Introduction
Murano Animals respects your privacy and is committed to handling personal information fairly, lawfully, transparently and securely.
This Privacy Policy explains how Murano Animals collects, holds, uses, discloses, transfers, protects and deletes personal information in connection with:
- exclusivedropshq.com;
- customer accounts;
- limited product drops;
- leaderboards and participation features;
- purchases and payments;
- product production, fulfilment and delivery;
- customer support;
- marketing communications;
- cookies and similar technologies;
- fraud prevention and website security; and
- other services provided by Murano Animals.
It also explains the privacy rights that may be available to you and how to contact us about a privacy or security concern.
References to “Murano Animals”, “we”, “us” or “our” mean the organisation identified below.
Organisation responsible for your information
The organisation responsible for the personal information described in this Privacy Policy is:
Murano Animals ABN: 96 220 324 478 Morphett Vale, South Australia 5162 Australia
Website: exclusivedropshq.com
Where applicable, Murano Animals is the data controller, responsible organisation or business that determines why and how personal information is processed.
Some third parties involved in payments, delivery, legal compliance or other independently regulated activities may also process limited information as independent controllers under their own privacy notices.
Contact details
3.1 Privacy enquiries and rights requests
For access requests, correction requests, deletion requests, consent withdrawals, privacy complaints or questions about this Privacy Policy, contact:
Email: edhqprivacy@exclusivedrops.com Recommended subject line: Privacy Request
3.2 Security concerns
To report suspected unauthorised access, phishing, impersonation, a vulnerability, possible data exposure or another security concern, contact:
Email: edhqsecurity@exclusivedrops.com Recommended subject line: Security Report
Do not include passwords, full payment-card numbers, card security codes or unnecessary sensitive information in your initial report.
3.3 General customer support
For order enquiries, delivery assistance, returns, refunds, product questions or general account assistance, contact:
Email: edhqsupport@exclusivedrops.com
General customer-service enquiries should not be sent to the privacy or security addresses unless the matter specifically concerns privacy or information security.
Scope of this Privacy Policy
This Privacy Policy applies when you:
- visit exclusivedropshq.com;
- create, access or manage an account;
- participate in a product drop;
- use a leaderboard or participation feature;
- place or attempt to place an order;
- receive a product or delivery;
- subscribe to marketing communications;
- change your privacy or cookie settings;
- contact customer support;
- submit a privacy request;
- report a security concern; or
- otherwise interact with Murano Animals.
Depending on your location and the circumstances, our activities may be subject to:
- the Australian Privacy Act 1988 and Australian Privacy Principles;
- the European Union General Data Protection Regulation;
- the United Kingdom General Data Protection Regulation;
- the UK Data Protection Act 2018;
- applicable electronic-marketing and cookie laws; and
- other privacy or consumer-protection laws.
References to particular rights or legal requirements apply only where the relevant law applies to Murano Animals and the processing concerned.
We nevertheless aim to apply reasonable privacy standards consistently to all customers.
Meaning of personal information
“Personal information” means information or an opinion about an identified individual or an individual who is reasonably identifiable.
Where European or United Kingdom data-protection law applies, this also includes “personal data”, meaning information relating to an identified or identifiable natural person.
Information that has been effectively anonymised so that an individual can no longer reasonably be identified is not generally treated as personal information.
Personal information we collect
The information we collect depends on how you interact with us.
6.1 Identity and contact information
We may collect:
- first and last name;
- username or display name;
- email address;
- telephone number;
- billing address;
- delivery address;
- country or region;
- communication preferences;
- social-media username where relevant; and
- other contact details you choose to provide.
6.2 Account and authentication information
When you create or use an account, we may collect:
- account identifier;
- email address;
- username or display name;
- securely hashed or encrypted authentication credentials;
- account creation date;
- account status;
- login dates and times;
- login attempts;
- password-reset activity;
- authentication tokens;
- session information;
- account preferences;
- privacy and consent choices; and
- security events associated with the account.
Passwords are not intended to be stored in readable plain-text form.
6.3 Order and transaction information
When you place or attempt to place an order, we may collect:
- products selected or purchased;
- product variations;
- quantity;
- price;
- discounts or promotional codes;
- order number;
- order date;
- order status;
- billing information;
- delivery information;
- delivery instructions;
- shipping method;
- tracking information;
- tax information;
- payment status;
- refund or replacement information;
- return information;
- chargeback or dispute information; and
- communications relating to the transaction.
