Our commitment to protecting your data under the General Data Protection Regulation
Last Updated: August 2026
merry-grove is committed to ensuring the protection of personal data in accordance with the General Data Protection Regulation (GDPR). While we are based in Australia, we recognise the importance of GDPR compliance for individuals located in the European Economic Area (EEA) who may interact with our services.
merry-grove acts as the data controller for personal data collected through this website. This means we determine the purposes and means of processing your personal data.
Contact details:
merry-grove
Level 4, 127 Collins Street
Melbourne VIC 3000
Australia
[email protected]
Under GDPR, we must have a lawful basis to process your personal data. We rely on the following bases:
If you are located in the EEA, you have the following rights regarding your personal data:
You have the right to request a copy of the personal data we hold about you and information about how we process it.
You have the right to request that we correct any inaccurate personal data or complete any incomplete data.
You have the right to request that we delete your personal data in certain circumstances, such as when the data is no longer necessary for the purposes for which it was collected.
You have the right to request that we restrict the processing of your personal data in certain circumstances.
You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller.
You have the right to object to the processing of your personal data in certain circumstances, including processing based on legitimate interests or for direct marketing purposes.
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you.
To exercise any of these rights, please contact us at [email protected]. We will respond to your request within one month. In some cases, we may need to verify your identity before processing your request.
As we are based in Australia, your personal data may be transferred to and processed in Australia, which is outside the EEA. When transferring data outside the EEA, we ensure appropriate safeguards are in place to protect your data, including standard contractual clauses approved by the European Commission.
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected or as required by law. When data is no longer needed, we securely delete or anonymise it.
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including encryption, access controls, and regular security assessments.
In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay and inform the relevant supervisory authority within 72 hours where required.
If you are not satisfied with how we handle your personal data, you have the right to lodge a complaint with a supervisory authority in the EU member state of your habitual residence, place of work, or place of the alleged infringement.
We may update this GDPR compliance notice from time to time. Any changes will be posted on this page with an updated revision date.