Skip to main content
Our Menu
Experience
FROSTLUMEN LEON
Our Chefs
Events
About Us
FROSTLUMEN LEON
Our Menu
Dining Experience
Our Chefs
Private Events
About Us

Frostlumen Leon Pty Ltd

17 Marungi Street, South Brisbane

FROSTLUMEN LEON

Privacy Policy

How we collect, use, disclose and protect personal information.

Last updated: 3 August 2026

Return to Home

Contents

  • 1. Purpose and scope
  • 2. Privacy administrator and contact details
  • 3. Categories of information we may collect
  • 4. How information is collected
  • 5. Purposes for using personal information
  • 6. Legal bases under the GDPR
  • 7. Sensitive information and dietary requirements
  • 8. Disclosure of information
  • 9. Overseas disclosures and international transfers
  • 10. Retention and deletion
  • 11. Security
  • 12. Accuracy, access and correction
  • 13. Additional GDPR rights
  • 14. Direct marketing
  • 15. Children
  • 16. Complaints
  • 17. Third-party links and services
  • 18. Changes to this Policy

1. Purpose and scope

This Privacy Policy explains how (referred to as “Frostlumen Leon”, “we”, “us” or “our”) collects, uses, stores, discloses and protects personal information when you visit this website, make an enquiry, subscribe to updates, arrange a private event, interact with our restaurant, or otherwise communicate with us. It is intended to provide transparent information about our handling practices and the choices available to you.

Our primary operations are based in Australia. We aim to handle personal information consistently with the Privacy Act 1988 (Cth) and the Australian Privacy Principles where they apply. Where the General Data Protection Regulation applies because we offer services to or monitor individuals in the European Economic Area, we also describe the relevant GDPR rights and legal bases in this Policy. Local law may provide additional or different rights, and those mandatory rights are not limited by this document.

This Policy applies to information handled through this website and our associated customer communications. It does not govern third-party websites, platforms or services that we do not control. This website has been prepared to operate without third-party analytics, advertising pixels, remote fonts or external content dependencies by default.

2. Privacy administrator and contact details

The organisation responsible for the personal information described in this Policy is Frostlumen Leon Pty Ltd , , located at 17 Marungi Street, South Brisbane, QLD 4101, Australia . Privacy questions, access requests, correction requests and complaints may be sent in writing to info@frostlumenleon-australia.com or delivered to the address shown above. The email address is displayed as text and is not a clickable mail link.

When contacting us about privacy, please provide enough information for us to understand the request and verify that it concerns you. Do not send unnecessary identity documents or sensitive information. We may ask for proportionate verification before disclosing or changing personal information.

3. Categories of information we may collect

Depending on how you interact with us, we may collect identity and contact details such as your name, email address, telephone number, organisation, role, preferred contact method and postal address. For private-event or dining enquiries, we may also collect the proposed date, guest numbers, event type, menu preferences, accessibility requirements, dietary information and other details that you voluntarily provide.

We may collect reservation and service information, including booking history, attendance details, seating preferences, correspondence, feedback, complaints, requests, and notes needed to deliver an agreed dining or event service. Payment information should only be supplied through an authorised payment process. This static website is not designed to collect full payment-card numbers.

Technical information may include an internet protocol address, browser type, device type, operating system, referring page, pages requested, approximate time of access, language settings and diagnostic information generated by the web server. The current frontend does not include third-party behavioural analytics or advertising scripts. A hosting provider may nevertheless create standard security and access logs as part of delivering the website.

If you provide dietary, allergy, accessibility or health-related information, that information may be sensitive personal information under applicable law. We ask that you provide only information that is reasonably necessary for us to accommodate you safely. We will use such information for the relevant service and handle it with additional care.

4. How information is collected

We generally collect information directly from you when you complete a website form, ask a question, make a reservation, request an event proposal, subscribe to communications, telephone us, visit our premises, or correspond with our team. Website forms on this static project provide local validation and a confirmation state; actual transmission requires the site owner to connect an authorised backend or form service.

We may receive information from a person arranging a group booking or private event on behalf of other guests. The organiser should only provide information they are authorised to share and should make relevant guests aware of this Policy. We may also receive information from professional advisers, service providers or public sources where lawful and reasonably necessary.

We do not intentionally collect personal information by unlawful or unfair means. Where practical, we will explain why information is requested and what may occur if it is not provided. You may interact anonymously or using a pseudonym where lawful and practical, although this may not be possible for reservations, contractual services, safety matters or personalised requests.

