Last updated: August 13, 2026
We are committed to protecting the privacy and security of your personal data in accordance with the General Data Protection Regulation (GDPR) and applicable data protection laws.
We process personal data under the following legal bases:
For the purposes of GDPR, the data controller is:
leaf-martin
142 Garden Route Boulevard
Wilderness, Western Cape
South Africa, 6560
Email: [email protected]
As a data subject, you have the following rights:
You have the right to request copies of your personal data. We may charge a reasonable fee if your request is clearly unfounded, repetitive, or excessive.
You have the right to request correction of any information you believe is inaccurate or completion of information you believe is incomplete.
You have the right to request erasure of your personal data under certain conditions, including when the data is no longer necessary for the purposes for which it was collected.
You have the right to request restriction of processing your personal data under certain conditions.
You have the right to object to our processing of your personal data under certain conditions.
You have the right to request transfer of your data to another organization or directly to you under certain conditions.
Where we rely on consent as the legal basis for processing, you have the right to withdraw that consent at any time.
To exercise any of these rights, please contact us at [email protected]. We will respond to your request within one month of receipt. If your request is complex or we have received multiple requests from you, we may extend this period by two further months, and we will inform you if this is the case.
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected or to comply with legal requirements. When data is no longer needed, we securely delete or anonymize it.
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
As we operate in South Africa, your data may be processed outside the European Economic Area. When this occurs, we ensure appropriate safeguards are in place to protect your data in accordance with GDPR requirements.
In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR.
We do not use automated decision-making or profiling that produces legal effects or similarly significantly affects you.
If you believe we have not handled your data in accordance with GDPR, you have the right to lodge a complaint with your local supervisory authority. However, we encourage you to contact us first so we can address your concerns directly.
We may update this GDPR compliance statement periodically to reflect changes in our practices or legal requirements. The "Last updated" date at the top indicates when the most recent changes were made.