GDPR Compliance

Last updated: 12 September 2025

How We Comply

  • Lawful Bases: consent, legitimate interests, contract performance, and legal obligations
  • Data Minimization: collect only what is necessary for clear purposes
  • Storage Limitation: defined retention schedules and secure deletion
  • Security by Design: access controls, encryption in transit, and vendor reviews

Data Subject Rights

  • Right of Access: receive a copy of your data
  • Right to Rectification: correct inaccurate data
  • Right to Erasure: request deletion where applicable
  • Right to Restrict Processing: limit how we use your data
  • Right to Object: opt out of certain processing
  • Right to Portability: obtain your data in a portable format

International Data Transfers

When data is transferred internationally, we use recognized mechanisms such as Standard Contractual Clauses and implement supplementary measures where needed.

Submit a GDPR Request

Email [email protected] with subject “GDPR Request”. We verify identity via reply and fulfill within statutory timelines.

  1. Verification steps shared by email
  2. Response typically within 30 days
  3. Appeals handled by senior reviewer

Submit GDPR Request

Data Protection Contact

  • Email: [email protected]
  • Postal: Level 11, 303 Collins Street, Melbourne VIC 3000, Australia
  • You may also contact your local supervisory authority