Information presented on this website is promotional in nature

GDPR Compliance

Your rights under the General Data Protection Regulation

Our Commitment to Data Protection

rustic blossom is committed to protecting the privacy and personal data of all individuals, including those located in the European Economic Area (EEA). We comply with the General Data Protection Regulation (GDPR) and ensure that personal data is processed lawfully, fairly, and transparently.

What is GDPR?

The General Data Protection Regulation (GDPR) is a comprehensive data protection law that came into effect on May 25, 2018. It applies to organizations that process personal data of individuals located in the European Economic Area, regardless of where the organization is based. GDPR establishes strict requirements for data protection and grants individuals significant rights over their personal data.

Lawful Basis for Processing

Under GDPR, we must have a lawful basis for processing your personal data. Depending on the nature of processing, we rely on the following legal bases:

Your Rights Under GDPR

If you are located in the EEA, you have the following rights regarding your personal data:

Right to Access

You have the right to request a copy of the personal data we hold about you. This is known as a "data subject access request." We will provide this information free of charge within one month of receiving your request.

Right to Rectification

You have the right to request that we correct any inaccurate personal data we hold about you. You also have the right to have incomplete personal data completed.

Right to Erasure

Also known as the "right to be forgotten," you have the right to request that we delete your personal data in certain circumstances, such as when the data is no longer necessary for the purpose for which it was collected or when you withdraw your consent.

Right to Restrict Processing

You have the right to request that we limit the processing of your personal data in certain circumstances, such as when you contest the accuracy of the data or when the processing is unlawful but you do not want the data erased.

Right to Data Portability

You have the right to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format. You also have the right to request that we transmit this data directly to another controller where technically feasible.

Right to Object

You have the right to object to processing of your personal data in certain circumstances, including processing for direct marketing purposes and processing based on legitimate interests.

Rights Related to Automated Decision Making

You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you.

International Data Transfers

As we are based in Canada, any personal data we collect from individuals in the EEA may be transferred to and processed in Canada. Canada has been recognized by the European Commission as providing an adequate level of data protection. Where we transfer data to other jurisdictions, we ensure appropriate safeguards are in place to protect your personal data.

Data Retention

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including to satisfy legal, accounting, or reporting requirements. To determine the appropriate retention period, we consider the amount, nature, and sensitivity of the data, the potential risk of harm from unauthorized use or disclosure, the purposes for which we process the data, and applicable legal requirements.

Data Security

We have implemented appropriate technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure, or destruction. These measures include encryption, access controls, and regular security assessments.

Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay.

Exercising Your Rights

To exercise any of your GDPR rights, please contact us using the information provided below. We may need to verify your identity before processing your request. We will respond to your request within one month, though this period may be extended by two additional months for complex requests.

Complaints

If you believe that we have not complied with your data protection rights, you have the right to lodge a complaint with a supervisory authority. You can contact the supervisory authority in your country of residence, place of work, or where you believe an infringement has occurred.

Contact Us

For any questions about this GDPR compliance statement or to exercise your data protection rights, please contact us at:

rustic blossom
245 Commerce Street, Suite 400
Toronto, ON M5V 2K4
Canada

Email: [email protected]