5. Purposes for using personal information

We may use personal information to respond to enquiries; manage reservations and event requests; prepare proposals; provide food, hospitality and customer services; accommodate dietary or accessibility needs; administer payments and refunds through authorised systems; communicate changes; maintain service records; and manage our relationship with guests, suppliers and business contacts.

We may also use information to operate, secure, troubleshoot and improve the website and our services; prevent misuse, fraud and security incidents; maintain business and accounting records; train staff; resolve disputes; establish, exercise or defend legal claims; comply with licences, food-safety duties, workplace obligations, tax requirements, court orders and other applicable laws.

Where permitted, we may send restaurant news, seasonal menu announcements or event information to people who have requested those communications. Marketing communications will identify the sender and provide a practical way to opt out. We do not sell personal information and do not use this website to run third-party targeted advertising.

6. Legal bases under the GDPR

Where the GDPR applies, we rely on one or more lawful bases. Processing may be necessary to take steps at your request before entering a contract or to perform a contract, such as responding to an event enquiry, managing a reservation or delivering an agreed service.

We may process information to comply with legal obligations, including accounting, taxation, food-safety, regulatory, employment and lawful disclosure requirements. We may rely on legitimate interests where processing is necessary for proportionate business purposes such as operating and securing the website, responding to routine communications, preventing fraud, improving service quality, protecting legal rights and administering customer relationships, provided those interests are not overridden by your rights and freedoms.

We rely on consent where the law requires it, including for certain electronic marketing, optional cookies or the processing of special-category information when another legal basis is unavailable. Consent may be withdrawn for future processing at any time. Withdrawal does not affect the lawfulness of processing that occurred before withdrawal. In exceptional circumstances, processing may be necessary to protect vital interests or perform a task in the public interest.

7. Sensitive information and dietary requirements

Dietary restrictions, allergies, accessibility needs and similar details can reveal health or religious information. We request only information needed to assess and provide the relevant accommodation. Such information is normally used with your consent or where otherwise permitted by law, including where necessary to protect health and safety or respond to an emergency.

Although we take reasonable care when recording and communicating dietary information, guests must clearly inform staff of allergies and requirements when making a booking and again on arrival. Privacy handling does not replace direct safety communication with restaurant staff.

8. Disclosure of information

We may disclose personal information to staff and contractors who need it to perform their duties; venue, catering, booking, information-technology, website-hosting, communications, security, payment, accounting, legal, insurance and professional service providers; and event suppliers selected or approved for a particular service. Recipients are expected to use the information only for authorised purposes and to protect it appropriately.

We may disclose information to regulators, courts, tribunals, law-enforcement bodies, emergency services, public-health authorities or other persons where required or authorised by law, where necessary to respond to a serious threat, or where needed to establish, exercise or defend legal rights. We may also disclose relevant information in connection with a proposed or completed sale, merger, restructuring or transfer of all or part of the business, subject to appropriate confidentiality and legal safeguards.

We do not disclose personal information to data brokers for sale. We do not allow third parties to place advertising trackers through this frontend by default.

9. Overseas disclosures and international transfers

Some technology, communications or professional service providers may store or access information outside Australia. The location may depend on the provider selected by the site operator. Before enabling any such provider, the operator should assess the destination, contractual protections, security measures and applicable cross-border disclosure obligations.

Where Australian Privacy Principle 8 applies, we will take reasonable steps required by law in relation to overseas recipients. Where the GDPR applies to a transfer outside the EEA, we will use an available transfer mechanism such as an adequacy decision, standard contractual clauses, binding corporate rules, or a permitted derogation, together with supplementary safeguards where appropriate.

10. Retention and deletion

We retain personal information only for as long as reasonably necessary for the purposes described in this Policy, including service delivery, customer support, safety, accounting, tax, insurance, dispute-resolution and legal requirements. Different categories may have different retention periods. Enquiry data that does not lead to a service may be retained for a limited follow-up period and then deleted or de-identified unless a longer period is justified.

Reservation and transaction records may need to be kept for statutory and financial recordkeeping periods. Information relevant to a complaint, incident or legal claim may be retained until the matter and any limitation period have ended. Marketing contact details are retained until consent is withdrawn, the person opts out, the address is no longer valid, or continued retention is no longer justified.

When information is no longer required and no law requires retention, we will take reasonable steps to delete it securely or de-identify it. Backups may retain data for a limited cycle before automatic replacement.

11. Security

We use reasonable administrative, physical and technical measures appropriate to the nature of the information and the risks involved. Measures may include role-based access, staff confidentiality obligations, software updates, secure configuration, backups, malware protection, access logging, vendor assessment, incident-response procedures and encryption where appropriate.

