Last Updated: June 19, 2026
This page outlines how maroon-mountain complies with the General Data Protection Regulation (GDPR) when processing personal data of individuals located in the European Union. While we primarily serve Australian clients, we recognize and respect the data protection rights of all individuals.
We process personal data under the following legal bases:
Under GDPR, you have the following rights regarding your personal data:
You can request confirmation of whether we process your personal data and obtain a copy of that data.
You can request correction of inaccurate or incomplete personal data we hold about you.
You can request deletion of your personal data in certain circumstances, such as when it is no longer necessary for the purposes for which it was collected.
You can request that we limit how we use your personal data in specific situations.
You can request to receive your personal data in a structured, commonly used format and transmit it to another controller.
You can object to processing of your personal data based on legitimate interests or for direct marketing purposes.
You have the right not to be subject to decisions based solely on automated processing that produces legal effects or significantly affects you.
To exercise any of these rights, contact us at [email protected]. We will respond to your request within one month. In complex cases, we may extend this period by two additional months and will inform you of any delay.
For questions about our GDPR compliance or data protection practices, you may contact our designated data protection contact at [email protected].
Your personal data is primarily stored and processed in Australia. If we transfer data outside the EU, we ensure appropriate safeguards are in place, such as standard contractual clauses or adequacy decisions.
Where we rely on consent for processing, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.
If you believe we have not handled your personal data properly, you have the right to lodge a complaint with a supervisory authority in your jurisdiction.
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, comply with legal obligations, and resolve disputes. Retention periods vary based on the nature of the data and legal requirements.
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify you and relevant supervisory authorities within 72 hours of becoming aware of the breach.
For GDPR-related inquiries or to exercise your rights:
maroon-mountain
Level 12, Riverside Centre
123 Eagle Street
Brisbane QLD 4000
Australia
Email: [email protected]