We use cookies to enhance your browsing experience. By continuing, you accept our use of cookies.

Whispered Stream
  • Home
  • Services
  • About
  • Contact

GDPR Compliance Statement

Last Updated: May 19, 2026

Our Commitment to Data Protection

While Whispered Stream is an Australian-based company, we recognize that we may process personal data of individuals located in the European Economic Area (EEA). We are committed to complying with the General Data Protection Regulation (GDPR) when handling such data.

Legal Basis for Processing

We process personal data under the following legal bases:

  • Consent: When you provide explicit consent for specific processing activities
  • Contract Performance: When processing is necessary to fulfill our service agreements
  • Legitimate Interests: When we have legitimate business interests that do not override your rights
  • Legal Obligation: When required to comply with applicable laws

Your Rights Under GDPR

If you are a resident of the EEA, you have the following rights regarding your personal data:

Right to Access

You have the right to request confirmation of whether we process your personal data and to access that data along with specific information about the processing.

Right to Rectification

You can request that we correct inaccurate personal data or complete incomplete data concerning you.

Right to Erasure (Right to be Forgotten)

Under certain circumstances, you can request that we delete your personal data, including:

  • When the data is no longer necessary for the purposes it was collected
  • When you withdraw consent and there is no other legal basis for processing
  • When you object to processing and there are no overriding legitimate grounds
  • When the data has been unlawfully processed

Right to Restriction of Processing

You can request that we restrict processing of your personal data in certain situations, such as when you contest the accuracy of the data or object to processing.

Right to Data Portability

Where processing is based on consent or contract and carried out by automated means, you have the right to receive your personal data in a structured, commonly used, and machine-readable format.

Right to Object

You have the right to object to processing of your personal data based on legitimate interests or for direct marketing purposes.

Right to Withdraw Consent

Where processing is based on consent, you have the right to withdraw that consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.

Right to Lodge a Complaint

You have the right to lodge a complaint with a supervisory authority in your country of residence, place of work, or where an alleged infringement occurred.

Data Protection Officer

For questions regarding GDPR compliance or to exercise your rights, please contact:

Email: [email protected]
Subject Line: GDPR Request - [Your Name]

We will respond to your request within 30 days of receipt.

International Data Transfers

As an Australian company, your personal data may be transferred to and processed in Australia. While Australia is not covered by an adequacy decision from the European Commission, we ensure appropriate safeguards are in place to protect your data in accordance with GDPR requirements.

Data Security Measures

We implement appropriate technical and organizational security measures to protect your personal data, including:

  • Encryption of data in transit and at rest
  • Access controls and authentication measures
  • Regular security assessments and updates
  • Staff training on data protection principles
  • Incident response and breach notification procedures

Data Retention

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including any legal, accounting, or reporting requirements. Retention periods vary depending on the type of data and the purpose of processing.

Automated Decision-Making

We do not engage in automated decision-making, including profiling, that produces legal effects or similarly significantly affects individuals.

Third-Party Processors

When we engage third-party service providers to process personal data on our behalf, we ensure they provide appropriate guarantees regarding data security and GDPR compliance through contractual agreements.

Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. If the breach poses a high risk, we will also notify affected individuals without undue delay.

Updates to This Statement

We may update this GDPR Compliance Statement periodically to reflect changes in our practices or legal requirements. We encourage you to review this page regularly for updates.

Contact Information

For any questions or concerns about our GDPR compliance or data protection practices:

Whispered Stream
Level 3, 247 Collins Street
Melbourne VIC 3000
Australia
Email: [email protected]

Whispered Stream

Transforming Australian homes with thoughtful design and expert craftsmanship.

Quick Links

  • Services
  • About Us
  • Contact

Legal

  • Privacy Policy
  • GDPR
  • Cookies Policy
  • Terms of Use

© 2026 Whispered Stream. All rights reserved.