Matrix is built for Australian businesses, but some of our customers, their customers and their staff are in
the European Economic Area or the United Kingdom. This statement explains how the EU General Data Protection
Regulation (GDPR) and the UK GDPR apply to Matrix. It supplements our
privacy policy.
Controller and processor
- For information your business records in Matrix, your business is the
controller and Imagineering Studios is a processor. We process it only
on your instructions — to provide the service — and under a data processing agreement, which is available
on request.
- For your own account, billing and usage information, Imagineering Studios is the
controller.
Lawful bases
- Contract — to provide Matrix to your business and bill for it.
- Legitimate interests — to keep the service secure, prevent misuse, fix faults and
improve performance.
- Legal obligation — to keep tax and financial records.
- Consent — where we ask for it, which you can withdraw at any time.
International transfers
Matrix stores customer records in Australia. Australia doesn't currently hold an EU adequacy decision, so
where personal data from the EEA or UK is transferred to us, we rely on the European Commission's Standard
Contractual Clauses (and the UK Addendum) together with the security measures described in our privacy
policy. Our service providers that process data elsewhere are bound by equivalent safeguards.
Your rights
Where the GDPR applies, you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have data erased, where we have no legal reason to keep it;
- restrict or object to certain processing;
- receive your data in a portable format;
- withdraw consent where processing relies on it;
- complain to your local supervisory authority.
If your data is held in a Matrix customer's books, that business is the controller — contact them first,
and we'll help them respond. Otherwise, contact us and choose
"Privacy". We respond within one month.
How we help customers comply
- Export of your business's data at any time.
- Role-based access, so each person sees only what they need.
- Passkeys, multi-factor sign-in and an audit trail of security events.
- Notification without undue delay if we become aware of a personal data breach affecting your data.
Retention
Financial records must usually be kept for several years under tax law. Where a request to erase data
conflicts with a legal obligation to keep it, we keep only what the law requires, restrict its use, and
delete it when the obligation ends.