Last Updated: July 21, 2026
storm-saga.com is committed to protecting your personal data and respecting your privacy rights under the General Data Protection Regulation (GDPR) and applicable Australian privacy laws. This page outlines how we comply with these regulations and your rights regarding your personal information.
For the purposes of GDPR, the data controller is:
storm-saga
147 Industrial Avenue
Collingwood, Melbourne VIC 3066
Australia
Email: [email protected]
We process your personal data based on the following legal grounds:
You have the following rights regarding your personal data:
You can request confirmation of whether we process your personal data and obtain a copy of that data.
You can request correction of inaccurate or incomplete personal data we hold about you.
You can request deletion of your personal data in certain circumstances, including when data is no longer necessary for the purposes it was collected.
You can request restriction of processing your personal data in specific situations.
You can request to receive your personal data in a structured, commonly used, and machine-readable format and have it transferred to another controller.
You can object to processing of your personal data based on legitimate interests or for direct marketing purposes.
Where processing is based on consent, you have the right to withdraw that consent at any time.
You have the right to lodge a complaint with a supervisory authority if you believe your data protection rights have been violated.
We may process the following categories of personal data:
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including:
After retention periods expire, data is securely deleted or anonymized.
We implement appropriate technical and organizational security measures to protect your personal data:
When transferring personal data outside the European Economic Area or Australia, we ensure adequate safeguards are in place, including:
In the event of a data breach that poses a risk to your rights and freedoms, we will notify the appropriate supervisory authority within 72 hours of becoming aware of the breach. If the breach poses a high risk to you, we will also notify you directly without undue delay.
We do not use automated decision-making or profiling that produces legal effects or similarly significantly affects you.
We work with carefully selected third-party service providers who process personal data on our behalf. All processors are bound by data processing agreements that ensure GDPR compliance and appropriate security measures.
To exercise any of your data protection rights, contact us at:
Email: [email protected]
Subject line: Data Protection Request
We will respond to your request within one month. In complex cases, we may extend this period by two additional months and will inform you of the extension.
We may need to verify your identity before processing your request. No fee is typically required, though we may charge a reasonable fee for excessive or manifestly unfounded requests.
We may update this GDPR compliance information to reflect changes in our practices or legal requirements. Please review this page periodically for the latest information.
If you have questions about our GDPR compliance or data protection practices, contact us at [email protected]