GDPR Compliance

Last updated: January 2024

Fluent Lesson is committed to protecting the privacy and rights of individuals in accordance with the General Data Protection Regulation (GDPR). This page explains how we comply with GDPR requirements and outlines your rights as a data subject.

Our Commitment to GDPR

Although Fluent Lesson is based in Australia, we recognise that we may process personal data of individuals located in the European Economic Area (EEA). We are committed to protecting this data in accordance with GDPR principles.

Data Controller Information

For the purposes of GDPR, the data controller is:

Fluent Lesson Pty Ltd
47 Garden Boulevard, Suite 12
Richmond VIC 3121
Australia
Email: [email protected]

Lawful Basis for Processing

We process personal data under the following lawful bases:

  • Consent: Where you have given clear consent for us to process your personal data for a specific purpose
  • Contract: Where processing is necessary for a contract we have with you or because you have asked us to take specific steps before entering into a contract
  • Legal obligation: Where processing is necessary for us to comply with the law
  • Legitimate interests: Where processing is necessary for our legitimate interests or those of a third party, unless your rights override those interests

Your Rights Under GDPR

If you are located in the EEA, you have the following rights regarding your personal data:

Right to Access

You have the right to request a copy of the personal data we hold about you, along with information about how we process it.

Right to Rectification

You have the right to request that we correct any inaccurate or incomplete personal data we hold about you.

Right to Erasure

You have the right to request that we delete your personal data in certain circumstances, such as when the data is no longer necessary for the purpose it was collected.

Right to Restrict Processing

You have the right to request that we restrict the processing of your personal data in certain circumstances, such as when you contest the accuracy of the data.

Right to Data Portability

You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit it to another controller.

Right to Object

You have the right to object to the processing of your personal data in certain circumstances, including processing for direct marketing purposes.

Rights Related to Automated Decision-Making

You have the right not to be subject to a decision based solely on automated processing that produces legal effects or similarly significantly affects you.

Exercising Your Rights

To exercise any of your rights, please contact us at [email protected]. We will respond to your request within one month. In certain circumstances, we may extend this period by two months, in which case we will inform you.

We may need to verify your identity before processing your request. There is no fee for exercising your rights, although we may charge a reasonable fee for manifestly unfounded or excessive requests.

International Data Transfers

As we are based in Australia, any personal data we collect from EEA residents will be transferred to and processed in Australia. We ensure that appropriate safeguards are in place to protect your data, including standard contractual clauses approved by the European Commission.

Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected. Specific retention periods depend on the type of data and the purposes for processing. When data is no longer needed, it is securely deleted or anonymised.

Data Security

We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:

  • Encryption of personal data where appropriate
  • Regular testing and evaluation of security measures
  • Staff training on data protection
  • Access controls to limit who can access personal data

Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. If the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly.

Complaints

If you believe that we have not complied with your data protection rights, you have the right to lodge a complaint with a supervisory authority. For EEA residents, this would be the data protection authority in your country of residence.

Contact Our Data Protection Team

For any questions or concerns about GDPR compliance or to exercise your rights, please contact:

Data Protection Officer
Fluent Lesson Pty Ltd
47 Garden Boulevard, Suite 12
Richmond VIC 3121
Australia
Email: [email protected]