GDPR Compliance

Last updated: January 2024

Clear Holdings is committed to protecting the personal data of all individuals, including those located in the European Economic Area (EEA). This page outlines our compliance with the General Data Protection Regulation (GDPR) and explains your rights under this legislation.

Our Commitment to GDPR

Although Clear Holdings is based in Australia, we recognise the importance of the GDPR and are committed to providing the same level of data protection to all our website visitors and clients, regardless of their location.

Data Controller

Clear Holdings acts as the data controller for personal information collected through our website and services. This means we determine the purposes and means of processing your personal data.

Contact Details:
Clear Holdings
142 Parkview Road
Thornbury VIC 3071, Australia
Email: [email protected]

Legal Basis for Processing

We process personal data on the following legal bases:

  • Consent: When you have given clear consent for us to process your personal data for a specific purpose
  • Contract: When processing is necessary for a contract we have with you, or because you have asked us to take specific steps before entering into a contract
  • Legal Obligation: When processing is necessary for us to comply with the law
  • Legitimate Interests: When processing is necessary for our legitimate interests or those of a third party, unless there is a good reason to protect your personal data which overrides those interests

Your Rights Under GDPR

If you are located in the EEA, you have the following rights regarding your personal data:

Right to Access

You have the right to request a copy of the personal data we hold about you. We will provide this information free of charge within one month of receiving your request.

Right to Rectification

You have the right to request that we correct any inaccurate personal data we hold about you. We will respond to such requests within one month.

Right to Erasure

You have the right to request that we delete your personal data in certain circumstances, including when:

  • The data is no longer necessary for the purpose it was collected
  • You withdraw consent and there is no other legal basis for processing
  • You object to processing and there are no overriding legitimate grounds
  • The data has been unlawfully processed

Right to Restriction of Processing

You have the right to request that we restrict the processing of your personal data in certain circumstances, such as when you contest the accuracy of the data or when you have objected to processing.

Right to Data Portability

You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller.

Right to Object

You have the right to object to the processing of your personal data based on legitimate interests or for direct marketing purposes.

Rights Related to Automated Decision Making

You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects or significantly affects you.

Exercising Your Rights

To exercise any of your rights under GDPR, please contact us using the details provided above. We may need to verify your identity before processing your request. We will respond to your request within one month, although this period may be extended by two further months for complex requests.

International Data Transfers

As we are based in Australia, your data may be transferred to and processed in Australia. We ensure that appropriate safeguards are in place to protect your personal data when it is transferred outside the EEA, including standard contractual clauses approved by the European Commission.

Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law. When personal data is no longer needed, we securely delete or anonymise it.

Data Security

We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:

  • Encryption of personal data where appropriate
  • Regular testing and evaluation of security measures
  • Staff training on data protection
  • Access controls and authentication procedures

Data Breach Notification

In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay and inform the relevant supervisory authority within 72 hours of becoming aware of the breach.

Complaints

If you are not satisfied with how we handle your personal data or your requests regarding your rights, you have the right to lodge a complaint with a supervisory authority. For EEA residents, this would be the data protection authority in your country of residence.

Updates to This Notice

We may update this GDPR compliance notice from time to time. We will notify you of any significant changes by posting the new notice on our website.

Contact Us

For any questions regarding GDPR or your data protection rights, please contact:

Clear Holdings
142 Parkview Road
Thornbury VIC 3071
Email: [email protected]