GDPR Compliance
mountain-ibis is committed to protecting your personal data in accordance with applicable data protection regulations, including the General Data Protection Regulation.
Data Controller
mountain-ibis acts as the data controller for personal information collected through our website and services. We determine the purposes and means of processing your personal data.
Legal Basis for Processing
We process personal data based on the following legal grounds:
- Consent: When you voluntarily provide information through forms or communications
- Contract Performance: To deliver services you have requested
- Legitimate Interests: To improve our services and communicate effectively with clients
- Legal Obligations: To comply with applicable laws and regulations
Your Rights Under GDPR
Right to Access
You have the right to request confirmation of whether we process your personal data and to obtain a copy of that data.
Right to Rectification
You can request correction of inaccurate personal data or completion of incomplete information.
Right to Erasure
Under certain circumstances, you have the right to request deletion of your personal data.
Right to Restriction
You may request restriction of processing your personal data in specific situations.
Right to Data Portability
You have the right to receive your personal data in a structured, commonly used format and to transmit it to another controller.
Right to Object
You can object to processing of your personal data for direct marketing purposes or based on legitimate interests.
Right to Withdraw Consent
Where processing is based on consent, you have the right to withdraw that consent at any time.
Exercising Your Rights
To exercise any of these rights, contact us at [email protected]. We will respond to your request within one month. If your request is complex or we receive multiple requests, we may extend this period by two months and will notify you.
Data Security
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including encryption, access controls, and regular security assessments.
Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected or to comply with legal requirements. Specific retention periods depend on the nature of the data and applicable regulations.
International Data Transfers
Your personal data may be processed in Australia. We ensure appropriate safeguards are in place for any international data transfers in accordance with GDPR requirements.
Automated Decision-Making
We do not use automated decision-making or profiling that produces legal effects or similarly significant impacts on individuals.
Data Protection Officer
For questions about data protection or to exercise your rights, contact us at [email protected].
Right to Lodge a Complaint
If you believe we have not handled your personal data appropriately, you have the right to lodge a complaint with the relevant data protection supervisory authority.
Changes to This Information
We may update our GDPR compliance information periodically. Changes will be posted on this page with an updated revision date.
Last updated: June 19, 2026