Information on this site is advertising in nature.

Last updated: October 2024

Our Commitment to GDPR

sepia-moon is committed to ensuring compliance with the General Data Protection Regulation (GDPR) for all users who access our services from the European Economic Area (EEA). This page outlines how we handle personal data in accordance with GDPR requirements and explains your rights as a data subject.

Data Controller Information

For the purposes of GDPR, sepia-moon acts as the data controller for personal information collected through our websites and services. Our contact details are:

sepia-moon
Level 12, 88 Walker Street
North Sydney NSW 2060
Australia
Email: [email protected]

Lawful Basis for Processing

Under GDPR, we must have a lawful basis for processing your personal data. Depending on the context, we rely on the following legal bases:

Your Rights Under GDPR

As a data subject under GDPR, you have the following rights:

Exercising Your Rights

To exercise any of your GDPR rights, please contact us at [email protected]. We will respond to your request within one month, as required by GDPR. In certain circumstances, we may extend this period by two additional months, in which case we will inform you of the extension and the reasons for it.

We may need to verify your identity before processing your request. If your request is manifestly unfounded or excessive, we may charge a reasonable fee or refuse to act on the request, providing you with an explanation of our reasons.

Data Transfers Outside the EEA

As an Australian company, we may transfer personal data outside the European Economic Area. When we do so, we ensure appropriate safeguards are in place to protect your data, including:

Data Protection Impact Assessments

Where required, we conduct Data Protection Impact Assessments (DPIAs) before undertaking processing that is likely to result in high risk to the rights and freedoms of individuals. This helps us identify and minimise data protection risks.

Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay.

Supervisory Authority

If you are located in the EEA and believe that we have not complied with GDPR, you have the right to lodge a complaint with a supervisory authority in the EU Member State of your habitual residence, place of work, or the place of the alleged infringement.

Updates to This Information

We may update this GDPR compliance information from time to time. Any changes will be posted on this page with an updated revision date.

Contact Us

For any questions about our GDPR compliance or to exercise your rights, please contact:

Email: [email protected]
Subject line: GDPR Enquiry