6.4 Payment information
Payments are processed through third-party ecommerce, payment and financial-service providers made available during checkout.
Murano Animals does not ordinarily receive or store:
- complete payment-card numbers;
- card security codes;
- online-banking passwords; or
- complete payment-account credentials.
We may receive limited payment-related information, such as:
- payment status;
- payment method type;
- transaction reference;
- billing address;
- refund status;
- fraud or risk indicators;
- chargeback information; and
- limited card information, such as the final digits, where supplied by the payment provider.
The relevant payment provider may be identified during checkout and may process information under its own privacy notice and legal obligations.
6.5 Product-drop information
When you register for or participate in a limited product drop, we may collect:
- registration status;
- customer or member status;
- eligibility information;
- product reservations;
- purchase history relevant to product limits;
- purchase attempts;
- quantities obtained;
- drop participation history;
- account milestones; and
- information required to administer limited product availability.
6.6 Leaderboard and participation information
Where a leaderboard or participation feature is offered, we may collect:
- display name;
- points;
- ranking;
- achievements;
- qualifying activities;
- participation status;
- account milestones; and
- related activity history.
We will not intentionally publish your private contact, payment, billing or delivery information through a leaderboard.
6.7 Customer-support information
When you contact us, we may collect:
- your name and contact details;
- the content of your message;
- account or order references;
- information about the issue;
- photographs or files you provide;
- requested outcomes;
- customer-service notes;
- records of our response; and
- information required to verify your identity.
6.8 Privacy and security correspondence
When you submit a privacy request or security report, we may collect:
- your identity and contact information;
- the details of the request or report;
- relevant account, transaction or device information;
- verification information;
- supporting documents;
- investigation notes;
- correspondence;
- actions taken; and
- the final outcome.
6.9 Marketing and consent information
We may collect:
- whether you subscribed to marketing;
- the date and time of consent;
- the method by which consent was provided;
- the wording or notice presented at the time;
- communication preferences;
- campaign delivery information;
- email interaction information where permitted;
- unsubscribe requests;
- withdrawn consent;
- cookie choices; and
- records demonstrating that your choices were respected.
6.10 Device and technical information
When you use our website, we or our authorised service providers may collect:
- Internet Protocol address;
- approximate region derived from an IP address;
- browser type and version;
- device type;
- operating system;
- language;
- referral source;
- pages and features viewed;
- dates and times of access;
- session duration;
- session identifiers;
- error messages;
- performance information;
- security events;
- login attempts;
- cookie identifiers; and
- server and application logs.
Approximate region information is not intended to identify your exact physical address.
6.11 Cookie and similar-technology information
We may collect information through:
- browser cookies;
- local storage;
- session storage;
- pixels;
- tags;
- scripts;
- embedded technologies; and
- similar technologies.
More information is provided in Section 15.
6.12 Social-media information
If you communicate with Murano Animals through a social-media service, we may receive:
- your public profile name;
- username;
- profile image;
- the content of your message or comment;
- public interactions;
- group or page activity; and
- other information you choose to share.
Your use of the social-media platform is also governed by the platform’s own privacy practices.
6.13 Sensitive information
Murano Animals does not intentionally request sensitive personal information such as information concerning:
- health or medical conditions;
- race or ethnicity;
- religious or philosophical beliefs;
- political opinions;
- trade-union membership;
- sexual orientation;
- genetic information;
- biometric identifiers; or
- criminal history.
Please do not provide sensitive information unless it is genuinely necessary and we have specifically requested it.
If sensitive information is provided without being requested, we will only use or retain it where legally permitted and reasonably necessary. Otherwise, we may delete or de-identify it.
How we collect personal information
7.1 Directly from you
We may collect information directly when you:
- create or update an account;
- complete a form;
- register for a product drop;
- use a website feature;
- place an order;
- provide billing or delivery details;
- subscribe to marketing;
- change cookie preferences;
- contact customer support;
- make a privacy request;
- report a security concern; or
- otherwise provide information to us.
7.2 Automatically
Information may be collected automatically through:
- website requests;
- authentication systems;
- application and server logs;
- security controls;
- fraud-prevention systems;
- cookies;
- browser storage;
- email-delivery systems; and
- website-performance technologies.
Non-essential technologies are handled according to the cookie-consent requirements described in Section 15.
