We use cookies to improve your experience. By continuing to browse, you agree to our use of cookies.

reef-leap
This site contains advertising material
  • Home
  • Services
  • About
  • Contact

GDPR Compliance

Last updated: July 29, 2026

Overview

Although we are based in Australia, we recognize that some of our website visitors and clients may be located in the European Union or other jurisdictions covered by the General Data Protection Regulation (GDPR). We are committed to protecting the privacy rights of all individuals, regardless of location.

Legal Basis for Processing

When we process personal data of individuals in the EU, we do so under one or more of the following legal bases:

  • Consent: You have given explicit consent for us to process your personal data for a specific purpose
  • Contract: Processing is necessary to fulfill a contract with you or to take steps at your request prior to entering a contract
  • Legal Obligation: Processing is necessary to comply with legal requirements
  • Legitimate Interests: Processing is necessary for our legitimate business interests, provided these do not override your fundamental rights

Your Rights Under GDPR

If you are located in the EU, you have the following rights regarding your personal data:

Right to Access

You have the right to request copies of your personal data. We may charge a reasonable fee if your request is clearly unfounded, repetitive, or excessive.

Right to Rectification

You have the right to request correction of inaccurate or incomplete personal data we hold about you.

Right to Erasure

You have the right to request deletion of your personal data in certain circumstances, including:

  • The data is no longer necessary for the purpose it was collected
  • You withdraw consent and there is no other legal basis for processing
  • You object to processing and there are no overriding legitimate grounds
  • The data has been unlawfully processed

Right to Restrict Processing

You have the right to request restriction of processing your personal data in certain situations, such as when you contest the accuracy of the data or object to processing.

Right to Data Portability

You have the right to request transfer of your personal data to another organization or directly to you, in a structured, commonly used, and machine-readable format.

Right to Object

You have the right to object to processing of your personal data where we are relying on legitimate interests or performing a task in the public interest. You also have the right to object to processing for direct marketing purposes.

Rights Related to Automated Decision-Making

You have the right not to be subject to decisions based solely on automated processing, including profiling, which produces legal effects or similarly significantly affects you. We do not currently engage in automated decision-making that would trigger this right.

How to Exercise Your Rights

To exercise any of your GDPR rights, please contact us at [email protected] with the subject line "GDPR Request." We will respond to your request within one month, though this period may be extended by two additional months for complex requests.

We may need to verify your identity before processing your request. We will not charge a fee for processing valid requests unless they are clearly unfounded, repetitive, or excessive.

Data Transfers

Your personal data may be transferred to and processed in Australia. While Australia does not have an adequacy decision from the European Commission, we ensure appropriate safeguards are in place when transferring data internationally, including:

  • Standard contractual clauses approved by the European Commission
  • Adequacy of recipient country's data protection laws
  • Your explicit consent to the transfer

Data Retention

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including any legal, accounting, or reporting requirements. Retention periods vary depending on the nature of the data and the purpose for processing.

Data Security

We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:

  • Encryption of personal data in transit and at rest
  • Regular security assessments and updates
  • Access controls and authentication measures
  • Staff training on data protection principles

Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you without undue delay and, where feasible, within 72 hours of becoming aware of the breach.

Supervisory Authority

If you are located in the EU and have concerns about our data processing practices that we have not adequately addressed, you have the right to lodge a complaint with your local data protection supervisory authority.

Contact Information

For questions about our GDPR compliance or to exercise your rights, please contact:

reef-leap
Level 12, 45 Clarence Street
Sydney NSW 2000
Australia
Email: [email protected]

reef-leap

Sustainable energy solutions for Australian businesses committed to a resilient future.

Services

  • Solar Integration
  • Energy Audits
  • Carbon Analysis
  • Building Consultation

Company

  • About Us
  • Contact

Legal

  • Privacy Policy
  • Terms of Use
  • GDPR
  • Cookies Policy

Disclaimer: The information provided on this website is for educational purposes and should not replace professional advice. Energy savings and carbon reduction outcomes may vary based on individual circumstances, facility characteristics, and implementation quality. We recommend consulting with qualified energy professionals before making significant infrastructure decisions. Results mentioned are indicative and not guaranteed.

© 2026 reef-leap. All rights reserved.