GDPR Compliance Statement
General Data Protection Regulation
Our Commitment to GDPR
petite-reserve is committed to protecting the privacy and security of personal data in accordance with the General Data Protection Regulation (GDPR) (EU) 2016/679. This statement outlines how we comply with GDPR requirements and protect the rights of individuals whose personal data we process.
Data Controller Information
Data Controller: petite-reserve
Address: 1255 Bay Street, Suite 800, Toronto, ON M5R 2A9, Canada
Email: [email protected]
Legal Basis for Processing
We process personal data under the following legal bases:
- Consent: You have given clear consent for us to process your personal data for specific purposes
- Contract: Processing is necessary for the performance of a contract with you or to take steps at your request before entering into a contract
- Legal Obligation: Processing is necessary for compliance with a legal obligation
- Legitimate Interests: Processing is necessary for our legitimate interests or those of a third party, except where such interests are overridden by your rights and freedoms
Your Rights Under GDPR
As a data subject, you have the following rights:
Right to Access
You have the right to request copies of your personal data. We may charge a reasonable fee for additional copies if requests are manifestly unfounded or excessive.
Right to Rectification
You have the right to request that we correct any information you believe is inaccurate or complete information you believe is incomplete.
Right to Erasure
You have the right to request that we erase your personal data, under certain conditions.
Right to Restrict Processing
You have the right to request that we restrict the processing of your personal data, under certain conditions.
Right to Object to Processing
You have the right to object to our processing of your personal data, under certain conditions.
Right to Data Portability
You have the right to request that we transfer the data we have collected to another organization, or directly to you, under certain conditions.
Right to Withdraw Consent
Where we rely on consent as the legal basis for processing, you have the right to withdraw that consent at any time.
How to Exercise Your Rights
To exercise any of your GDPR rights, please contact us at:
Email: [email protected]
Subject Line: GDPR Request
We will respond to your request within one month. If your request is particularly complex or you have made multiple requests, we may extend this period by two further months, and we will inform you of any such extension.
Data Protection Measures
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- Pseudonymization and encryption of personal data where appropriate
- Ensuring ongoing confidentiality, integrity, availability, and resilience of processing systems
- Regular testing, assessment, and evaluation of the effectiveness of security measures
- Staff training on data protection principles and practices
- Procedures for reporting and addressing personal data breaches
Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you without undue delay. We will also notify the relevant supervisory authority within 72 hours of becoming aware of the breach, where feasible.
International Data Transfers
When we transfer personal data outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, such as:
- Standard Contractual Clauses approved by the European Commission
- Adequacy decisions recognizing that certain countries provide adequate data protection
- Other legally approved transfer mechanisms
Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including:
- Satisfying any legal, accounting, or reporting requirements
- Establishing, exercising, or defending legal claims
- Maintaining business records for legitimate business purposes
When personal data is no longer required, we will securely delete or anonymize it.
Automated Decision-Making
We do not engage in automated decision-making or profiling that produces legal effects or similarly significantly affects individuals.
Third-Party Processors
When we engage third-party processors to handle personal data on our behalf, we ensure they:
- Process data only on our documented instructions
- Implement appropriate technical and organizational security measures
- Maintain confidentiality of personal data
- Assist us in meeting our GDPR obligations
Complaints
If you believe we have not handled your personal data in accordance with GDPR, you have the right to lodge a complaint with a supervisory authority. In the European Union, you may contact your local data protection authority. You may also contact:
Office of the Privacy Commissioner of Canada
30 Victoria Street, Gatineau, Quebec K1A 1H3
Toll-free: 1-800-282-1376
Website: www.priv.gc.ca
Updates to This Statement
We may update this GDPR Compliance Statement from time to time to reflect changes in our practices or legal requirements. Any updates will be posted on this page with a revised date.
Contact Information
For any questions regarding our GDPR compliance or data protection practices, please contact:
Email: [email protected]
Address: 1255 Bay Street, Suite 800, Toronto, ON M5R 2A9, Canada