Privacy & data protection
Privacy Policy
Last updated: 7 August 2026
1. Privacy commitment and scope
This Privacy Policy explains how Snow Marrow Atelier Pty Ltd (we, us, our) collects, uses, holds, discloses and protects personal information when you visit our website, contact our team, make an enquiry, attend our venue, interact with our services or otherwise communicate with us. We aim to handle personal information in accordance with applicable Australian privacy requirements, including the Privacy Act 1988 (Cth) and the Australian Privacy Principles where they apply, and we also apply GDPR-style transparency and data-subject safeguards where European data protection law is applicable to a particular interaction.
This policy applies to information collected through this website and through associated customer-service interactions. It does not create rights that are unavailable under applicable law, and where a mandatory law imposes a higher standard, that higher standard prevails.
2. Privacy administrator and contact
Privacy administrator / business operator: Snow Marrow Atelier Pty Ltd
Registered and operating address: 14 Macaulay Road, Reservoir VIC 3073, Australia
Email: info@snowmarrowatelier.com
Phone: +61 3 9472 6815
Questions about privacy, requests to exercise privacy rights, or complaints may be sent to the contact details above. Email and telephone details are displayed as plain text and are not clickable links.
3. Personal information we may collect
Depending on how you interact with us, we may collect identifiers and contact details such as your name, email address, telephone number and correspondence details; enquiry and service information; records of communications; booking or event information that you choose to provide; feedback and complaint details; and technical information generated when you use the website.
Technical information may include IP address, browser and device type, operating system, approximate region derived from technical signals, referring page, requested pages, dates and times of access, language settings and diagnostic information. We seek to avoid collecting sensitive information unless it is reasonably necessary, lawful and voluntarily provided for a specific purpose, such as accessibility or dietary information relevant to an enquiry.
4. How we collect information
We may collect information directly from you when you contact us, submit an enquiry, communicate with staff, attend an event, provide feedback or otherwise choose to provide information. We may also collect limited technical information automatically through essential website functionality and server logs.
If another person provides information about you, we expect that person to have authority to do so and to make this Privacy Policy available to you where appropriate. We do not intentionally collect personal information from children through this website without appropriate involvement of a parent or guardian where required.
5. Purposes and lawful bases
We use personal information to respond to enquiries, provide requested information or services, manage customer relationships, maintain website security and functionality, administer our operations, improve service quality, comply with legal obligations, protect legitimate business interests, prevent misuse and resolve disputes.
Where the GDPR applies, processing may rely on one or more lawful bases: performance of a contract or steps requested before entering a contract; compliance with a legal obligation; our legitimate interests in operating, securing and improving our services where those interests are not overridden by your rights; protection of vital interests in exceptional circumstances; or your consent where consent is required. You may withdraw consent at any time for future processing where consent is the relevant basis.
6. Data minimisation and retention
We seek to collect only information reasonably necessary for the relevant purpose. We retain information only for as long as needed for the purposes described in this policy, to meet legal, accounting, tax, operational and record-keeping obligations, to resolve disputes and to enforce agreements. Retention periods vary according to the category of information, the nature of our relationship and applicable legal requirements.
When information is no longer required, we take reasonable steps to delete, destroy or de-identify it, subject to backup cycles, legal holds and technical limitations. De-identified information may be retained for analytical or operational purposes where it can no longer reasonably identify an individual.
7. Disclosure and service providers
We may disclose personal information to personnel who need it for their duties; professional advisers; IT, hosting, security and maintenance providers; payment or operational providers where relevant; insurers; regulators, courts and law-enforcement bodies where legally required; and a purchaser or successor in connection with a genuine business reorganisation, subject to appropriate confidentiality and legal safeguards.
We do not sell personal information. Service providers are expected to handle information only for authorised purposes and with appropriate confidentiality and security measures. Where a provider acts as an independent controller, its own privacy terms may also apply.
8. International transfers
Some service providers or technical infrastructure may process information outside Australia. Where personal information is transferred internationally and data protection law requires safeguards, we seek to use appropriate contractual, organisational or legal mechanisms designed to protect the information. For GDPR-regulated transfers, this may include an adequacy decision, standard contractual clauses or another permitted transfer mechanism.
You may contact us for further information about material international transfer safeguards applicable to your information, subject to legitimate confidentiality and security limitations.
9. Security
We use reasonable administrative, technical and physical measures designed to protect personal information against loss, misuse, interference, unauthorised access, alteration and disclosure. Measures may include access controls, least-privilege practices, secure configuration, software maintenance, monitoring, backups and staff procedures.
No system can be guaranteed completely secure. If a data incident occurs, we assess it promptly and take steps required by applicable law, which may include containment, remediation, notification to affected individuals and notification to relevant regulators.
10. Your privacy rights
Depending on applicable law and your circumstances, you may have rights to request access to personal information, correction of inaccurate or incomplete information, deletion in certain circumstances, restriction of processing, objection to certain processing, withdrawal of consent, data portability, and information about the processing of your data. Australian law also provides rights to seek access and correction subject to permitted exceptions.
We may need to verify your identity before acting on a request. Some rights are subject to legal exceptions, and we may retain information where required by law or where a lawful ground permits continued retention. We will explain a refusal where required.
11. Automated decision-making
We do not use this website to make decisions producing legal or similarly significant effects about individuals solely through automated processing. If that changes, we will provide the information and safeguards required by applicable law.
12. Cookies and local storage
Our website may use strictly necessary browser storage or similar technologies required for basic functionality and security. Any non-essential analytics, preference or marketing technology should be used only where legally permitted and, where required, after appropriate consent. Detailed information is provided in our Cookie Policy.
13. Third-party sites
This website may refer to third-party services or information, but we are not responsible for the privacy practices of independent third parties. You should review the privacy information of a third party before providing personal information to it. We have removed unnecessary external social links from this local website build so that the site itself does not depend on third-party resources.
14. Complaints
If you believe we have mishandled personal information, contact us first so we can investigate and respond. Please describe the issue and the outcome you seek. We aim to address complaints within a reasonable period. If you are not satisfied, you may have the right to complain to the Office of the Australian Information Commissioner or, where the GDPR applies, the competent data protection supervisory authority in your jurisdiction.
15. Changes to this policy
We may update this policy to reflect changes in law, technology or business practices. The revised version will be posted on this page with an updated date. Material changes may be highlighted where appropriate. Continued use of the website after an update does not override any consent requirement imposed by law.