Last Updated: September 2026
The General Data Protection Regulation (GDPR) is a comprehensive data protection law that applies to the processing of personal data of individuals in the European Union. While spring-ocelot is based in Australia, we recognize the importance of GDPR compliance for any European customers or partners who may use our services.
This document outlines how we handle personal data in accordance with GDPR principles and describes the rights available to individuals under this regulation.
For the purposes of GDPR, spring-ocelot acts as the data controller for personal information collected through our website and services.
Contact details:
spring-ocelot
Level 12, 385 Bourke Street
Melbourne VIC 3000
Australia
Email: [email protected]
We process personal data based on the following legal grounds under GDPR:
Contractual Necessity: Processing is necessary to perform our contract with you when you use our payment processing services.
Legitimate Interests: We process certain data based on our legitimate business interests, such as fraud prevention, network security, and service improvement, provided these interests do not override your fundamental rights.
Legal Obligation: We process data when required to comply with legal obligations, including financial regulations, tax laws, and anti-money laundering requirements.
Consent: For certain processing activities, such as marketing communications or optional features, we rely on your explicit consent.
If you are located in the European Union, you have the following rights regarding your personal data:
Right of Access: You have the right to request a copy of the personal data we hold about you.
Right to Rectification: You can request that we correct inaccurate or incomplete personal data.
Right to Erasure: In certain circumstances, you can request deletion of your personal data (also known as the "right to be forgotten").
Right to Restriction: You can request that we restrict the processing of your personal data in specific situations.
Right to Data Portability: You have the right to receive your personal data in a structured, commonly used format and to transmit it to another data controller.
Right to Object: You can object to processing based on legitimate interests or for direct marketing purposes.
Rights Related to Automated Decision-Making: You have the right not to be subject to decisions based solely on automated processing that significantly affects you.
To exercise any of your GDPR rights, please contact us at [email protected] with your request. We will respond to your request within one month, though this period may be extended by two additional months for complex requests.
We may need to verify your identity before processing your request to ensure we are disclosing information only to the correct individual.
You also have the right to lodge a complaint with your local data protection authority if you believe we have not handled your personal data appropriately.
We adhere to the GDPR data protection principles, ensuring that personal data is:
Processed Lawfully, Fairly, and Transparently: We inform you about how we use your data and process it only for legitimate purposes.
Collected for Specified Purposes: We collect data only for explicit, legitimate purposes and do not process it in ways incompatible with those purposes.
Adequate, Relevant, and Limited: We collect only the minimum data necessary for our purposes.
Accurate and Up to Date: We take reasonable steps to ensure personal data is accurate and update it when necessary.
Stored for No Longer Than Necessary: We retain data only as long as required for the purposes for which it was collected or as required by law.
Processed Securely: We implement appropriate technical and organizational measures to protect personal data against unauthorized or unlawful processing and accidental loss or damage.
As we are based in Australia, personal data collected from European users may be transferred outside the European Economic Area. When we transfer data internationally, we ensure appropriate safeguards are in place, such as:
Standard contractual clauses approved by the European Commission.
Ensuring the recipient country has been deemed to provide adequate data protection by the European Commission.
Implementing additional security measures to protect data in transit and at rest.
We retain personal data for different periods depending on the type of data and purpose for processing:
Account information is retained for the duration of your relationship with us and for a period afterward as required by law or legitimate business purposes.
Transaction data is typically retained for seven years to comply with financial record-keeping requirements.
Marketing consent records are retained until you withdraw consent, after which we retain only a record of your withdrawal to respect your preferences.
Technical logs and security data may be retained for shorter periods necessary for security monitoring and troubleshooting.
We implement comprehensive security measures to protect personal data, including:
Encryption of data in transit using TLS protocols and at rest using industry-standard encryption algorithms.
Access controls ensuring only authorized personnel can access personal data on a need-to-know basis.
Regular security assessments, vulnerability testing, and penetration testing.
Staff training on data protection and security best practices.
Incident response procedures to detect, investigate, and respond to data breaches.
In the event of a data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. If the breach is likely to result in a high risk to your rights, we will also notify you directly without undue delay.
We work with third-party service providers who process personal data on our behalf. These processors are carefully selected and bound by data processing agreements that require them to:
Process data only according to our documented instructions.
Implement appropriate technical and organizational security measures.
Assist us in responding to data subject requests.
Delete or return data when the processing services are no longer required.
Maintain confidentiality and comply with GDPR requirements.
Our services are not intended for children under 16 years of age. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child without appropriate parental consent, we will delete that information promptly.
We may update this GDPR compliance statement periodically to reflect changes in our practices or legal requirements. Significant changes will be communicated through our website and, where appropriate, via direct communication to affected individuals.
If you have questions about our GDPR compliance, data protection practices, or wish to exercise your rights, please contact our data protection team:
Email: [email protected]
Address: Level 12, 385 Bourke Street, Melbourne VIC 3000, Australia