Last Updated: January 1, 2026
This document outlines how clever-brook complies with the General Data Protection Regulation and protects the rights of individuals regarding their personal data.
We process personal data under the following legal bases:
If you are located in the European Economic Area or other jurisdictions with similar data protection laws, you have the following rights:
You have the right to request confirmation of whether we process your personal data and to obtain a copy of that data in a structured, commonly used format.
You may request correction of inaccurate personal data or completion of incomplete information we hold about you.
You can request deletion of your personal data when it is no longer necessary for the purposes for which it was collected, or when you withdraw consent. This right is subject to legal retention obligations.
You may request that we limit how we use your personal data in certain circumstances, such as when you contest the accuracy of the data.
Where technically feasible, you have the right to receive personal data you provided to us in a structured format and to transmit that data to another controller.
You may object to processing of your personal data for direct marketing purposes or when processing is based on legitimate interests.
Where processing is based on consent, you have the right to withdraw that consent at any time, without affecting the lawfulness of processing before withdrawal.
You have the right to lodge a complaint with a supervisory authority if you believe we have violated your data protection rights.
To exercise any of these rights, please contact us at [email protected]. Include sufficient information to identify yourself and specify which right you wish to exercise. We will respond to your request within the timeframe required by applicable law, typically within 30 days.
For data protection inquiries or concerns, you may contact our data protection representative at [email protected].
Your personal data is primarily processed and stored within Australia. If we transfer data internationally, we ensure appropriate safeguards are in place to protect your information in accordance with applicable data protection laws.
We do not use automated decision-making or profiling that produces legal effects or similarly significant impacts on individuals.
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
In the event of a data breach that poses a risk to your rights and freedoms, we will notify affected individuals and relevant supervisory authorities as required by law, without undue delay.
We may update this GDPR compliance document to reflect changes in our practices or legal requirements. Significant changes will be communicated through our website.