merry-loop
Home Services About Contact Advertising Content

GDPR Compliance

Last updated: August 7, 2026

This page outlines how merry-loop complies with the General Data Protection Regulation (GDPR) and your rights regarding the processing of your personal data.

Data Controller

merry-loop acts as the data controller for any personal information collected through this website and our services. We are responsible for ensuring that your data is processed lawfully, fairly, and transparently.

Legal Basis for Processing

We process your personal data based on the following legal grounds:

  • Consent: When you provide explicit consent for specific purposes
  • Contract performance: When processing is necessary to fulfill our services
  • Legitimate interests: When we have a legitimate business interest that does not override your rights
  • Legal obligation: When required to comply with applicable laws

Your GDPR Rights

Under GDPR, you have the following rights:

  • Right to access: Request a copy of the personal data we hold about you
  • Right to rectification: Request correction of inaccurate or incomplete data
  • Right to erasure: Request deletion of your personal data under certain circumstances
  • Right to restrict processing: Request limitation on how we use your data
  • Right to data portability: Receive your data in a structured, machine-readable format
  • Right to object: Object to processing based on legitimate interests
  • Right to withdraw consent: Withdraw consent at any time where processing is based on consent

Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including:

  • Active project inquiries and ongoing client relationships
  • Compliance with legal and regulatory requirements
  • Resolution of disputes and enforcement of agreements

Once data is no longer needed, it will be securely deleted or anonymized.

International Data Transfers

Your personal data is primarily processed and stored within Australia. If data is transferred outside of the European Economic Area, we ensure appropriate safeguards are in place to protect your information.

Security Measures

We implement technical and organizational measures to protect your personal data against unauthorized access, loss, or alteration. These measures include:

  • Encryption of data in transit and at rest
  • Access controls and authentication procedures
  • Regular security assessments and updates

Automated Decision-Making

We do not use automated decision-making or profiling that would have legal or significant effects on you.

Exercising Your Rights

To exercise any of your GDPR rights, please contact us at [email protected]. We will respond to your request within one month of receipt. In complex cases, this period may be extended by up to two additional months.

Right to Lodge a Complaint

If you believe your data protection rights have been violated, you have the right to lodge a complaint with a supervisory authority in your country of residence, place of work, or where the alleged infringement occurred.

Updates to This Notice

We may update this GDPR compliance notice from time to time to reflect changes in our practices or applicable regulations. Updates will be posted on this page with a revised date.

Contact Information

For any questions regarding GDPR compliance or to exercise your rights, please contact us at [email protected].

merry-loop

Custom furniture crafted in Melbourne, Australia

Information

  • Privacy Policy
  • GDPR
  • Cookies Policy
  • Terms of Use

Connect

[email protected]