Last Updated: September 2, 2026
Branch-lark is committed to protecting the personal data of individuals in accordance with the General Data Protection Regulation (GDPR) and applicable Australian privacy legislation. This document outlines how we comply with GDPR requirements for any European Union residents who use our services or website.
We process personal data based on the following legal grounds:
Under GDPR, you have the following rights regarding your personal data:
To exercise any of these rights, contact us at [email protected] with your request. We will respond within 30 days and may request additional information to verify your identity before processing certain requests.
You also have the right to lodge a complaint with a supervisory authority if you believe we have not handled your data appropriately. For EU residents, this is the data protection authority in your country of residence.
We collect and process personal data only for specified, explicit purposes related to providing architectural consultation services. Data is not used for purposes incompatible with the original collection purpose without obtaining new consent.
Categories of personal data we may process include contact information, project details, correspondence records, and technical data from website usage.
Personal data may be shared with specialist consultants or service providers when necessary to deliver services, and only with appropriate safeguards in place. We do not engage in bulk data sales or marketing list sharing.
As we operate from Australia, data may be transferred outside the European Economic Area. When such transfers occur, we ensure appropriate safeguards are implemented, such as standard contractual clauses or adequacy decisions.
We retain personal data only as long as necessary for the purposes for which it was collected, or to comply with legal and professional obligations. Consultation records are typically retained for seven years, while website analytics data is retained for two years.
Upon expiration of retention periods, personal data is securely deleted or anonymized unless ongoing retention is required by law.
We implement appropriate technical and organizational measures to protect personal data against unauthorized access, accidental loss, destruction, or damage. These measures include encryption, access controls, secure storage systems, and regular security assessments.
For questions specifically related to GDPR compliance or data protection matters, you may contact our data protection contact at [email protected]. We will address data protection inquiries separately from general business communications.
Where processing is based on consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing that occurred before withdrawal. Note that withdrawing consent may prevent us from providing certain services that require the data in question.
Our services are not directed at individuals under 16 years of age. We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected such data, we will take steps to delete it promptly.
This GDPR compliance statement may be updated to reflect changes in our practices or legal requirements. Material changes will be communicated through prominent website notice, and where required, through direct communication to affected individuals.