Last Updated: January 2024
Bright Reef is committed to protecting the privacy and security of personal data in accordance with the General Data Protection Regulation (GDPR). This page outlines how we comply with GDPR requirements and explains your rights as a data subject.
While Bright Reef is based in New Zealand, we recognise the importance of GDPR compliance for any customers or visitors from the European Economic Area (EEA).
Bright Reef acts as the data controller for personal information collected through our website and services. This means we determine the purposes and means of processing your personal data.
Contact details:
Email: [email protected]
Address: Level 2, 45 Commerce Street, Auckland CBD, Auckland 1010, New Zealand
We process personal data based on one or more of the following legal grounds:
If you are located in the EEA, you have the following rights regarding your personal data:
You have the right to request a copy of the personal data we hold about you. We will provide this information within one month of receiving your request.
If your personal data is inaccurate or incomplete, you have the right to request that we correct or complete it.
You have the right to request the deletion of your personal data in certain circumstances, such as when the data is no longer necessary for the purposes for which it was collected.
You have the right to request that we limit the processing of your personal data in certain circumstances, such as when you contest the accuracy of the data.
You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit that data to another controller.
You have the right to object to processing of your personal data based on legitimate interests or for direct marketing purposes.
You have the right not to be subject to decisions based solely on automated processing, including profiling, that produce legal effects concerning you.
To exercise any of these rights, please contact us at [email protected]. We will respond to your request within one month. In certain cases, we may extend this period by two additional months if necessary, and we will inform you of any such extension.
We may need to verify your identity before processing your request to ensure the security of your personal data.
As Bright Reef is based in New Zealand, personal data from EEA residents may be transferred to New Zealand. New Zealand has been recognised by the European Commission as providing an adequate level of data protection, meaning your data enjoys similar protections as it would within the EEA.
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay. We will also notify the relevant supervisory authority within 72 hours of becoming aware of the breach, where required by law.
For any questions regarding our GDPR compliance or to exercise your rights, please contact us at [email protected].
If you believe that we have not complied with your data protection rights, you have the right to lodge a complaint with a supervisory authority. For EEA residents, this would be the data protection authority in your country of residence.
We may update this GDPR compliance information from time to time. Any changes will be posted on this page with an updated revision date.