Skip to content
English Chevron
Germany EUR Chevron

Privacy policy

Version 1.1 (July 2026)

This Privacy Policy explains how Green Loop Global Pty Ltd collects, holds, uses, discloses, transfers and protects Personal Information when you visit the Website, request a quotation, place an Order directly or through an authorised agentic-commerce service, receive Goods, or otherwise interact with us. It should be read with our Terms of Service and any collection notice presented when information is collected.

1. WHO WE ARE AND SCOPE

  1. Green Loop Global Pty Ltd (ABN 47 684 637 125), of Level 5, 447 Collins Street, Melbourne, Victoria 3000, Australia, is responsible for the Personal Information described in this Policy, except where another organisation states that it is independently responsible for its own processing.
  2. Our designated Privacy Officer is Bernard Stephens. Privacy enquiries and requests may be sent to info@greenloopglobal.com, by telephone on +61 411 485 757, or by post to the address above.
  3. This Policy applies to greenloopglobal.com, our Shopify store and checkout, authorised agentic-commerce interfaces and other electronic ordering channels operated or authorised by us. It does not govern a third-party website, AI service, marketplace, or payment service that processes information for its own purposes under its own privacy policy.
  4. We comply with the privacy and data-protection laws that apply to our activities and to the individuals with whom we deal. Country-specific provisions appear in the Schedules and prevail to the extent of any inconsistency.

2. DEFINITIONS

Applicable Privacy Laws means the privacy, data-protection, electronic-marketing and related laws applying to the relevant processing, including the Privacy Act 1988 (Cth) where it applies, applicable United States state privacy laws, Canadian federal and provincial private-sector privacy laws, the UK GDPR and Data Protection Act 2018, and the EU General Data Protection Regulation and applicable Dutch law.

Business Day means a day other than a Saturday, Sunday or public holiday in Melbourne, Victoria, Australia.

Customer means a person who requests a quotation, places or proposes to place an Order, receives Goods or otherwise deals with us as a customer or prospective customer.

Enhanced Services means Shopify services that use information from interactions with our store and, where enabled and permitted, interactions with Shopify and other Shopify merchants to provide features such as fraud protection, analytics, personalisation or advertising.

Goods means the products offered or supplied by us under our Terms of Service.

Order means an offer or accepted order for Goods as described in our Terms of Service.

Personal Information means information or an opinion relating to an identified or reasonably identifiable individual, and includes personal data and similar terms used in Applicable Privacy Laws.

Services means our Website, quotations, customer service, sales, manufacture coordination, delivery administration, warranty administration and related services.

Website means greenloopglobal.com and any checkout, agentic-commerce interface or ordering channel operated or authorised by us.

we, us and our means Green Loop Global Pty Ltd.

you and your means a Website visitor, prospective customer, Customer, recipient, business contact or other individual whose Personal Information we process.

3. PERSONAL INFORMATION WE COLLECT

Depending on how you interact with us, we may collect and hold the following categories of Personal Information:

  • Identity and contact information: name, title, company, postal, billing and delivery addresses, email address, telephone number and customer-account details.
  • Quotation, Order and commercial information: products viewed or selected, dimensions, finishes and specifications, quotation and Order history, transaction values, deposits and balances, delivery instructions, customs and tax information, warranty records, returns, complaints and product-safety communications.
  • Payment information: billing details, payment method, payment status, transaction identifier and limited card information made available by the payment provider, such as the card type and final digits. Shopify and our payment providers process full payment-card details; we do not ordinarily receive or store the complete card number or security code.
  • Communications and project information: enquiry, quotation and customer-service content; correspondence; chat messages; photographs, drawings and specifications; feedback; and information transmitted to us through an authorised shopping agent or AI service.
  • Device, usage and online activity: IP address, approximate location derived from IP, device and browser information, operating system, referring source, pages and products viewed, searches, clicks, cart activity, session identifiers, cookie identifiers and interactions with our Website and communications.
  • Marketing and preference information: marketing choices, cookie preferences, unsubscribe records, product interests and, where permitted, inferences about likely interests based on browsing or purchasing activity.
  • Security and fraud information: login and authentication data, risk indicators, suspected fraud, chargeback information, access logs and information required to protect customers, the Website and our business.
  • Business-contact information: professional role, employer, business contact details and procurement or project responsibilities.
  • Sensitive information: we do not seek health, biometric, racial or ethnic, religious, political or similarly sensitive information. Payment and account credentials may be treated as sensitive under some laws and are processed only as reasonably necessary for payment, authentication, security and legal compliance. Please do not provide other sensitive information unless we specifically request it and explain why it is required.

