GDPR Compliance
Last updated: August 2026
Our Commitment to GDPR
storm-tale respects the privacy rights of individuals in the European Union and European Economic Area. We are committed to complying with the General Data Protection Regulation (GDPR) when processing personal data of EU/EEA residents.
Data Controller
storm-tale acts as the data controller for personal information collected through this website. Our contact details are:
Email: [email protected]
Address: 47 Craft Lane, Woodstock, Cape Town, 7925, South Africa
Legal Basis for Processing
We process personal data under the following legal bases:
- Consent: When you submit forms or opt into communications
- Contract: When processing is necessary to provide services you have requested
- Legitimate Interests: For improving our services and website functionality, where this does not override your rights
- Legal Obligation: When we must comply with applicable laws
Your Rights Under GDPR
If you are located in the EU/EEA, you have the following rights regarding your personal data:
Right of Access: You may request a copy of the personal data we hold about you.
Right to Rectification: You may request that we correct any inaccurate or incomplete personal data.
Right to Erasure: You may request that we delete your personal data in certain circumstances.
Right to Restrict Processing: You may request that we limit how we use your data in certain circumstances.
Right to Data Portability: You may request to receive your data in a structured, machine-readable format.
Right to Object: You may object to processing based on legitimate interests or for direct marketing purposes.
Right to Withdraw Consent: Where processing is based on consent, you may withdraw that consent at any time.
Exercising Your Rights
To exercise any of these rights, please contact us at [email protected]. We will respond to your request within 30 days. We may need to verify your identity before processing your request.
International Data Transfers
As we are based in South Africa, data transferred to us from the EU/EEA involves international transfer. We ensure appropriate safeguards are in place, including standard contractual clauses where applicable.
Data Retention
We retain personal data only for as long as necessary for the purposes for which it was collected. Specific retention periods depend on the nature of the data and the purpose of processing.
Automated Decision-Making
We do not engage in automated decision-making or profiling that produces legal or similarly significant effects on individuals.
Supervisory Authority
If you are located in the EU/EEA and believe we have not adequately addressed your concerns, you have the right to lodge a complaint with your local data protection supervisory authority.
Updates to This Notice
We may update this GDPR notice periodically. Any changes will be posted on this page with an updated revision date.