GDPR Compliance
Last updated: 12 September 2025
How We Comply
- Lawful Bases: consent, legitimate interests, contract performance, and legal obligations
- Data Minimization: collect only what is necessary for clear purposes
- Storage Limitation: defined retention schedules and secure deletion
- Security by Design: access controls, encryption in transit, and vendor reviews
Data Subject Rights
- Right of Access: receive a copy of your data
- Right to Rectification: correct inaccurate data
- Right to Erasure: request deletion where applicable
- Right to Restrict Processing: limit how we use your data
- Right to Object: opt out of certain processing
- Right to Portability: obtain your data in a portable format
International Data Transfers
When data is transferred internationally, we use recognized mechanisms such as Standard Contractual Clauses and implement supplementary measures where needed.
Submit a GDPR Request
Email [email protected] with subject “GDPR Request”. We verify identity via reply and fulfill within statutory timelines.
- Verification steps shared by email
- Response typically within 30 days
- Appeals handled by senior reviewer
Data Protection Contact
- Email: [email protected]
- Postal: Level 11, 303 Collins Street, Melbourne VIC 3000, Australia
- You may also contact your local supervisory authority