Last Updated: August 11, 2026
We are committed to protecting the privacy and security of personal data in accordance with the General Data Protection Regulation (GDPR) and applicable Australian privacy laws. This statement outlines how we handle data for individuals within the European Economic Area.
We process personal data based on the following legal grounds:
Under GDPR, you have the following rights regarding your personal data:
The data controller responsible for your personal information is neo-grove, located at Level 14, 287 Collins Street, Melbourne VIC 3000, Australia. For GDPR-related inquiries, contact us at [email protected].
Your personal data may be transferred to and processed in Australia. We ensure appropriate safeguards are in place to protect your data in accordance with GDPR requirements, including standard contractual clauses where applicable.
We process personal data for the following purposes:
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, comply with legal obligations, resolve disputes, and enforce agreements. Specific retention periods vary based on data type and applicable legal requirements.
We implement technical and organizational measures to protect personal data against unauthorized access, accidental loss, destruction, or damage. These measures include encryption, access controls, and regular security assessments.
In the event of a data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and inform affected individuals without undue delay.
We may engage third-party service providers to process personal data on our behalf. All processors are carefully selected and contractually bound to handle data in compliance with GDPR requirements.
To exercise any of your GDPR rights, submit a request to [email protected]. We will respond to verified requests within one month. In complex cases, this period may be extended by an additional two months with notification.
If you believe your data protection rights have been violated, you have the right to lodge a complaint with your local data protection supervisory authority in the European Economic Area.
We may update this GDPR compliance statement to reflect changes in our practices or legal requirements. Significant updates will be communicated through our website or direct notification.