Last updated: September 2026
The General Data Protection Regulation (GDPR) is a European Union regulation that governs the collection, processing, and storage of personal data of individuals within the European Economic Area (EEA). Although ivory-dune is based in Australia, we are committed to protecting the privacy of all our website visitors and clients, including those from the EEA.
This page outlines how we comply with GDPR requirements for any personal data we may process relating to EEA residents.
For the purposes of the GDPR, ivory-dune acts as the data controller for personal data we collect directly from individuals. Our contact details are:
ivory-dune
42 Collins Street, Level 8
Melbourne VIC 3000
Australia
Email: [email protected]
We process personal data based on the following legal grounds:
If you are located in the EEA, you have the following rights regarding your personal data:
To exercise any of your rights under the GDPR, please contact us at [email protected]. We will respond to your request within one month. In certain circumstances, we may extend this period by two months, in which case we will inform you of the extension and the reasons for it.
We may need to verify your identity before processing your request. If your request is manifestly unfounded or excessive, we may charge a reasonable fee or refuse to act on the request.
As an Australian organisation, any personal data we collect may be transferred to and stored in Australia. When transferring data from the EEA to Australia, we ensure appropriate safeguards are in place to protect your personal data in accordance with GDPR requirements.
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable laws. When determining the retention period, we consider the nature and sensitivity of the data, potential risks, and applicable legal requirements.
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, or destruction. These measures include encryption, access controls, and regular security assessments.
Our services are not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If you become aware that a child has provided us with personal data, please contact us so we can take appropriate action.
We do not engage in automated decision-making or profiling that produces legal effects or similarly significantly affects individuals.
We may update this GDPR compliance information from time to time. Any changes will be posted on this page with an updated revision date.
For any questions about our GDPR compliance or to exercise your rights, please contact us:
ivory-dune
42 Collins Street, Level 8
Melbourne VIC 3000
Australia
Email: [email protected]
If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority.