Privacy & Security
HARLI + HARPA (“we”, “us”, “our”) takes your privacy seriously and works to ensure your
personal data is protected at all times. This policy explains how we collect,
use, store, and share your information when you use our website or services and
sets out what your rights are in relation to that data.
We are the data controller in respect of your personal data under applicable data protection laws, including the UK General Data Protection Regulation (UK GDPR) and EU General Data Protection Regulation (EU GDPR) where applicable.
We have appointed a Data Protection Officer (DPO) who is responsible for overseeing questions about this policy. If you have any questions, please contact the DPO using the details in Section 17.
HARLI + HARPA is an Australian-based business. All personal data we collect is stored and hosted in Australia. We do not store personal data in the United Kingdom or the European Economic Area (EEA).
Where personal data is collected from UK or EEA residents, it is transferred internationally to Australia. We ensure appropriate safeguards are in place for these transfers, including:
• Standard Contractual Clauses (SCCs) incorporating the UK Addendum (for UK transfers via the International Data Transfer Agreement / IDTA)
• Standard Contractual Clauses (SCCs) for EU transfers
• Data processing agreements with all third-party providers
• Transfer risk assessments where required
Certain business operations or personnel may be based in or operate from the United Kingdom. Any access to personal data from outside Australia is strictly
controlled and limited to authorised purposes only, with appropriate
contractual and technical safeguards in place.
By using our services, you acknowledge that your personal data will be transferred to and stored in Australia, which may have different data protection laws than your country of residence. If you would like more information about the safeguards we use, please contact us at hello@harliandharpa.com.
Depending on
how you interact with us, we may collect and process the following categories
of personal data:
Identity & Contact Data
• Full name
• Email address
• Telephone number
• Billing and shipping address
Financial & Transaction Data
• Payment information (processed securely by third-party providers — we do not store your full card details)
• Purchase and order history
Technical Data
• IP address
• Browser type and version
• Device identifiers and operating system
• Time zone and location data
Profile & Usage Data
• Account details and preferences
• Purchase behaviour and browsing activity on our site
• Marketing preferences
Communication Data
• Customer service enquiries
• Feedback, reviews, and general correspondence
We do not knowingly collect special category (sensitive) personal data unless explicitly required and with your prior consent.
We collect personal data through:
• Direct interactions — when you create an account, make a purchase, or get in touch with us
• Automated technologies — cookies, analytics tools, and server logs as you browse our site
(please see our Cookies section below)
• Third parties — payment providers, analytics platforms, and advertising partners may share data with us
• Data aggregators — Identity and contact data from aggregators based inside or outside the UK
We may use cookies and similar technologies (we will refer to all of these as “Cookies”) to enable you to use certain features on our website, store your preferences, recognise you when you return to our website and maintain information about your use of our website. Cookies are small files that are saved on your device with the help of your internet browser.
Specifically, we use the following Cookies (unless other Cookies are specified elsewhere in this policy or on our website):
- Session Cookies: These Cookies are required to save certain technical data during your visit to our website, e.g. to determine whether you have logged in.
- Log in Cookies: These Cookies are required to save your login over a session if you want to.
The following points only apply to users in the EU and the UK:
- The legal basis for the use of these Cookies is Sec 25 para 2 no 2 German Telecommunications and Telemedia Data Protection Act (TTDSG) and Art 6 para 1 lit f) GDPR, insofar as these Cookies are essentially necessary for the us to provide you with our website content.
- For all other (non-essential) Cookies we will only use these Cookies based upon your consent. If we use Cookies based upon your consent, you can withdraw your consent at any time with effect for the future by adjusting your Cookie settings. Alternatively, you can change your settings at any time. You will find the link in the footer of the website. Your withdrawal does not affect the lawfulness of the processing carried out up to the point.
We may send you
marketing emails and other communications if you have opted in or were
permitted under applicable law. You can unsubscribe at any time by clicking the
unsubscribe link in any of our emails or by contacting us directly at
hello@harliandharpa.com.
