Our Commitment to Data Protection

quaint-stone respects your privacy rights under the General Data Protection Regulation (GDPR). This page outlines how we handle personal data in compliance with GDPR requirements.

Legal Basis for Processing

We process personal data on the following legal bases:

Data We Collect

When you interact with quaint-stone, we may collect:

Your GDPR Rights

Under GDPR, you have the following rights:

Right to Access

You can request a copy of all personal data we hold about you. We will provide this information in a structured, commonly used format within 30 days of your request.

Right to Rectification

If any personal information we hold is inaccurate or incomplete, you have the right to request correction.

Right to Erasure

You may request deletion of your personal data. We will comply unless we have a legal obligation to retain certain information, such as transaction records for tax purposes.

Right to Restriction

You can request that we limit how we use your personal data in certain circumstances, such as while we verify the accuracy of disputed information.

Right to Data Portability

Where technically feasible, you can request that we transfer your data to another service provider in a machine-readable format.

Right to Object

You may object to processing based on legitimate interests. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests.

Data Retention

We retain personal data only as long as necessary for the purposes outlined in our Privacy Policy or as required by law. Order information is typically retained for seven years to comply with accounting and tax regulations.

International Data Transfers

Your data is processed and stored within Australia. If we engage service providers outside Australia, we ensure appropriate safeguards are in place to protect your information in accordance with GDPR standards.

Automated Decision-Making

We do not use automated decision-making or profiling that produces legal effects or similarly significant impacts on individuals.

Data Breach Notification

In the event of a data breach that poses a risk to your rights and freedoms, we will notify affected individuals within 72 hours of becoming aware of the breach, as required by GDPR.

Exercising Your Rights

To exercise any of your GDPR rights, contact us at: [email protected]

Please include sufficient information to identify your account and specify which right you wish to exercise. We will respond within 30 days.

Supervisory Authority

If you believe we have not handled your data in compliance with GDPR, you have the right to lodge a complaint with your local data protection authority.