Your data protection rights under the General Data Protection Regulation
Last updated: September 2026
The Blade & Beard Co is committed to complying with the General Data Protection Regulation (GDPR) for all individuals whose personal data we process, regardless of their location. This page outlines how we uphold your rights under GDPR.
The Blade & Beard Co acts as the data controller for personal information collected through this website and our services. Our contact details are:
Email: [email protected]
Address: 142 Crown Street, Surry Hills NSW 2010, Australia
We process personal data under the following lawful bases:
As a data subject, you have the following rights:
You have the right to request a copy of the personal data we hold about you. We will provide this information within 30 days of your request.
If any personal data we hold about you is inaccurate or incomplete, you have the right to request correction.
You may request that we delete your personal data in certain circumstances, such as when the data is no longer necessary for its original purpose.
You have the right to request that we limit how we use your data in certain situations.
Where technically feasible, you can request your data in a structured, commonly used, machine-readable format for transfer to another service provider.
You may object to processing based on legitimate interests or for direct marketing purposes.
Where processing is based on consent, you may withdraw that consent at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, please contact us at [email protected]. We will respond to your request within 30 days. We may need to verify your identity before processing your request.
If we transfer personal data outside the European Economic Area, we ensure appropriate safeguards are in place to protect your data in accordance with GDPR requirements.
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law. Booking information is typically retained for 24 months after your last appointment.
We implement technical and organisational measures appropriate to the risk level, including encryption, access controls, and regular security assessments.
If you believe we have not handled your personal data appropriately, you have the right to lodge a complaint with a supervisory authority. In Australia, this is the Office of the Australian Information Commissioner (OAIC).
We may update this GDPR information from time to time. Material changes will be communicated through our website.