Your data protection rights under GDPR
Last updated: September 22, 2026
The General Data Protection Regulation (GDPR) is a comprehensive data protection law that grants individuals in the European Union extensive rights over their personal data. While Deft Sparrow primarily operates in Australia, we respect the data protection rights of all individuals who interact with our website and services.
This page outlines your rights under GDPR and explains how we comply with data protection principles.
We process personal data based on the following legal grounds:
Under GDPR, you have the following rights regarding your personal data:
You have the right to request confirmation of whether we process your personal data and to obtain a copy of that data. We will provide this information in a commonly used electronic format.
You have the right to request correction of inaccurate personal data and to have incomplete data completed. We will update your information promptly upon receiving your request.
Also known as the "right to be forgotten," you can request deletion of your personal data when it is no longer necessary for the purposes for which it was collected, when you withdraw consent, or when you object to processing.
You can request that we limit the processing of your personal data in certain circumstances, such as when you contest the accuracy of the data or object to processing.
You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller without hindrance.
You can object to processing of your personal data based on legitimate interests or for direct marketing purposes. We will cease processing unless we can demonstrate compelling legitimate grounds.
Where we process your data based on consent, you have the right to withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.
You have the right to lodge a complaint with a supervisory authority if you believe our processing of your personal data violates data protection laws.
We adhere to the following GDPR principles when processing personal data:
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include:
If we transfer your personal data outside the European Economic Area, we ensure appropriate safeguards are in place to protect your data in accordance with GDPR requirements.
We do not use automated decision-making or profiling that produces legal effects or similarly significant effects on individuals.
To exercise any of your GDPR rights, please contact us using the following information:
Email: [email protected]
Address: Level 3, 142 Collins Street, Melbourne VIC 3000, Australia
We will respond to your request within one month of receipt. In complex cases, we may extend this period by an additional two months and will inform you of any such extension.
To protect your privacy and security, we may require verification of your identity before processing requests related to your personal data. We will request only the minimum information necessary to confirm your identity.
We may update this GDPR compliance statement to reflect changes in our practices or legal requirements. Material changes will be communicated through our website or directly to affected individuals when appropriate.