GDPR Compliance
Last updated: October 6, 2026
Introduction
While lavender-mesa.com operates primarily in Australia, we recognize that some users may be located in the European Union or European Economic Area. This document outlines how we comply with the General Data Protection Regulation (GDPR) when processing personal data of EU/EEA residents.
Legal Basis for Processing
We process personal data under the following legal bases:
- Consent: When you provide explicit consent for specific processing activities such as newsletter subscriptions
- Contract Performance: When processing is necessary to fulfill services you have requested
- Legitimate Interests: When we have legitimate business reasons to process data, balanced against your rights and freedoms
- Legal Obligation: When required by applicable laws or regulations
Your Rights Under GDPR
If you are an EU/EEA resident, you have the following rights regarding your personal data:
- Right to Access: Request confirmation of whether we process your data and receive a copy
- Right to Rectification: Request correction of inaccurate or incomplete personal data
- Right to Erasure: Request deletion of your personal data in certain circumstances
- Right to Restriction: Request limitation of how we process your data
- Right to Data Portability: Receive your data in a structured, commonly used format
- Right to Object: Object to processing based on legitimate interests or for direct marketing
- Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent
- Right to Lodge a Complaint: File a complaint with your local data protection authority
How to Exercise Your Rights
To exercise any of the above rights, contact us at [email protected] with the following information:
- Your full name and contact information
- Specific right you wish to exercise
- Details to help us locate your information in our systems
- Verification of your identity (we may request additional documentation)
We will respond to your request within one month, though complex requests may require up to three months. We will inform you if an extension is necessary.
Data Processing Activities
We process the following categories of personal data:
- Identity data: name, username
- Contact data: email address, postal address
- Technical data: IP address, browser type, device information
- Usage data: website interaction patterns, pages viewed
- Communication data: inquiries, feedback, correspondence
For detailed information about how we use this data, see our Privacy Policy.
Data Recipients and Transfers
We may share personal data with:
- Service providers who assist with website hosting, analytics, and communications
- Professional advisors including lawyers and accountants
- Regulatory authorities when required by law
When we transfer data outside the EU/EEA, we ensure appropriate safeguards are in place, such as:
- Standard contractual clauses approved by the European Commission
- Adequacy decisions recognizing equivalent data protection standards
- Other legally approved transfer mechanisms
Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including legal, accounting, or reporting requirements. Retention periods vary based on:
- The nature of the data and purpose of processing
- Legal obligations requiring retention
- Potential for legal claims requiring data preservation
When data is no longer needed, we securely delete or anonymize it.
Automated Decision-Making
We do not use personal data for automated decision-making or profiling that produces legal effects or similarly significant impacts on individuals.
Security Measures
We implement technical and organizational measures to ensure appropriate security for personal data, including:
- Encryption of data in transit and at rest
- Regular security assessments and vulnerability testing
- Access controls limiting data access to authorized personnel
- Staff training on data protection and security
- Incident response procedures for potential data breaches
Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you without undue delay. We will also notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR.
Contact Information
For questions about our GDPR compliance or to exercise your rights:
lavender-mesa.com
Level 14, 235 Queen Street
Brisbane QLD 4000
Australia
Email: [email protected]
Supervisory Authority
If you are not satisfied with our response to your data protection concerns, you have the right to lodge a complaint with the data protection authority in your EU/EEA country of residence or place of work.