Privacy Policy
1. Scope and identity of the controller
This Privacy Policy explains how Pearl Bit Star Zau Gallery Pty Ltd. ("we", "us" or "our") collects, uses, stores, discloses and protects personal information when you visit this website, make an enquiry, express interest in educational updates, participate in an event, use an observatory program or otherwise interact with us.
For Australian privacy purposes, we handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles where those laws apply. For individuals located in the European Economic Area, the United Kingdom or another jurisdiction that applies comparable privacy rules, we also describe the safeguards and rights relevant under the General Data Protection Regulation and the UK GDPR.
Controller and organisation: Pearl Bit Star Zau Gallery Pty Ltd.Registered and operational address: 7 Halifax Street, Botany NSW 2019, Australia
ABN: 94 627 841 395
ACN: 627 841 395
Privacy email: info@pearlbitstarzaugallery.com
Telephone: +61 2 8394 6217
2. Personal information we may collect
Depending on how you interact with us, we may collect identification and contact details, enquiry content, booking or event preferences, accessibility requirements that you voluntarily provide, education or institutional affiliation, newsletter preferences, correspondence records, feedback, complaint information and records needed to administer attendance or provide requested services.
We may also collect technical information created when a browser accesses the website, such as browser type, device type, approximate time of access, requested page, referring page and error information. This local version of the website does not intentionally load third-party analytics, advertising networks, external fonts or social-media tracking resources. If the website is later connected to such services, this Policy and the Cookie Policy must be updated before those services are activated.
3. Sensitive information and information about children
We do not seek sensitive information unless it is reasonably necessary for a particular program and you provide it voluntarily or the law permits its collection. Examples may include accessibility, dietary or health-related information required to safely support a visitor. We limit access to such information and retain it only for as long as necessary.
Educational programs may involve children and school groups. A parent, guardian, teacher or authorised institution should provide personal information on behalf of a child where appropriate. We do not knowingly use children’s information for behavioural advertising or unrelated profiling.
4. How we collect information
We may collect personal information directly from you through forms, event registrations, enquiries, correspondence, feedback, telephone conversations and in-person interactions. We may receive information from a school, employer, event organiser, parent, guardian or other authorised representative when they arrange participation on your behalf.
Where lawful and reasonable, we may receive limited information from publicly available sources or professional partners. We do not purchase consumer marketing lists for unrelated advertising.
5. Purposes and lawful bases
We use personal information to respond to enquiries; provide observatory, gallery, event, research and educational services; administer attendance and safety; communicate scheduling changes; maintain records; improve accessibility and service quality; protect visitors, staff and property; comply with legal obligations; establish or defend legal claims; and send updates where you have requested them.
For GDPR purposes, our lawful bases may include performance of a contract or steps requested before a contract, compliance with a legal obligation, protection of vital interests, our legitimate interests in operating and improving our services, performance of a task in the public interest where applicable, and consent where the law requires consent. You may withdraw consent at any time, without affecting processing already carried out lawfully.
6. Website storage, cookies and similar technologies
The website is designed to operate without external advertising or analytics services. It may use browser storage for essential interface functions and to remember a newsletter preference submitted through the footer form on the same device. Such information remains in the browser unless a connected service is introduced or the user sends information through another channel.
More information about essential storage, consent and browser controls appears in the Cookie Policy. Blocking storage may affect preference-saving functions but should not prevent access to core editorial content.
7. Disclosure of personal information
We may disclose personal information to personnel who need it to perform their duties, contracted service providers, event or education partners, professional advisers, insurers, payment or booking providers where used, technology and security providers, regulators, law-enforcement bodies, courts and other recipients required or authorised by law.
We require service providers to use information only for agreed purposes, protect it appropriately and comply with applicable privacy obligations. We do not sell personal information. We do not disclose personal information to third parties for their independent behavioural advertising without valid consent.
8. International transfers
Some service providers or collaboration partners may operate outside Australia. Before making a transfer, we take reasonable steps to assess the recipient, limit the information transferred and implement contractual, organisational or legal safeguards. For transfers of EEA or UK personal data, safeguards may include an adequacy decision, standard contractual clauses, the UK International Data Transfer Agreement or another lawful mechanism.
You may contact us for information about the categories of recipients and safeguards relevant to a particular transfer, subject to confidentiality and security limitations.
9. Retention and deletion
We retain personal information only for as long as reasonably necessary for the purpose for which it was collected, to meet legal, accounting, insurance, safety and recordkeeping requirements, or to resolve disputes. Retention periods differ according to the nature of the record and the applicable law.
When information is no longer required, we take reasonable steps to delete, destroy or de-identify it. Backup copies may remain for a limited period until they are overwritten through normal security processes.
10. Security
We use proportionate administrative, physical and technical safeguards designed to protect personal information from misuse, interference, loss, unauthorised access, modification and disclosure. Measures may include access controls, staff confidentiality duties, secure configuration, patching, backup procedures, incident response and minimisation of collected data.
No method of transmission or storage is completely secure. You should avoid sending unnecessary sensitive information and should contact us promptly if you believe information has been compromised.
11. Your privacy rights
Subject to applicable law, you may request access to personal information, correction of inaccurate or incomplete information, deletion, restriction of processing, objection to processing, portability of information you provided, and withdrawal of consent. You may also object to direct marketing at any time.
Australian individuals may request access and correction under the Privacy Act. EEA and UK individuals may exercise GDPR rights and may lodge a complaint with their local supervisory authority. We may need to verify identity before acting on a request. Legal exceptions may apply, and if we decline a request we will explain the basis where required.
12. Automated decision-making and profiling
We do not currently use personal information collected through this website to make solely automated decisions that produce legal or similarly significant effects. We do not conduct behavioural advertising profiles through the local website. If that changes, we will provide additional notice and any choices required by law.
13. Marketing communications
We send electronic updates only where permitted by law. You may unsubscribe or withdraw a preference at any time. The footer form in this local build stores a preference in the browser; it does not by itself transmit information to a remote mailing platform. A production mailing service must not be connected without appropriate disclosure, consent and security controls.
14. Data breaches
We maintain procedures for assessing suspected data breaches. Where a breach is likely to result in serious harm or creates a risk requiring notification, we will notify affected individuals and the relevant regulator as required, including the Office of the Australian Information Commissioner where the Notifiable Data Breaches scheme applies.
15. Complaints
Direct privacy questions or complaints to the contact details above. Please describe the issue and the outcome you seek. We will acknowledge and investigate complaints within a reasonable period. If you are not satisfied, you may contact the Office of the Australian Information Commissioner or, where GDPR applies, the competent data protection supervisory authority.
16. Third-party websites
This website may describe partners or resources, but the local build does not rely on external content. If a future version includes links to third-party websites, their privacy practices will be governed by their own notices. We are not responsible for third-party privacy practices and recommend reviewing their policies before providing information.
17. Changes to this Policy
We may update this Policy to reflect changes in law, technology, services or operational practices. The current version will be published on this page with an updated effective date. Material changes will be highlighted or otherwise communicated where required.