harbor-swan

GDPR Information

Your Rights Under the General Data Protection Regulation

Last updated: July 29, 2026

1. Introduction

The General Data Protection Regulation (GDPR) is a comprehensive data protection law that applies to the processing of personal data of individuals in the European Union and European Economic Area. Although harbor-swan.com operates from Australia, we respect GDPR principles for all our users.

This document explains your rights under GDPR and how we handle your personal data in compliance with these regulations.

2. Data Controller Information

For the purposes of GDPR, the data controller is:

harbor-swan.com
Level 14, 287 Collins Street
Melbourne VIC 3000
Australia
Email: [email protected]

3. Legal Basis for Processing

We process your personal data based on the following legal grounds:

3.1 Contractual Necessity

Processing is necessary to fulfill our contract with you when you enroll in our courses. This includes:

  • Providing access to course materials and platform features
  • Facilitating live tutoring sessions
  • Processing payments and managing your account
  • Communicating about your courses and enrollment

3.2 Legitimate Interests

We process certain data based on our legitimate business interests, including:

  • Improving our platform and educational content
  • Analyzing usage patterns to enhance user experience
  • Detecting and preventing fraud or security threats
  • Communicating about service updates and improvements

We ensure that such processing does not override your fundamental rights and freedoms.

3.3 Consent

For certain processing activities, we rely on your explicit consent, such as:

  • Sending marketing communications about new courses
  • Using non-essential cookies and tracking technologies
  • Sharing your testimonials or feedback publicly

You can withdraw consent at any time without affecting the lawfulness of processing based on consent before withdrawal.

3.4 Legal Obligation

We process data when required to comply with legal obligations, such as:

  • Tax and accounting requirements
  • Responding to lawful requests from authorities
  • Maintaining records as required by law

4. Your GDPR Rights

Under GDPR, you have the following rights regarding your personal data:

4.1 Right of Access

You have the right to obtain confirmation about whether we process your personal data and to access that data. You can request a copy of your personal information in a commonly used electronic format.

4.2 Right to Rectification

You have the right to request correction of inaccurate personal data and to complete incomplete personal data. We will make corrections within one month of your request.

4.3 Right to Erasure (Right to be Forgotten)

You can request deletion of your personal data when:

  • The data is no longer necessary for the purposes it was collected
  • You withdraw consent and there is no other legal basis for processing
  • You object to processing and there are no overriding legitimate grounds
  • The data was unlawfully processed
  • Deletion is required to comply with legal obligations

This right is not absolute; we may retain certain data where legally required or for legitimate purposes such as establishing legal claims.

4.4 Right to Restriction of Processing

You can request that we restrict processing of your personal data when:

  • You contest the accuracy of the data (during verification)
  • Processing is unlawful but you prefer restriction over erasure
  • We no longer need the data, but you need it for legal claims
  • You have objected to processing (pending verification of legitimate grounds)

4.5 Right to Data Portability

You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit it to another controller where:

  • Processing is based on consent or contract
  • Processing is carried out by automated means

This applies to data you provided to us, not to derived or inferred data.

4.6 Right to Object

You can object to processing of your personal data based on legitimate interests or for direct marketing purposes. We will cease processing unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.

For direct marketing, we will stop processing immediately upon your objection.

4.7 Right Not to be Subject to Automated Decision-Making

You have the right not to be subject to decisions based solely on automated processing, including profiling, which produce legal effects or similarly significantly affect you. We do not currently engage in such automated decision-making.

4.8 Right to Withdraw Consent

Where processing is based on consent, you have the right to withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.

5. Exercising Your Rights

To exercise any of your GDPR rights, contact us at [email protected] with:

  • Your full name and email address associated with your account
  • Specific right you wish to exercise
  • Any relevant details to help us process your request

We will respond to your request within one month. If your request is complex or we receive multiple requests, we may extend this period by two additional months, and we will inform you of such extension.

We may request additional information to verify your identity before processing your request to protect your personal data from unauthorized access.

6. Data Transfers

As we operate from Australia, your data may be transferred outside the European Economic Area. We ensure appropriate safeguards are in place through:

  • Standard contractual clauses approved by the European Commission
  • Adequacy decisions recognizing equivalent data protection standards
  • Other mechanisms approved under GDPR

7. Data Retention

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including:

  • Duration of your course enrollment plus reasonable period for queries
  • Legal and regulatory retention requirements (typically 7 years for financial records)
  • Resolving disputes and enforcing agreements

After retention periods expire, we securely delete or anonymize personal data.

8. Data Security

We implement appropriate technical and organizational measures to protect personal data against unauthorized or unlawful processing, accidental loss, destruction, or damage. These measures include:

  • Encryption of data in transit and at rest
  • Access controls and authentication mechanisms
  • Regular security assessments and testing
  • Employee training on data protection
  • Incident response procedures

9. Data Breach Notification

In the event of a data breach that poses a risk to your rights and freedoms, we will notify you without undue delay and within 72 hours of becoming aware of the breach, as required by GDPR. The notification will include:

  • Nature of the breach and categories of data affected
  • Likely consequences of the breach
  • Measures taken or proposed to address the breach
  • Contact point for further information

10. Children's Privacy

Our services are not directed at children under 16. We do not knowingly collect personal data from children under 16 without parental consent. If we become aware of such collection, we will delete the data promptly.

11. Complaints and Supervisory Authority

If you believe we have not handled your personal data in accordance with GDPR, you have the right to lodge a complaint with a supervisory authority, particularly in the EU member state of your residence, place of work, or place of alleged infringement.

We encourage you to contact us first so we can address your concerns directly.

12. Updates to This Information

We may update this GDPR information to reflect changes in our practices or legal requirements. Significant changes will be communicated to users via email or prominent notice on our website.

13. Contact Information

For questions about GDPR compliance or to exercise your rights, contact us at:

Email: [email protected]
Address: Level 14, 287 Collins Street, Melbourne VIC 3000, Australia