GDPR Compliance
Last Updated: September 22, 2026
Our Commitment to Data Protection
Tide Panther is committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR). This page outlines your rights under GDPR and how we handle your personal information.
Legal Basis for Processing
We process your personal data based on the following legal grounds:
- Contract Performance: Processing necessary to fulfill our service agreement with you
- Consent: You have given explicit consent for specific processing activities
- Legitimate Interest: Processing necessary for our legitimate business operations
- Legal Obligation: Processing required to comply with legal requirements
Your GDPR Rights
Under GDPR, you have the following rights:
Right to Access
You have the right to request a copy of the personal data we hold about you. We will provide this information in a structured, commonly used, and machine-readable format.
Right to Rectification
You can request correction of inaccurate or incomplete personal data we hold about you.
Right to Erasure (Right to be Forgotten)
You can request deletion of your personal data when it is no longer necessary for the purposes for which it was collected, or if you withdraw consent.
Right to Restriction of Processing
You can request that we limit the processing of your personal data in certain circumstances.
Right to Data Portability
You have the right to receive your personal data in a portable format and transmit it to another controller.
Right to Object
You can object to processing of your personal data based on legitimate interests or for direct marketing purposes.
Rights Related to Automated Decision-Making
You have the right not to be subject to decisions based solely on automated processing that produce legal effects concerning you.
How to Exercise Your Rights
To exercise any of your GDPR rights, please contact us at [email protected] with the subject line "GDPR Request". We will respond within 30 days of receiving your request.
Please provide sufficient information to allow us to verify your identity and process your request efficiently.
Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including:
- Account and order information: retained for 7 years for accounting and legal purposes
- Marketing communications: retained until you withdraw consent
- Website analytics data: aggregated and anonymized after 24 months
Data Transfers
We primarily store and process data within New Zealand and the European Economic Area. If we transfer data outside these regions, we ensure appropriate safeguards are in place.
Data Security Measures
We implement technical and organizational measures to protect your data, including:
- Encryption of data in transit and at rest
- Regular security assessments and audits
- Access controls and authentication requirements
- Staff training on data protection practices
Data Breach Notification
In the event of a data breach that poses a risk to your rights and freedoms, we will notify you and the relevant supervisory authority within 72 hours of becoming aware of the breach.
Supervisory Authority
You have the right to lodge a complaint with your local data protection authority if you believe we have not complied with GDPR requirements.
Contact Our Data Protection Officer
For questions about data protection or to exercise your rights, contact us at [email protected].