We use cookies to enhance your browsing experience and analyze site traffic. Your privacy matters to us.

slumbering-fog
  • Home
  • Services
  • About
  • Contact

GDPR Compliance

Last Updated: May 19, 2026

Our Commitment to GDPR

While slumbering-fog is based in Australia, we respect the data protection rights of individuals in the European Economic Area (EEA) under the General Data Protection Regulation (GDPR). This page outlines how we comply with GDPR requirements when processing personal data of EEA residents.

Legal Basis for Processing

We process your personal data only when we have a legal basis to do so. Our legal bases include:

  • Consent: You have given clear consent for us to process your personal data for specific purposes (e.g., marketing communications)
  • Contract: Processing is necessary for a contract we have with you or to take steps at your request before entering into a contract
  • Legal Obligation: Processing is necessary to comply with the law
  • Legitimate Interests: Processing is necessary for our legitimate interests or those of a third party, provided your rights do not override those interests

Your Rights Under GDPR

If you are an EEA resident, you have the following rights regarding your personal data:

Right to Access

You have the right to request copies of your personal data. We may charge a small fee for this service if the request is excessive or unfounded.

Right to Rectification

You have the right to request correction of any information you believe is inaccurate or incomplete.

Right to Erasure

You have the right to request deletion of your personal data under certain conditions, such as when the data is no longer necessary for the purposes it was collected.

Right to Restrict Processing

You have the right to request that we restrict the processing of your personal data under certain conditions.

Right to Object

You have the right to object to our processing of your personal data under certain conditions, particularly for direct marketing purposes.

Right to Data Portability

You have the right to request transfer of your data to another organization or directly to you, in a structured, commonly used, and machine-readable format.

Right to Withdraw Consent

Where processing is based on consent, you have the right to withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing based on consent before its withdrawal.

How to Exercise Your Rights

To exercise any of your GDPR rights, please contact us at:

Email: [email protected]

Subject Line: GDPR Request

We will respond to your request within one month. In complex cases, we may extend this period by two additional months, and we will inform you of any such extension.

Data Processing and Storage

Data Location

Your personal data is primarily processed and stored in Australia. When data is transferred outside the EEA, we ensure appropriate safeguards are in place, such as:

  • Standard contractual clauses approved by the European Commission
  • Adequacy decisions by the European Commission
  • Binding corporate rules

Data Security

We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:

  • Encryption of personal data in transit and at rest
  • Regular security assessments and audits
  • Access controls and authentication procedures
  • Staff training on data protection

Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you without undue delay. Where required, we will also notify the relevant supervisory authority within 72 hours of becoming aware of the breach.

Data Protection Officer

For matters specifically related to GDPR compliance, you may contact our designated data protection contact:

Email: [email protected]

Subject Line: Attention: Data Protection

Supervisory Authority

If you are not satisfied with our response to your data protection concerns, you have the right to lodge a complaint with a supervisory authority in the EEA. You can find your local data protection authority at:

https://edpb.europa.eu/about-edpb/board/members_en

Children's Data

We do not knowingly collect or process personal data from children under 16 years of age without parental consent, as required by GDPR. If we become aware that we have collected such data without proper consent, we will take steps to delete it promptly.

Automated Decision-Making

We do not use automated decision-making or profiling that produces legal effects concerning you or similarly significantly affects you.

Updates to This Policy

We may update this GDPR compliance page to reflect changes in our practices or legal requirements. We will notify you of any material changes by updating the "Last Updated" date and, where appropriate, providing additional notice.

Contact Information

For any questions about our GDPR compliance or to exercise your rights, please contact:

slumbering-fog
Level 3, 142 Victoria Road
Gladesville NSW 2111
Australia

Email: [email protected]

slumbering-fog

Professional interior design and renovation services across Australia.

Quick Links

  • Home
  • Services
  • About
  • Contact

Legal

  • Privacy Policy
  • GDPR
  • Cookies Policy
  • Terms of Use

Connect

Email: [email protected]

Business Hours: Mon-Fri 8:00 AM - 6:00 PM AEST

© 2026 slumbering-fog. All rights reserved.