Our Commitment to Data Protection
nimble lotus is committed to protecting the privacy and security of personal data. Although we are based in Australia, we recognise and respect the data protection rights of individuals in the European Economic Area (EEA) under the General Data Protection Regulation (GDPR).
This page outlines our approach to GDPR compliance and explains your rights as a data subject.
Legal Basis for Processing
We process personal data on the following legal bases:
- Contract: Processing necessary to perform our contract with you, such as providing language education services.
- Consent: Where you have given clear consent for us to process your personal data for specific purposes.
- Legitimate Interests: Processing necessary for our legitimate business interests, provided these do not override your rights and freedoms.
- Legal Obligation: Processing necessary to comply with legal requirements.
Your Rights Under GDPR
If you are located in the EEA, you have the following rights regarding your personal data:
Right to Access
You have the right to request a copy of the personal data we hold about you and information about how we process it.
Right to Rectification
You have the right to request correction of inaccurate personal data or completion of incomplete data.
Right to Erasure
You have the right to request deletion of your personal data in certain circumstances, such as when the data is no longer necessary for the purposes it was collected.
Right to Restriction
You have the right to request that we restrict processing of your personal data in certain circumstances, such as when you contest the accuracy of the data.
Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit it to another controller.
Right to Object
You have the right to object to processing of your personal data based on legitimate interests or for direct marketing purposes.
Right to Withdraw Consent
Where we rely on consent as the legal basis for processing, you have the right to withdraw your consent at any time.
International Data Transfers
As an Australian company, we may transfer personal data outside the EEA. When we do so, we ensure appropriate safeguards are in place to protect your data, such as:
- Standard contractual clauses approved by the European Commission
- Ensuring the recipient country has adequate data protection laws
- Other legally recognised transfer mechanisms
Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy legal, accounting, or reporting requirements. Specific retention periods depend on the nature of the data and our legal obligations.
Security Measures
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
- Encryption of personal data where appropriate
- Regular security assessments and testing
- Access controls and authentication procedures
- Staff training on data protection
Exercising Your Rights
To exercise any of your rights under GDPR, please contact us using the details below. We will respond to your request within one month. In complex cases, we may extend this period by two months, but we will inform you of any extension within the first month.
You also have the right to lodge a complaint with a supervisory authority if you believe your rights have been violated.
Contact Our Data Protection Team
For GDPR-related enquiries or to exercise your data protection rights:
Data Protection Officer
nimble lotus
123 Language Lane
Sydney NSW 2000
Australia