4. HOW WE COLLECT PERSONAL INFORMATION

We may collect Personal Information:

  • directly from you when you browse the Website, create an account, subscribe, request a quotation, place an Order, communicate with us, submit a claim or exercise a privacy right;
  • automatically through cookies, pixels, local storage, server logs and similar technologies;
  • from a person or service you authorise to act for you, including a purchasing agent, AI shopping assistant, marketplace, designer, architect, employer or project manager;
  • from Shopify, payment providers, fraud-prevention providers, freight carriers, customs brokers, delivery providers and other service providers involved in a transaction;
  • from referrals, publicly available business sources and professional directories where permitted by law; and
  • from third parties in connection with a dispute, legal claim, security incident or suspected unlawful activity.

If you provide Personal Information about another person, you must be authorised to do so and, where required, direct that person to this Policy.

5. HOW AND WHY WE USE PERSONAL INFORMATION

The table below summarises our principal purposes. The legal-basis column applies where Applicable Privacy Laws require a stated legal basis. More than one basis may apply, and a legal basis may change if reasonably necessary and permitted by law.

Purpose Typical information Why we need it Legal basis where required
Quotations, Orders and fulfilment Identity, contact, specifications, Order, payment and delivery data Provide quotations; accept and administer Orders; coordinate manufacturing, freight, customs, delivery, installation where agreed, returns and warranty support Contract and pre-contract steps; legal obligation
Payments, fraud and security Payment status, identifiers, device and risk data Process payments; authenticate users; prevent fraud, abuse, cyber incidents and chargebacks Contract; legal obligation; legitimate interests
Customer service and product safety Communications, Order, warranty, complaint and safety data Respond to enquiries; resolve issues; provide recalls, safety notices and corrective action Contract; legal obligation; legitimate interests
Website operation and improvement Device, usage, cookie and interaction data Operate, troubleshoot, secure, measure and improve the Website and customer experience Legitimate interests; consent where required for non-essential technologies
Marketing and personalisation Contact, preference, commercial and interaction data Send requested marketing; tailor content and measure campaigns; show relevant advertising where enabled Consent where required; otherwise legitimate interests as permitted by law
Legal, tax and corporate administration Transaction, identity, correspondence and compliance data Maintain records; comply with tax, customs and regulatory duties; establish or defend claims; obtain professional advice; support a corporate transaction Legal obligation; legitimate interests
Analytics and de-identified insights Usage, commercial and service data Understand demand, performance and trends; improve products and operations using aggregated or de-identified information Legitimate interests; consent where required

6. WHEN INFORMATION IS REQUIRED

  1. You may browse some parts of the Website without identifying yourself. You may also use a pseudonym when making a general enquiry where it is lawful and practicable to do so.
  2. We need specified identity, contact, payment, delivery and transaction information to provide a quotation, enter into or perform a contract, comply with tax or customs requirements, prevent fraud and deliver the Goods. If required information is not provided, we may be unable to process the request or Order.
  3. When information is optional, we will indicate this where reasonably practicable. Consent to optional marketing, analytics or advertising is not a condition of purchasing Goods.