7.3 From service providers
We may receive information from third parties involved in:
- website and application hosting;
- database services;
- account authentication;
- ecommerce;
- payment processing;
- fraud prevention;
- email delivery;
- product production;
- order fulfilment;
- delivery;
- returns; and
- customer support.
7.4 From production, fulfilment and delivery partners
Organisations involved in producing or delivering an order may provide:
- production status;
- fulfilment status;
- tracking numbers;
- delivery events;
- failed-delivery information;
- address corrections;
- customs information;
- return-to-sender information; and
- returned-parcel details.
7.5 From public sources
In limited circumstances, we may collect information from publicly available sources where reasonably necessary to:
- investigate suspected fraud;
- respond to a security incident;
- verify a business or delivery issue;
- address misuse of the website;
- protect customers; or
- protect our legal rights.
Why we use personal information
We use personal information for the purposes described below.
Where the EU GDPR or UK GDPR applies, the table also identifies the lawful basis we normally rely upon.
| Purpose | Information normally used | Lawful basis where applicable |
|---|---|---|
| Creating and managing accounts | Identity, contact, authentication and account information | Contractual necessity or steps requested before entering into a contract |
| Authenticating users | Account, login and security information | Contractual necessity and legitimate interests |
| Processing password resets | Email, account and authentication information | Contractual necessity and legitimate interests |
| Operating product drops | Account, participation, eligibility and order information | Contractual necessity and legitimate interests |
| Enforcing product limits | Account, order, transaction and technical information | Contractual necessity and legitimate interests |
| Operating participation features | Display name, points, activities and ranking | Providing the requested service and legitimate interests |
| Processing orders | Identity, contact, order, billing and delivery information | Contractual necessity |
| Processing payments and refunds | Billing, transaction and payment-status information | Contractual necessity and legal obligations |
| Producing and fulfilling products | Product, order, identity and delivery information | Contractual necessity |
| Delivering orders | Identity, delivery, contact and tracking information | Contractual necessity |
| Providing customer support | Contact, account, order and communication information | Contractual necessity and legitimate interests |
| Sending account and order communications | Contact, account and order information | Contractual necessity |
| Preventing fraud and abuse | Account, transaction, device, network and security information | Legitimate interests and legal obligations |
| Protecting accounts and systems | Authentication, device, network and security information | Legitimate interests and legal obligations |
| Investigating security incidents | Account, technical, communication and security information | Legititimate interests, legal obligations and legal claims |
| Maintaining financial and tax records | Order, billing, transaction and refund information | Legal obligations |
| Handling disputes and chargebacks | Account, order, transaction and communication information | Legitimate interests and legal claims |
| Responding to lawful requests | Information reasonably required by the request | Legal obligations and legitimate interests |
| Sending marketing communications | Contact and marketing-preference information | Consent or another permission expressly allowed by law |
| Operating optional analytics | Cookie, device and usage information | Consent where required by law |
| Remembering optional preferences | Cookie and preference information | Consent where required by law |
| Improving website usability | Feedback and limited usage information | Legitimate interests or consent, depending on the technology |
| Managing privacy requests | Identity, contact and verification information | Legal obligations |
| Maintaining consent records | Contact, cookie and consent information | Legal obligations and legitimate interests |
| Enforcing terms and protecting legal rights | Account, order, transaction and communication information | Legitimate interests and legal claims |
Our legitimate interests may include:
- providing a secure and reliable service;
- administering limited product drops;
- preventing fraud and misuse;
- providing effective customer support;
- improving website performance;
- keeping appropriate records;
- protecting customers;
- protecting our systems; and
- establishing, exercising or defending legal rights.
Before relying on legitimate interests, we consider whether the processing is necessary and whether our interests are overridden by your rights and interests.
Information required to provide services
Some information is necessary to provide the service you request.
For example:
- an email address may be required to create and secure an account;
- delivery information is required to send a physical product;
- billing and payment information is required to process a purchase;
- order details may be required to provide support;
- verification information may be required before personal information is released; and
- technical information may be required to maintain website and account security.
If required information is not provided, we may be unable to:
- create an account;
- authenticate you;
- process an order;
- accept a payment;
- fulfil or deliver an order;
- investigate an account issue; or
- complete a privacy request.
Marketing consent and acceptance of non-essential cookies are optional.
Accounts and authentication
You are responsible for keeping your account credentials confidential and using a strong, unique password.
We may:
- record security-related login activity;
- limit repeated login attempts;
- require additional verification;
- require a password reset;
- end active sessions;
- temporarily restrict account access;
- suspend an account where misuse is suspected; or
- take other reasonable steps to protect accounts and customers.
