond to your request within 30 days. We may need to verify your identity before processing your request.

Data Transfers

As Iris-zone is based in Australia, your personal data may be transferred to and processed in Australia. Australia is recognised by the European Commission as providing an adequate level of data protection. We ensure that any international transfers of personal data are conducted in compliance with applicable data protection laws.

Data Retention

We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected. Booking-related data is typically retained for seven years for legal and accounting purposes. Marketing consent data is retained until you withdraw consent.

Data Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These measures include:

  • Secure data storage and transmission
  • Access controls limiting who can access your data
  • Regular security assessments
  • Staff training on data protection

Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly.

Third-Party Services

We may share your data with third-party service providers who assist in delivering our services. These providers are contractually obligated to protect your data and process it only according to our instructions.

Children's Data

We do not knowingly collect personal data from children under 16. If we become aware that we have collected data from a child without parental consent, we will take steps to delete that information.

Updates to This Notice

We may update this GDPR compliance notice from time to time. Changes will be posted on this page with an updated revision date.

Contact Us

For questions about GDPR compliance or to exercise your rights, please contact us:

Iris-zone
Level 4, 221 Queen Street
Melbourne VIC 3000
Australia

Supervisory Authority

If you are located in the EU and believe we have not adequately addressed your data protection concerns, you have the right to lodge a complaint with your local data protection supervisory authority.