Last Updated: June 19, 2026
While cerulean-aurora is based in Australia, we recognize the importance of the General Data Protection Regulation (GDPR) for individuals residing in the European Economic Area (EEA). This statement outlines our commitment to GDPR compliance for EEA residents who interact with our services.
We process personal data under the following legal bases:
cerulean-aurora acts as the data controller for personal information collected through our website and services.
Data Controller:
cerulean-aurora
Level 4, 127 St Georges Terrace
Perth WA 6000, Australia
Email: [email protected]
If you are a resident of the EEA, you have the following rights under GDPR:
You have the right to request confirmation of whether we process your personal data and to obtain a copy of that data.
You have the right to request correction of inaccurate or incomplete personal data.
You have the right to request deletion of your personal data under certain circumstances, including when data is no longer necessary for the purposes collected or when you withdraw consent.
You have the right to request restriction of processing your personal data in specific situations, such as when you contest the accuracy of the data.
You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit that data to another controller.
You have the right to object to processing of your personal data based on legitimate interests or for direct marketing purposes.
Where processing is based on consent, you have the right to withdraw that consent at any time without affecting the lawfulness of processing based on consent before withdrawal.
You have the right to lodge a complaint with a supervisory authority in your country of residence if you believe our processing of your personal data violates GDPR.
To exercise any of these rights, contact us at [email protected]. We will respond to your request within one month. In complex cases, this period may be extended by two additional months, and we will inform you of such extension.
We may request specific information from you to help us confirm your identity and ensure your right to access personal data or exercise other rights.
Your personal data may be transferred to and processed in Australia, which may not provide the same level of data protection as EEA countries. When we transfer data outside the EEA, we ensure appropriate safeguards are in place, such as:
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including legal, accounting, or reporting requirements. Specific retention periods include:
We do not engage in automated decision-making or profiling that produces legal effects or similarly significantly affects individuals.
While not legally required to appoint a Data Protection Officer, we have designated a privacy contact for GDPR-related matters:
Email: [email protected]
Subject Line: GDPR Enquiry
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you without undue delay and, where feasible, within 72 hours of becoming aware of the breach.
We engage third-party service providers who process personal data on our behalf. We ensure these processors:
Our services are not directed to individuals under 16 years of age. We do not knowingly collect or process personal data from children. If we become aware of such collection, we will take steps to delete the data.
We may update this GDPR Compliance Statement to reflect changes in our practices or legal requirements. Material changes will be communicated through our website or directly to affected individuals where required.
For GDPR-related questions, concerns, or to exercise your rights, contact us at [email protected].
If you are unsatisfied with our response, you may lodge a complaint with your local supervisory authority. For residents of the UK, this would be the Information Commissioner's Office (ICO). For other EEA countries, contact details for supervisory authorities can be found on the European Data Protection Board website.