7. SHOPIFY AND SHOPIFY NETWORK INTELLIGENCE

  1. Our store is hosted by Shopify. Shopify processes Personal Information to host and operate the store, provide checkout, payments, fraud prevention, analytics, customer-account and commerce services, and maintain the security and performance of its platform. Shopify may act as our service provider or processor for some activities and as an independently responsible organisation for its own consumer services.
  2. Shopify explains its independent processing in the Shopify Consumer Privacy Policy. Shopify privacy choices, including choices relating to advertising based on interactions with different merchants, may also be exercised through the Shopify Privacy Portal.
  3. Where Shopify Network Intelligence is enabled, Shopify may use information from interactions with our store together with information from interactions with Shopify and other Shopify merchants to provide Enhanced Services, including fraud protection, store performance, personalisation and advertising features. No other merchant is given direct access to our customer data.
  4. Where consent is required, Shopify Network Intelligence and non-essential Shopify technologies will be used only in accordance with the choices recorded through our cookie banner or an integrated consent tool. Where an applicable United States law provides an opt-out of sale, sharing or targeted advertising, eligible users may use the Your Privacy Choices link in the Website footer or a recognised Global Privacy Control signal.
  5. Shopify settings and services may change. We will review this Policy and our Website privacy controls when we enable, disable or materially change Shopify Network Intelligence, Shop Pay, Shop, pixels or other Shopify features.

8. AGENTIC COMMERCE AND AI CHANNELS

  1. Our product catalogue may be made discoverable through AI shopping channels, search services and authorised agentic-commerce interfaces. Product catalogue data is not Personal Information unless it is linked to an identifiable person.
  2. If you use an AI service or shopping agent, that provider may collect your prompts, account information, device data and interactions under its own privacy policy. We receive the enquiry, authority, Order and other information that the service transmits to us on your behalf.
  3. We use Personal Information received through an agentic channel for the same purposes as information received directly, including quotation, Order verification, payment, manufacture coordination, delivery, fraud prevention and customer service. We may seek direct confirmation before accepting an unusual, high-value or materially customised Order.
  4. We do not use customer Order or enquiry information to train a general-purpose AI model unless we first provide a specific notice and obtain any consent required by law. This does not prevent the use of limited automated tools for security, fraud detection, product discovery, customer-service support or operational analytics as described in this Policy.

9. COOKIES AND SIMILAR TECHNOLOGIES

  1. We and our partners, including Shopify, use cookies, pixels, local storage, tags and similar technologies. The technologies actually used and their current duration are described in our cookie banner or preference centre.
    1. Strictly necessary technologies enable core functions such as security, network management, cart, checkout, payment, account access and recording privacy choices. These generally cannot be disabled through our preference centre.
    2. Analytics technologies help us understand Website use, performance and conversion and improve the Services.
    3. Functional and personalisation technologies remember preferences and may tailor content or recommendations.
    4. Advertising technologies, where enabled, may measure campaigns or support advertising based on activity across services or merchants.
  2. In the United Kingdom, EEA and any other jurisdiction requiring prior consent, we will not activate non-essential cookies or similar technologies until valid consent is obtained. Consent can be changed or withdrawn through Cookie Preferences in the Website footer.
  3. Browser settings may block or delete cookies, but may not communicate all legally recognised choices. Eligible United States users may also use the Your Privacy Choices link and Global Privacy Control as described in clause 7(d).
  4. Third-party apps, custom pixels or integrations must be configured to respect applicable consent and opt-out choices. Their use may be governed by the provider’s own privacy policy.

10. DIRECT MARKETING

  1. We may send email, SMS or other direct marketing where you have consented or where another lawful basis permits it. We will identify ourselves and provide a practical method to opt out.
  2. You can unsubscribe using the link in a marketing message or by contacting the Privacy Officer. We may retain a minimal suppression record to ensure that the opt-out is respected.
  3. Opting out of marketing does not prevent transactional or service communications about an enquiry, Order, payment, delivery, warranty, safety issue or legal notice.

