Last Updated: September 2, 2026
This statement outlines how moss-robin.com complies with the General Data Protection Regulation (GDPR) when processing personal data of individuals located in the European Economic Area (EEA), United Kingdom, and Switzerland.
We process your personal data under the following legal bases:
moss-robin acts as the data controller for personal information collected through our website and booking services. Our contact details:
moss-robin
Level 3, 142 Collins Street
Melbourne VIC 3000, Australia
Email: [email protected]
If you are located in the EEA, UK, or Switzerland, you have the following rights:
You may request a copy of the personal data we hold about you. We will provide this information in a commonly used electronic format within 30 days of your request.
You can request correction of inaccurate or incomplete personal data. We will update our records promptly upon verification.
You may request deletion of your personal data when it is no longer necessary for the purposes for which it was collected, subject to legal retention requirements.
You can request limitation of how we process your data in certain circumstances, such as when you contest the accuracy of the data.
You have the right to receive your personal data in a structured, commonly used, machine-readable format and transmit it to another controller.
You may object to processing based on legitimate interests or for direct marketing purposes. We will cease processing unless we demonstrate compelling legitimate grounds.
We do not use automated decision-making or profiling that produces legal effects or significantly affects you.
To exercise any of these rights, send a written request to [email protected]. We will respond within 30 days and may request identity verification to protect your information.
While not legally required to appoint a Data Protection Officer, we have designated a privacy compliance contact for GDPR-related inquiries. Contact this person at [email protected] with "GDPR Inquiry" in the subject line.
Your personal data is primarily stored and processed in Australia. When we transfer data outside the EEA, we implement appropriate safeguards including:
We retain personal data only as long as necessary:
We implement technical and organizational measures to ensure data security appropriate to the risk, including:
In the event of a data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware. If the breach poses a high risk, we will also notify affected individuals without undue delay.
Where processing is based on consent, you may withdraw consent at any time by contacting [email protected] or using unsubscribe links in marketing communications. Withdrawal does not affect the lawfulness of processing before withdrawal.
You have the right to lodge a complaint with a supervisory authority, particularly in your country of residence, workplace, or where an alleged infringement occurred. For the UK, this is the Information Commissioner's Office (ICO). For other EEA countries, contact your national data protection authority.
We do not knowingly process personal data of individuals under 16 years old without parental consent. If we become aware of such processing, we will delete the data promptly.
We may update this GDPR compliance statement to reflect changes in our practices or legal requirements. Significant changes will be communicated to registered users. The last updated date appears at the top of this document.