If you believe your account has been accessed without permission:
- change your password immediately where possible;
- change the password on any other service where you reused it; and
- contact edhqsecurity@exclusivedrops.com.
Orders, payments and refunds
11.1 Order processing
We use order information to:
- confirm a purchase;
- enforce product limits;
- process payment;
- arrange product production;
- fulfil the order;
- arrange delivery;
- provide tracking;
- process returns, refunds or replacements;
- prevent fraud;
- comply with legal and accounting obligations; and
- resolve disputes.
11.2 Payment processing
Payments are processed by authorised ecommerce, payment and financial-service providers.
The relevant payment service may be identified during checkout.
Murano Animals does not ordinarily store complete payment-card information. Payment providers are responsible for applying their own payment-security, fraud-prevention, regulatory and privacy controls.
11.3 Fraud prevention
Payment and ecommerce providers may process:
- billing information;
- transaction information;
- IP addresses;
- device information;
- payment history;
- account information; and
- risk indicators
to identify suspected fraud, account misuse or unauthorised transactions.
An order may be delayed, reviewed, restricted or cancelled where fraud or misuse is reasonably suspected.
11.4 Refunds, disputes and chargebacks
Where a refund, dispute or chargeback occurs, relevant information may be shared with:
- ecommerce providers;
- payment processors;
- financial institutions;
- insurers;
- professional advisers; and
- dispute-resolution organisations.
Only information reasonably necessary to investigate and resolve the matter will be disclosed.
Product production, fulfilment and delivery
We use contracted production, fulfilment, logistics and delivery providers to complete physical orders.
Information shared for these purposes may include:
- customer name;
- delivery address;
- email address where operationally required;
- telephone number where required by a carrier;
- product ordered;
- product variation;
- quantity;
- order reference;
- shipping method; and
- delivery instructions.
The relevant provider may use production facilities, fulfilment centres, subprocessors, postal services or delivery carriers to complete the order.
Delivery information may also be disclosed to:
- postal operators;
- couriers;
- freight providers;
- logistics companies;
- customs brokers;
- customs authorities;
- border authorities; and
- tax authorities.
For international orders, legally required information may appear on shipping, tax or customs documents.
We cannot prevent information from being disclosed to delivery or government authorities where that disclosure is required to complete the delivery or comply with law.
Email and other communications
13.1 Essential communications
We may send messages necessary to provide or secure a service, including:
- account verification;
- password resets;
- login and security notices;
- product-drop administration;
- order confirmations;
- payment notifications;
- refund notifications;
- production updates;
- shipping and tracking updates;
- delivery issues;
- account changes;
- privacy-request communications;
- security notices; and
- customer-support responses.
These messages are not marketing communications.
You generally cannot opt out of an essential message while continuing to use the related service.
13.2 Marketing communications
We may send marketing communications where:
- you have provided valid consent;
- the communication is otherwise legally permitted; or
- applicable law permits the communication within an existing customer relationship.
Marketing communications may include:
- product-drop announcements;
- advance release information;
- product availability;
- newsletters;
- promotional offers;
- community announcements; and
- related Murano Animals news.
Where consent is relied upon:
- participation will be optional;
- consent will not be assumed from silence;
- marketing choices will not be preselected;
- consent will be separated from general terms where required;
- consent records will be maintained; and
- withdrawal will be made reasonably easy.
13.3 Unsubscribing
Marketing emails will provide an unsubscribe method.
You may also withdraw marketing consent by contacting:
edhqprivacy@exclusivedrops.com
Unsubscribing from marketing does not stop essential account, order, delivery, privacy or security messages.
13.4 Suppression records
After you unsubscribe, we may retain limited information on a suppression list, including:
- your email address;
- unsubscribe status;
- date of withdrawal; and
- source of the request.
This is necessary to ensure that your choice continues to be respected.
Leaderboards and public features
Some website features may display limited participation information publicly or to other registered users.
Depending on the feature, this may include:
- display name;
- points;
- ranking;
- achievement;
- participation status; or
- limited qualifying activity.
We will not intentionally display through these features:
- your email address;
- telephone number;
- billing address;
- delivery address;
- payment information;
- password; or
- private customer-support correspondence.
You should choose a display name that does not reveal unnecessary personal information.
Where a feature is optional, information about participation and visibility will be provided through the relevant interface.