11. WHO WE DISCLOSE PERSONAL INFORMATION TO

We may disclose Personal Information to the following categories of recipients where reasonably necessary for the purposes in this Policy:

  • Shopify and providers of e-commerce hosting, checkout, customer accounts, payments, fraud prevention, analytics and Enhanced Services;
  • payment processors, banks, card networks and providers involved in deposits, final payments, refunds and chargebacks;
  • manufacturing, sourcing, quality-control and packaging partners in China, ordinarily limited to Order specifications, recipient and delivery information necessary to manufacture or fulfil the Order;
  • freight forwarders, carriers, customs brokers, importers of record, warehouses, installers and final-mile delivery providers;
  • providers of cloud hosting, security, email, communications, customer service, analytics, marketing, consent management and business software;
  • professional advisers, insurers, auditors, accountants and legal representatives;
  • regulators, courts, law-enforcement bodies and other persons where disclosure is required or authorised by law or reasonably necessary to protect rights, safety or security;
  • an actual or prospective buyer, investor, financier or adviser in connection with a merger, sale, restructuring, financing or transfer of all or part of our business, subject to appropriate confidentiality arrangements; and
  • another person at your direction or with your consent.

We do not sell Personal Information for monetary payment. Some disclosures made through Shopify Network Intelligence or advertising technologies may nevertheless be defined as sale, sharing or targeted advertising under particular United States state laws. Clause 7(d) and Schedule 2 explain the applicable choices.

12. INTERNATIONAL DISCLOSURES AND TRANSFERS

  1. We are based in Australia and operate internationally. Personal Information may be processed in Australia and in countries where our providers and commercial partners operate. Likely locations include Australia, Canada, the United States, the United Kingdom, countries in the EEA, and China, as well as the Customer’s delivery country.
  2. Overseas recipients may include Shopify and its affiliates, payment and technology providers, our manufacturing and quality-control partners in China, and logistics, customs and delivery providers in the destination country.
  3. Where the UK GDPR or EU GDPR applies, we use an applicable adequacy regulation or decision, approved standard contractual clauses, the United Kingdom International Data Transfer Agreement or Addendum, or another lawful safeguard. You may request information about the relevant safeguard from the Privacy Officer, subject to lawful redactions.
  4. Where Australian law applies to a cross-border disclosure, we take reasonable steps required by law in relation to the overseas recipient. Where Quebec law applies, we will conduct any required privacy impact assessment and put appropriate contractual measures in place before communicating Personal Information outside Quebec.
  5. No transfer mechanism can eliminate all risks arising from foreign laws or remote access. We assess providers and apply safeguards proportionate to the nature and sensitivity of the information.

13. RETENTION AND DELETION

We keep Personal Information only for as long as reasonably necessary for the purposes for which it was collected, to provide the Services, meet legal and accounting obligations, manage warranty and product-safety responsibilities, resolve disputes and enforce agreements. Our usual retention approach is:

Record category Usual retention approach
Orders, invoices, payments, tax and customs records Generally seven years after the end of the relevant financial or reporting period, or longer where required by law, audit, dispute or enforcement needs.
Warranty, complaint, repair, safety and recall records For the applicable warranty period and a reasonable period afterwards having regard to product life, limitation periods and safety or recall responsibilities; generally no longer than ten years unless a longer period is justified.
Quotations and enquiries that do not become Orders Generally two years after the last substantive interaction, unless the information remains relevant to an active project, consented marketing or a legal issue.
Website, fraud and security logs For the period reasonably required to secure the Website, investigate incidents, prevent fraud and comply with provider or legal requirements; ordinarily up to twelve months unless an incident or legal hold requires longer retention.
Marketing records Until consent is withdrawn, an objection is made or the information is no longer needed. A minimal suppression record may be retained to honour the opt-out.
Cookie and analytics data For the period stated in the cookie banner or preference centre and subject to the applicable consent or opt-out choice.

When retention is no longer justified, we take reasonable steps to delete, destroy or de-identify the information, subject to backup cycles and legal holds. De-identified or aggregated information that can no longer reasonably identify an individual may be retained and used for legitimate business purposes.

