Last updated: September 2, 2026
While sapphire-thicket operates primarily in Australia, we recognize the extraterritorial reach of the General Data Protection Regulation (GDPR) for any clients or website visitors located in the European Economic Area. This page outlines how we comply with GDPR principles when handling personal data of EU residents.
We process personal data under the following legal bases:
Under GDPR, you have the following rights regarding your personal data:
You may request confirmation of whether we process your personal data and obtain a copy of that data in a structured, commonly used format.
You may request correction of inaccurate personal data or completion of incomplete data we hold about you.
You may request deletion of your personal data when it is no longer necessary for the purposes for which it was collected, when you withdraw consent, or when there is no overriding legitimate interest for continued processing.
You may request that we limit how we use your data in certain circumstances, such as when you contest the accuracy of the data or object to processing.
You may request transfer of your data to another service provider in a machine-readable format where technically feasible.
You may object to processing based on legitimate interests or for direct marketing purposes. We will cease such processing unless we demonstrate compelling legitimate grounds that override your interests.
For GDPR-related inquiries, requests to exercise your rights, or concerns about how we handle EU resident data, contact our data protection team at [email protected] with the subject line "GDPR Request".
Personal data of EU residents may be transferred to and processed in Australia. We ensure such transfers comply with GDPR requirements through appropriate safeguards and by ensuring recipients provide adequate data protection levels.
We do not use automated decision-making or profiling that produces legal effects or similarly significantly affects individuals. All analysis and recommendations are produced through human review and professional judgment.
In the event of a data breach that poses a risk to your rights and freedoms, we will notify affected individuals within 72 hours of becoming aware of the breach, in accordance with GDPR requirements. Such notification will include the nature of the breach, likely consequences, and measures taken to address it.
If you are an EU resident and believe we have not adequately addressed your GDPR concerns, you have the right to lodge a complaint with your local data protection supervisory authority.
Our services are not directed to individuals under 16 years of age. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child without parental consent, we will delete that information promptly.
We regularly review our GDPR compliance practices and update this page to reflect any changes in how we process EU resident data. Material changes will be communicated to affected individuals via email.