Last Updated: September 29, 2026
Although Vermilion-pebble operates primarily in Australia, we recognize the importance of data protection for individuals located in the European Union. This page outlines how we handle personal data in accordance with the General Data Protection Regulation.
Vermilion-pebble acts as the data controller for personal information collected through this website. We determine the purposes and means of processing your personal data.
We process personal data based on the following legal grounds:
We collect personal data including names, email addresses, and business information when you submit inquiries or service requests. This information is used to communicate with you about payment solutions, prepare service proposals, and maintain business relationships.
If you are located in the European Union, you have the following rights regarding your personal data:
You can request confirmation of whether we process your personal data and obtain a copy of that data.
You can request correction of inaccurate personal data we hold about you.
You can request deletion of your personal data in certain circumstances, such as when the data is no longer necessary for the purposes it was collected.
You can request that we restrict processing of your personal data under specific conditions.
You can request to receive your personal data in a structured, commonly used format and transmit it to another controller.
You can object to processing of your personal data based on legitimate interests or for direct marketing purposes.
Where processing is based on consent, you can withdraw that consent at any time.
We retain personal data only for as long as necessary to fulfill the purposes outlined in our Privacy Policy or as required by applicable law. When data is no longer needed, we securely delete or anonymize it.
Personal data may be transferred to and stored on servers located in Australia. We ensure appropriate safeguards are in place for such transfers in accordance with GDPR requirements.
We implement technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure, or destruction. These measures include encryption, access controls, and regular security assessments.
We do not use automated decision-making or profiling that produces legal effects or similarly significant impacts on individuals.
To exercise any of your GDPR rights, contact us at:
Email: [email protected]
Subject: GDPR Rights Request
We will respond to your request within one month, as required by GDPR. In complex cases, we may extend this period by two additional months and will inform you of any such extension.
If you believe we have not adequately addressed your concerns, you have the right to lodge a complaint with your local data protection supervisory authority in the European Union.
For questions specifically related to data protection and GDPR compliance, contact our data protection team at [email protected].
We may update this GDPR compliance statement periodically to reflect changes in our practices or legal requirements. Updates will be posted on this page with a revised date.