14. SECURITY AND DATA BREACHES

  1. We use technical and organisational measures appropriate to the nature of the information and the risks, including access controls, authentication, secure transmission, provider due diligence, contractual safeguards, monitoring, backup and incident-response measures where appropriate.
  2. Payment-card data is processed by Shopify and our payment providers. We do not ordinarily store complete payment-card numbers or card security codes.
  3. No system or method of transmission is completely secure. You should protect account credentials, use a unique password and notify us promptly of suspected unauthorised access.
  4. We assess suspected data breaches and notify affected individuals and regulators where required by Applicable Privacy Laws. We may also contact you with protective steps or service notices.

15. YOUR PRIVACY RIGHTS

  1. Depending on where you live and the law that applies, you may have rights to:

• request access to or a copy of your Personal Information;

• request correction of inaccurate or incomplete information;

• request deletion or erasure;

• restrict or object to processing, including direct marketing;

• withdraw consent without affecting earlier lawful processing;

• receive specified information in a portable format;

• opt out of sale, sharing, targeted advertising or specified profiling where applicable;

• request review of a decision based solely on automated processing where applicable;

• appeal a refusal where a law provides that right; and

• complain to us or to a competent regulator.

  1. To exercise a right, contact the Privacy Officer. Please identify the right and the information concerned. We may request information reasonably necessary to verify identity, authority and jurisdiction, and will use verification information only for that purpose.
  2. An authorised agent may submit a request where permitted by law. We may require evidence of authority and may also verify the request directly with you.
  3. Rights are subject to legal exceptions, including where information must be retained for tax, transaction, fraud-prevention, warranty, safety, legal-claim or other lawful purposes. We will explain a material refusal where required.
  4. We do not discriminate against a person for exercising a privacy right. We may be unable to provide a requested service where the relevant information is objectively necessary to provide it.

16. AUTOMATED DECISION-MAKING AND PROFILING

  1. We may use automated tools to identify fraud or security risk, measure Website activity, personalise content, route customer-service requests and assist with Order validation. Shopify, payment providers and fraud-prevention providers may also use automated risk tools.
  2. We do not currently make decisions based solely on automated processing that produce legal effects or similarly significant effects for an individual. A material adverse Order or account decision is subject to human review where required by law.
  3. If we introduce solely automated decision-making that could significantly affect rights or interests, we will update this Policy and provide the information and review rights required by Applicable Privacy Laws before or when the processing begins.

17. CHILDREN

  1. The Website and Goods are not directed to children, and an Order may be placed only by a person with legal capacity to contract or through an authorised adult or organisation.
  2. We do not knowingly collect Personal Information directly from a child under 16 for marketing or profiling. If you believe a child has provided information without valid authorisation, contact the Privacy Officer so that we can assess and delete it where appropriate.

18. THIRD-PARTY LINKS AND SERVICES

The Website may link to third-party sites, social networks, AI services, payment services or integrations. We do not control their independent privacy practices. Review the relevant third-party privacy policy before providing information. A link or integration does not make us responsible for the third party’s independent processing.

19. PRIVACY COMPLAINTS

  1. Please first send a written complaint to the Privacy Officer with sufficient details for us to investigate. We aim to acknowledge a complaint within five Business Days and to provide a substantive response within 30 days, although a complex matter may require longer. We will keep you informed of material delay.
  2. If you remain dissatisfied, you may complain to the regulator identified in the Schedule applying to you. The availability of a regulator or remedy depends on the law and jurisdiction concerned.

20. CHANGES TO THIS POLICY

  1. We may update this Policy to reflect changes in law, technology, Shopify settings, service providers or our information-handling practices. The current version and effective date will be published on the Website.
  2. If a change materially affects how we use information already collected, we will provide additional notice or obtain consent where required. Earlier versions will be retained for an appropriate period.

