We use essential cookies to ensure our website functions properly. By continuing, you accept our cookie policy.

subtle-brick
  • Home
  • Services
  • About
  • Contact

GDPR Compliance Statement

Last updated: May 22, 2026

Introduction

Although subtle-brick is based in Australia, we are committed to respecting the data protection rights of all individuals, including those in the European Union. This statement outlines how we comply with the General Data Protection Regulation (GDPR) when processing personal data of EU residents.

Legal Basis for Processing

We process personal data only when we have a lawful basis to do so under GDPR Article 6:

  • Consent: You have given clear consent for us to process your personal data for a specific purpose
  • Contract: Processing is necessary for a contract we have with you, or because you have asked us to take specific steps before entering into a contract
  • Legal obligation: Processing is necessary for us to comply with the law
  • Legitimate interests: Processing is necessary for our legitimate interests or the legitimate interests of a third party, unless there is a good reason to protect your personal data which overrides those interests

Your Rights Under GDPR

If you are an EU resident, you have the following rights regarding your personal data:

Right to Access

You have the right to request copies of your personal data. We may charge a small fee for this service in certain circumstances.

Right to Rectification

You have the right to request that we correct any information you believe is inaccurate or complete information you believe is incomplete.

Right to Erasure

You have the right to request that we erase your personal data, under certain conditions.

Right to Restrict Processing

You have the right to request that we restrict the processing of your personal data, under certain conditions.

Right to Object to Processing

You have the right to object to our processing of your personal data, under certain conditions.

Right to Data Portability

You have the right to request that we transfer the data we have collected to another organization, or directly to you, under certain conditions.

How to Exercise Your Rights

To exercise any of these rights, please contact us at:

Email: [email protected]
Subject line: GDPR Data Request

We will respond to your request within one month. In complex cases, we may extend this period by two additional months, and we will inform you if this is necessary.

Data Protection Officer

For GDPR-related inquiries, you may contact our designated data protection contact:

Email: [email protected]
Reference: Data Protection Inquiry

Data Retention

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including:

  • For the duration of our business relationship with you
  • As required by applicable laws and regulations
  • To establish, exercise, or defend legal claims
  • With your consent, until you withdraw that consent

International Data Transfers

Your personal data may be transferred to and processed in Australia. While Australia is not covered by an EU adequacy decision, we ensure appropriate safeguards are in place to protect your data in accordance with GDPR requirements.

Security Measures

We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:

  • Encryption of personal data in transit and at rest
  • Regular security assessments and audits
  • Access controls and authentication procedures
  • Staff training on data protection obligations

Data Breach Notification

In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR Article 33.

Automated Decision-Making and Profiling

We do not use automated decision-making or profiling that produces legal effects or similarly significantly affects you.

Children's Data

We do not knowingly collect or process personal data from children under 16 without parental consent. If we become aware that we have collected such data, we will take steps to delete it promptly.

Complaints

If you are an EU resident and believe we have not handled your personal data in accordance with GDPR, you have the right to lodge a complaint with your local supervisory authority.

You can find your data protection authority contact details at: https://edpb.europa.eu/about-edpb/board/members_en

Updates to This Statement

We may update this GDPR compliance statement from time to time. Any changes will be posted on this page with an updated revision date.

Contact Information

For any questions about this GDPR compliance statement or our data protection practices, please contact:

subtle-brick
47 Rainforest Drive
Byron Bay, NSW 2481
Australia
Email: [email protected]

subtle-brick

Regenerative ecology solutions backed by science and field experience.

Services

  • All Services
  • Habitat Reconstruction
  • Biodiversity Assessment
  • Consulting

Company

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Use

Legal

  • GDPR
  • Cookies Policy

© 2026 subtle-brick. All rights reserved.