Privacy Policy
Last updated: 7 August 2026
1. Scope and Purpose
This Privacy Policy explains how Seravellawhiteworks handles personal information when you visit this website, make an enquiry, request a workspace tour, communicate with us, or otherwise interact with our coworking services. It is intended to provide clear information about our data-handling practices under applicable Australian privacy law and, where the European Union General Data Protection Regulation (GDPR) applies to a particular individual or processing activity, the additional rights and safeguards available under that framework.
This policy applies to website visitors, prospective members, members, business contacts, suppliers and other individuals whose personal information we handle in connection with our services. It does not override contractual terms that contain more specific privacy provisions.
2. Personal Information We May Collect
Depending on your interaction with us, we may collect identification and contact details such as your name, business or organisation, email address, telephone number and postal address; enquiry details and communications; workspace preferences; requested tour dates and times; service interests; transaction and account administration information where relevant to a membership relationship; and technical information that a browser may make available when you use the website.
We aim to collect only information reasonably necessary for our functions and services. Please do not provide sensitive information through general website forms unless we specifically request it and explain why it is required.
3. How We Collect Information
We may collect information directly from you when you complete a form, contact our team, arrange a tour, ask for information, enter into a workspace agreement, attend our premises, or otherwise communicate with us. We may also receive business contact information from an organisation that you represent, from service providers acting on our behalf, or from publicly available professional sources where lawful and appropriate.
When information is collected from a third party, we take reasonable steps to ensure that the collection and subsequent use are lawful, fair and consistent with the purpose for which the information was provided.
4. Purposes of Processing
We may use personal information to respond to enquiries, arrange tours and meetings, provide and administer coworking services, manage member relationships, maintain business records, provide customer support, improve our premises and services, protect the security of people and property, comply with legal obligations, establish or defend legal claims, and communicate operational information relevant to a service relationship.
Where required, marketing communications are sent only where there is an appropriate legal basis and an available method to opt out. We do not sell personal information.
5. Legal Bases Where the GDPR Applies
Where the GDPR applies, processing may be based on one or more lawful bases: steps requested before entering a contract or performance of a contract; compliance with a legal obligation; our legitimate interests in operating, securing and improving our coworking business where those interests are not overridden by your rights; your consent where consent is the appropriate basis; or protection of vital interests in exceptional circumstances.
Where consent is relied upon, you may withdraw it at any time for future processing. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
6. Disclosure and Service Providers
We may disclose personal information to service providers that support hosting, information technology, security, professional advice, payment or accounting functions, facilities management, communications or other operational needs. We require service providers to use information only for authorised purposes and to apply appropriate confidentiality and security measures.
We may also disclose information where required by law, court order or regulatory authority, or where reasonably necessary to protect our legal rights, users, staff, premises or other persons.
7. Cross-Border Handling
Some technology or professional service providers may process information outside Australia. Where cross-border disclosure occurs, we take reasonable steps appropriate to the circumstances to protect personal information and to address applicable Australian Privacy Principle requirements. Where the GDPR applies to an international transfer, we use an available transfer mechanism and supplementary safeguards where required.
The specific countries involved can change as service providers change. You may contact us for current information relevant to your personal information.
8. Data Retention
We retain personal information only for as long as reasonably necessary for the purposes described in this policy, to maintain appropriate business and financial records, to comply with legal obligations, and to resolve disputes or enforce agreements. Retention periods vary according to the nature of the information and the legal or operational reason for keeping it.
When information is no longer required, we take reasonable steps to delete, destroy or de-identify it, subject to lawful archival or record-keeping requirements.
9. Security
We use reasonable administrative, technical and physical safeguards designed to protect personal information from misuse, interference, loss, unauthorised access, modification and disclosure. Measures may include access controls, restricted administrative privileges, secure device practices, staff procedures, backups and appropriate service-provider controls.
No internet transmission or storage environment is completely secure. If we identify a data incident, we assess it and respond in accordance with applicable breach-notification requirements.
10. Access, Correction and Privacy Rights
Subject to applicable law, you may request access to personal information we hold about you and ask us to correct inaccurate, out-of-date, incomplete, irrelevant or misleading information. We may need to verify your identity before acting on a request.
Where the GDPR applies, you may also have rights to erasure, restriction of processing, data portability, objection to certain processing, withdrawal of consent, and protection in relation to qualifying solely automated decisions. These rights are subject to legal conditions and exceptions.
11. Complaints
If you believe we have mishandled your personal information, contact us using the details below and provide enough information for us to understand and investigate the concern. We will acknowledge and assess privacy complaints within a reasonable period and may ask for further information where necessary.
If an Australian privacy matter is not resolved to your satisfaction, you may be able to raise it with the Office of the Australian Information Commissioner. If the GDPR applies, you may also have the right to lodge a complaint with the competent supervisory authority in the European Economic Area or United Kingdom, as applicable.
12. Children
Our coworking services and this website are directed to adults and business users. We do not intentionally seek to collect personal information from children through general website forms. If you believe a child has provided personal information without appropriate authority, contact us so that we can assess and address the information.
13. Automated Decision-Making
We do not use website enquiry information to make decisions based solely on automated processing that produce legal effects or similarly significant effects on individuals. If this practice changes, we will provide the information and safeguards required by applicable law before such processing is used.
14. Changes to this Policy
We may update this Privacy Policy when our services, systems, legal obligations or information-handling practices change. The current version is identified by the “Last updated” date. Material changes will be communicated through an appropriate notice on the website or through another suitable channel where required.
Administrator and Contact
Controller / business: Seravellawhiteworks Pty Ltd
Address: 85 Castlereagh Street, Sydney NSW 2000, Australia
Email: info@seravellawhiteworks.com
Phone: +61 2 8015 4276