GDPR Compliance
Last Updated: July 23, 2026
This page explains how geyser-sparrow complies with the General Data Protection Regulation (GDPR) and your rights under this regulation if you are located in the European Economic Area.
1. Legal Basis for Processing
We process your personal data under the following legal bases:
- Consent: When you submit a contact form or subscribe to communications, you provide explicit consent for us to process your data
- Contractual Necessity: Processing necessary to fulfill service requests and contractual obligations
- Legitimate Interests: Processing necessary for our legitimate business interests, such as improving services and website functionality
- Legal Obligations: Processing required to comply with applicable laws and regulations
2. Your Rights Under GDPR
If you are located in the European Economic Area, you have the following rights:
2.1 Right of Access
You have the right to request a copy of the personal data we hold about you. We will provide this information in a structured, commonly used, and machine-readable format.
2.2 Right to Rectification
You have the right to request correction of inaccurate or incomplete personal data we hold about you.
2.3 Right to Erasure
You have the right to request deletion of your personal data under certain circumstances, including when:
- The data is no longer necessary for the purposes for which it was collected
- You withdraw consent and there is no other legal basis for processing
- You object to processing and there are no overriding legitimate grounds
- The data has been unlawfully processed
2.4 Right to Restriction of Processing
You have the right to request that we restrict processing of your personal data in certain situations, such as when you contest the accuracy of the data or object to processing.
2.5 Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, and machine-readable format and transmit it to another controller.
2.6 Right to Object
You have the right to object to processing of your personal data for direct marketing purposes or when processing is based on legitimate interests.
2.7 Right to Withdraw Consent
Where processing is based on consent, you have the right to withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing based on consent before its withdrawal.
2.8 Right to Lodge a Complaint
You have the right to lodge a complaint with a supervisory authority if you believe our processing of your personal data violates GDPR.
3. How to Exercise Your Rights
To exercise any of the rights listed above, please contact us at:
Email: [email protected]
Subject Line: GDPR Request
We will respond to your request within one month of receipt. In complex cases, we may extend this period by two additional months, in which case we will inform you of the extension and reasons for delay.
4. Data Processing Activities
4.1 Contact Form Submissions
- Purpose: To respond to inquiries and provide requested services
- Legal Basis: Consent and contractual necessity
- Data Collected: Name, email address, service selection, message content
- Retention Period: Three years from last interaction
4.2 Website Analytics
- Purpose: To improve website functionality and user experience
- Legal Basis: Legitimate interests
- Data Collected: IP address, browser type, pages visited, time spent on site
- Retention Period: 26 months
4.3 Cookies
- Purpose: To remember user preferences and analyze site usage
- Legal Basis: Consent (for non-essential cookies)
- Data Collected: Cookie consent preferences, session identifiers
- Retention Period: As specified in our Cookies Policy
5. International Data Transfers
We primarily operate in Australia. If we transfer your data outside the European Economic Area, we ensure appropriate safeguards are in place, such as:
- Standard contractual clauses approved by the European Commission
- Transfer to countries deemed to provide adequate protection by the European Commission
- Your explicit consent for the specific transfer
6. Data Security Measures
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- Encryption of data in transit using SSL/TLS protocols
- Access controls limiting data access to authorized personnel only
- Regular security assessments and updates
- Secure data backup and recovery procedures
7. Data Protection Officer
For questions specifically related to data protection and GDPR compliance, you may contact our Data Protection Officer at:
Email: [email protected]
Subject Line: Attention Data Protection Officer
8. Automated Decision-Making
We do not engage in automated decision-making or profiling that produces legal effects or similarly significantly affects you.
9. Children's Data
We do not knowingly collect or process personal data from individuals under 16 years of age. If we become aware that we have collected data from a child under this age, we will take steps to delete such information promptly.
10. Changes to GDPR Compliance Statement
We may update this GDPR compliance statement from time to time. We will notify you of significant changes by posting a notice on our website or by sending you an email if we have your contact information.
11. Contact Information
For any questions or concerns about our GDPR compliance or to exercise your rights, please contact us:
Email: [email protected]
Address: 287 Wickham Terrace, Spring Hill QLD 4000, Australia