GDPR Compliance Statement
Effective Date: June 19, 2026
1. Overview
While amber-isle is based in Australia, we recognize that some of our website visitors may be located in the European Union. This document outlines our commitment to complying with the General Data Protection Regulation (GDPR) for individuals located in the EU.
2. Legal Basis for Processing
We process personal data based on the following legal grounds:
- Consent: When you explicitly agree to provide your information
- Contractual Necessity: When processing is necessary to perform our services
- Legitimate Interests: When we have a legitimate business interest that does not override your privacy rights
- Legal Obligation: When required by law
3. Your Rights Under GDPR
If you are an EU resident, you have the following rights regarding your personal data:
- Right to Access: You can request a copy of the personal data we hold about you
- Right to Rectification: You can request correction of inaccurate or incomplete data
- Right to Erasure: You can request deletion of your personal data in certain circumstances
- Right to Restrict Processing: You can request that we limit how we use your data
- Right to Data Portability: You can request your data in a structured, machine-readable format
- Right to Object: You can object to processing based on legitimate interests or direct marketing
- Right to Withdraw Consent: You can withdraw consent at any time where consent was the basis for processing
4. Data Protection Principles
We adhere to the following GDPR data protection principles:
- Lawfulness, fairness, and transparency in data processing
- Purpose limitation - data collected for specific, explicit purposes
- Data minimization - collecting only what is necessary
- Accuracy - maintaining accurate and up-to-date records
- Storage limitation - retaining data only as long as necessary
- Integrity and confidentiality - implementing appropriate security measures
- Accountability - demonstrating compliance with GDPR principles
5. Data Transfers
If we transfer your personal data outside the EU, we ensure appropriate safeguards are in place, such as:
- Standard contractual clauses approved by the European Commission
- Adequacy decisions for countries with equivalent data protection standards
- Other mechanisms approved under GDPR
6. Data Breach Notification
In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the relevant supervisory authority within 72 hours of becoming aware of the breach.
7. Automated Decision-Making
We do not engage in automated decision-making or profiling that produces legal effects or similarly significantly affects you.
8. Children's Privacy
Our services are not directed to individuals under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child without parental consent, we will take steps to delete that information.
9. Exercising Your Rights
To exercise any of your GDPR rights, please contact us at:
Email: [email protected]
Address: Level 12, 456 George Street, Sydney NSW 2000, Australia
We will respond to your request within one month. In complex cases, we may extend this period by two additional months, and we will inform you of any such extension.
10. Supervisory Authority
If you are not satisfied with how we handle your personal data, you have the right to lodge a complaint with your local supervisory authority in the EU.
11. Contact Information
For questions about our GDPR compliance or to exercise your rights, please contact us at [email protected].