Last Updated: October 2026
Comet-nest is committed to protecting the personal data of all individuals, including those residing in the European Economic Area (EEA). While we are based in Australia, we recognise the importance of the General Data Protection Regulation (GDPR) and have implemented measures to ensure compliance when processing personal data of EU residents.
Comet-nest acts as the data controller for the personal data we collect through our website and services. This means we determine the purposes and means of processing your personal data.
We process personal data on the following legal bases:
If you are a resident of the European Economic Area, you have the following rights:
You have the right to request a copy of the personal data we hold about you. We will provide this information within one month of your request.
You have the right to request that we correct any inaccurate or incomplete personal data we hold about you.
You have the right to request that we delete your personal data in certain circumstances, such as when the data is no longer necessary for the purpose for which it was collected.
You have the right to request that we restrict the processing of your personal data in certain circumstances, such as when you contest the accuracy of the data.
You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller.
You have the right to object to the processing of your personal data in certain circumstances, including processing for direct marketing purposes.
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you.
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy legal, accounting, or reporting requirements. The retention period may vary depending on the context and the type of data.
As we are based in Australia, personal data collected from EU residents may be transferred to and processed in Australia. We ensure that such transfers are conducted in compliance with applicable data protection laws and that appropriate safeguards are in place to protect your personal data.
We have implemented appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, or destruction. These measures include encryption, access controls, and regular security assessments.
In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. If the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly.
To exercise any of your rights under GDPR, please contact us using the details below. We will respond to your request within one month. In some cases, we may need to verify your identity before processing your request.
For any questions or requests regarding your personal data or this GDPR policy, please contact:
Comet-nest
Level 12, 45 Collins Street
Melbourne VIC 3000
Australia
Email: [email protected]
If you believe that your data protection rights have been violated, you have the right to lodge a complaint with a supervisory authority in the EU member state of your habitual residence, place of work, or place of the alleged infringement.