When we disclose personal information
We disclose personal information only where reasonably necessary for the purposes described in this Privacy Policy, where you instruct us to do so, or where disclosure is authorised or required by law.
We describe recipients by category rather than publishing a complete list of commercial suppliers and technical providers.
Recipient categories may include:
16.1 Website and infrastructure providers
Providers supporting:
- website hosting;
- server infrastructure;
- network availability;
- content delivery;
- database hosting;
- data storage;
- backups;
- logging;
- monitoring; and
- technical security.
16.2 Authentication and account-service providers
Providers supporting:
- account registration;
- authentication;
- password resets;
- session management;
- identity verification; and
- account security.
16.3 Ecommerce and payment providers
Providers supporting:
- storefront functions;
- shopping carts;
- checkout;
- payment processing;
- refunds;
- order administration;
- taxation;
- fraud prevention; and
- payment disputes.
The relevant payment provider may be identified at checkout.
16.4 Production and fulfilment providers
Providers supporting:
- product production;
- printing or manufacturing;
- order fulfilment;
- packaging;
- dispatch;
- tracking; and
- fulfilment-related support.
16.5 Delivery and logistics providers
Recipients may include:
- postal services;
- couriers;
- freight providers;
- customs brokers;
- delivery networks;
- logistics companies; and
- parcel-tracking services.
16.6 Communications providers
Providers supporting:
- transactional email;
- account-verification messages;
- password-reset messages;
- order notifications;
- security communications;
- customer-support email; and
- authorised marketing communications.
16.7 Security and fraud-prevention providers
Providers supporting:
- network security;
- account protection;
- abuse prevention;
- fraud detection;
- incident investigation;
- vulnerability management; and
- service monitoring.
16.8 Professional advisers
Information may be disclosed to:
- lawyers;
- accountants;
- auditors;
- insurers;
- cybersecurity specialists;
- tax advisers; and
- other professional advisers
where reasonably necessary and subject to professional or contractual duties.
16.9 Government and legal recipients
Information may be disclosed to:
- courts;
- regulators;
- tax authorities;
- customs authorities;
- border authorities;
- law-enforcement agencies; and
- other legally authorised bodies
where required or permitted by law.
We may also disclose information where reasonably necessary to:
- respond to valid legal process;
- investigate suspected fraud;
- protect a person from serious harm;
- investigate a security incident;
- enforce an agreement; or
- establish, exercise or defend legal rights.
16.10 Business transfers
If all or part of Murano Animals is sold, reorganised, financed, merged, transferred or wound down, personal information may be disclosed to:
- prospective purchasers;
- actual purchasers;
- financiers;
- professional advisers; and
- successor organisations.
Any recipient must handle personal information consistently with applicable privacy law.
Information about particular providers
We do not publish a complete list of suppliers, subprocessors, infrastructure providers or commercial partners in this Privacy Policy.
This is because:
- service arrangements may change;
- not every provider handles personal information;
- publishing detailed infrastructure relationships may create commercial or security risks; and
- applicable privacy laws generally permit recipients to be described by category.
Where legally required or reasonably necessary, information about a particular recipient may be:
- displayed at the point where you interact with that provider;
- shown during checkout;
- included in a cookie-preference tool;
- included in a transaction or delivery notice;
- provided in response to a valid privacy request; or
- provided to a regulator or supervisory authority.
A request for information about recipients may be sent to:
edhqprivacy@exclusivedrops.com
We may withhold confidential commercial or security information where the law permits, while still providing the information required for you to understand how your personal information is handled.
Service-provider protections
Where another organisation processes personal information on our behalf, we seek to maintain appropriate contractual and organisational protections.
Depending on the service and applicable law, these may include:
- data-processing terms;
- confidentiality obligations;
- limitations on permitted processing;
- security requirements;
- breach-notification obligations;
- subprocessor controls;
- assistance with privacy requests;
- deletion or return requirements;
- assurance or audit provisions; and
- international-transfer safeguards.
Service providers acting on our instructions are not authorised by Murano Animals to use customer information for unrelated marketing.
A third party may independently process limited information where it acts as a separate controller and applicable law permits that processing.
Selling or sharing personal information
Murano Animals does not sell personal information in exchange for money.
We do not authorise processors acting on our behalf to sell customer information or use it for unrelated advertising.
Some privacy laws define “sale” or “sharing” more broadly and may include certain advertising, analytics or cross-context tracking arrangements.
