GDPR Compliance
Our commitment to protecting your data rights under the General Data Protection Regulation
Last Updated: July 2026
1. Introduction
mist-tapir is committed to protecting the privacy and security of personal data in accordance with the General Data Protection Regulation (GDPR) and applicable Australian privacy laws. This page outlines how we comply with data protection requirements and explains your rights as a data subject.
2. Data Controller
mist-tapir acts as the data controller for personal information collected through our website and services. This means we determine the purposes and means of processing your personal data.
Contact Details:
mist-tapir
Level 8, 221 Queen Street
Melbourne VIC 3000
Australia
Email: [email protected]
3. Legal Basis for Processing
We process personal data only when we have a valid legal basis to do so. The legal bases we rely on include:
- Consent: Where you have given explicit consent for us to process your data for specific purposes.
- Contract: Where processing is necessary to perform a contract with you or take steps at your request prior to entering a contract.
- Legal Obligation: Where processing is necessary to comply with legal requirements.
- Legitimate Interests: Where processing is necessary for our legitimate interests and does not override your rights and freedoms.
4. Your Data Subject Rights
Under the GDPR, you have the following rights regarding your personal data:
4.1 Right to Access
You have the right to request a copy of the personal data we hold about you and information about how we process it.
4.2 Right to Rectification
You have the right to request that we correct any personal data that is inaccurate or incomplete.
4.3 Right to Erasure
You have the right to request that we delete your personal data in certain circumstances, such as when the data is no longer necessary for the purpose it was collected.
4.4 Right to Restrict Processing
You have the right to request that we limit the processing of your personal data in certain circumstances, such as when you contest the accuracy of the data.
4.5 Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit it to another controller.
4.6 Right to Object
You have the right to object to the processing of your personal data in certain circumstances, including processing for direct marketing purposes.
4.7 Rights Related to Automated Decision-Making
You have the right not to be subject to decisions based solely on automated processing, including profiling, that produce legal effects or similarly significantly affect you.
5. How to Exercise Your Rights
To exercise any of these rights, please contact us at:
Email: [email protected]
We will respond to your request within one month. In complex cases or where we receive a large number of requests, we may extend this period by a further two months, in which case we will inform you of the extension and the reasons for it.
We may need to verify your identity before processing your request. If your request is manifestly unfounded or excessive, we may charge a reasonable fee or refuse to act on the request.
6. Data Security
We implement appropriate technical and organisational measures to protect personal data against unauthorised or unlawful processing, accidental loss, destruction, or damage. These measures include:
- Secure data storage with access controls
- Encryption of data in transit
- Regular security assessments
- Staff training on data protection
- Data minimisation practices
7. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law. Retention periods vary depending on the type of data and the purpose of processing. When data is no longer needed, we securely delete or anonymise it.
8. International Data Transfers
Where we transfer personal data outside the European Economic Area (EEA) or Australia, we ensure appropriate safeguards are in place to protect your data in accordance with applicable data protection laws.
9. Data Breach Notification
In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify the relevant supervisory authority and affected individuals without undue delay, in accordance with our legal obligations.
10. Complaints
If you believe that your data protection rights have been violated, you have the right to lodge a complaint with a supervisory authority. In Australia, you may contact the Office of the Australian Information Commissioner (OAIC). If you are in the EU, you may contact your local data protection authority.
11. Changes to This Notice
We may update this GDPR compliance notice from time to time. Any changes will be posted on this page with an updated revision date. We encourage you to review this notice periodically.
12. Contact Us
For any questions or concerns about our GDPR compliance or data protection practices, please contact us at:
mist-tapir
Level 8, 221 Queen Street
Melbourne VIC 3000
Australia
Email: [email protected]