Last updated: January 2024
This document outlines how Mellow-raven complies with the General Data Protection Regulation (GDPR) for users located in the European Economic Area (EEA).
Mellow-raven acts as the data controller for personal information collected through our website and services. Our contact details are:
Mellow-raven
42 Coastal Drive
Cape Town, 8001
South Africa
Email: [email protected]
We process your personal data under the following legal bases:
If you are a resident of the EEA, you have the following data protection rights:
Right of Access: You have the right to request copies of your personal data. We may charge a small fee for this service.
Right to Rectification: You have the right to request that we correct any information you believe is inaccurate or complete information you believe is incomplete.
Right to Erasure: You have the right to request that we erase your personal data, under certain conditions.
Right to Restrict Processing: You have the right to request that we restrict the processing of your personal data, under certain conditions.
Right to Object to Processing: You have the right to object to our processing of your personal data, under certain conditions.
Right to Data Portability: You have the right to request that we transfer the data that we have collected to another organisation, or directly to you, under certain conditions.
To exercise any of these rights, please contact us at [email protected]. We will respond to your request within one month. In certain circumstances, this period may be extended by two further months, in which case we will inform you of the extension and the reasons for it.
As our business is based in South Africa, your personal data may be transferred to and processed in a country outside the EEA. When we transfer your data outside the EEA, we ensure appropriate safeguards are in place to protect your personal data in accordance with GDPR requirements.
We retain personal data for as long as necessary to fulfil the purposes for which it was collected, including satisfying any legal, accounting, or reporting requirements. For booking enquiries that do not result in a purchase, we typically retain data for 24 months before deletion.
We do not use automated decision-making or profiling that produces legal effects concerning you or similarly significantly affects you.
Our services are not directed to individuals under the age of 16. We do not knowingly collect personal data from children under 16. If you become aware that a child has provided us with personal data, please contact us immediately.
For any questions regarding our data protection practices or to exercise your rights, please contact us at [email protected]
If you are located in the EEA and believe we have not adequately addressed your data protection concerns, you have the right to lodge a complaint with your local data protection supervisory authority.
We may update this GDPR compliance notice from time to time. Any changes will be posted on this page with an updated revision date.