GDPR Compliance Statement
Last Updated: September 2, 2026
Overview
While khaki-frost operates primarily in Australia, we recognize that some of our website visitors and potential clients may be located in the European Union. This document outlines how we comply with the General Data Protection Regulation (GDPR) when processing personal data of EU residents.
Legal Basis for Processing
We process personal data based on the following legal grounds:
- Consent: When you voluntarily submit information through our contact forms
- Contractual Necessity: To provide architectural services you have requested
- Legitimate Interests: To improve our website and services
- Legal Obligation: When required to retain records for professional practice compliance
Your GDPR Rights
If you are an EU resident, you have the following rights:
Right to Access
You may request a copy of the personal data we hold about you.
Right to Rectification
You may request correction of inaccurate or incomplete personal data.
Right to Erasure
You may request deletion of your personal data when it is no longer necessary for the purposes for which it was collected, subject to legal retention requirements.
Right to Restrict Processing
You may request that we limit how we use your personal data in certain circumstances.
Right to Data Portability
You may request transfer of your data to another service provider in a structured, commonly used format.
Right to Object
You may object to processing of your personal data based on legitimate interests.
Right to Withdraw Consent
Where processing is based on consent, you may withdraw that consent at any time.
Data Protection Officer
For questions regarding GDPR compliance or to exercise your rights, contact:
Email: [email protected]
Subject line: GDPR Request
Data Transfers
Your personal data may be stored and processed in Australia. We ensure appropriate safeguards are in place when transferring data outside the EU.
Data Breach Notification
In the event of a data breach affecting your personal information, we will notify you and relevant supervisory authorities as required by GDPR within 72 hours of becoming aware of the breach.
Retention Periods
We retain personal data only for as long as necessary to fulfill the purposes described in our Privacy Policy or as required by applicable law. Specific retention periods vary based on the nature of the information and applicable legal requirements.
Automated Decision Making
We do not use automated decision-making or profiling that would produce legal effects concerning you or similarly significantly affect you.
Supervisory Authority
You have the right to lodge a complaint with a supervisory authority in your EU member state if you believe we have not complied with GDPR requirements.
Children's Privacy
Our services are not directed to individuals under 16 years of age. We do not knowingly collect personal data from children.
Updates to This Statement
We may update this GDPR Compliance Statement to reflect changes in our practices or legal requirements. Material changes will be communicated through our website.