Last updated: August 2026
hazy-egret is committed to protecting the privacy and rights of individuals in accordance with the General Data Protection Regulation (GDPR). Although we are based in Australia, we recognise the importance of GDPR compliance for individuals located in the European Economic Area (EEA) who may interact with our services.
For the purposes of GDPR, the data controller is:
hazy-egret
42 Greenfield Avenue
Sydney NSW 2000
Australia
Email: [email protected]
We process personal data under the following legal bases:
If you are located in the EEA, you have the following rights regarding your personal data:
You have the right to request a copy of the personal data we hold about you and information about how we process it.
You have the right to request correction of any inaccurate or incomplete personal data we hold about you.
You have the right to request deletion of your personal data in certain circumstances, such as when the data is no longer necessary for the purposes for which it was collected.
You have the right to request that we limit the processing of your personal data in certain circumstances, such as when you contest the accuracy of the data.
You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit it to another controller.
You have the right to object to processing of your personal data based on legitimate interests or for direct marketing purposes.
Where processing is based on consent, you have the right to withdraw that consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
To exercise any of these rights, please contact us at [email protected]. We will respond to your request within one month. In complex cases, this period may be extended by two additional months, and we will inform you of any such extension within the initial one-month period.
We may request verification of your identity before processing your request to ensure the security of your personal data.
As we are based in Australia, personal data collected from EEA residents may be transferred to and processed in Australia. We ensure that appropriate safeguards are in place to protect your personal data in accordance with GDPR requirements.
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, taking into account legal, accounting, and reporting requirements. When data is no longer needed, we securely delete or anonymise it.
We implement appropriate technical and organisational measures to protect personal data against unauthorised or unlawful processing, accidental loss, destruction, or damage. These measures are regularly reviewed and updated as necessary.
In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. Where the breach is likely to result in a high risk to individuals, we will also notify affected individuals without undue delay.
If you believe that your data protection rights have been violated, you have the right to lodge a complaint with a supervisory authority in the EEA member state where you reside, work, or where the alleged infringement occurred.
We may update this GDPR compliance information from time to time. Any changes will be posted on this page with an updated revision date.