Our commitment to protecting your data under the General Data Protection Regulation
Last Updated: 1 January 2026
maple-tale is committed to ensuring compliance with the General Data Protection Regulation (GDPR) for all individuals located in the European Economic Area (EEA). This page outlines how we handle personal data in accordance with GDPR requirements.
For the purposes of GDPR, maple-tale acts as the data controller for personal information collected through our website and services.
Contact Details:
maple-tale
Level 8, 121 Flinders Lane
Melbourne VIC 3000
Australia
Email: [email protected]
If you are located in the EEA, you have the following rights regarding your personal data:
You have the right to request a copy of the personal data we hold about you. We will provide this information free of charge within one month of receiving your request.
You have the right to request that we correct any personal data that is inaccurate or complete any data that is incomplete.
You have the right to request deletion of your personal data in certain circumstances, including:
You have the right to request that we limit the processing of your personal data in certain circumstances, such as when you contest the accuracy of the data or object to processing.
You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller.
You have the right to object to processing of your personal data for direct marketing purposes or where processing is based on legitimate interests.
You have the right not to be subject to decisions based solely on automated processing, including profiling, that produce legal effects or similarly significantly affect you.
We process personal data under the following legal bases:
As maple-tale is based in Australia, your personal data may be transferred outside the EEA. When we transfer data internationally, we ensure appropriate safeguards are in place, such as:
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected. Specific retention periods depend on the type of data and the purposes for processing. When data is no longer required, it is securely deleted or anonymised.
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, destruction, or alteration. These measures include encryption, access controls, and regular security assessments.
To exercise any of your GDPR rights, please contact us at [email protected]. We will respond to your request within one month. In complex cases, we may extend this period by up to two additional months, in which case we will inform you of the extension and reasons.
There is no fee for exercising your rights, although we may charge a reasonable fee for manifestly unfounded or excessive requests.
If you believe your data protection rights have been violated, you have the right to lodge a complaint with a supervisory authority. For individuals in the EEA, this would be the data protection authority in your country of residence.
We may update this GDPR compliance information from time to time. Any changes will be posted on this page with an updated revision date.