Last Updated: July 10, 2026
The General Data Protection Regulation (GDPR) is a comprehensive data protection law of the European Union that came into effect in May 2018. While frost-vector operates from Australia, we process data of individuals who may be protected by GDPR. This page explains how we comply with GDPR principles and how you can exercise your rights.
For the purposes of GDPR, frost-vector acts as the data controller for personal information collected through our services.
Data Controller:
frost-vector
127 Collins Street
Melbourne VIC 3000
Australia
Email: [email protected]
We process personal data only when we have a legal basis to do so. Our legal bases include:
Processing necessary to perform our contract with you when you enroll in courses. This includes:
Processing necessary for our legitimate business interests, provided these interests do not override your fundamental rights. This includes:
Processing based on your explicit consent, which you can withdraw at any time. This includes:
Processing necessary to comply with legal requirements such as:
GDPR grants you specific rights regarding your personal data. You may exercise these rights by contacting us at [email protected].
You have the right to obtain confirmation of whether we process your personal data and to receive a copy of that data along with supplementary information about how it's processed.
You have the right to have inaccurate personal data corrected and incomplete data completed. You can update much of this information directly through your student dashboard.
You have the right to request deletion of your personal data when:
This right is not absolute. We may retain data when required by law or for legitimate purposes such as defending legal claims or fulfilling contractual obligations.
You have the right to request that we restrict processing of your personal data when:
You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit that data to another controller when:
You have the right to object to processing of your personal data when:
For direct marketing, your right to object is absolute. For other processing, we must cease unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.
You have the right not to be subject to decisions based solely on automated processing, including profiling, that produce legal effects or similarly significantly affect you. We do not engage in automated decision-making that produces such effects.
Where processing is based on consent, you have the right to withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing conducted prior to withdrawal.
To exercise any of these rights, send a request to [email protected] with:
We will respond within one month of receiving your request. In complex cases, this may be extended by two additional months with notification. We do not charge a fee for exercising your rights unless requests are manifestly unfounded or excessive.
We may request additional information to verify your identity before fulfilling requests, particularly for data access or deletion, to ensure we do not disclose or delete data belonging to another person.
Our data processing adheres to GDPR principles:
We process data lawfully based on identified legal grounds, treat data subjects fairly, and provide transparent information about our processing activities.
We collect data for specified, explicit, legitimate purposes and do not process it in ways incompatible with those purposes.
We collect only data that is adequate, relevant, and limited to what is necessary for the purposes for which it's processed.
We take reasonable steps to ensure personal data is accurate and kept up to date, and we erase or rectify inaccurate data without delay.
We retain personal data only as long as necessary for the purposes for which it was collected or as required by law.
We implement appropriate technical and organizational measures to protect personal data against unauthorized or unlawful processing and accidental loss, destruction, or damage.
We are responsible for and can demonstrate compliance with GDPR principles through our policies, procedures, and documentation.
We operate from Australia, which means personal data of EU residents may be transferred outside the European Economic Area. When we transfer data internationally, we ensure appropriate safeguards are in place:
You may request information about the specific safeguards applied to your data by contacting us.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you without undue delay. We will also notify relevant supervisory authorities as required by GDPR.
Our services may be used by individuals under 16 years of age through our Youth Language Academy. For users under 16, we require parental or guardian consent before processing personal data. We take additional care to ensure information directed to children is explained in clear, plain language appropriate to their age.
If you believe our processing of your personal data violates GDPR, you have the right to lodge a complaint with a supervisory authority in the EU member state of your habitual residence, place of work, or place of the alleged infringement. A list of supervisory authorities is available at: edpb.europa.eu/about-edpb/board/members_en
We may update this GDPR compliance information to reflect changes in our practices or legal requirements. Material changes will be communicated via email or prominent website notice.
For questions about GDPR compliance or to exercise your rights, contact us at:
frost-vector
127 Collins Street
Melbourne VIC 3000
Australia
Email: [email protected]