Last Updated: September 2, 2026
Although we operate primarily in Australia, we recognize that some of our website visitors and service users may be located in the European Economic Area (EEA). We are committed to complying with the General Data Protection Regulation (GDPR) for all individuals whose personal data we process, regardless of location.
We process personal data only when we have a valid legal basis, including:
If you are an EEA resident, you have the following rights regarding your personal data:
You may request confirmation of whether we process your personal data and obtain a copy of that data.
You can request correction of inaccurate or incomplete personal data we hold about you.
Under certain circumstances, you may request deletion of your personal data (the "right to be forgotten").
You may request that we limit how we use your personal data in specific situations.
You can request to receive your personal data in a structured, commonly used, machine-readable format and have it transmitted to another controller.
You may object to processing of your personal data based on legitimate interests or for direct marketing purposes.
You have the right not to be subject to decisions based solely on automated processing that produce legal effects or similarly significant impacts.
To exercise any of these rights, please submit a written request to:
Email: [email protected]
Subject Line: "GDPR Data Subject Request"
We will respond to your request within one month, though this period may be extended by two additional months for complex requests. We will inform you of any such extension and the reasons for it.
For questions specifically related to GDPR compliance or data protection, you may contact our designated data protection officer at [email protected].
When we transfer personal data from the EEA to countries outside the EEA (including Australia), we ensure appropriate safeguards are in place, such as:
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including:
We implement technical and organizational measures to ensure a level of security appropriate to the risk, including:
In the event of a data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. If the breach poses a high risk, we will also notify affected individuals without undue delay.
If you believe we have not handled your personal data in accordance with GDPR, you have the right to lodge a complaint with a supervisory authority in the EEA country where you reside, work, or where the alleged infringement occurred.
We do not knowingly process personal data of children under 16 without parental consent. If we become aware that we have collected such data without appropriate consent, we will take steps to delete it promptly.
We may update this GDPR compliance statement to reflect changes in our practices or legal requirements. Material changes will be communicated through prominent notices on our website.