Information on this site is advertising in nature

Overview

The General Data Protection Regulation (GDPR) is a regulation in EU law on data protection and privacy for all individuals within the European Union and the European Economic Area. Although Plateau-sequoia is based in Canada, we are committed to providing GDPR-level protections for all our users, regardless of their location.

Data Controller

For the purposes of the GDPR, Plateau-sequoia acts as the data controller for personal data collected through our website and services. Our contact details are:

Plateau-sequoia
215 Richmond Street West
Toronto, ON M5V 1W2
Canada

Email: [email protected]

Lawful Basis for Processing

We process personal data only when we have a lawful basis to do so. The lawful bases we rely on include:

  • Consent: You have given clear consent for us to process your personal data for a specific purpose.
  • Contract: Processing is necessary for a contract we have with you, or because you have asked us to take specific steps before entering into a contract.
  • Legal obligation: Processing is necessary for us to comply with the law.
  • Legitimate interests: Processing is necessary for our legitimate interests or the legitimate interests of a third party, unless there is a good reason to protect your personal data which overrides those legitimate interests.

Your Rights Under GDPR

Under the GDPR, you have the following rights regarding your personal data:

Right to Access

You have the right to request copies of your personal data. We may charge a small fee for this service in certain circumstances.

Right to Rectification

You have the right to request that we correct any information you believe is inaccurate. You also have the right to request that we complete information you believe is incomplete.

Right to Erasure

You have the right to request that we erase your personal data, under certain conditions. This is also known as the "right to be forgotten."

Right to Restrict Processing

You have the right to request that we restrict the processing of your personal data, under certain conditions.

Right to Object to Processing

You have the right to object to our processing of your personal data, under certain conditions, particularly where we are processing data based on our legitimate interests.

Right to Data Portability

You have the right to request that we transfer the data we have collected to another organization, or directly to you, under certain conditions.

Exercising Your Rights

If you wish to exercise any of these rights, please contact us at [email protected]. We will respond to your request within one month of receipt. In certain circumstances, this period may be extended by two further months, in which case we will inform you of the extension and the reasons for it.

We may ask you to verify your identity before fulfilling your request. This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it.

Data Retention

We will only retain your personal data for as long as necessary to fulfill the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.

To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorized use or disclosure, the purposes for which we process your personal data, and whether we can achieve those purposes through other means.

International Transfers

Your personal data may be transferred to and processed in countries outside the European Economic Area. When we transfer your data outside the EEA, we ensure that appropriate safeguards are in place to protect your personal data, such as standard contractual clauses approved by the European Commission.

Data Security

We have implemented appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:

  • Encryption of personal data where appropriate
  • Regular testing and evaluation of technical and organizational measures
  • Procedures for regularly assessing security measures
  • Access controls to limit access to personal data

Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. If the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly.

Complaints

If you have concerns about how we handle your personal data, you have the right to lodge a complaint with a supervisory authority. For EU residents, you can find your local supervisory authority through the European Data Protection Board website.

Updates to This Information

We may update this GDPR compliance information from time to time. Any changes will be posted on this page with an updated revision date.

Last updated: October 2024