Where an activity is legally classified as a sale, sharing or targeted-advertising activity, we will provide any consent, opt-out or browser-signal controls required by applicable law.
International transfers
Murano Animals is based in Australia and uses service providers and commercial arrangements that may operate internationally.
Personal information may be:
- stored outside your country;
- accessed by authorised personnel outside your country;
- transferred through international technical infrastructure;
- sent to a production or fulfilment location in another country;
- processed through international payment networks; or
- disclosed to a carrier or customs authority in connection with an international delivery.
Depending on the service and transaction, personal information may be processed in:
- Australia;
- the United States;
- the United Kingdom;
- Switzerland;
- countries in the European Economic Area;
- countries where hosting or technical infrastructure is located;
- countries where production or fulfilment facilities operate;
- countries where authorised subprocessors operate; and
- the destination country of an international order.
The exact country may depend on the product, customer location, payment method, delivery destination and service architecture.
Privacy protections may differ between countries.
Where required by applicable law, international transfers are supported by measures such as:
- adequacy decisions;
- approved standard contractual clauses;
- approved United Kingdom transfer arrangements;
- binding corporate rules;
- recognised privacy frameworks;
- processor contractual obligations;
- transfer-risk assessments;
- encryption;
- access controls; and
- other legally approved safeguards.
For Australian personal information, we take reasonable steps where required to ensure overseas recipients handle information consistently with applicable Australian privacy requirements.
You may contact edhqprivacy@exclusivedrops.com for further information about safeguards relevant to your personal information.
Retention of personal information
We keep personal information only for as long as reasonably necessary for:
- the purpose for which it was collected;
- another legally permitted purpose;
- fulfilling an order;
- tax and accounting requirements;
- fraud prevention;
- dispute resolution;
- security investigations;
- legal claims;
- regulatory requirements; or
- enforcing your privacy choices.
Our general retention schedule is:
| Information | General retention period |
|---|---|
| Active account information | While the account remains active |
| Closed or inactive account information | Usually up to 24 months after closure or last meaningful activity |
| Order, transaction, tax and accounting records | For the period required by applicable tax, accounting and business-record laws |
| Fulfilment and shipping records | Usually retained with the associated order record |
| Customer-support records | Usually up to 24 months after the matter is resolved |
| Refund, complaint, chargeback and dispute records | Until resolution and for the applicable legal limitation period |
| Marketing subscription information | Until consent is withdrawn or the information is no longer required |
| Marketing suppression records | For as long as reasonably necessary to continue respecting the opt-out |
| Cookie-consent records | Usually up to three years after the relevant consent or preference event |
| Routine security and access logs | Usually up to 12 months |
| Confirmed security-incident records | For as long as required to investigate, remedy and meet legal obligations |
| Incomplete registrations | Usually up to 90 days |
| Abandoned transaction information | Usually up to 90 days unless needed for fraud prevention or legal purposes |
| Privacy-request records | Usually up to three years after the request is completed |
| Information subject to a legal hold | Until the hold, investigation, claim or proceeding ends |
These periods are general guidelines. A shorter or longer period may apply depending on:
- the nature of the information;
- legal requirements;
- an active dispute;
- fraud risk;
- security requirements;
- an unresolved order; or
- a valid deletion request.
When information is no longer required, we will take reasonable steps to:
- delete it;
- securely destroy it; or
- de-identify it.
Deleted information may remain temporarily in protected backups until it is overwritten or removed under the relevant backup cycle.
Backup information is not intended to be restored to active use except where necessary for disaster recovery, system integrity or legal compliance.
We may retain aggregated or anonymised information where it can no longer reasonably identify an individual.
Information security
We use technical and organisational safeguards intended to protect personal information against:
- misuse;
- interference;
- loss;
- unauthorised access;
- unauthorised disclosure;
- alteration; and
- destruction.
Our safeguards may include:
- encrypted transmission;
- secure password handling;
- multifactor authentication for privileged access;
- role-based access controls;
- least-privilege access;
- database access restrictions;
- secure hosting;
- network protections;
- logging and monitoring;
- software updates;
- vulnerability remediation;
- protected backups;
- data minimisation;
- service-provider due diligence;
- confidentiality requirements;
- incident-response procedures; and
- access reviews.
Access to customer information is limited to authorised persons who require it for a legitimate operational purpose.
We do not publicly disclose detailed infrastructure diagrams, credentials, internal security configurations, vulnerability information or other information that could weaken our security.
