Last Updated: May 11, 2026
Crystal Pebble is committed to complying with the General Data Protection Regulation (GDPR) and protecting the rights of individuals in the European Economic Area (EEA), even though we are based in Australia.
We process personal data under the following legal bases:
If you are located in the EEA, you have the following rights:
You can request a copy of the personal data we hold about you.
You can request correction of inaccurate or incomplete personal data.
You can request deletion of your personal data in certain circumstances.
You can request that we limit how we use your personal data.
You can request to receive your personal data in a structured, commonly used format.
You can object to processing of your personal data based on legitimate interests.
Where processing is based on consent, you can withdraw that consent at any time.
You have the right to lodge a complaint with a supervisory authority in the EEA.
To exercise any of these rights, please contact us at:
Email: [email protected]
We will respond to your request within one month of receipt.
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
As we are based in Australia, personal data from the EEA may be transferred to and processed in Australia. We ensure appropriate safeguards are in place for such transfers.
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by law. Specific retention periods depend on the type of data and the purpose of processing.
We do not use automated decision-making or profiling that produces legal effects or similarly significantly affects individuals.
We work with carefully selected third-party service providers who process personal data on our behalf. We ensure these processors comply with GDPR requirements through contractual agreements.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the relevant supervisory authority within 72 hours of becoming aware of the breach.
We may update this GDPR Compliance Statement to reflect changes in our practices or legal requirements. The updated version will be indicated by the "Last Updated" date.
For questions about our GDPR compliance or to exercise your rights, please contact:
Email: [email protected]
Address: Level 12, 180 Lonsdale Street, Melbourne VIC 3000, Australia