We use cookies to enhance your browsing experience and analyze site traffic. Choose your preference below.

scarlet bark
Our Story Experiences Get In Touch Book Your Walk

GDPR Compliance Statement

Last Updated: May 13, 2026

Our Commitment to GDPR

Scarlet Bark is committed to complying with the General Data Protection Regulation (GDPR), which governs how we process personal data of individuals in the European Economic Area (EEA), United Kingdom, and Switzerland.

This statement outlines how we fulfill our obligations under GDPR and respect your data protection rights.

Legal Basis for Processing

We process your personal data based on the following legal grounds:

Contract Performance

Processing necessary to fulfill booking agreements and provide walking experiences you've requested. This includes processing booking details, payment information, and service delivery communications.

Legitimate Interests

Processing necessary for our legitimate business interests, such as:

  • Improving our services and customer experience
  • Ensuring safety and security of participants
  • Preventing fraud and maintaining system security
  • Analyzing website usage to optimize functionality

Legal Obligations

Processing required to comply with legal obligations, including tax laws, financial regulations, and safety requirements.

Consent

Processing based on your explicit consent, such as receiving marketing communications or non-essential cookies. You may withdraw consent at any time.

Your GDPR Rights

Under GDPR, you have the following rights regarding your personal data:

Right to Access

You have the right to request copies of your personal data. We will provide this information within one month of your request.

Right to Rectification

You have the right to request correction of inaccurate or incomplete personal data we hold about you.

Right to Erasure ("Right to be Forgotten")

You have the right to request deletion of your personal data when:

  • The data is no longer necessary for the purposes it was collected
  • You withdraw consent (where processing was based on consent)
  • You object to processing and there are no overriding legitimate grounds
  • The data has been unlawfully processed
  • Deletion is required for compliance with legal obligations

Note: We may be unable to delete data if retention is required by law or for establishing legal claims.

Right to Restriction of Processing

You have the right to request limitation on how we process your data in certain circumstances, such as when you contest data accuracy or object to processing.

Right to Data Portability

You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit it to another controller.

Right to Object

You have the right to object to processing of your personal data based on legitimate interests or for direct marketing purposes. We will cease processing unless we demonstrate compelling legitimate grounds.

Right to Withdraw Consent

Where processing is based on consent, you have the right to withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing conducted before withdrawal.

Rights Related to Automated Decision-Making

We do not engage in automated decision-making or profiling that produces legal effects or similarly significant effects on individuals.

How to Exercise Your Rights

To exercise any of your GDPR rights, contact us at:

Email: [email protected]
Subject line: "GDPR Request"

Please include:

  • Your full name and contact details
  • Description of your request and which right you're exercising
  • Any relevant booking or account information

We will respond to requests within one month. In complex cases, we may extend this by two additional months with explanation.

Data Protection Officer

For data protection inquiries, contact our Data Protection Officer:

Email: [email protected]
Subject line: "Data Protection Officer"

Data Security Measures

We implement appropriate technical and organizational measures to ensure data security, including:

  • Encryption of data in transit and at rest
  • Regular security assessments and penetration testing
  • Access controls limiting data access to authorized personnel
  • Staff training on data protection requirements
  • Incident response procedures for data breaches

Data Breach Notification

In the event of a personal data breach that poses a risk to your rights and freedoms, we will:

  • Notify the relevant supervisory authority within 72 hours of becoming aware
  • Notify affected individuals without undue delay if the breach poses high risk
  • Provide clear information about the nature of the breach and measures taken

International Data Transfers

We primarily process data within Australia. When data is transferred outside the EEA, we ensure appropriate safeguards are in place, such as:

  • Standard contractual clauses approved by the European Commission
  • Adequacy decisions recognizing equivalent data protection
  • Binding corporate rules for intra-organizational transfers

Data Retention Periods

We retain personal data only as long as necessary:

  • Booking and payment records: 7 years (tax and accounting requirements)
  • Marketing communications data: Until consent is withdrawn
  • Website analytics: 26 months
  • Inquiry correspondence: 2 years after resolution

Third-Party Processors

We work with trusted third-party processors who assist with specific services. All processors:

  • Process data only on our documented instructions
  • Implement appropriate security measures
  • Maintain confidentiality obligations
  • Comply with GDPR requirements

Complaints and Supervisory Authority

If you believe we have not handled your personal data in accordance with GDPR, you have the right to lodge a complaint with a supervisory authority.

For EEA residents, contact your local data protection authority. For UK residents, contact the Information Commissioner's Office (ICO).

We encourage you to contact us first so we can address your concerns directly.

Updates to This Statement

We may update this GDPR compliance statement to reflect changes in our practices or legal requirements. Significant changes will be communicated through our website and, where appropriate, by email.

Contact Information

For any questions about our GDPR compliance or data protection practices:

Email: [email protected]
Address: 127 Wattle Grove Lane, Fitzroy, Victoria 3065, Australia

scarlet bark

Guided walking experiences across Australia's diverse landscapes.

Navigate

  • Our Story
  • All Experiences
  • Contact

Legal

  • Privacy Policy
  • GDPR Compliance
  • Cookie Policy
  • Terms of Use

Connect

scarlet-bark.com

Crafted for those who walk deliberately.

© 2026 Scarlet Bark. All trails walked with intention.