GDPR Compliance
Last Updated: May 22, 2026
Our Commitment to Data Protection
Although Brightify Construct is based in Australia, we recognize the importance of the General Data Protection Regulation (GDPR) and extend similar protections to all our clients, regardless of location. This page outlines how we comply with GDPR principles and protect your data rights.
Legal Basis for Processing
We process your personal data based on one or more of the following legal grounds:
- Consent: You have given clear consent for us to process your personal data for specific purposes
- Contract: Processing is necessary for a contract we have with you, or because you have asked us to take specific steps before entering into a contract
- Legal obligation: Processing is necessary for us to comply with the law
- Legitimate interests: Processing is necessary for our legitimate interests or those of a third party, provided your interests and rights do not override those interests
Your Rights Under GDPR
If you are located in the European Economic Area (EEA), you have the following data protection rights:
Right to Access
You have the right to request copies of your personal data from us.
Right to Rectification
You have the right to request that we correct any information you believe is inaccurate or complete information you believe is incomplete.
Right to Erasure
You have the right to request that we erase your personal data, under certain conditions.
Right to Restrict Processing
You have the right to request that we restrict the processing of your personal data, under certain conditions.
Right to Object to Processing
You have the right to object to our processing of your personal data, under certain conditions.
Right to Data Portability
You have the right to request that we transfer the data we have collected to another organization, or directly to you, under certain conditions.
Right to Withdraw Consent
Where we rely on consent to process your personal data, you have the right to withdraw that consent at any time.
How to Exercise Your Rights
To exercise any of these rights, please contact us at [email protected] with the subject line "GDPR Data Request".
We will respond to your request within 30 days. Please note that we may ask you to verify your identity before responding to such requests.
Data Processing Activities
What Data We Collect
- Contact information (name, email, postal address)
- Project details and service preferences
- Communication history
- Website usage data and cookies
Why We Collect It
- To provide renovation and design services
- To communicate about projects and inquiries
- To improve our website and services
- To comply with legal obligations
Who We Share It With
- Service providers (email services, website hosting)
- Professional advisors (legal, accounting)
- Subcontractors involved in your project
- Law enforcement when legally required
International Data Transfers
Your information may be transferred to and maintained on servers located outside of your country where data protection laws may differ. We ensure that appropriate safeguards are in place to protect your data in accordance with GDPR requirements.
Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including for legal, accounting, or reporting requirements. Specific retention periods include:
- Project-related data: 7 years after project completion (for warranty and legal purposes)
- Marketing communications: Until you unsubscribe or request deletion
- Website analytics: 26 months
- Inquiry forms: 2 years if no project proceeds
Data Security Measures
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- Encryption of data in transit and at rest
- Regular security assessments and updates
- Access controls and authentication procedures
- Staff training on data protection
- Incident response procedures
Data Breach Notification
In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the relevant supervisory authority within 72 hours of becoming aware of the breach.
Complaints
If you believe we have not handled your data in accordance with GDPR, you have the right to lodge a complaint with a supervisory authority. In Australia, you can contact the Office of the Australian Information Commissioner (OAIC). If you are in the EEA, you can contact your local data protection authority.
Contact Our Data Protection Officer
For any questions about our GDPR compliance or to exercise your data rights:
Data Protection Officer
Brightify Construct
Level 2, 47 Bourke Street
Surry Hills NSW 2010
Australia
Email: [email protected]