GDPR Compliance
Last updated: 19 June 2026
1. Introduction
While savanna-swan.com primarily operates in Australia, we recognize the importance of the General Data Protection Regulation (GDPR) for individuals in the European Economic Area (EEA). This document outlines how we comply with GDPR requirements when processing personal data of EEA residents.
2. Legal Basis for Processing
We process personal data under the following legal bases:
- Consent: When you provide explicit consent for specific processing activities
- Contract Performance: When processing is necessary to fulfil our service obligations to you
- Legitimate Interests: When we have legitimate business reasons that do not override your rights
- Legal Obligation: When required by law to process your data
3. Your GDPR Rights
If you are a resident of the EEA, you have the following rights regarding your personal data:
Right to Access
You have the right to request a copy of the personal data we hold about you.
Right to Rectification
You can request correction of inaccurate or incomplete personal data.
Right to Erasure
You may request deletion of your personal data in certain circumstances, such as when it is no longer necessary for the purposes for which it was collected.
Right to Restrict Processing
You can request that we limit how we use your personal data in specific situations.
Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, machine-readable format and transfer it to another controller.
Right to Object
You may object to processing of your personal data based on legitimate interests or for direct marketing purposes.
Right to Withdraw Consent
Where processing is based on consent, you may withdraw that consent at any time.
Right to Lodge a Complaint
You have the right to lodge a complaint with a supervisory authority in your jurisdiction.
4. Data Protection Principles
We adhere to the following GDPR principles:
- Lawfulness, Fairness, and Transparency: We process data lawfully and transparently
- Purpose Limitation: We collect data for specified, explicit purposes
- Data Minimisation: We only collect data that is necessary
- Accuracy: We keep personal data accurate and up to date
- Storage Limitation: We retain data only as long as necessary
- Integrity and Confidentiality: We implement appropriate security measures
- Accountability: We demonstrate compliance with these principles
5. International Data Transfers
Personal data collected from EEA residents may be transferred to and processed in Australia. We ensure appropriate safeguards are in place for such transfers, including standard contractual clauses or other approved mechanisms.
6. Data Security
We implement technical and organisational measures to ensure a level of security appropriate to the risk, including:
- Encryption of personal data
- Regular security assessments
- Access controls and authentication
- Staff training on data protection
- Incident response procedures
7. Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the relevant supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach.
8. Automated Decision-Making
We do not use automated decision-making or profiling that produces legal effects or similarly significantly affects individuals.
9. Children's Privacy
Our services are not directed to individuals under 16 years of age. We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child without parental consent, we will take steps to delete that information.
10. Exercising Your Rights
To exercise any of your GDPR rights, please contact us at:
Email: [email protected]
Address: Level 12, 485 La Trobe Street, Melbourne VIC 3000, Australia
We will respond to your request within one month. In complex cases, we may extend this period by two additional months and will inform you of any such extension.
11. Supervisory Authority
If you are located in the EEA and believe we have not handled your personal data in accordance with GDPR, you have the right to lodge a complaint with your local data protection authority.
12. Updates to This Policy
We may update this GDPR compliance statement to reflect changes in our practices or legal requirements. Significant changes will be communicated through our website.