While vale-node operates primarily within Australia, we recognize and respect data protection principles aligned with the General Data Protection Regulation for individuals located in the European Economic Area.
This page outlines how we handle personal data in accordance with internationally recognized privacy standards.
Data Controller
vale-node acts as the data controller for personal information collected through our website and business operations.
Legal Basis for Processing
We process personal data under the following legal grounds:
- Consent: When you submit forms or communicate with us voluntarily
- Contractual necessity: To fulfill consulting service agreements
- Legitimate interests: To improve our services and maintain business operations
- Legal compliance: To meet regulatory and legal obligations
Your Rights Under GDPR
Individuals in the EEA have the following rights regarding their personal data:
- Right to access: Request confirmation of what personal data we hold
- Right to rectification: Correct inaccurate or incomplete data
- Right to erasure: Request deletion of personal data under certain conditions
- Right to restrict processing: Limit how we use your data
- Right to data portability: Receive your data in a structured, commonly used format
- Right to object: Object to processing based on legitimate interests
- Right to withdraw consent: Withdraw previously given consent at any time
Data Retention
Personal data is retained only as long as necessary for the purposes specified, or as required by applicable law. Retention periods vary based on:
- Active client relationships and ongoing projects
- Legal and regulatory requirements
- Legitimate business interests such as dispute resolution
Once data is no longer needed, it is securely deleted or anonymized.
Data Transfers
Personal data collected may be processed and stored in Australia. We ensure appropriate safeguards are in place when transferring data internationally.
Security Measures
We implement technical and organizational measures to protect personal data against unauthorized access, loss, or alteration. These include:
- Encrypted data transmission
- Access controls and authentication protocols
- Regular security assessments
- Staff training on data protection
Automated Decision-Making
We do not use automated decision-making or profiling that produces legal effects or similarly significant impacts on individuals.
Exercising Your Rights
To exercise any of your data protection rights, please contact us at:
We will respond to requests within one month. In complex cases, this period may be extended by two additional months with notification.
Complaints
If you believe your data protection rights have been violated, you have the right to lodge a complaint with your local data protection authority in the European Economic Area.
Updates to This Information
We may update this page to reflect changes in data protection practices or legal requirements. Material changes will be communicated through our website.