We will never sell your personal data to third parties for their own marketing purposes.
Subject to your prior express consent, we may share your personal data with trusted third-party partners who may send you marketing communications about their products and
services.
We may share your data with trusted third parties who provide services on our behalf, including:
• Payment processors and financial institutions (such as Stripe or similar providers)
• Shipping and logistics providers
• Cloud hosting and IT infrastructure providers
• Marketing and analytics platforms
• Professional
advisers including legal, accounting, and auditing firms
• Regulatory or law enforcement authorities where required by law
All third parties are contractually bound to protect your personal data and are only
permitted to process it for the specific purposes we have authorised.
Because all personal data collected by HARLI + HARPA is stored in Australia, any data collected from UK or EEA residents involves an international transfer.
Australia does not currently have a formal UK or EU adequacy decision, so we
rely on the following mechanisms to ensure your data remains protected:
• International
Data Transfer Agreement (IDTA) and Standard Contractual Clauses (SCCs) with UK Addendum for UK transfers
• Standard Contractual Clauses (SCCs) for EU transfers
•Data
processing agreements with all relevant third-party processors
• Transfer impact assessments where required
No personal data is stored in the UK or EEA unless explicitly stated otherwise.
We take the security of your personal data seriously and implement robust technical and organisational measures to protect it, including:
• SSL/TLS encryption for all data in transit
• Secure server infrastructure hosted in Australia
• Role-based access controls and authentication measures
• Regular security monitoring and vulnerability assessments
• PCI-DSS compliant payment processing
No system is completely immune to risk, but we continuously review and improve our safeguards to keep your data as secure as possible.
We only keep your personal data for as long as necessary to fulfil the purposes it was collected for, including to meet legal, regulatory, accounting, or reporting
requirements, and to resolve disputes or enforce our agreements.
Retention periods are determined based on the type of data and the applicable legal
requirements. For example, financial and transaction records are typically
retained for seven years in line with standard accounting obligations.
If you are located in the UK or EEA, you have the following rights in relation to your personal data:
• Right of access — to request a copy of the data we hold about you
• Right to rectification — to ask us to correct inaccurate or incomplete data
• Right to erasure — to request that we delete your data in certain circumstances
• Right to restrict processing — to ask us to limit how we use your data
• Right to object — to object to processing based on legitimate interests
• Right to data portability — to receive your data in a structured, commonly used
format
• Right to withdraw consent — at any time, where processing is based on consent
To exercise any of these rights, please contact us at hello@harliandharpa.com. We will respond to your request within 30 days.
You also have the right to lodge a complaint with the Information Commissioner’s Office
(ICO), the UK supervisory authority for data protection, at any time. You can
reach them at www.ico.org.uk. We would, however, appreciate the chance to
address any concerns you have directly first — so please do contact us in the
first instance.
If you are based in the EEA, you have the right to complain to your local data protection supervisory authority.
Our website and services are not intended for anyone under the age of 16. We do not knowingly collect personal data from children. If you are under 16, please do not use our services without first speaking to a parent or guardian and obtaining their
agreement to this policy.
If we become aware that we have collected personal data from a child without appropriate consent, we will take steps to delete it as soon as possible.
If you have any questions about this policy or how we handle your personal data, please get in touch:
HARLI + HARPA
Email: hello@harliandharpa.com
Address: 11 Hall Street, Hawthorn, Victoria, Australia
In the event of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data, HARLI + HARPA will assess the risk to your rights and freedoms and if appropriate report this breach to the relevant authorities.
16.1 RIGHT TO ACCESS
You have the right to request information on the Personal Data that HARLI + HARPA holds about you. You are entitled to know what Personal Data we are processing, why we have processed it, and whether we have shared your Personal Data. You may exercise your right to request access and to obtain copies of any Personal Data we have collected from you, and request that your Personal Data be provided to you in a format that can be easily read.
You can contact our Privacy Officer using the contact details in the contact section of this Privacy Policy and we will provide you with your Personal Data via e-mail.