21. CONTACT DETAILS

Privacy Officer: Bernard Stephens

Email: info@greenloopglobal.com

Telephone: +61 411 485 757

Post: Green Loop Global Pty Ltd, Level 5, 447 Collins Street, Melbourne, Victoria 3000, Australia

COUNTRY-SPECIFIC PRIVACY SCHEDULES

The following provisions apply to individuals in the stated jurisdiction and supplement the general provisions.
They prevail to the extent of any inconsistency.

SCHEDULE 1 - AUSTRALIA

  1. Where the Privacy Act 1988 (Cth) applies, we handle Personal Information in accordance with the Australian Privacy Principles. This Policy also states our voluntary privacy practices where the small-business exemption or another exemption may apply.
  2. You may request access to and correction of Personal Information by contacting the Privacy Officer. We may refuse or limit a request only where permitted by law and will provide reasons where required.
  3. Where lawful and practicable, you may deal with us anonymously or using a pseudonym. Identification is generally required for quotations involving delivery, Orders, payments, customs, warranty claims and legal or fraud-prevention requirements.
  4. We are likely to disclose Personal Information to overseas recipients in Canada, the United States, the United Kingdom, the EEA and China, and may disclose it in the Customer’s destination country. Clause 12 describes the recipients and safeguards.
  5. After first raising a complaint with us and allowing a reasonable time for response, you may complain to the Office of the Australian Information Commissioner where it has jurisdiction.

SCHEDULE 2 - UNITED STATES

  1. This Schedule applies to the extent a United States state privacy law applies to us or we voluntarily extend the relevant right. Rights and definitions vary by state and may be subject to thresholds, exemptions and verification requirements.
  2. Depending on the applicable state law, you may have rights to know or access, correct, delete, obtain a portable copy, opt out of sale, sharing, targeted advertising or specified profiling, limit specified uses of sensitive Personal Information, appeal a refusal and receive equal service and pricing.
  3. We do not sell Personal Information for monetary consideration and do not offer a financial incentive for Personal Information. If Shopify Network Intelligence or advertising technologies are enabled, disclosures of identifiers, commercial information, device or usage activity and related inferences may be treated as sharing or targeted advertising. Eligible users can opt out through the Your Privacy Choices link in the Website footer. We honour a recognised Global Privacy Control signal where required.
  4. We do not knowingly sell or share Personal Information of individuals under 16. We do not use sensitive Personal Information to infer characteristics except where expressly disclosed and permitted by law.
  5. A request may be submitted by emailing bernie@greenloopglobal.com. Where an appeal right applies, state in the subject line that the request is a privacy appeal and explain why you believe the decision should be reconsidered.
  6. The following table summarises categories that we may have collected and disclosed for business purposes during the preceding 12 months. Actual collection depends on the interaction and enabled Website features.
US category Examples Business purposes Recipient categories
Identifiers and customer records Name, contact, account, IP, transaction and delivery identifiers Orders, customer service, security, legal compliance, marketing where permitted Shopify; payment, IT, manufacturing, logistics, professional and legal recipients
Commercial information Products viewed or purchased, quotations, Orders, warranty and transaction history Fulfilment, customer service, analytics, warranty, product safety and business administration Shopify; manufacturing, logistics, analytics, advisers and transaction participants
Internet or network activity Device, browser, search, page, cart, click, cookie and interaction data Website operation, security, analytics, personalisation and advertising where enabled Shopify; security, analytics, consent and advertising providers
Approximate geolocation General location inferred from IP and delivery location Market selection, fraud prevention, tax, delivery and analytics Shopify; security, payment and logistics providers
Communications and content Emails, chats, enquiries, photographs, drawings and support records Quotations, customer service, dispute and warranty administration Shopify; communications providers, manufacturers, advisers and service providers
Professional information Employer, role, business contact and project responsibilities B2B quotations, procurement, account and project administration Shopify; service providers, advisers and project participants
Inferences Likely product or content interests inferred from activity where enabled Personalisation, analytics and advertising subject to consent or opt-out Shopify and analytics or advertising providers where enabled
Sensitive Personal Information Account credentials and payment information processed through secure providers Authentication, payment, fraud prevention and security Shopify; payment and fraud-prevention providers

