Privacy Policy
This policy describes how Opal Ivory Leon handles personal information under Australian privacy law and, where applicable, the GDPR.
Effective date: 3 August 2026
1. About this Privacy Policy
This Privacy Policy explains how Opal Ivory Leon Pty Ltd (we, us or our) collects, holds, uses, discloses, secures and otherwise handles personal information when you visit this website, make an enquiry, request a consultation, attend our workshop or otherwise interact with us.
We seek to handle personal information consistently with the Privacy Act 1988 (Cth), the Australian Privacy Principles and, where applicable to individuals located in the European Economic Area or United Kingdom, the General Data Protection Regulation and corresponding local data-protection laws.
2. Privacy administrator and contact details
Opal Ivory Leon Pty Ltd is the controller or responsible organisation for personal information handled through this website and our customer-enquiry activities. Our registered office and primary contact details are shown below.
Legal entity: Opal Ivory Leon Pty Ltd
Registered office: 7 Heather Street, Windsor, QLD 4030, Australia
ABN: 83 174 296 531
ACN: 672 918 364
Email: info@opalivoryleon-au.com
Phone: +61 7 3184 5297
3. Meaning of personal information
Personal information is information or an opinion about an identified individual, or an individual who is reasonably identifiable. Depending on the circumstances, this can include contact details, communications, appointment information, purchase or service history, preferences and technical information associated with the use of this website.
We do not intentionally request sensitive information through the website. Please avoid including health information, government identifiers, financial account credentials or other sensitive details in free-text enquiry fields unless they are genuinely necessary and you have considered the risks.
4. Information we may collect
We may collect your name, email address, telephone number, postal or workshop-visit details, enquiry category, jewellery preferences, ring-size or design information, appointment requests, correspondence and any information you choose to include in a message.
When the website is served through a web server, limited technical records may also be generated, such as an Internet Protocol address, browser type, operating system, referring page, requested pages, date and time, and diagnostic or security logs. The local version of this website is designed without third-party analytics, advertising pixels, remote fonts, embedded social feeds or external map requests.
5. How information is collected
We collect information directly from you when you complete a form, contact us, request a quotation, book a consultation, provide design requirements, visit the workshop or correspond with us. We may also receive information from an authorised representative acting for you.
Where technically necessary, a web server may collect routine connection and security logs automatically. Browser storage may be used only for essential interface preferences or to retain a locally saved enquiry in the browser, as explained in the Cookie Policy.
6. Purposes of processing and use
We use personal information to respond to enquiries, arrange consultations, prepare design discussions or quotations, provide requested services, manage customer relationships, deliver aftercare, address warranty or repair matters, keep appropriate business records, maintain website security and comply with legal obligations.
We may also use information to improve our service, investigate errors, prevent misuse, establish or defend legal claims, and communicate operational information that is relevant to an existing enquiry or customer relationship.
7. Legal bases under the GDPR
Where the GDPR applies, we process personal data when it is necessary to take steps at your request before entering into a contract, to perform a contract, to comply with a legal obligation, for our legitimate interests where those interests are not overridden by your rights, or on the basis of consent where consent is specifically requested.
Legitimate interests may include responding to genuine enquiries, protecting the security and integrity of our systems, maintaining business records, preventing fraud, improving customer service and establishing or defending legal rights. You may object to processing based on legitimate interests in the circumstances described below.
8. Direct marketing
We do not send direct marketing merely because you visited this website. If you separately choose to receive promotional communications, we will provide a practical method to withdraw consent or unsubscribe. Withdrawal does not affect processing that occurred lawfully before the withdrawal.
We will not sell your personal information to third-party advertisers or permit unrelated businesses to use your information for their own direct marketing without an appropriate legal basis.
9. Disclosure of personal information
We may disclose personal information to personnel and contractors who need it to perform their duties, professional advisers, insurers, secure technology or hosting providers, payment or delivery providers where relevant to a transaction, and government or regulatory bodies when required or authorised by law.
We require service providers to handle information only for authorised purposes and with appropriate confidentiality and security safeguards. This local website build does not make automatic requests to external social networks, font providers, analytics services or advertising platforms.
10. Overseas disclosures and international transfers
Some service providers used in ordinary business operations may store or process information outside Australia. Before making an international transfer, we consider the nature of the information, the destination, contractual safeguards and applicable legal requirements.
Where the GDPR applies to a restricted transfer, we seek to use an approved transfer mechanism or another lawful basis, together with supplementary safeguards where appropriate. Contact us for information about the safeguards relevant to a particular transfer.
11. Retention
We retain personal information only for as long as reasonably necessary for the purpose for which it was collected, to complete an enquiry or service, maintain appropriate transaction and warranty records, meet tax, accounting, consumer-law or other legal obligations, resolve disputes and enforce agreements.
Retention periods vary according to the nature of the record. When information is no longer required, we take reasonable steps to delete, destroy or de-identify it, subject to backup cycles and lawful recordkeeping requirements.
12. Security
We use reasonable administrative, physical and technical measures designed to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. Measures may include access controls, least-privilege practices, secure configuration, backups, staff confidentiality obligations and incident-response procedures.
No method of storage or transmission is completely secure. You should not send highly confidential information through a general website enquiry form. If you suspect unauthorised use of your information, contact us promptly.
13. Data breaches
We assess suspected data incidents and take steps to contain, investigate and remediate them. Where the Notifiable Data Breaches scheme applies and an eligible data breach is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner as required.
Where another applicable law requires notification to a supervisory authority or affected individuals, we will follow the relevant notification and documentation obligations.
14. Access and correction
You may request access to personal information we hold about you and ask us to correct information that is inaccurate, out of date, incomplete, irrelevant or misleading. We may need to verify your identity before responding.
In limited circumstances the law permits or requires us to refuse access or correction. If that occurs, we will generally provide written reasons and information about available complaint mechanisms, unless the law allows otherwise.
15. Additional rights for EEA and UK individuals
Where applicable, you may have rights to be informed, obtain access, request rectification or erasure, restrict processing, object to certain processing, receive portable data and withdraw consent. You may also have rights relating to decisions based solely on automated processing. We do not use this website to make decisions producing legal or similarly significant effects solely by automated means.
Rights are subject to conditions and exceptions in applicable law. We may ask for information necessary to verify identity and clarify the scope of a request. You may lodge a complaint with the supervisory authority in the country where you live or work.
16. Anonymity and pseudonymity
Where lawful and practicable, you may make a general enquiry without identifying yourself or by using a pseudonym. We may need accurate identifying and contact information when it is necessary to provide a personalised consultation, prepare a quotation, perform a contract, verify ownership for aftercare or comply with law.
17. Children
This website and our jewellery services are directed to adults. We do not knowingly collect personal information from children through the website without appropriate involvement of a parent or guardian. A parent or guardian who believes a child has provided information should contact us so we can assess and, where appropriate, delete it.
18. Third-party websites
This local website build does not embed third-party social feeds or remote maps. If you later follow a link to a website operated by another organisation, that organisation controls its own privacy practices. Review its privacy information before providing personal data.
19. Complaints
If you have a privacy concern, contact us with sufficient detail for us to investigate. We aim to acknowledge complaints promptly and provide a substantive response within a reasonable period, taking into account complexity and legal requirements.
If you are not satisfied with our response, you may be able to complain to the Office of the Australian Information Commissioner or, where applicable, a European or UK data-protection supervisory authority.
20. Changes to this policy
We may update this Privacy Policy to reflect changes in law, technology, services or information-handling practices. The revised version will be published on this page with an updated effective date. Material changes will be highlighted where reasonably practicable.