Last Updated: October 7, 2026
Calm-tale is committed to protecting the privacy and personal data of all individuals, including those covered by the European Union's General Data Protection Regulation (GDPR). This statement outlines how we comply with GDPR requirements and your rights under this regulation.
For the purposes of GDPR, the data controller is:
Calm-tale
Level 12, 167 Eagle Street
Brisbane City QLD 4000
Australia
Email: [email protected]
We process personal data under the following legal bases:
Under GDPR, you have the following rights regarding your personal data:
You have the right to request copies of your personal data. We may charge a reasonable fee for additional copies if your request is clearly unfounded or excessive.
You have the right to request that we correct any information you believe is inaccurate or complete information you believe is incomplete.
You have the right to request that we erase your personal data under certain conditions, such as when the data is no longer necessary for the purposes for which it was collected.
You have the right to request that we restrict the processing of your personal data under certain conditions.
You have the right to object to our processing of your personal data under certain conditions.
You have the right to request that we transfer the data we have collected to another organization, or directly to you, under certain conditions.
Where we rely on consent to process your personal data, you have the right to withdraw that consent at any time. This will not affect the lawfulness of processing based on consent before its withdrawal.
To exercise any of your GDPR rights, please contact us at [email protected]. We will respond to your request within one month of receipt. If your request is complex or you have made multiple requests, we may extend this period by two further months, and we will inform you of any such extension.
We are committed to processing data in accordance with GDPR principles:
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. If the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay.
If we transfer your personal data outside the European Economic Area (EEA), we ensure that appropriate safeguards are in place, such as:
Where we use third-party service providers to process personal data on our behalf, we ensure that:
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by law. When determining retention periods, we consider:
We do not use automated decision-making or profiling that produces legal effects or similarly significantly affects individuals.
Our services are not directed at children under 16 years of age. We do not knowingly process personal data of children without appropriate parental or guardian consent as required by GDPR.
You have the right to lodge a complaint with a supervisory authority if you believe we have processed your personal data in a manner that violates GDPR. While we encourage you to contact us first, you may contact your local data protection authority.
We may update this GDPR compliance statement periodically to reflect changes in our practices or legal requirements. We will notify you of any material changes by posting the updated statement on our website.
For questions or concerns about our GDPR compliance or to exercise your rights, please contact us:
Email: [email protected]
Address: Level 12, 167 Eagle Street, Brisbane City QLD 4000, Australia