Last Updated: July 2026
While amethyst-orchard operates primarily in South Africa, we recognize that some of our customers may be residents of the European Union or European Economic Area. This document outlines our compliance with the General Data Protection Regulation and how we protect the personal data of EU residents.
We process personal data under the following legal bases:
We collect and process the following categories of personal data:
If you are an EU resident, you have the following rights regarding your personal data:
You have the right to request copies of your personal data. We may charge a reasonable fee if your request is clearly unfounded or excessive.
You have the right to request correction of any inaccurate or incomplete personal data we hold about you.
You have the right to request deletion of your personal data in certain circumstances, such as when the data is no longer necessary for the purposes it was collected, or when you withdraw consent.
You have the right to request restriction of processing your personal data in specific situations, such as when you contest the accuracy of the data.
You have the right to request transfer of your personal data to another organization or directly to you in a structured, commonly used, and machine-readable format.
You have the right to object to processing of your personal data where we rely on legitimate interest as the legal basis, or for direct marketing purposes.
We do not use automated decision-making or profiling that produces legal effects or significantly affects you.
To exercise any of your GDPR rights, please contact us at [email protected] with the subject line "GDPR Request". We will respond to your request within one month, though this may be extended by two additional months for complex requests.
You will need to provide sufficient information to verify your identity before we can process your request.
Your personal data is stored and processed in South Africa. If data is transferred to third parties outside the EU/EEA, we ensure appropriate safeguards are in place, such as standard contractual clauses approved by the European Commission.
We retain personal data only for as long as necessary to fulfill the purposes outlined in our Privacy Policy and to comply with legal obligations. Specific retention periods include:
We implement appropriate technical and organizational measures to protect your personal data against unauthorized or unlawful processing, accidental loss, destruction, or damage. These measures include:
In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the relevant supervisory authority within 72 hours of becoming aware of the breach, in accordance with GDPR requirements.
We work with trusted third-party service providers who process personal data on our behalf. These processors are contractually obligated to implement appropriate security measures and process data only according to our instructions.
We use cookies and similar tracking technologies on our website. You can manage your cookie preferences through our cookie banner or browser settings. For detailed information, please see our Cookies Policy.
Our services are not intended for individuals under 18 years of age. We do not knowingly collect or process personal data of children. If we become aware that we have collected data from a child, we will delete it immediately.
If you are an EU resident and believe we have not handled your personal data appropriately, you have the right to lodge a complaint with your local data protection supervisory authority.
We may update this GDPR compliance statement to reflect changes in our practices or legal requirements. Material changes will be communicated through our website and, where appropriate, via email.
For questions about our GDPR compliance or to exercise your data protection rights:
Email: [email protected]
Address: 142 Long Street, Cape Town, Western Cape, 8001, South Africa