SCHEDULE 3 - CANADA, INCLUDING QUEBEC

  1. We apply the accountability, consent, purpose limitation, safeguards, openness, access and correction principles required by applicable Canadian federal and provincial private-sector privacy laws.
  2. Bernard Stephens is our designated Privacy Officer. You may request access to or correction of Personal Information, withdraw consent where processing depends on consent, or make a complaint by using the contact details in clause 21. Withdrawal does not affect earlier lawful processing and may prevent an optional service where the information is necessary for that service.
  3. Personal Information may be processed outside Canada, including in Australia, the United States, the United Kingdom, the EEA and China. While outside Canada, it may be subject to lawful access under the laws of the receiving jurisdiction.
  4. For Quebec residents:
    1. our Privacy Officer is the person in charge of the protection of Personal Information for customer-facing purposes. Green Loop Global must maintain any written delegation and internal governance documentation required by Quebec law;
    2. a French version of this Policy and material collection notices will be made available before or when Personal Information is collected through a Quebec-facing service;
    3. we will inform you where technology identifies, locates or profiles you and provide the applicable means to activate or control that function;
    4. if a decision is based exclusively on automated processing, we will provide the notice, explanation, correction and human-review opportunity required by law; and
    5. before communicating Personal Information outside Quebec, we will complete any required privacy impact assessment and contractual safeguards.
  5. A Canadian resident may complain to the Office of the Privacy Commissioner of Canada or an applicable provincial regulator. A Quebec resident may also contact the Commission d’accès à l’information du Québec.

SCHEDULE 4 - UNITED KINGDOM

  1. For processing subject to the UK GDPR, Green Loop Global Pty Ltd is the controller. The purposes and lawful bases are described in clause 5. Where we rely on legitimate interests, those interests include operating and securing our business, preventing fraud, administering customer relationships, improving the Services and establishing or defending legal claims, balanced against your rights and interests.
  2. You may have rights of access, rectification, erasure, restriction, data portability, objection, withdrawal of consent and protection against qualifying solely automated decisions. You have an absolute right to object to direct marketing.
  3. International transfers are handled as described in clause 12, including through UK adequacy regulations, the International Data Transfer Agreement, the UK Addendum to EU Standard Contractual Clauses or another lawful safeguard.
  4. We have not appointed a statutory data protection officer. The Privacy Officer is the contact for UK privacy matters, and we will appoint a data protection officer if our activities require one under applicable law.
  5. You may complain to the UK Information Commissioner’s Office. You may contact the ICO without first complaining to us, although it generally assists if we have had an opportunity to respond.

SCHEDULE 5 - NETHERLANDS AND EEA

  1. For processing subject to the EU GDPR, Green Loop Global Pty Ltd is the controller. The purposes and legal bases are described in clause 5. Where we rely on legitimate interests, those interests include operating and securing our business, preventing fraud, administering customer relationships, improving the Services and establishing or defending legal claims, balanced against your rights and interests.
  2. You may have rights of access, rectification, erasure, restriction, data portability, objection, withdrawal of consent and protection against qualifying solely automated decisions. You have an absolute right to object to direct marketing.
  3. International transfers are handled as described in clause 12, including through an EU adequacy decision, EU Standard Contractual Clauses or another safeguard permitted by Chapter V of the EU GDPR.
  4. We have not appointed a statutory data protection officer. The Privacy Officer is the contact for EEA privacy matters, and we will appoint a data protection officer if our activities require one under applicable law.
  5. A person in the Netherlands may complain to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) or another competent EEA supervisory authority.
  6. If the Website, checkout or customer communications are offered in Dutch, we will make this Policy and material collection notices available in Dutch or otherwise ensure that the information is concise, transparent, intelligible and readily accessible to the intended audience.