GDPR Compliance
Last updated: October 6, 2026
Our commitment to data protection
vermilion-wind is committed to protecting your personal data and respecting your privacy rights under the General Data Protection Regulation and other applicable data protection laws.
This page explains how we comply with GDPR requirements and outlines your rights as a data subject.
Legal basis for processing
We process your personal data only when we have a lawful basis to do so. The legal bases we rely on include:
Consent
We process certain personal data based on your explicit consent, such as when you subscribe to newsletters or opt into marketing communications. You may withdraw consent at any time.
Contractual necessity
We process personal data necessary to fulfill our contractual obligations when you subscribe to our services, such as processing payments and delivering content you have purchased.
Legitimate interests
We process personal data based on our legitimate interests in operating our business, improving our services, and ensuring security, provided these interests are not overridden by your rights and freedoms.
Legal obligations
We process personal data when required to comply with legal obligations, such as tax reporting, responding to legal requests, or preventing fraud.
Your GDPR rights
Under GDPR, you have the following rights regarding your personal data:
Right of access
You have the right to request confirmation of whether we are processing your personal data and to receive a copy of that data. We will provide this information free of charge upon request.
Right to rectification
If your personal data is inaccurate or incomplete, you have the right to request that we correct or complete it.
Right to erasure
Also known as the "right to be forgotten," you may request deletion of your personal data in certain circumstances, such as when the data is no longer necessary for the purposes for which it was collected.
Right to restriction of processing
You have the right to request that we restrict processing of your personal data in specific situations, such as when you contest the accuracy of the data or object to processing.
Right to data portability
You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller.
Right to object
You may object to processing of your personal data based on legitimate interests or for direct marketing purposes. We will cease processing unless we have compelling legitimate grounds.
Rights related to automated decision-making
You have the right not to be subject to decisions based solely on automated processing, including profiling, that produce legal effects or similarly significant effects concerning you.
How to exercise your rights
To exercise any of your GDPR rights, please contact us using the information provided at the end of this page.
When making a request, please provide:
- Your full name and email address associated with your account
- A clear description of the right you wish to exercise
- Any specific information relevant to your request
We will respond to your request within one month. In complex cases, we may extend this period by an additional two months and will notify you of any such extension.
Identity verification
To protect your privacy and security, we may need to verify your identity before processing requests to access, modify, or delete your personal data.
We may request additional information to confirm your identity. This verification process helps prevent unauthorized disclosure of personal data.
Data protection officer
We have appointed a Data Protection Officer to oversee our compliance with data protection laws and to serve as a point of contact for privacy-related inquiries.
You may contact our Data Protection Officer at:
Email: [email protected]
Address: Level 14, Collins Tower, 384 Collins Street, Melbourne VIC 3000, Australia
International data transfers
When we transfer personal data outside the European Economic Area, we implement appropriate safeguards to ensure your data remains protected in accordance with GDPR requirements.
These safeguards may include:
- Standard contractual clauses approved by the European Commission
- Adequacy decisions confirming adequate protection in the recipient country
- Binding corporate rules for intra-group transfers
Data retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected or as required by law.
Our retention periods vary depending on the type of data and purpose of processing:
- Account information: Retained while your account is active and for a reasonable period thereafter
- Transaction records: Retained for the period required by tax and accounting regulations
- Marketing communications: Retained until you unsubscribe or withdraw consent
- Website usage data: Typically retained for 12-24 months
Data security measures
We implement appropriate technical and organizational measures to protect your personal data against unauthorized or unlawful processing, accidental loss, destruction, or damage.
Our security measures include:
- Encryption of data in transit and at rest
- Regular security assessments and penetration testing
- Access controls and authentication requirements
- Employee training on data protection and security
- Incident response procedures and breach notification protocols
Data breach notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the relevant supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach.
We will provide information about the nature of the breach, its likely consequences, and the measures we have taken or propose to take to address it.
Children's privacy
Our services are not directed to children under 16 years of age. We do not knowingly collect or process personal data from children.
If we learn that we have collected personal data from a child under 16, we will take steps to delete that information as quickly as possible. If you believe we may have data from or about a child, please contact us immediately.
Supervisory authority
You have the right to lodge a complaint with a supervisory authority if you believe our processing of your personal data violates data protection laws.
While we encourage you to contact us first to resolve any concerns, you may contact your local data protection authority or the authority in the country where you work, reside, or where an alleged infringement occurred.
Updates to this page
We may update this GDPR compliance information from time to time to reflect changes in our practices or legal requirements. We will post any updates on this page and update the "Last updated" date.
Contact us
For questions about GDPR compliance or to exercise your data protection rights, please contact us:
Data Protection Officer
Email: [email protected]
Address: Level 14, Collins Tower, 384 Collins Street, Melbourne VIC 3000, Australia