About GDPR
The General Data Protection Regulation (GDPR) is a comprehensive data protection law that governs how organisations collect, process, and protect personal data of individuals within the European Union and European Economic Area. Although Prime Cove is based in Australia, we are committed to extending GDPR protections to all users who access our website from EU/EEA countries.
Data Controller
Prime Cove acts as the data controller for personal information collected through this website. As the data controller, we determine the purposes and means of processing personal data and are responsible for ensuring compliance with applicable data protection laws.
Contact details:
Email: [email protected]
Address: 42 Industrial Avenue, Smithfield NSW 2164, Australia
Legal Basis for Processing
We process personal data under the following legal bases as defined by GDPR:
- Consent: When you voluntarily submit information through our contact forms or subscribe to communications
- Contractual necessity: When processing is required to fulfil a contract or respond to your enquiry about our services
- Legitimate interests: When processing is necessary for our legitimate business interests, such as improving our website and services, provided these interests do not override your fundamental rights
- Legal obligation: When we are required to process data to comply with applicable laws
Your Rights Under GDPR
If you are located in the EU/EEA, you have the following rights regarding your personal data:
- Right of access: You may request a copy of the personal data we hold about you
- Right to rectification: You may request correction of inaccurate or incomplete data
- Right to erasure: You may request deletion of your personal data in certain circumstances
- Right to restrict processing: You may request that we limit the processing of your data
- Right to data portability: You may request your data in a structured, commonly used format
- Right to object: You may object to processing based on legitimate interests
- Right to withdraw consent: Where processing is based on consent, you may withdraw it at any time
Exercising Your Rights
To exercise any of these rights, please contact us using the details provided above. We will respond to your request within one month of receipt. In certain circumstances, we may extend this period by two months, in which case we will inform you of the extension and the reasons for it.
We may request verification of your identity before processing your request to ensure we do not disclose personal data to unauthorised parties.
International Data Transfers
As we are based in Australia, your personal data may be transferred to and processed in Australia. Australia is not currently subject to an EU adequacy decision; however, we implement appropriate safeguards to protect your data during such transfers, including standard contractual clauses approved by the European Commission.
Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected. The retention period varies depending on the nature of the data and our legal obligations. When data is no longer required, it is securely deleted or anonymised.
Complaints
If you believe that your data protection rights have been violated, you have the right to lodge a complaint with a supervisory authority. For EU/EEA residents, this would be the data protection authority in your country of residence. You may also contact the Australian Information Commissioner at oaic.gov.au.
Updates to This Notice
We may update this GDPR compliance notice from time to time to reflect changes in our practices or legal requirements. The date of the last update is shown below.
Last updated: August 2026