GDPR Compliance
Last updated: June 19, 2026
General Data Protection Regulation
While we are based in Australia, we recognize the importance of data protection standards established by the European Union's General Data Protection Regulation. We extend these principles to all users regardless of geographic location.
Legal Basis for Processing
We process personal data under the following legal grounds:
- Consent: You have explicitly agreed to our processing of your data for specific purposes
- Contract performance: Processing is necessary to fulfill services you have requested
- Legitimate interests: Processing serves our legitimate business interests while respecting your privacy rights
- Legal obligations: Compliance with applicable laws and regulations
Data Controller Information
For the purposes of data protection legislation, the data controller is bright-reef, located at Level 12, 348 Edward Street, Brisbane QLD 4000, Australia.
Your GDPR Rights
If you are located in the European Economic Area, you have the following rights:
- Right of access: Obtain confirmation of whether we process your data and receive a copy
- Right to rectification: Request correction of inaccurate or incomplete data
- Right to erasure: Request deletion of your personal data under certain circumstances
- Right to restriction: Request limitation of processing activities
- Right to data portability: Receive your data in a structured, commonly used format
- Right to object: Object to processing based on legitimate interests or for direct marketing
- Right to withdraw consent: Withdraw previously given consent at any time
Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including satisfying legal, accounting, or reporting requirements. Retention periods vary depending on the nature of the data and the purpose of processing.
International Data Transfers
Your personal information is primarily stored and processed in Australia. If data transfer to other jurisdictions becomes necessary, we will ensure appropriate safeguards are in place to protect your information in accordance with applicable data protection laws.
Automated Decision-Making
We do not engage in automated decision-making or profiling that produces legal effects or similarly significant impacts on individuals.
Data Breach Notification
In the event of a data breach that poses a risk to your rights and freedoms, we will notify you and relevant supervisory authorities within 72 hours of becoming aware of the breach, as required by applicable regulations.
Exercising Your Rights
To exercise any of the rights outlined above, please contact us at [email protected]. We will respond to your request within one month, though this period may be extended by two additional months for complex requests.
Supervisory Authority
You have the right to lodge a complaint with a data protection supervisory authority if you believe our processing of your personal data violates applicable regulations.