Your data protection rights under the General Data Protection Regulation
maple cypress respects the privacy of individuals located in the European Economic Area (EEA) and is committed to compliance with the General Data Protection Regulation (GDPR). This page explains how we process personal data in accordance with GDPR requirements and outlines your rights as a data subject.
maple cypress acts as the data controller for personal information collected through our website and services. Our contact details are:
maple cypress
42 Harbour Street
Sydney NSW 2000
Australia
Email: [email protected]
We process personal data based on the following legal grounds:
If you are located in the EEA, you have the following rights regarding your personal data:
To exercise any of these rights, please contact us at [email protected]. We will respond to your request within one month, as required by GDPR. In complex cases, we may extend this period by up to two additional months, in which case we will inform you of the extension and the reasons for it.
We may need to verify your identity before processing your request. If your request is manifestly unfounded or excessive, we may charge a reasonable fee or refuse to act on it.
As we are based in Australia, personal data collected from individuals in the EEA may be transferred to and processed in Australia. Australia is not subject to an adequacy decision by the European Commission. We ensure appropriate safeguards are in place to protect your data, including standard contractual clauses approved by the European Commission where applicable.
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy legal, accounting, or reporting requirements. The retention period depends on the nature of the data and the purposes for processing.
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including protection against unauthorised or unlawful processing and accidental loss, destruction, or damage.
In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay, as required by GDPR Article 34.
If you believe that our processing of your personal data violates GDPR, you have the right to lodge a complaint with a supervisory authority in the EU member state where you reside, work, or where the alleged infringement occurred.
We may update this GDPR compliance information from time to time. Any changes will be posted on this page with an updated date.
Last updated: June 2026