Last updated: July 29, 2026
Although we are based in Australia, we recognize that some of our website visitors and clients may be located in the European Union or other jurisdictions covered by the General Data Protection Regulation (GDPR). We are committed to protecting the privacy rights of all individuals, regardless of location.
When we process personal data of individuals in the EU, we do so under one or more of the following legal bases:
If you are located in the EU, you have the following rights regarding your personal data:
You have the right to request copies of your personal data. We may charge a reasonable fee if your request is clearly unfounded, repetitive, or excessive.
You have the right to request correction of inaccurate or incomplete personal data we hold about you.
You have the right to request deletion of your personal data in certain circumstances, including:
You have the right to request restriction of processing your personal data in certain situations, such as when you contest the accuracy of the data or object to processing.
You have the right to request transfer of your personal data to another organization or directly to you, in a structured, commonly used, and machine-readable format.
You have the right to object to processing of your personal data where we are relying on legitimate interests or performing a task in the public interest. You also have the right to object to processing for direct marketing purposes.
You have the right not to be subject to decisions based solely on automated processing, including profiling, which produces legal effects or similarly significantly affects you. We do not currently engage in automated decision-making that would trigger this right.
To exercise any of your GDPR rights, please contact us at [email protected] with the subject line "GDPR Request." We will respond to your request within one month, though this period may be extended by two additional months for complex requests.
We may need to verify your identity before processing your request. We will not charge a fee for processing valid requests unless they are clearly unfounded, repetitive, or excessive.
Your personal data may be transferred to and processed in Australia. While Australia does not have an adequacy decision from the European Commission, we ensure appropriate safeguards are in place when transferring data internationally, including:
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including any legal, accounting, or reporting requirements. Retention periods vary depending on the nature of the data and the purpose for processing.
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you without undue delay and, where feasible, within 72 hours of becoming aware of the breach.
If you are located in the EU and have concerns about our data processing practices that we have not adequately addressed, you have the right to lodge a complaint with your local data protection supervisory authority.
For questions about our GDPR compliance or to exercise your rights, please contact:
reef-leap
Level 12, 45 Clarence Street
Sydney NSW 2000
Australia
Email: [email protected]