Your rights under the General Data Protection Regulation
Last updated: 30 June 2026
The General Data Protection Regulation (GDPR) is a regulation in EU law on data protection and privacy. While river-grouse operates from Australia, we respect the rights of visitors from the European Union and European Economic Area, and comply with GDPR requirements when processing data of EU residents.
river-grouse acts as the data controller for personal information collected through this website. We determine the purposes and means of processing personal data in accordance with applicable laws.
Contact details:
river-grouse
42 Timber Lane
Collingwood, VIC 3066
Australia
Email: [email protected]
We process personal data based on the following legal grounds:
Under GDPR, you have the following rights regarding your personal data:
You may request a copy of the personal data we hold about you and information about how it is processed.
You may request correction of inaccurate personal data or completion of incomplete data.
You may request deletion of your personal data in certain circumstances, such as when the data is no longer necessary for its original purpose.
You may request limitation of processing in specific situations, such as when you contest the accuracy of your data.
You may request your personal data in a structured, commonly used format for transfer to another service provider.
You may object to processing based on legitimate interests, including profiling and direct marketing.
You have rights concerning automated individual decision-making, including profiling. We do not currently use automated decision-making that produces legal effects.
We retain personal data only as long as necessary for the purposes described in our Privacy Policy, or as required by law. Enquiry data is typically retained for project reference and follow-up purposes, then securely deleted when no longer needed.
As we operate from Australia, data may be transferred outside the EU/EEA. We implement appropriate safeguards for such transfers, including adherence to privacy principles comparable to GDPR standards.
We implement technical and organisational measures appropriate to the risk level, including encryption, access controls, and regular security assessments.
To exercise any of your GDPR rights, please contact us at [email protected]. We will respond to requests within one month. In complex cases, we may extend this period by two additional months with notification.
We may request identification verification to ensure we release information only to the appropriate individual.
If you believe your data protection rights have been violated, you have the right to lodge a complaint with a supervisory authority. For EU residents, this is typically the data protection authority in your country of residence.
We may update this GDPR information periodically. Material changes will be communicated through our website. We encourage regular review of this page.