vibrant-heath
  • Home
  • About
  • Services
  • Contact
Get Started

GDPR Compliance

Last updated: 1 June 2026

Although vibrant-heath is an Australian company, we are committed to protecting the privacy rights of all individuals, including those in the European Economic Area (EEA) and United Kingdom. This page outlines how we comply with the General Data Protection Regulation (GDPR) for visitors and customers from these regions.

Data Controller

vibrant-heath Pty Ltd acts as the data controller for personal data collected through our website and services. Our contact details are:

vibrant-heath Pty Ltd
Level 4, 127 Creek Street
Brisbane QLD 4000
Australia
Email: [email protected]

Legal Basis for Processing

We process personal data under the following legal bases:

  • Consent: Where you have given clear consent for us to process your personal data for specific purposes (e.g., marketing communications)
  • Contract: Where processing is necessary for the performance of a contract with you or to take steps at your request before entering into a contract
  • Legitimate Interests: Where processing is necessary for our legitimate business interests, provided these are not overridden by your rights
  • Legal Obligation: Where processing is necessary to comply with legal requirements

Your Rights Under GDPR

If you are located in the EEA or UK, you have the following rights regarding your personal data:

Right of Access

You have the right to request copies of your personal data. We may charge a small fee for this service if requests are excessive or unfounded.

Right to Rectification

You have the right to request that we correct any information you believe is inaccurate or complete information you believe is incomplete.

Right to Erasure

You have the right to request that we erase your personal data, under certain conditions. This right is not absolute and may be subject to legal retention requirements.

Right to Restrict Processing

You have the right to request that we restrict the processing of your personal data, under certain conditions.

Right to Object

You have the right to object to our processing of your personal data, under certain conditions, particularly for direct marketing purposes.

Right to Data Portability

You have the right to request that we transfer the data we have collected to another organisation, or directly to you, under certain conditions.

Right to Withdraw Consent

Where we rely on consent as our legal basis, you have the right to withdraw that consent at any time. This does not affect the lawfulness of processing based on consent before withdrawal.

International Data Transfers

As an Australian company, personal data we collect may be stored and processed in Australia. Australia is not considered to have an adequacy decision from the European Commission. When we transfer personal data from the EEA or UK to Australia, we implement appropriate safeguards including:

  • Standard contractual clauses approved by the European Commission
  • Ensuring our Australian data protection practices align with GDPR requirements
  • Only transferring data that is necessary for the purposes outlined

Data Retention

We will only retain your personal data for as long as necessary to fulfil the purposes for which we collected it, including satisfying legal, accounting, or reporting requirements. When determining retention periods, we consider:

  • The nature and sensitivity of the data
  • Potential risk of harm from unauthorised use or disclosure
  • Purposes for which we process the data
  • Whether we can achieve those purposes through other means
  • Applicable legal requirements

Automated Decision-Making

We do not use automated decision-making or profiling that produces legal effects or similarly significantly affects you.

Data Protection Officer

While not required for our organisation under GDPR, we have appointed a privacy officer who oversees data protection matters. Contact:

Email: [email protected]

Supervisory Authority

If you are located in the EEA or UK and believe we have not adequately addressed your concerns, you have the right to lodge a complaint with your local data protection supervisory authority.

Exercising Your Rights

To exercise any of your GDPR rights, please contact us at [email protected]. We will respond to your request within one month. In complex cases, this may be extended by two further months, in which case we will inform you.

We may need to verify your identity before processing your request. We will not charge a fee to access your personal data unless your request is clearly unfounded, repetitive, or excessive.

Updates to This Notice

We may update this GDPR compliance notice from time to time. Any changes will be posted on this page with an updated revision date.

vibrant-heath

Empowering Australians with sustainable energy solutions since 2012. CEC Approved Retailer committed to quality installations and genuine long-term support.

Services

  • Residential Solar
  • Commercial Systems
  • Battery Storage
  • Energy Audits

Company

  • About Us
  • Contact
  • Services

Legal

  • Privacy Policy
  • Terms of Use
  • Cookie Policy
  • GDPR

© 2026 vibrant-heath. All rights reserved. ABN 45 678 912 340

Privacy Terms Cookies

We use cookies to improve your experience on our site. By continuing to browse, you agree to our use of cookies. Learn more