quiet-moor
Home About Services Contact Information on this site is advertising in nature

GDPR Compliance

General Data Protection Regulation Information

Introduction

The General Data Protection Regulation (GDPR) is a comprehensive data protection law that applies to the processing of personal data of individuals in the European Union and European Economic Area. While quiet-moor is based in Australia, we are committed to meeting GDPR standards when processing data of EU residents.

Data Controller Information

For the purposes of GDPR, quiet-moor acts as the data controller for personal information we collect through our website and services.

Data Controller: quiet-moor
Address: Level 3, 127 Collins Street, Melbourne VIC 3000, Australia
Email: [email protected]

Lawful Basis for Processing

We process personal data only when we have a lawful basis under GDPR Article 6:

  • Consent (Article 6(1)(a)): You have given explicit consent for processing your personal data for specific purposes
  • Contract (Article 6(1)(b)): Processing is necessary for performing a contract with you or taking steps at your request before entering into a contract
  • Legal Obligation (Article 6(1)(c)): Processing is necessary for compliance with legal obligations
  • Legitimate Interests (Article 6(1)(f)): Processing is necessary for our legitimate interests or those of a third party, except where your interests or fundamental rights override those interests

Your Rights Under GDPR

As a data subject under GDPR, you have the following rights:

Right of Access (Article 15)

You have the right to obtain confirmation about whether we are processing your personal data and, if so, to access that data along with specific information about the processing.

Right to Rectification (Article 16)

You have the right to have inaccurate personal data corrected and incomplete personal data completed.

Right to Erasure (Article 17)

Also known as the "right to be forgotten," you have the right to have your personal data erased in certain circumstances, including:

  • The data is no longer necessary for the purposes for which it was collected
  • You withdraw consent and there is no other legal basis for processing
  • You object to processing and there are no overriding legitimate grounds
  • The data has been unlawfully processed
  • Erasure is required to comply with a legal obligation

Right to Restriction of Processing (Article 18)

You have the right to restrict processing of your personal data in certain situations:

  • You contest the accuracy of the data
  • Processing is unlawful but you oppose erasure
  • We no longer need the data but you require it for legal claims
  • You have objected to processing pending verification of legitimate grounds

Right to Data Portability (Article 20)

You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller.

Right to Object (Article 21)

You have the right to object to processing of your personal data based on legitimate interests or for direct marketing purposes.

Rights Related to Automated Decision-Making (Article 22)

You have the right not to be subject to decisions based solely on automated processing, including profiling, which produces legal effects or similarly significantly affects you. We do not engage in automated decision-making or profiling.

Right to Withdraw Consent

Where processing is based on consent, you have the right to withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing based on consent before withdrawal.

Exercising Your Rights

To exercise any of your GDPR rights, please contact us at [email protected] with your request. We will respond within one month of receiving your request, though this period may be extended by two additional months in complex cases.

When submitting a request, please provide sufficient information to allow us to verify your identity and locate your data. We may request additional information to confirm your identity before processing your request.

There is no charge for exercising your rights unless your request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse to act on the request.

Data Protection Principles

We process personal data in accordance with GDPR principles:

  • Lawfulness, Fairness, and Transparency: We process data lawfully, fairly, and in a transparent manner
  • Purpose Limitation: We collect data for specified, explicit, and legitimate purposes only
  • Data Minimization: We collect only data that is adequate, relevant, and limited to what is necessary
  • Accuracy: We keep data accurate and up to date
  • Storage Limitation: We retain data only as long as necessary for the stated purposes
  • Integrity and Confidentiality: We implement appropriate security measures to protect data
  • Accountability: We are responsible for and can demonstrate compliance with these principles

International Data Transfers

When we transfer personal data from the EU to countries outside the European Economic Area, including Australia, we ensure appropriate safeguards are in place, such as:

  • Standard Contractual Clauses approved by the European Commission
  • Adequacy decisions by the European Commission
  • Other legally recognized transfer mechanisms

Data Breach Notification

In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. If the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay.

Data Protection Officer

While we are not required to appoint a Data Protection Officer under GDPR, our designated contact for data protection matters is available at [email protected].

Supervisory Authority

You have the right to lodge a complaint with a supervisory authority, particularly in the EU member state of your habitual residence, place of work, or place of the alleged infringement if you believe our processing of your personal data violates GDPR.

Cookies and Similar Technologies

We use cookies and similar tracking technologies in compliance with GDPR requirements. For detailed information, please see our Cookies Policy.

Children's Data

We do not knowingly collect or process personal data of children under 16 years of age without parental consent, in accordance with GDPR Article 8.

Updates to This Information

We may update this GDPR compliance information periodically. Any material changes will be communicated through our website.

Contact Us

For any questions or concerns regarding GDPR compliance or to exercise your data subject rights, please contact us:

Email: [email protected]
Address: Level 3, 127 Collins Street, Melbourne VIC 3000, Australia

quiet-moor

Supporting cultural heritage preservation across Australia through community-centered programs and partnerships.

Quick Links

  • About Us
  • Services
  • Contact

Legal

  • Privacy Policy
  • GDPR
  • Cookies Policy
  • Terms of Use

Contact

[email protected]

Melbourne, Australia

© 2026 quiet-moor. All rights reserved.