Last Updated: January 2024
brave-sprout is committed to complying with the General Data Protection Regulation (GDPR) for all users located in the European Union and European Economic Area. This page outlines how we handle personal data in accordance with GDPR requirements.
brave-sprout acts as the data controller for personal information collected through our website and services. Our contact details are:
brave-sprout Pty Ltd
Level 12, 100 Collins Street
Melbourne VIC 3000, Australia
Email: [email protected]
We process personal data under the following legal bases:
We process data necessary to provide our travel card services to you, including account creation, transaction processing, and customer support.
We process data required by law, including anti-money laundering regulations, identity verification requirements, and financial reporting obligations.
We process data for legitimate business purposes, including fraud prevention, service improvement, and marketing (where appropriate). We always balance our interests against your rights and freedoms.
Where required, we obtain your explicit consent before processing personal data, such as for marketing communications or optional analytics.
If you are located in the EU/EEA, you have the following rights regarding your personal data:
You have the right to request a copy of the personal data we hold about you. We will provide this information within 30 days of your request.
You have the right to request correction of any inaccurate or incomplete personal data we hold about you.
You have the right to request deletion of your personal data in certain circumstances, such as when the data is no longer necessary for the purposes for which it was collected.
You have the right to request that we restrict the processing of your personal data in certain circumstances, such as when you contest the accuracy of the data.
You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit that data to another controller.
You have the right to object to processing of your personal data in certain circumstances, including processing for direct marketing purposes.
Where processing is based on consent, you have the right to withdraw your consent at any time. This will not affect the lawfulness of processing based on consent before its withdrawal.
As an Australian company, we may transfer your personal data outside the EU/EEA. When we do so, we ensure appropriate safeguards are in place, including:
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law. Retention periods vary based on the type of data and legal requirements. When data is no longer needed, we securely delete or anonymise it.
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly.
To exercise any of your rights under GDPR, please contact us at:
Email: [email protected]
We will respond to your request within 30 days. We may ask you to verify your identity before processing your request.
If you are not satisfied with how we handle your personal data or respond to your requests, you have the right to lodge a complaint with a supervisory authority in the EU member state of your residence, place of work, or where the alleged infringement took place.
We may update this GDPR compliance information from time to time. We will notify you of any significant changes via email or through our website.