GDPR Compliance Statement
Last Updated: August 11, 2026
Introduction
While our primary operations are based in Australia and serve Australian customers, we respect the privacy rights of all website visitors including those from the European Union. This document outlines how we comply with General Data Protection Regulation principles.
Legal Basis for Processing
We process personal data based on the following legal grounds:
- Consent: When you submit an inquiry form, you provide explicit consent for us to process your information to respond to your request.
- Legitimate Interest: We process data necessary to operate our business, improve our services, and communicate with customers about their installations and warranties.
- Contractual Necessity: For customers who proceed with installation, we process information necessary to fulfill contractual obligations.
Data Controller Information
The data controller responsible for your personal information is:
hazy-fell
127 Creek Street
Brisbane QLD 4000
Australia
Email: [email protected]
Your GDPR Rights
Under GDPR, you have the following rights regarding your personal data:
Right to Access
You may request confirmation of whether we process your personal data and receive a copy of that data. We will provide this information in a commonly used electronic format within 30 days of your request.
Right to Rectification
If personal information we hold about you is inaccurate or incomplete, you have the right to request correction. We will update records promptly upon verification of corrected information.
Right to Erasure
You may request deletion of your personal data under certain circumstances, including when the data is no longer necessary for the purposes it was collected, when you withdraw consent, or when you object to processing. Some legal or contractual obligations may require us to retain certain information despite erasure requests.
Right to Restrict Processing
You may request that we limit how we use your personal data in specific situations, such as when you contest the accuracy of the data or object to processing based on legitimate interests.
Right to Data Portability
You have the right to receive personal data you provided to us in a structured, commonly used, machine-readable format, and to transmit that data to another controller where technically feasible.
Right to Object
You may object to processing of your personal data based on legitimate interests or for direct marketing purposes. We will cease processing unless we demonstrate compelling legitimate grounds that override your interests.
Right to Withdraw Consent
Where processing is based on consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing conducted before withdrawal.
Data Protection Measures
We implement appropriate technical and organizational measures to ensure data security, including:
- Encryption of data in transit and at rest
- Access controls limiting employee access to necessary information only
- Regular security assessments and updates
- Secure data centers with physical and digital protections
- Employee training on data protection responsibilities
International Data Transfers
Your data is stored on servers located in Australia. If you are located in the European Union, this represents an international data transfer. Australia is not currently recognized by the European Commission as providing adequate data protection, so we rely on your explicit consent for such transfers when you submit information through our website.
Data Retention Periods
We retain personal data only as long as necessary for the purposes it was collected:
- Inquiry data: 2 years from initial contact
- Customer data: Duration of relationship plus 7 years for warranty and legal purposes
- Cookie consent records: 12 months
Automated Decision Making
We do not use automated decision-making or profiling that produces legal effects or similarly significantly affects individuals.
Data Breach Notification
In the event of a data breach that poses a risk to your rights and freedoms, we will notify affected individuals within 72 hours of becoming aware of the breach, as required by GDPR. Notifications will include the nature of the breach, likely consequences, and measures taken to address it.
Children's Data
We do not knowingly process data of individuals under 16 years of age. If we discover we have collected such data, we will delete it immediately.
Lodging a Complaint
If you believe we have not handled your personal data in accordance with GDPR, you have the right to lodge a complaint with your local supervisory authority in the European Union.
Exercising Your Rights
To exercise any of your GDPR rights, contact us at the email address provided above. We will respond to requests within 30 days. We may request additional information to verify your identity before fulfilling requests.
Updates to This Statement
We may update this GDPR compliance statement to reflect changes in our practices or legal requirements. Material changes will be communicated to affected individuals where we have contact information available.