We will respond to all requests for access to Personal Data within a reasonable time. We may require you to verify your identity before we can release your Personal Data. On the rare occasions when we refuse access, we will provide you with a written notice stating our reasons for refusing access. Where permitted by law, we may seek to recover from you reasonable costs incurred for providing you with access to any of the Personal Data we hold about you.
16.2 RIGHT TO RECTIFICATION
You have the right to ask us to rectify information you think is inaccurate. You also have the right to ask us to complete information you think is incomplete by contacting our Privacy Officer.
We will respond to all requests for correction of Personal Data within a reasonable time. We are not obliged to correct any Personal Data if we do it does not agree that it requires correction. If we refuse a correction request, we will provide you with a written notice stating our reasons for refusing.
If you are dissatisfied with HARLI + HARPA’s refusal of a correction request, you may make a complaint to the relevant regulatory authority, including the Office of the Australian Information Commissioner.
16.3 RIGHT TO OBJECT
To the extent the GDPR applies, you have the right to object to the processing of your Personal Data that is done based upon Art 6 para 1 lit e) or f) GDPR (Art 6 para 1 lit f) GDPR, being HARLI + HARPA’s legitimate interests. In response to a valid objection, HARLI + HARPA will not continue to process the Personal Data unless we can demonstrate a legitimate ground which overrides your interest and rights, or due to legal claims.
You also have the right to object to direct marketing. You can opt out from HARLI + HARPA direct marketing by following the instructions contained in each marketing e-mail. After your objection, we will stop the processing.
16.4 RIGHT TO RESTRICTION
To the extent the GDPR applies and in limited circumstances, you have the right to request that HARLI + HARPA restricts the processing of your Personal Data. These circumstances include:
- If you object to a processing based on HARLI + HARPA’s legitimate interest, in which case HARLI + HARPA shall restrict all processing the data pending the verification of the legitimate interest;
- If your Personal Data is incorrect, in which case HARLI + HARPA will restrict the processing of your data pending verification of the accuracy of your Personal Data;
- If the processing is unlawful, in which case you can request restriction of your Personal Data as opposed to deletion; and
- If HARLI + HARPA no longer requires your Personal Data but it is required by you to defend legal claims.
We process the Personal Data you provide HARLI + HARPA when making use of your aforementioned rights for the purpose enabling these rights and to be able to provide proof thereof. This processing is based on the legal basis of Art 6 para 1 lit c) GDPR in conjunction with Art 15 - 22 GDPR and Section 34 para 2 German Federal Data Protection Act (“BDSG”).
16.5 RIGHT TO DATA PORTABILITY
To the extent the GDPR applies, you have the right to ask that we transfer the information you gave us from one organisation to another or give it to you. The right only applies to information you have given us and only applies if we are processing information based on your consent or under or in talks about entering into a contract and the processing is automated
16.6 RIGHT TO LODGE A COMPLAINT
You have a right to make a complaint if you are unhappy with how your Personal Data has been treated under this privacy policy. Such complaints should be sent to the HARLI + HARPA Privacy Officer at admin@harliandharpa.com. Please provide as much detail as possible about your complaint so we can review and consider it appropriately. At all times, privacy complaints:
- will be treated seriously;
- will be dealt with promptly;
- will be dealt with in a confidential manner; and
- will not affect your existing obligations or affect the commercial arrangements between you and HARLI + HARPA.
We will seek to resolve your complaint within [30] days of receipt, unless we inform you otherwise and seek your agreement in writing. We may request additional information so that we can investigate your complaint appropriately.
On receipt of your complaint, our Privacy Officer will commence an investigation, and you will be informed of the outcome following completion of the investigation. In the event that you are dissatisfied with the outcome of your complaint, or an extension to the time in which HARLI + HARPA will resolve it, you may refer the complaint to the Office of the Australian Information Commissioner (www.oaic.gov.au) or other relevant privacy regulator in your region.
If you didn't find an answer to your query, please Contact Us - Our DPO officer is Liam Houlder
We aim to respond to all queries in up to 48 hours.
