Effective Date: May 11, 2026
This page provides information for visitors from the European Economic Area (EEA) regarding our compliance with the General Data Protection Regulation (GDPR).
While Wildflower Shore is an Australian business primarily serving Australian clients, we recognize the rights of EEA individuals and commit to GDPR principles for all personal data we process.
Wildflower Shore is the data controller for personal information collected through our website and services:
Wildflower Shore
Level 12, Collins Tower
487 Collins Street
Melbourne VIC 3000
Australia
Email: [email protected]
We process personal data under the following legal bases:
As an EEA resident, you have the following rights regarding your personal data:
You have the right to request a copy of the personal data we hold about you, along with information about how we process it.
You can request correction of inaccurate or incomplete personal data.
You may request deletion of your personal data in certain circumstances, including when:
Note: This right may be limited by legal retention requirements for financial services records.
You may request that we limit how we use your personal data in certain situations, such as when you contest the accuracy of the data or object to processing.
You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit it to another controller.
You can object to processing based on legitimate interests or for direct marketing purposes. We will cease processing unless we demonstrate compelling legitimate grounds that override your interests.
We do not engage in automated decision-making or profiling that produces legal effects or similarly significant effects.
Where processing is based on consent, you have the right to withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.
To exercise any of these rights, please contact us at [email protected] with the subject line "GDPR Rights Request." We will respond within one month of receiving your request.
We may need to verify your identity before processing certain requests. If your request is complex or you have made multiple requests, we may extend the response period by up to two months, notifying you of the extension.
As an Australian-based organization, your personal data will be transferred to and processed in Australia. We ensure appropriate safeguards are in place for international data transfers, including:
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including:
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
In the event of a data breach that is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay (within 72 hours of becoming aware) and provide:
You have the right to lodge a complaint with a supervisory authority if you believe our processing of your personal data violates GDPR. For EEA residents, you may contact your local data protection authority.
A list of supervisory authorities is available at:
https://edpb.europa.eu/about-edpb/board/members_en
Our services are not directed at children under 16 years of age. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child without parental consent, we will delete it promptly.
We use cookies and similar technologies in accordance with GDPR requirements. You can manage cookie preferences through our cookie banner. For detailed information, see our Cookies Policy.
We may update this GDPR compliance notice from time to time. Material changes will be communicated through our website with an updated effective date.
For questions about our GDPR compliance or to exercise your rights, contact us at:
Email: [email protected]
Subject: GDPR Inquiry