GDPR Compliance
Last Updated: June 17, 2026
Introduction
This page explains how cascade-lark complies with the General Data Protection Regulation (GDPR) for individuals located in the European Economic Area (EEA). While we are based in Australia, we recognize the importance of protecting the privacy rights of all visitors to our website.
Data Controller
For the purposes of GDPR, the data controller is:
cascade-lark
Level 12, 125 St Georges Terrace
Perth WA 6000
Australia
Email: [email protected]
Legal Basis for Processing
We process personal data under the following legal bases:
- Consent: When you provide explicit consent through forms or cookie acceptance
- Contract: When processing is necessary to provide services you request
- Legitimate Interests: When we have a legitimate business interest that does not override your rights
- Legal Obligation: When required to comply with legal requirements
Your Rights Under GDPR
If you are located in the EEA, you have the following rights regarding your personal data:
Right to Access
You have the right to request a copy of the personal data we hold about you, including information about how we use it.
Right to Rectification
You have the right to request correction of inaccurate or incomplete personal data.
Right to Erasure
You have the right to request deletion of your personal data in certain circumstances, such as when it is no longer necessary for the purposes for which it was collected.
Right to Restriction of Processing
You have the right to request that we restrict the processing of your personal data in certain situations, such as when you contest the accuracy of the data.
Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller.
Right to Object
You have the right to object to processing of your personal data based on legitimate interests or for direct marketing purposes.
Right to Withdraw Consent
Where processing is based on consent, you have the right to withdraw that consent at any time. This does not affect the lawfulness of processing based on consent before its withdrawal.
Right to Lodge a Complaint
You have the right to lodge a complaint with a supervisory authority in your country of residence, place of work, or place of alleged infringement.
How to Exercise Your Rights
To exercise any of these rights, please contact us at [email protected] with your request. We will respond within one month of receiving your request. In complex cases, we may extend this period by two additional months and will inform you of any such extension.
Data We Collect
We collect the following categories of personal data:
- Identity data (name)
- Contact data (email address)
- Technical data (IP address, browser type, device information)
- Usage data (how you interact with our website)
- Financial information (when you request our services)
How We Use Your Data
We use your personal data for the following purposes:
- Providing and managing our services
- Communicating with you about your inquiries
- Improving our website and services
- Complying with legal obligations
- Protecting against fraud and unauthorized activity
Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including to satisfy legal, accounting, or reporting requirements. When determining retention periods, we consider:
- The nature and sensitivity of the data
- The purposes for which we process the data
- Whether we can achieve those purposes through other means
- Applicable legal requirements
International Data Transfers
Your personal data may be transferred to and processed in Australia. When we transfer data from the EEA to countries that do not provide an adequate level of data protection, we implement appropriate safeguards, such as:
- Standard contractual clauses approved by the European Commission
- Ensuring the recipient is certified under an approved certification mechanism
- Obtaining your explicit consent for the transfer
Data Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized or unlawful processing, accidental loss, destruction, or damage. These measures include:
- Encryption of data in transit and at rest
- Access controls and authentication mechanisms
- Regular security assessments and updates
- Staff training on data protection
Third-Party Processing
We may engage third-party service providers to process personal data on our behalf. When we do so, we ensure that:
- The provider offers sufficient guarantees of compliance with GDPR
- Processing is governed by a contract that meets GDPR requirements
- The provider only processes data according to our instructions
Automated Decision-Making
We do not use automated decision-making or profiling that produces legal effects or similarly significant effects on individuals.
Cookies and Tracking
We use cookies and similar tracking technologies only with your consent. You can manage your cookie preferences through our cookie banner or browser settings. For more information, see our Cookies Policy.
Children's Data
We do not knowingly collect or process personal data from individuals under 16 years of age without parental consent. If we become aware that we have collected such data, we will delete it promptly.
Changes to This Notice
We may update this GDPR compliance notice from time to time. We will notify you of any material changes by posting the updated notice on our website and updating the date at the top of this page.
Contact and Complaints
If you have questions about our GDPR compliance or wish to exercise your rights, please contact us:
Email: [email protected]
Address: Level 12, 125 St Georges Terrace, Perth WA 6000, Australia
If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority.