GDPR Statement

Provider and, where applicable, controller: Raynux Pty Ltd (ABN 38 700 717 166). Version 2.0. Effective date: 30 September 2026. Supersedes the previous GDPR statement.

This statement explains how Librarika meets the EU General Data Protection Regulation (GDPR) and the UK GDPR for our global library customers and their users. It sits alongside our Privacy Policy (for individuals) and our Data Processing Addendum (DPA) (for customers who are controllers). Where this statement summarises those documents and they conflict, the Privacy Policy and DPA prevail.

1. Who we are

Librarika is operated by Raynux Pty Ltd, Level 29, 221 St Georges Terrace, Perth WA 6000, Australia. Contact: info@raynux.com or info@librarika.com. Librarika is now provided by Raynux Pty Ltd, which has taken over its operation from the previous operator; this statement replaces the earlier one.

2. Our roles: processor and controller

  • Processor. When a library uses Librarika to process its patrons' and members' personal data, the library is the data controller and Raynux acts as its processor, handling that data on the library's documented instructions. This is governed by our DPA.
  • Controller. For information we decide how to use ourselves — account, billing, support and website-visitor data — Raynux is the controller, as described in our Privacy Policy.

3. Lawful bases and individual rights

We rely on the GDPR lawful bases set out in our Privacy Policy (contract, legitimate interests, consent, and legal obligation). Individuals can exercise their rights — access, correction, erasure, restriction, objection, data portability and withdrawal of consent — as described there; patrons should contact their library first, as the library controls their record. Complaints may be made to an EU supervisory authority, the UK Information Commissioner's Office, or, in Australia, the Office of the Australian Information Commissioner (OAIC).

4. International data transfers

Librarika is a global service. Personal data is hosted primarily in Amsterdam, Netherlands, with cloud servers in various locations. Our personnel, contractors and service providers who help operate, support and develop the Service may access personal data from various countries, including countries that do not have an EU/UK adequacy decision. Personal data may be processed in Australia, the Netherlands, the United Kingdom, the United States, Singapore and Bangladesh. The specific recipients and the countries involved are identified in our Sub-processors list (see section 5).

Where we transfer personal data from the EEA or UK to a country that does not have an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (2021) and, for UK data, the UK International Data Transfer Addendum, supported by a transfer risk assessment and appropriate technical and organisational measures. We do not rely on the EU–US Privacy Shield, which is no longer a valid transfer mechanism; any earlier reference to it is withdrawn. Under the Australian Privacy Act (APP 8) we also take reasonable steps to ensure overseas recipients handle personal data consistently with the Australian Privacy Principles, and we remain accountable under section 16C for how our overseas recipients handle personal information subject to that Act.

5. Sub-processors

We use vetted sub-processors — including cloud hosting and infrastructure, object/file storage, payment processing, transactional email, analytics and error/crash diagnostics, login/identity and anti-abuse providers, support tools (including limited AI assistance used under human review to help draft support replies), and our development and support contractors — each bound by data-protection terms. A current list of our sub-processors and the countries in which they operate is available on request at info@raynux.com, and we notify customers of changes to it as required by the DPA, so that ordinary changes do not require re-issuing this statement.

6. Security and breach notification

We apply technical and organisational measures appropriate to the risk, including encryption in transit, access controls, role-based permissions and monitoring. We will notify affected customers/controllers, and regulators and individuals where the law requires, in line with the GDPR (including supporting the controller's 72-hour notification duty) and the Australian Notifiable Data Breaches scheme.

7. Data retention

We keep personal data only as long as needed for the purposes described in our Privacy Policy; for patron data we act on the library's instructions and on account closure.

8. Data Processing Addendum for customers

Customers who are controllers can enter our DPA, which incorporates the Standard Contractual Clauses and the UK Addendum for international transfers. The DPA forms part of our terms; a counter-signed copy is available on request at info@raynux.com.

9. EU / UK representative and contact

As we provide Librarika to customers and users in the EU and UK, we are appointing a representative in the EU under Article 27 of the GDPR and a representative in the UK under the UK GDPR; their contact details will be added here once appointed. A Data Protection Officer is not mandatory for our processing and has not been appointed. Contact: Raynux Pty Ltd, Level 29, 221 St Georges Terrace, Perth WA 6000, Australia — info@raynux.com / info@librarika.com.