Our Commitment to GDPR
stellar-heron is committed to protecting the personal data of all individuals, including those located in the European Economic Area (EEA). This page explains how we comply with the General Data Protection Regulation (GDPR) and outlines your rights under this regulation.
Data Controller
stellar-heron acts as the data controller for personal data collected through our website and services. This means we determine the purposes and means of processing your personal data.
Contact information:
stellar-heron
245 King Street West, Suite 1200
Toronto, ON M5V 1J2
Canada
Email: [email protected]
Legal Basis for Processing
We process personal data only when we have a valid legal basis under the GDPR. Our processing activities are based on:
- Consent: Where you have given clear consent for us to process your personal data for specific purposes
- Contract: Where processing is necessary for the performance of a contract with you or to take steps at your request before entering into a contract
- Legitimate Interests: Where processing is necessary for our legitimate interests or those of a third party, provided those interests are not overridden by your rights
- Legal Obligation: Where processing is necessary to comply with legal requirements
Your Rights Under GDPR
If you are located in the EEA, you have the following rights regarding your personal data:
Right of Access
You have the right to request a copy of the personal data we hold about you and information about how we process it.
Right to Rectification
You have the right to request that we correct any inaccurate personal data or complete any incomplete personal data.
Right to Erasure
You have the right to request that we delete your personal data in certain circumstances, such as when the data is no longer necessary for the purposes for which it was collected.
Right to Restrict Processing
You have the right to request that we restrict the processing of your personal data in certain circumstances, such as when you contest the accuracy of the data.
Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller.
Right to Object
You have the right to object to processing of your personal data based on legitimate interests or for direct marketing purposes.
Right to Withdraw Consent
Where we process your data based on consent, you have the right to withdraw that consent at any time. This will not affect the lawfulness of processing based on consent before its withdrawal.
Exercising Your Rights
To exercise any of these rights, please contact us at [email protected]. We will respond to your request within one month of receiving it. In certain circumstances, this period may be extended by two additional months, in which case we will inform you of the extension and the reasons for it.
International Data Transfers
As we are based in Canada, your personal data may be transferred to and processed in Canada. Canada has been recognized by the European Commission as providing an adequate level of data protection. Where we transfer data to other countries, we ensure appropriate safeguards are in place.
Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by applicable laws. When determining retention periods, we consider the amount and nature of the data, the purposes of processing, and legal requirements.
Complaints
If you believe we have not handled your personal data properly or have concerns about our data practices, you have the right to lodge a complaint with a supervisory authority in the EU member state where you live, work, or where the alleged infringement occurred.
Updates to This Information
We may update this GDPR compliance information from time to time to reflect changes in our practices or legal requirements. We encourage you to review this page periodically.