Last updated: January 2024
Sepia-willow is committed to ensuring compliance with the General Data Protection Regulation (GDPR) for users located in the European Economic Area (EEA). This page outlines how we meet our obligations under the GDPR and explains your rights as a data subject.
Sepia-willow acts as the data controller for personal information collected through our website and services. As the data controller, we determine the purposes and means of processing your personal data.
Contact details:
Sepia-willow
Level 8, 123 Collins Street
Melbourne VIC 3000
Australia
Email: [email protected]
We process personal data under the following legal bases as permitted by the GDPR:
If you are located in the EEA, you have the following rights regarding your personal data:
You have the right to request a copy of the personal data we hold about you, along with information about how we process it.
You have the right to request correction of any inaccurate personal data we hold about you, and to have incomplete data completed.
You have the right to request deletion of your personal data in certain circumstances, such as when the data is no longer necessary for the purposes for which it was collected.
You have the right to request that we restrict the processing of your personal data in certain circumstances, such as when you contest the accuracy of the data.
You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit that data to another controller.
You have the right to object to processing of your personal data based on legitimate interests or for direct marketing purposes.
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects or similarly significantly affects you.
To exercise any of these rights, please contact us at [email protected]. We will respond to your request within one month. In some cases, we may need to verify your identity before processing your request.
You also have the right to lodge a complaint with a supervisory authority if you believe your rights have been violated.
As we are based in Australia, your personal data may be transferred to and processed in Australia. When transferring data outside the EEA, we ensure appropriate safeguards are in place, such as standard contractual clauses approved by the European Commission, to protect your personal data.
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk of processing personal data, including:
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours where feasible. If the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly.
For any questions or concerns about our GDPR compliance or to exercise your rights, please contact us at:
Email: [email protected]