Last updated: September 2024
Overview
brave-moss is committed to protecting the privacy and security of personal data in accordance with the General Data Protection Regulation (GDPR) and applicable data protection laws. This page outlines how we comply with GDPR requirements when processing personal data of individuals in the European Economic Area (EEA).
Data Controller
brave-moss acts as the data controller for personal information collected through our website and business operations. Our contact details are:
brave-moss
450 Riverside Drive, Suite 302
Toronto, ON M4J 1A4
Canada
Email: [email protected]
Lawful Basis for Processing
We process personal data under the following lawful bases:
- Consent: When you submit inquiry forms or subscribe to communications, you provide explicit consent for us to process your data for the specified purposes.
- Contractual Necessity: Processing required to fulfill service agreements or take pre-contractual steps at your request.
- Legitimate Interests: Processing necessary for our legitimate business interests, provided these do not override your fundamental rights and freedoms.
- Legal Obligation: Processing required to comply with applicable laws and regulations.
Your Rights Under GDPR
If you are located in the EEA, you have the following rights regarding your personal data:
- Right of Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete personal data.
- Right to Erasure: Request deletion of your personal data under certain circumstances.
- Right to Restrict Processing: Request limitation of processing activities in specific situations.
- Right to Data Portability: Receive your personal data in a structured, commonly used format.
- Right to Object: Object to processing based on legitimate interests or for direct marketing purposes.
- Right to Withdraw Consent: Withdraw previously given consent at any time.
How to Exercise Your Rights
To exercise any of these rights, please contact us at [email protected] with your request. We will respond within one month of receiving your request, unless the request is complex, in which case we may extend this period by up to two additional months.
We may need to verify your identity before processing your request. There is generally no fee for exercising your rights, though we may charge a reasonable fee for manifestly unfounded or excessive requests.
International Data Transfers
As we are based in Canada, personal data collected from EEA residents may be transferred to Canada. Canada has been recognized by the European Commission as providing an adequate level of data protection. Where data is transferred to other jurisdictions, we ensure appropriate safeguards are in place, such as standard contractual clauses.
Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including satisfying legal, accounting, or reporting requirements. The retention period may vary depending on the context and our legal obligations.
Data Security
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk of processing. These measures include encryption, access controls, and regular security assessments.
Data Breach Notification
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. Where the breach is likely to result in a high risk, we will also notify affected individuals directly.
Supervisory Authority
If you are located in the EEA and believe we have not adequately addressed your concerns, you have the right to lodge a complaint with your local data protection supervisory authority.
Updates to This Information
We may update this GDPR compliance information periodically. Any changes will be posted on this page with an updated revision date.