GDPR Compliance Statement
Last updated: May 10, 2026
Our Commitment to Data Protection
mystic-expenses is committed to protecting the personal data of all individuals, including visitors from the European Economic Area (EEA), in accordance with the General Data Protection Regulation (GDPR).
Legal Basis for Processing
We process personal data based on the following legal grounds:
- Consent: You have given explicit consent for processing your personal data for specific purposes
- Contract performance: Processing is necessary for performing our services to you
- Legal obligation: Processing is required to comply with legal requirements
- Legitimate interests: Processing is necessary for our legitimate business interests, provided these don't override your rights
Your GDPR Rights
Under GDPR, you have the following rights regarding your personal data:
Right to Access
You have the right to request copies of your personal data. We may charge a reasonable fee for multiple copies or manifestly unfounded requests.
Right to Rectification
You have the right to request correction of inaccurate or incomplete personal data we hold about you.
Right to Erasure
You have the right to request deletion of your personal data under certain circumstances, including when:
- The data is no longer necessary for the purpose it was collected
- You withdraw consent and there's no other legal basis for processing
- You object to processing and there are no overriding legitimate grounds
- The data has been unlawfully processed
Right to Restrict Processing
You have the right to request restriction of processing your personal data in specific situations, such as when you contest the accuracy of the data.
Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, and machine-readable format and transmit it to another controller.
Right to Object
You have the right to object to processing of your personal data based on legitimate interests or for direct marketing purposes.
Rights Related to Automated Decision-Making
You have the right not to be subject to decisions based solely on automated processing, including profiling, which produces legal effects concerning you. We do not currently use automated decision-making processes.
Data Controller Information
mystic-expenses is the data controller responsible for your personal data.
Contact details:
Email: [email protected]
Address: Level 12, 180 Lonsdale Street, Melbourne VIC 3000, Australia
Data Processing Activities
What Data We Collect
- Contact information (name, email)
- Business information provided for service delivery
- Technical data (IP address, browser type, usage data)
- Communication records
Purpose of Processing
- Providing financial management services
- Responding to inquiries
- Improving our website and services
- Compliance with legal obligations
Data Retention
We retain personal data only for as long as necessary to fulfill the purposes outlined in our Privacy Policy or as required by law. Specific retention periods depend on:
- The nature of the data
- Legal and regulatory requirements
- Our legitimate business needs
International Data Transfers
Your data is primarily processed and stored in Australia. If we transfer data outside the EEA, we ensure appropriate safeguards are in place, such as:
- Standard contractual clauses approved by the European Commission
- Adequacy decisions for specific countries
- Other legally approved transfer mechanisms
Data Security
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- Encryption of data in transit and at rest
- Regular security assessments
- Access controls and authentication measures
- Staff training on data protection
Data Breach Notification
In the event of a data breach that poses a risk to your rights and freedoms, we will notify you and the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR.
Third-Party Processing
We only engage third-party processors who provide sufficient guarantees of GDPR compliance. All processors are bound by data processing agreements that comply with Article 28 of the GDPR.
Consent Management
Where we rely on consent as the legal basis for processing, you have the right to withdraw consent at any time. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
Exercising Your Rights
To exercise any of your GDPR rights, please contact us at [email protected]. We will respond to your request within one month, or inform you if we require an extension.
Complaints
You have the right to lodge a complaint with a supervisory authority, particularly in the EU member state of your habitual residence, place of work, or place of alleged infringement.
Updates to This Statement
We may update this GDPR compliance statement periodically. Significant changes will be communicated through our website and, where appropriate, directly to you.