GDPR Compliance
Last updated: September 22, 2026
Introduction
This page provides information about how Hyper Willow complies with the General Data Protection Regulation (GDPR) for individuals in the European Economic Area (EEA) and the United Kingdom. While we are based in Australia, we are committed to respecting data protection principles globally.
Legal Basis for Processing
We process personal data only when we have a legal basis to do so. Our legal bases include:
- Consent: When you have given clear consent for us to process your personal data for a specific purpose
- Contract: When processing is necessary for the performance of a contract with you
- Legal Obligation: When we must process your data to comply with the law
- Legitimate Interests: When processing is necessary for our legitimate business interests, provided these do not override your rights
Your Rights Under GDPR
If you are located in the EEA or UK, you have the following rights regarding your personal data:
Right to Access
You have the right to request copies of your personal data. We may charge a reasonable fee if your request is clearly unfounded, repetitive, or excessive.
Right to Rectification
You have the right to request that we correct any information you believe is inaccurate or complete information you believe is incomplete.
Right to Erasure
You have the right to request that we erase your personal data under certain conditions, such as when the data is no longer necessary for the purposes for which it was collected.
Right to Restrict Processing
You have the right to request that we restrict the processing of your personal data under certain conditions.
Right to Object
You have the right to object to our processing of your personal data under certain conditions, particularly when processing is based on legitimate interests.
Right to Data Portability
You have the right to request that we transfer the data we have collected to another organization, or directly to you, under certain conditions.
Right to Withdraw Consent
When processing is based on consent, you have the right to withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing based on consent before its withdrawal.
How to Exercise Your Rights
To exercise any of these rights, please contact us at [email protected]. We will respond to your request within one month, though this period may be extended by two additional months where necessary, taking into account the complexity and number of requests.
Data Protection Officer
For questions specifically related to data protection and GDPR compliance, you may contact our designated data protection contact at [email protected].
Data Processing Activities
What Data We Collect
- Contact information (name, email, address)
- Service inquiry details
- Property information relevant to service delivery
- Communication records
- Website usage data
Purpose of Processing
- Providing and managing our services
- Responding to inquiries
- Improving our services and website
- Complying with legal obligations
- Protecting our rights and preventing fraud
Data Recipients
We may share your data with:
- Service providers who assist in operating our business (subject to data processing agreements)
- Legal and regulatory authorities when required by law
- Professional advisors such as lawyers and accountants
International Data Transfers
As we are based in Australia, your personal data may be transferred to and processed in Australia. We ensure that appropriate safeguards are in place to protect your data in accordance with GDPR requirements.
Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including to satisfy legal, accounting, or reporting requirements. Retention periods vary depending on the type of data and the purpose for which it is processed.
Automated Decision-Making
We do not use automated decision-making or profiling that produces legal effects or similarly significantly affects you.
Data Security
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- Encryption of data in transit and at rest
- Regular security assessments
- Access controls and authentication measures
- Staff training on data protection
Data Breach Notification
In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the relevant supervisory authority within 72 hours of becoming aware of the breach.
Right to Lodge a Complaint
If you believe we have not complied with GDPR requirements, you have the right to lodge a complaint with a supervisory authority, particularly in the EU member state where you reside, work, or where an alleged infringement occurred.
Changes to This Statement
We may update this GDPR compliance statement from time to time. We will notify you of any significant changes by posting the updated statement on our website.
Contact Information
For any questions or concerns regarding GDPR compliance or to exercise your rights, please contact us at:
Hyper Willow
45 Botanical Terrace
Newtown, NSW 2042
Australia
Email: [email protected]