Information for visitors from the European Union
Last Updated: January 2024
The General Data Protection Regulation (GDPR) is a regulation in EU law on data protection and privacy for all individuals within the European Union and the European Economic Area. Although Frost Bear is based in South Africa, we are committed to protecting the privacy rights of all our visitors, including those from the EU.
This page provides additional information specifically for EU residents regarding how we handle personal data in compliance with the GDPR.
For the purposes of the GDPR, the data controller is:
Frost Bear
45 Waterkloof Ridge
Pretoria, Gauteng 0181
South Africa
Email: [email protected]
If you are a resident of the European Union, you have the following rights regarding your personal data:
You have the right to request a copy of the personal data we hold about you. We will provide this information within one month of your request, free of charge in most cases.
You have the right to request that we correct any inaccurate personal data or complete any incomplete data we hold about you.
You have the right to request that we delete your personal data in certain circumstances, such as when the data is no longer necessary for the purpose for which it was collected.
You have the right to request that we restrict the processing of your personal data in certain circumstances, such as when you contest the accuracy of the data.
You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit that data to another controller.
You have the right to object to the processing of your personal data in certain circumstances, including processing for direct marketing purposes.
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you.
Under the GDPR, we must have a valid legal basis for processing your personal data. The legal bases we rely on include:
As a South African company, when you provide personal data to us, it will be transferred to and processed in South Africa. South Africa is not currently subject to an adequacy decision by the European Commission.
We implement appropriate safeguards to ensure that your personal data receives an adequate level of protection when transferred outside the EU, including standard contractual clauses approved by the European Commission where applicable.
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, unless a longer retention period is required by law. When determining retention periods, we consider:
To exercise any of your GDPR rights, please contact us using the details provided above. We may need to verify your identity before processing your request.
We will respond to your request within one month. This period may be extended by two further months where necessary, taking into account the complexity and number of requests.
If you are not satisfied with our response, you have the right to lodge a complaint with a supervisory authority in your EU member state.
We may update this GDPR compliance information from time to time. Any changes will be posted on this page with an updated revision date.