While our primary operations are based in Canada, we recognize that some users may be located in the European Economic Area. We have implemented practices aligned with the General Data Protection Regulation to protect the rights of all users.
We process personal data based on the following legal grounds:
Under GDPR, you have the following rights regarding your personal data:
You may request confirmation of what personal data we hold about you and obtain a copy of that data. We provide this information in a commonly used electronic format.
If personal information we hold is inaccurate or incomplete, you may request corrections. We will update records and notify relevant third parties where appropriate.
You may request deletion of your personal data when it is no longer necessary for the purposes collected, when you withdraw consent, or when you object to processing. Some data must be retained for legal compliance.
You may request that we limit how we use your data in specific circumstances, such as when you contest the accuracy of information or object to processing.
You may receive your personal data in a structured, commonly used format and transmit it to another service provider where technically feasible.
You may object to processing based on legitimate interests or for direct marketing purposes. We will cease such processing unless we demonstrate compelling legitimate grounds.
We do not make decisions based solely on automated processing that produce legal effects or similarly significant impacts on individuals.
To exercise any of these rights, submit a written request to [email protected]. We may request additional information to verify your identity before processing requests.
We respond to requests within one month of receipt. If the request is complex or we receive multiple requests, we may extend the response period by two months and will notify you of the extension.
We implement technical and organizational measures to protect personal data:
In the event of a data breach that poses a risk to your rights and freedoms, we will notify affected individuals within 72 hours of becoming aware of the breach. Notifications will include the nature of the breach, likely consequences, and measures taken to address it.
When transferring data outside the EEA, we use appropriate safeguards such as Standard Contractual Clauses approved by the European Commission. You may request copies of these safeguards.
Where we rely on consent for processing, you may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing that occurred before withdrawal.
We maintain records demonstrating when and how consent was obtained for marketing communications and non-essential cookies.
If you believe our data processing practices violate GDPR, you have the right to lodge a complaint with a supervisory authority in your jurisdiction. We encourage you to contact us first so we can address concerns directly.
For data protection inquiries, contact [email protected]. We treat privacy concerns seriously and will investigate all reported issues.