GDPR Compliance
Last updated: July 21, 2026
Introduction
While jade-seed operates primarily in Australia, we recognize the importance of the European Union's General Data Protection Regulation (GDPR) for any European Union residents who may interact with our services.
This document outlines how we comply with GDPR principles when processing personal data of EU residents.
Legal Basis for Processing
We process personal data under the following legal bases as defined by GDPR:
- Contract performance: Processing necessary to fulfill furniture manufacturing contracts and respond to service inquiries
- Legitimate interests: Processing for business operations, maintaining project records, and improving our services
- Consent: Processing for specific purposes where you have provided explicit consent
- Legal obligation: Processing required to comply with Australian and international legal requirements
Data Subject Rights Under GDPR
If you are an EU resident, you have the following rights regarding your personal data:
Right to Access
You may request confirmation of whether we process your personal data and obtain a copy of that data.
Right to Rectification
You may request correction of inaccurate personal data and completion of incomplete data.
Right to Erasure
You may request deletion of your personal data when it is no longer necessary for the purposes for which it was collected, subject to legal retention obligations.
Right to Restriction of Processing
You may request that we limit processing of your personal data in certain circumstances, such as when you contest data accuracy.
Right to Data Portability
You may request to receive your personal data in a structured, commonly used, machine-readable format and transmit it to another controller.
Right to Object
You may object to processing of your personal data based on legitimate interests or for direct marketing purposes.
Right to Withdraw Consent
Where processing is based on consent, you may withdraw that consent at any time without affecting the lawfulness of processing before withdrawal.
Right to Lodge a Complaint
You have the right to lodge a complaint with a supervisory authority in the EU member state of your residence, workplace, or where an alleged infringement occurred.
Data Protection Principles
We adhere to GDPR data protection principles:
- Lawfulness, fairness, and transparency: We process data lawfully and inform you about processing activities
- Purpose limitation: We collect data for specific, legitimate purposes and do not process it in ways incompatible with those purposes
- Data minimization: We collect only data that is necessary for the stated purposes
- Accuracy: We take reasonable steps to ensure personal data is accurate and up to date
- Storage limitation: We retain data only as long as necessary for the purposes collected
- Integrity and confidentiality: We implement appropriate security measures to protect personal data
- Accountability: We take responsibility for compliance and can demonstrate adherence to these principles
International Data Transfers
As an Australian-based business, personal data of EU residents is transferred to and processed in Australia. We ensure such transfers comply with GDPR requirements:
- We implement appropriate safeguards for international data transfers
- We maintain documentation of data processing activities
- We ensure third-party processors also comply with adequate data protection standards
Data Breach Notification
In the event of a personal data breach that poses a risk to your rights and freedoms, we will:
- Notify the relevant supervisory authority within 72 hours of becoming aware of the breach
- Notify affected individuals without undue delay if the breach poses a high risk
- Document the breach, its effects, and remedial actions taken
Automated Decision-Making
We do not use automated decision-making or profiling that produces legal effects or similarly significant effects on individuals.
Children's Data
We do not knowingly process personal data of individuals under 16 years of age. Our services are directed to adults.
Data Protection Officer
For GDPR-related inquiries, data subject rights requests, or concerns about how we process personal data, contact us at:
Email: [email protected]
Subject line: GDPR Inquiry
We will respond to GDPR-related requests within one month, extendable by two additional months for complex requests.
Third-Party Data Processors
We work with the following categories of third-party processors who may access personal data:
- Email service providers for communication management
- Cloud storage providers for project documentation
- Delivery services for furniture installation coordination
All third-party processors are contractually bound to GDPR-compliant data processing terms.
Record of Processing Activities
We maintain records of all data processing activities as required by GDPR Article 30, including:
- Purposes of processing
- Categories of data subjects and personal data
- Categories of recipients of personal data
- International data transfers
- Retention periods
- Security measures implemented
Updates to GDPR Compliance
We regularly review our GDPR compliance practices and update this document as needed. Material changes will be communicated through our website.
Exercising Your Rights
To exercise any GDPR rights or make inquiries about our data processing practices, email [email protected] with "GDPR Request" in the subject line. Include:
- Your full name and contact information
- Description of the specific right you wish to exercise
- Any relevant details that help us locate your personal data
We may request additional information to verify your identity before processing requests.