GDPR Compliance
Our commitment to data protection and your privacy rights
fell-finch is committed to protecting the privacy and security of personal data in compliance with the General Data Protection Regulation (GDPR) and other applicable data protection laws.
Data Controller
fell-finch acts as the data controller for personal information collected through our website. Our contact details are:
fell-finch
250 Front Street West, Suite 1400
Toronto, ON M5V 3G5
Canada
Email: [email protected]
Legal Basis for Processing
We process personal data under one or more of the following legal bases:
- Consent: Where you have given clear consent for us to process your personal data for a specific purpose
- Contractual necessity: Where processing is necessary to perform a contract with you or to take steps at your request before entering into a contract
- Legal obligation: Where processing is necessary to comply with applicable laws
- Legitimate interests: Where processing is necessary for our legitimate business interests, provided these do not override your fundamental rights and freedoms
Your Rights Under GDPR
If you are in the European Economic Area, you have the following rights regarding your personal data:
Right to Access
You have the right to request copies of your personal data. We may charge a reasonable fee for additional copies.
Right to Rectification
You have the right to request correction of any information you believe is inaccurate or to complete information you believe is incomplete.
Right to Erasure
You have the right to request deletion of your personal data under certain conditions, including when the data is no longer necessary for its original purpose.
Right to Restrict Processing
You have the right to request that we restrict the processing of your personal data under certain conditions.
Right to Object
You have the right to object to our processing of your personal data under certain conditions, including processing for direct marketing purposes.
Right to Data Portability
You have the right to request that we transfer data we have collected to another organization, or directly to you, under certain conditions.
Right to Withdraw Consent
Where we rely on consent as the legal basis for processing, you have the right to withdraw your consent at any time.
Exercising Your Rights
To exercise any of your rights, please contact us at [email protected]. We will respond to your request within one month. This period may be extended by two additional months if necessary, taking into account the complexity and number of requests.
International Data Transfers
Your personal data may be transferred to and processed in countries outside the European Economic Area. When we transfer data internationally, we ensure appropriate safeguards are in place, such as standard contractual clauses approved by the European Commission.
Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, unless a longer retention period is required by law or for legitimate business purposes.
Data Security
We implement appropriate technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure, or destruction. These measures include encryption, access controls, and regular security assessments.
Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. If the breach is likely to result in a high risk, we will also notify affected individuals without undue delay.
Complaints
If you believe your data protection rights have been violated, you have the right to lodge a complaint with a supervisory authority. In Canada, you may contact the Office of the Privacy Commissioner of Canada. For EU residents, you may contact your local data protection authority.
Updates to This Notice
We may update this GDPR compliance notice from time to time. We encourage you to review this page periodically for the latest information on our data protection practices.