No internet transmission or storage method can be guaranteed completely secure. You should avoid sending sensitive information through ordinary email and should use authorised channels for payment data. If we become aware of a suspected breach, we will investigate, contain and assess it and will notify affected individuals and the Office of the Australian Information Commissioner where the Notifiable Data Breaches scheme requires notification. Where the GDPR applies, we will also meet applicable supervisory-authority and data-subject notification duties.

12. Accuracy, access and correction

We take reasonable steps to keep personal information accurate, complete, current and relevant for its intended use. Please tell us when your contact details, reservation information or requirements change.

You may request access to personal information we hold about you and ask for correction of inaccurate, outdated, incomplete, irrelevant or misleading information. We may need to verify identity and clarify the scope of a request. Access may be refused or limited where permitted by law, for example where disclosure would unreasonably affect another person, reveal privileged material, prejudice an investigation or be otherwise unlawful. If access or correction is refused, we will ordinarily provide reasons and available complaint options unless the law prevents us from doing so.

13. Additional GDPR rights

Where the GDPR applies, you may have the right to request access, rectification, erasure, restriction of processing, data portability and objection to processing based on legitimate interests or direct marketing. You may withdraw consent at any time for future processing and may lodge a complaint with a competent supervisory authority.

These rights are subject to conditions and exceptions. For example, erasure may not apply where information is needed to comply with a legal obligation, perform a contract, protect public health, exercise freedom of expression, or establish, exercise or defend legal claims. Portability generally applies to data you provided where processing is automated and based on consent or contract.

We do not use this website to make decisions producing legal or similarly significant effects solely through automated processing. If that changes, we will provide information required by applicable law about the logic, significance and consequences of the processing.

14. Direct marketing

We may send direct marketing only where permitted and where the recipient has requested it, consented, or another lawful basis applies. Every electronic marketing message should provide a clear unsubscribe method. You may opt out at any time. We will not charge a fee for an opt-out request and will action it within the period required by applicable law.

Service messages about an existing reservation, enquiry, event or important operational matter are not marketing and may continue where needed to perform the service or protect guests.

15. Children

Our website and restaurant information are directed to a general audience and are not designed to collect personal information directly from children without appropriate adult involvement. A parent, guardian or event organiser should provide information required for a child’s booking, dietary or accessibility needs. If we learn that personal information was collected from a child in circumstances requiring parental consent and valid consent was not obtained, we will take reasonable steps to delete or otherwise lawfully handle it.

16. Complaints

Please send privacy complaints to the contact details in section 2. Describe the concern, the relevant interaction and the outcome sought. We will acknowledge and investigate complaints within a reasonable period, communicate with you about the process, and provide a response based on the available evidence and applicable law.

If you are not satisfied, you may be able to complain to the Office of the Australian Information Commissioner. Individuals in the EEA may also complain to the supervisory authority in the country of habitual residence, place of work or the alleged infringement. We encourage you to contact us first so we have an opportunity to address the issue.

17. Third-party links and services

The website may occasionally refer to an external service or third-party venue provider. A third party’s privacy policy governs its own collection and use of information. We are not responsible for third-party practices that we do not control. Before adding an external integration, the site operator should review its privacy, security, cookie and cross-border transfer implications.

18. Changes to this Policy

We may update this Policy when our services, technology, legal obligations or information practices change. The revised version will be published on this page with an updated date. Material changes may also be communicated through an appropriate additional notice. Continued use of the website after an update does not replace consent where consent is legally required.

Important notice

This document is a general website policy and does not replace advice from a qualified professional about the operator’s specific systems, contracts or legal obligations.

Frostlumen Leon

Contemporary Australian Excellence

A destination for refined culinary craftsmanship, celebrating the finest seasonal ingredients and premium Australian hospitality in the heart of South Brisbane.

Explore

  • Homepage
  • Our Menu
  • Dining Experience
  • Our Chefs
  • Private Events
  • About Us

Guest Services

  • Frequently Asked Questions
  • Reservations & Enquiries
  • Contact & Enquiries
  • Hospitality Pledge
  • Contact & Location

Contact & Location

17 Marungi Street, South Brisbane, QLD 4101, Australia
+61 7 3184 7296
info@frostlumenleon-australia.com

The Culinary Journal

Join our community for seasonal menu reveals and exclusive dining events.

Enter your email address to join the culinary journal updates.
© 2026 Frostlumen Leon Pty Ltd · 17 Marungi Street, South Brisbane, QLD 4101, Australia . All rights reserved.
Privacy Policy
Terms & Conditions
Cookie Policy