No website, internet transmission or electronic-storage system can be guaranteed to be completely secure.
You should:
- use a strong and unique password;
- protect access to your email account;
- log out of shared devices;
- avoid sending sensitive information through unsecured channels; and
- report suspicious activity promptly.
Personal-data breaches
Murano Animals maintains a documented data-breach response and escalation process.
Where a suspected breach occurs, we will take reasonable steps to:
- identify and contain the incident;
- protect affected systems and accounts;
- investigate what occurred;
- determine what information was involved;
- identify affected individuals where possible;
- assess the likelihood and seriousness of harm;
- preserve relevant evidence;
- involve relevant service providers;
- notify regulators where required;
- notify affected individuals where required;
- remedy identified weaknesses; and
- document the incident and response.
23.1 Australian notification
Where the Australian Notifiable Data Breaches scheme applies, we will notify the Office of the Australian Information Commissioner and affected individuals where an eligible data breach is likely to result in serious harm and no applicable exception applies.
23.2 European and United Kingdom notification
Where the EU GDPR or UK GDPR applies, we will notify the appropriate supervisory authority without undue delay and, where required, within 72 hours after becoming aware of a reportable personal-data breach.
Where a breach is likely to result in a high risk to affected individuals, we will notify those individuals without undue delay unless a legal exception applies.
23.3 Breach notifications
Where legally required and reasonably available, a notification may explain:
- the nature of the incident;
- categories of information involved;
- possible consequences;
- actions we have taken;
- steps you should consider;
- how to contact us; and
- where to obtain further assistance.
To report a suspected security incident, contact:
Your privacy rights
The rights available to you depend on your location, the law that applies and the circumstances of the processing.
Subject to applicable exceptions, you may have the following rights.
24.1 Access
You may request:
- confirmation that we process personal information about you;
- access to that information; and
- information about how it is processed.
24.2 Correction
You may request correction of information that is:
- inaccurate;
- incomplete;
- out of date; or
- misleading.
Some account information may be corrected through your account settings.
24.3 Deletion
You may request deletion of personal information.
Deletion is not an absolute right. We may retain information where reasonably necessary to:
- complete an order;
- comply with tax or accounting obligations;
- prevent fraud;
- maintain a marketing suppression record;
- resolve a dispute;
- protect account or system security;
- investigate an incident;
- establish, exercise or defend a legal claim;
- respond to a regulator; or
- comply with another legal obligation.
24.4 Restriction
Where applicable, you may request that processing be restricted while:
- accuracy is reviewed;
- an objection is considered;
- the lawfulness of processing is reviewed; or
- information is required for a legal claim.
24.5 Data portability
Where applicable, you may request information you provided to us in a structured, commonly used and machine-readable format.
Where legally required and technically feasible, you may also request transmission to another controller.
24.6 Objection
Where we rely on legitimate interests, you may object to processing based on your particular circumstances.
We will consider the objection and stop the processing unless:
- compelling legitimate grounds override your interests and rights; or
- processing is required for a legal claim.
You may object to direct marketing at any time.
24.7 Withdrawal of consent
Where processing relies on consent, you may withdraw consent at any time.
Withdrawal does not affect processing that lawfully occurred before consent was withdrawn.
24.8 Automated decision-making
You may have rights concerning decisions based solely on automated processing that produce legal or similarly significant effects.
Murano Animals does not currently use solely automated processing to make decisions that produce legal or similarly significant effects about customers.
Automated systems may assist with:
- account security;
- fraud-risk indicators;
- product limits;
- stock availability;
- product-drop administration;
- account verification; and
- leaderboard calculations.
These operational functions do not ordinarily produce a legal or similarly significant effect by themselves.
24.9 Privacy complaints
You may complain about how we handle personal information.
Send complaints to:
edhqprivacy@exclusivedrops.com
Include:
- your name;
- contact information;
- a description of the concern;
- any relevant order or account reference;
- relevant dates; and
- the outcome you are seeking.
We aim to acknowledge a privacy complaint within seven business days and provide a substantive response within 30 days.
Complex matters may require additional time. Where reasonably possible, we will explain any delay.
Exercising your rights
Send a privacy request to:
edhqprivacy@exclusivedrops.com
Use the subject line:
Privacy Request
Please identify:
- the right you wish to exercise;
- the relevant account or email address;
- any relevant order number; and
- enough information for us to locate the relevant records.
