Last Updated: July 29, 2026
Although crimson-stone operates primarily in South Africa, we recognize the importance of data protection principles established by the General Data Protection Regulation (GDPR) and apply similar standards to all personal data we process.
We process personal data based on the following legal grounds:
In accordance with GDPR principles, you have the following rights:
You have the right to request confirmation of whether we process your personal data and to receive a copy of that data in a commonly used format.
You have the right to request correction of inaccurate personal data and completion of incomplete personal data.
You have the right to request deletion of your personal data in certain circumstances, including when:
You have the right to request restriction of processing in certain circumstances, such as when you contest the accuracy of the data or object to processing.
You have the right to receive personal data you provided to us in a structured, commonly used, machine-readable format and to transmit that data to another controller.
You have the right to object to processing of your personal data based on legitimate interests or for direct marketing purposes.
You have the right not to be subject to decisions based solely on automated processing that produce legal effects or similarly significant effects. We do not engage in automated decision-making that would affect your rights.
To exercise any of these rights, contact us at [email protected] with your request. We will respond within 30 days of receiving a valid request. We may need to verify your identity before processing your request.
For questions about data protection or to exercise your rights, you can contact our data protection representative at:
Email: [email protected]
Subject Line: Data Protection Inquiry
We primarily store and process data within South Africa. If we transfer personal data internationally, we ensure appropriate safeguards are in place to protect your data in accordance with applicable data protection laws.
We implement appropriate technical and organizational security measures to protect personal data against unauthorized or unlawful processing, accidental loss, destruction, or damage. These measures include:
In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify you without undue delay and provide information about the nature of the breach and measures taken to address it.
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including legal, accounting, or reporting requirements. Typical retention periods include:
Our services are not directed at individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child, we will take steps to delete that information.
If you believe we have not addressed your data protection concerns adequately, you have the right to lodge a complaint with the relevant supervisory authority in your jurisdiction.
We may update this GDPR compliance statement periodically to reflect changes in our practices or legal requirements. Significant changes will be communicated through our website.
For any questions or concerns regarding GDPR compliance or data protection:
crimson-stone
127 Rivonia Road
Sandton, Johannesburg, 2196
South Africa
Email: [email protected]