Effective date: July 14, 2026
While alpine-iris operates primarily in Australia, we recognize that some visitors may be located in the European Union or European Economic Area. This document outlines how we comply with the General Data Protection Regulation (GDPR) when processing data of EU/EEA residents.
We process personal data under the following legal bases:
For purposes of GDPR, the data controller is:
alpine-iris
247 Collins Street
Melbourne VIC 3000
Australia
Email: [email protected]
If you are an EU/EEA resident, you have the following rights:
You may request confirmation of whether we process your personal data and obtain a copy of that data.
You may request correction of inaccurate or incomplete personal data.
You may request deletion of your personal data when it is no longer necessary for the purposes for which it was collected, or if you withdraw consent.
You may request temporary restriction of processing in certain circumstances, such as when contesting data accuracy.
You may request your personal data in a structured, machine-readable format for transfer to another controller.
You may object to processing based on legitimate interests or for direct marketing purposes.
We do not use automated decision-making or profiling that produces legal effects or similarly significant impacts.
To exercise any GDPR rights, send a request to [email protected] with "GDPR Request" in the subject line. Include sufficient information to identify yourself and specify which right you wish to exercise.
We will respond within 30 days of receiving a valid request. If your request is complex or we receive multiple requests, we may extend this period by an additional 60 days with notification.
Your personal data is primarily stored on servers located in Australia. If data is transferred outside the EU/EEA, we ensure appropriate safeguards are in place through:
We retain personal data only for as long as necessary to fulfill the purposes outlined in our Privacy Policy or as required by law. Inquiry data is retained for two years. Customer data is retained for seven years to maintain warranty and service records.
We implement technical and organizational measures appropriate to the risk, including:
In the event of a data breach affecting your personal data, we will notify you without undue delay when the breach is likely to result in a high risk to your rights and freedoms.
If you are unsatisfied with how we handle your personal data, you have the right to lodge a complaint with your local supervisory authority. For EU/EEA residents, this is typically the data protection authority in your country of residence.
Our services are not directed to individuals under 16. We do not knowingly collect personal data from children. If you believe we have collected data from a child, contact us immediately for deletion.
We may update this GDPR compliance notice to reflect changes in our practices or legal requirements. Material changes will be communicated through our website and, where appropriate, via email.
For questions about GDPR compliance or to exercise your rights, contact:
Email: [email protected]
Subject line: GDPR Inquiry
We aim to respond to all GDPR-related inquiries within five business days.