Last updated: September 2024

Overview

brave-moss is committed to protecting the privacy and security of personal data in accordance with the General Data Protection Regulation (GDPR) and applicable data protection laws. This page outlines how we comply with GDPR requirements when processing personal data of individuals in the European Economic Area (EEA).

Data Controller

brave-moss acts as the data controller for personal information collected through our website and business operations. Our contact details are:

brave-moss
450 Riverside Drive, Suite 302
Toronto, ON M4J 1A4
Canada
Email: [email protected]

Lawful Basis for Processing

We process personal data under the following lawful bases:

Your Rights Under GDPR

If you are located in the EEA, you have the following rights regarding your personal data:

How to Exercise Your Rights

To exercise any of these rights, please contact us at [email protected] with your request. We will respond within one month of receiving your request, unless the request is complex, in which case we may extend this period by up to two additional months.

We may need to verify your identity before processing your request. There is generally no fee for exercising your rights, though we may charge a reasonable fee for manifestly unfounded or excessive requests.

International Data Transfers

As we are based in Canada, personal data collected from EEA residents may be transferred to Canada. Canada has been recognized by the European Commission as providing an adequate level of data protection. Where data is transferred to other jurisdictions, we ensure appropriate safeguards are in place, such as standard contractual clauses.

Data Retention

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including satisfying legal, accounting, or reporting requirements. The retention period may vary depending on the context and our legal obligations.

Data Security

We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk of processing. These measures include encryption, access controls, and regular security assessments.

Data Breach Notification

In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. Where the breach is likely to result in a high risk, we will also notify affected individuals directly.

Supervisory Authority

If you are located in the EEA and believe we have not adequately addressed your concerns, you have the right to lodge a complaint with your local data protection supervisory authority.

Updates to This Information

We may update this GDPR compliance information periodically. Any changes will be posted on this page with an updated revision date.