25.1 Identity verification
Before releasing, correcting or deleting information, we may take reasonable steps to verify your identity.
Verification may include:
- confirming access to the registered email address;
- confirming an order reference;
- confirming limited account details; or
- requesting another proportionate form of identification.
Do not send identity documents unless we specifically request them.
We will not request more verification information than is reasonably necessary.
25.2 Authorised representatives
An authorised representative may submit a request where permitted by law.
We may request:
- evidence of the representative’s authority;
- confirmation directly from the individual; and
- identity verification.
25.3 Response times
Where the EU GDPR or UK GDPR applies, we will generally respond within one month, subject to any legally permitted extension.
Under other laws, we will respond within the legally required period or within a reasonable time.
25.4 Fees and excessive requests
Privacy requests are normally handled without charge.
Where legally permitted, we may charge a reasonable fee or refuse to act where a request is:
- manifestly unfounded;
- excessive;
- repetitive; or
- intended to interfere unreasonably with our operations.
We will explain a refusal where legally required.
25.5 No unlawful discrimination
We will not unlawfully discriminate against you because you exercised a privacy right.
Australian privacy rights
Where the Australian Privacy Act applies, you may:
- request access to personal information we hold about you;
- request correction of inaccurate, incomplete, out-of-date or misleading information;
- complain about a suspected breach of applicable Australian privacy requirements; and
- ask how your complaint will be investigated.
If you are dissatisfied with our response, you may be entitled to complain to the Office of the Australian Information Commissioner.
European Economic Area and United Kingdom rights
Where the EU GDPR or UK GDPR applies, you may have rights to:
- receive privacy information;
- access personal data;
- correct personal data;
- request erasure;
- restrict processing;
- receive portable data;
- object to legitimate-interest processing;
- object to direct marketing;
- withdraw consent;
- challenge qualifying automated decisions; and
- complain to a supervisory authority.
You may lodge a complaint with a supervisory authority in:
- the country where you live;
- the country where you work; or
- the country where you believe an infringement occurred.
Individuals in the United Kingdom may complain to the UK Information Commissioner’s Office.
27.1 EEA and UK representatives
Murano Animals is established in Australia.
At the effective date of this Privacy Policy, Murano Animals has not appointed a formal representative in the European Economic Area or United Kingdom because its relevant processing is presently assessed as limited and occasional.
This assessment will be reviewed as:
- the European or UK customer base changes;
- marketing activities change;
- transaction frequency increases;
- monitoring practices change; or
- legal requirements change.
If appointment of a representative becomes legally required, the representative’s contact information will be added to this Privacy Policy.
Rights in other jurisdictions
Privacy rights vary between countries and states.
Where another applicable law provides additional rights, including rights to opt out of certain targeted advertising, sale, sharing or profiling, we will process valid requests and provide controls as required by that law.
Requests may be sent to:
Children’s privacy
The website and product-drop services are not directed to children under 16.
We do not knowingly create accounts for or collect personal information directly from children under 16 without appropriate parental or guardian involvement where required by law.
A parent or guardian should supervise purchases by a person who has not reached the age at which they may independently enter into a binding purchase contract.
If you believe a child has provided information without appropriate permission, contact:
edhqprivacy@exclusivedrops.com
We will investigate and, where appropriate:
- delete the information;
- restrict the account;
- request parental or guardian confirmation; or
- take another action required by law.
Third-party websites and independent services
The website may contain links to:
- payment services;
- social-media platforms;
- delivery services;
- external websites; or
- other independent services.
Murano Animals does not control the independent privacy practices of an external service.
You should review the relevant third party’s privacy information before providing personal information directly to it.
Changes to this Privacy Policy
We may update this Privacy Policy where:
- the website changes;
- a new feature is introduced;
- service arrangements change;
- processing activities change;
- retention periods change;
- legal requirements change;
- security practices change; or
- clarification is required.
The current version will be published on exclusivedropshq.com with its updated effective date or revision date.
Where a material change affects existing personal information, we will provide additional notice or request new consent where legally required.
Previous versions may be retained for legal, compliance and audit purposes.
Contact us
Privacy matters
Murano Animals ABN: 96 220 324 478 Morphett Vale, South Australia 5162 Australia
Email: edhqprivacy@exclusivedrops.com Website: exclusivedropshq.com Recommended subject line: Privacy Request
Security matters
Email: edhqsecurity@exclusivedrops.com Recommended subject line: Security Report