Last Updated: September 2, 2026
While topaz-savanna is based in Australia, we recognize that individuals from the European Union may interact with our website. This page outlines how we comply with the General Data Protection Regulation (GDPR) principles when processing personal data of EU residents.
For the purposes of GDPR, the data controller is:
topaz-savanna
127 Macquarie Street
Hobart, Tasmania 7000
Australia
Email: [email protected]
We process personal data only when we have a lawful basis to do so:
If you are an EU resident, you have the following rights regarding your personal data:
You may request confirmation of whether we process your personal data and obtain a copy of that data.
You may request correction of inaccurate or incomplete personal data we hold about you.
You may request deletion of your personal data under certain circumstances, including when the data is no longer necessary for the purposes for which it was collected or when you withdraw consent.
You may request that we limit the processing of your personal data in specific situations, such as when you contest the accuracy of the data.
You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller.
You may object to processing of your personal data based on legitimate interests or for direct marketing purposes.
Where processing is based on consent, you may withdraw that consent at any time without affecting the lawfulness of processing based on consent before withdrawal.
You have the right to lodge a complaint with a supervisory authority in the EU member state of your residence, place of work, or place of the alleged infringement.
Personal data collected through our website is processed and stored in Australia. We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, comply with legal obligations, resolve disputes, and enforce our agreements. Specific retention periods are outlined in our Privacy Policy.
We do not sell personal data to third parties. When we share data with service providers, we ensure they are contractually obligated to process data in compliance with GDPR principles and maintain appropriate security measures.
We do not engage in automated decision-making or profiling that produces legal effects or similarly significantly affects individuals.
If personal data is transferred outside the European Economic Area, we ensure appropriate safeguards are in place, such as standard contractual clauses approved by the European Commission.
Our website uses cookies as described in our Cookies Policy. You can manage cookie preferences through the cookie banner displayed on your first visit or through your browser settings.
To exercise any of your GDPR rights, please contact us at [email protected] with the subject line "GDPR Request." We will respond to your request within one month, though this period may be extended by two additional months if the request is complex.
To verify your identity, we may request additional information before processing certain requests.
We may update this GDPR compliance statement to reflect changes in our practices or legal requirements. The updated version will be posted on this page with a revised date.