Our commitment to protecting your data under the General Data Protection Regulation
Last updated: August 2026
merry-panther is committed to protecting the privacy and security of personal data in accordance with the General Data Protection Regulation (GDPR) and other applicable data protection laws. This page outlines how we comply with GDPR requirements and your rights under this regulation.
merry-panther acts as the data controller for personal information collected through this website and in the course of providing our services. Our contact details are:
merry-panther
Level 12, 180 George Street
Sydney NSW 2000
Australia
Email: [email protected]
Under GDPR, we must have a lawful basis for processing personal data. We rely on the following legal bases:
If you are located in the European Economic Area (EEA) or the United Kingdom, you have the following rights under GDPR:
You have the right to request copies of your personal data. We may charge a small fee for this service in certain circumstances.
You have the right to request that we correct any information you believe is inaccurate. You also have the right to request that we complete any information you believe is incomplete.
You have the right to request that we erase your personal data, under certain conditions. This is also known as the "right to be forgotten".
You have the right to request that we restrict the processing of your personal data, under certain conditions.
You have the right to object to our processing of your personal data, under certain conditions, particularly where we are processing data based on legitimate interests.
You have the right to request that we transfer the data we have collected to another organisation, or directly to you, under certain conditions.
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you.
To exercise any of your GDPR rights, please contact us using the details provided above. We will respond to your request within one month. In certain circumstances, we may extend this period by up to two additional months, in which case we will inform you of the extension and the reasons for it.
We may request specific information from you to help us confirm your identity and ensure your right to access your personal data. This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it.
As an Australian company, any personal data we collect may be transferred to and processed in Australia. We ensure that any international transfers of personal data comply with GDPR requirements and that appropriate safeguards are in place to protect your data.
We have implemented appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach. We will also notify affected individuals where the breach is likely to result in a high risk to their rights and freedoms.
For questions or concerns about our GDPR compliance or data protection practices, please contact us at:
Email: [email protected]
If you are not satisfied with how we handle your personal data or your data protection requests, you have the right to lodge a complaint with a supervisory authority. For individuals in the EEA, this would be the data protection authority in your country of residence, place of work, or place of the alleged infringement.
We may update this GDPR compliance information from time to time. We encourage you to review this page periodically for the latest information on our data protection practices.