Information on this site is advertising in nature

Last Updated: July 2026

Introduction

The General Data Protection Regulation (GDPR) is a European Union regulation that governs the processing of personal data of individuals within the EU. Although stormy-beam is based in Australia, we are committed to protecting the privacy of all our website visitors and customers, including those in the European Economic Area (EEA).

This page explains how we comply with GDPR requirements and outlines your rights as a data subject.

Data Controller

stormy-beam is the data controller responsible for your personal data. If you have any questions about this policy or our data practices, please contact us at:

stormy-beam
47 Workshop Lane
Marrickville NSW 2204
Australia
Email: [email protected]

Legal Basis for Processing

We process personal data only when we have a lawful basis to do so. The legal bases we rely on include:

  • Consent: You have given clear consent for us to process your personal data for a specific purpose
  • Contract: Processing is necessary for the performance of a contract with you or to take steps at your request before entering into a contract
  • Legal obligation: Processing is necessary for us to comply with the law
  • Legitimate interests: Processing is necessary for our legitimate interests or those of a third party, and your interests and fundamental rights do not override those interests

Your Rights Under GDPR

If you are located in the EEA, you have the following rights regarding your personal data:

Right to Access

You have the right to request a copy of the personal data we hold about you and information about how we process it.

Right to Rectification

You have the right to request that we correct any inaccurate personal data we hold about you without undue delay.

Right to Erasure

You have the right to request that we delete your personal data in certain circumstances, including when the data is no longer necessary for the purposes for which it was collected.

Right to Restrict Processing

You have the right to request that we restrict the processing of your personal data in certain circumstances, such as when you contest the accuracy of the data.

Right to Data Portability

You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit that data to another controller.

Right to Object

You have the right to object to the processing of your personal data in certain circumstances, including processing for direct marketing purposes.

Rights Related to Automated Decision-Making

You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you.

Exercising Your Rights

To exercise any of these rights, please contact us using the contact details provided above. We will respond to your request within one month. In some cases, we may need to verify your identity before processing your request.

There is no fee for exercising your rights, but we may charge a reasonable fee for requests that are manifestly unfounded or excessive.

Data Transfers

As we are based in Australia, any personal data you provide to us may be transferred to and stored in Australia. Australia is not considered by the European Commission to provide an adequate level of data protection. However, we implement appropriate safeguards to protect your personal data in compliance with GDPR requirements.

Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, unless a longer retention period is required by law. When determining how long to keep data, we consider:

  • The purpose for which the data was collected
  • Legal and regulatory requirements
  • The nature and sensitivity of the data
  • Potential risk of harm from unauthorised use or disclosure

Data Security

We implement appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures include:

  • Secure data storage
  • Access controls
  • Regular security assessments
  • Staff training on data protection

Complaints

If you believe that we have not complied with your data protection rights, you have the right to lodge a complaint with a supervisory authority. For EEA residents, this would be the data protection authority in your country of residence.

Updates to This Policy

We may update this GDPR compliance information from time to time. Any changes will be posted on this page with an updated revision date.