1. Data Controller
The data controller responsible for your personal data is:
Mobilityregen
417–457 Bridge Rd, Richmond VIC 3121, Australia
Phone: +61 3 9429 8800
Email: hello@mobilityregen.world
Website: mobilityregen.world
For any questions regarding this Privacy Policy or the processing of your personal data, you may contact us using the details above. We aim to respond to all privacy-related enquiries within thirty calendar days.
2. Personal Data We Collect
We collect personal data only when necessary for the operation of our website and cycling meetup services. The categories of data we may collect include:
2.1 Data You Provide Directly
- Contact form submissions: Your name, email address, message content, and GDPR consent confirmation when you submit an enquiry through our contact form.
- Program registrations: Name, email address, experience level, and ride format preferences when you register interest in a meetup or workshop.
- Communication records: Content of emails, phone conversations, and written correspondence related to your enquiries or participation in our programs.
2.2 Data Collected Automatically
- Technical data: IP address, browser type and version, operating system, device type, screen resolution, and referring URL.
- Usage data: Pages visited, time spent on pages, click patterns, scroll depth, and navigation paths within the website.
- Cookie data: Information stored through cookies and similar technologies as described in our Cookie Policy.
2.3 Data We Do Not Collect
We do not intentionally collect sensitive personal data such as health records, financial account details, government identification numbers, or biometric data. We do not collect data from individuals under the age of sixteen without verifiable parental consent.
3. Legal Basis for Processing
Under the General Data Protection Regulation (GDPR), we process personal data based on the following legal grounds:
- Consent (Article 6(1)(a)): When you submit the contact form and check the GDPR consent checkbox, you provide explicit consent for us to process your name, email, and message for the purpose of responding to your enquiry. You may withdraw this consent at any time.
- Legitimate interests (Article 6(1)(f)): We process technical and usage data to maintain website security, improve user experience, and analyse aggregate traffic patterns. Our legitimate interest is balanced against your rights and freedoms.
- Contractual necessity (Article 6(1)(b)): When you register for a paid program or workshop, we process your data as necessary to fulfil our contractual obligations to you.
- Legal obligation (Article 6(1)(c)): We may process and retain certain data where required by applicable Australian or international law, including tax and accounting regulations.
4. Purpose of Data Usage
We use collected personal data exclusively for the following purposes:
- Responding to enquiries submitted through the contact form or other communication channels
- Confirming registration for cycling meetups, workshops, and seasonal programs
- Sending pre-ride briefings, route information, and schedule updates to registered participants
- Maintaining internal records of program participation and community feedback
- Improving website functionality, content relevance, and user navigation experience
- Detecting and preventing fraudulent activity, security threats, and unauthorised access
- Complying with legal obligations and responding to lawful requests from authorities
- Generating anonymised, aggregated statistical reports about website usage and program attendance
We do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects. We do not sell personal data to third parties.
5. Data Retention Period
We retain personal data only for as long as necessary to fulfil the purposes described in this policy, unless a longer retention period is required by law.
- Contact form data: Retained for twelve months from the date of submission, unless an ongoing correspondence relationship exists. Upon expiry, data is securely deleted or anonymised.
- Program registration data: Retained for the duration of your active participation plus twenty-four months thereafter for reference and feedback purposes.
- Technical and usage logs: Retained for ninety days, after which they are aggregated and anonymised or deleted.
- Cookie consent records: Retained for twelve months in local storage on your device, as described in our Cookie Policy.
- Financial transaction records: Retained for seven years in accordance with Australian tax and accounting requirements.
When the retention period expires, personal data is permanently deleted from our active systems and backups within a reasonable timeframe, unless legal obligations require continued storage.
7. International Data Transfers
Your personal data is primarily stored and processed within Australia. In cases where data is transferred to service providers located outside the European Economic Area (EEA) or Australia, we ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses approved by the European Commission
- Verification that the recipient country provides an adequate level of data protection
- Binding corporate rules or certification mechanisms where applicable
You may request information about the specific safeguards applied to international transfers by contacting us at the address provided in Section 1.
8. Security Measures
We implement technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These measures include:
- HTTPS encryption for all data transmitted between your browser and our servers
- Access controls limiting personal data access to authorised personnel only
- Regular security assessments and vulnerability monitoring of our website infrastructure
- Secure storage of contact form submissions with encryption at rest where technically feasible
- Employee training on data protection principles and incident response procedures
- Incident logging and breach notification procedures compliant with GDPR Article 33 and 34 requirements
While we take reasonable precautions, no method of electronic transmission or storage is completely secure. If you believe your data has been compromised, please contact us immediately.
9. Your Rights Under GDPR
If you are located in the European Economic Area, you have the following rights regarding your personal data:
- Right of access (Article 15): Request a copy of the personal data we hold about you.
- Right to rectification (Article 16): Request correction of inaccurate or incomplete personal data.
- Right to erasure (Article 17): Request deletion of your personal data where there is no compelling reason for continued processing.
- Right to restrict processing (Article 18): Request that we limit the processing of your data under certain circumstances.
- Right to data portability (Article 20): Receive your data in a structured, commonly used, machine-readable format.
- Right to object (Article 21): Object to processing based on legitimate interests or for direct marketing purposes.
- Right to withdraw consent (Article 7(3)): Withdraw consent at any time without affecting the lawfulness of prior processing.
- Right to lodge a complaint: File a complaint with your local data protection supervisory authority.
To exercise any of these rights, contact us at hello@mobilityregen.world with sufficient detail to identify your request. We will respond within thirty days.
10. Australian Privacy Act Compliance
As an organisation operating in Victoria, Australia, we comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Under the APPs, you have the right to:
- Know why your personal information is being collected and how it will be used
- Access your personal information held by us
- Request correction of inaccurate, out-of-date, incomplete, or misleading information
- Make a complaint about a breach of the APPs
Complaints may be directed to us in the first instance. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.
11. Children's Privacy
Our website and services are not directed at children under sixteen years of age. We do not knowingly collect personal data from children without verifiable parental or guardian consent. Participants aged twelve to fifteen may join meetups when accompanied by a parent or legal guardian, but we collect data only from the accompanying adult for registration purposes.
If you believe we have inadvertently collected data from a child without appropriate consent, please contact us and we will promptly delete the information.
12. Changes to This Policy
We may update this Privacy Policy periodically to reflect changes in our data practices, legal requirements, or service offerings. The date at the top of this page indicates when the policy was last revised. Material changes will be communicated through a notice on our website homepage.
We encourage you to review this policy regularly. Continued use of the website after changes are published constitutes acceptance of the updated policy.
13. Contact Information
For privacy-related enquiries, data subject requests, or concerns about how your personal data is handled, please contact:
Mobilityregen — Privacy Enquiries
417–457 Bridge Rd, Richmond VIC 3121, Australia
Phone: +61 3 9429 8800
Email: hello@mobilityregen.world
You may also use our contact form and specify that your message relates to a privacy matter.