Last updated: May 11, 2026
While Bright Stance is based in Australia, we respect the data protection rights of individuals in the European Union and comply with the General Data Protection Regulation (GDPR) for any EU residents who use our services.
We process your personal data under the following legal bases:
If you are an EU resident, you have the following rights:
You can request confirmation of whether we process your personal data and obtain a copy of that data.
You can request correction of inaccurate or incomplete personal data.
You can request deletion of your personal data under certain circumstances, including when the data is no longer necessary for the purposes collected.
You can request that we restrict processing of your personal data in specific situations.
You can request to receive your personal data in a structured, commonly used format and transmit it to another controller.
You can object to processing of your personal data based on legitimate interests or for direct marketing purposes.
Where processing is based on consent, you can withdraw that consent at any time.
You can lodge a complaint with your local supervisory authority if you believe we have violated your data protection rights.
For GDPR-related inquiries, you can contact our data protection representative at:
Email: [email protected]
Subject Line: GDPR Inquiry
If we transfer your personal data outside the EU, we ensure appropriate safeguards are in place, including:
We retain personal data only for as long as necessary to fulfill the purposes outlined in our Privacy Policy or as required by law. Retention periods vary depending on:
We do not engage in automated decision-making or profiling that produces legal or similarly significant effects on individuals.
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
To exercise any of your GDPR rights, please contact us at:
Email: [email protected]
Subject: GDPR Rights Request
We will respond to your request within one month, or notify you if we require an extension.
We may update this GDPR compliance notice to reflect changes in our practices or legal requirements. Significant changes will be communicated through our website.