Last updated: September 2024
This page provides information about how Royal River complies with the General Data Protection Regulation (GDPR) for visitors and customers located in the European Economic Area (EEA).
Data Controller
Royal River acts as the data controller for personal information collected through this website. Our contact details are:
Royal River
42 Riverside Drive
Christchurch 8011
New Zealand
Email: [email protected]
Legal Basis for Processing
We process personal data under the following legal bases:
- Consent: When you provide your information through our enquiry forms or subscribe to our services, you consent to our processing of that data for the stated purposes.
- Contract: Processing necessary to fulfil a contract with you, such as delivering services you have requested.
- Legitimate interests: Processing necessary for our legitimate business interests, such as improving our services and communicating with customers, where these interests do not override your rights.
- Legal obligation: Processing necessary to comply with legal requirements.
Your Rights Under GDPR
If you are located in the EEA, you have the following rights regarding your personal data:
- Right of access: You may request a copy of the personal data we hold about you.
- Right to rectification: You may request that we correct any inaccurate or incomplete personal data.
- Right to erasure: You may request that we delete your personal data in certain circumstances.
- Right to restriction: You may request that we restrict the processing of your personal data.
- Right to data portability: You may request that we provide your personal data in a structured, commonly used format.
- Right to object: You may object to our processing of your personal data for certain purposes.
- Right to withdraw consent: Where processing is based on consent, you may withdraw that consent at any time.
Exercising Your Rights
To exercise any of these rights, please contact us using the details provided above. We will respond to your request within 30 days. In certain cases, we may request additional information to verify your identity before processing your request.
International Data Transfers
As Royal River is based in New Zealand, your personal data may be transferred to and processed in New Zealand. The European Commission has recognised New Zealand as providing adequate protection for personal data. Where we use service providers in other countries, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission.
Data Retention
We retain personal data for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable laws. When determining retention periods, we consider the nature of the data, the purposes for processing, and legal requirements.
Data Security
We implement appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures include encryption, access controls, and regular security assessments.
Supervisory Authority
If you are located in the EEA and believe that we have not adequately addressed your concerns, you have the right to lodge a complaint with your local data protection supervisory authority.
Changes to This Information
We may update this GDPR information periodically. Any changes will be posted on this page with an updated revision date.