General Data Protection Regulation Information
Although our operations are based in Canada, we recognize that individuals from the European Union may use our services. This page outlines how we comply with the General Data Protection Regulation (GDPR) when processing personal data of EU residents.
We process personal data based on the following legal grounds:
For the purposes of GDPR, the data controller is:
snug-cliff
427 Wilderness Trail
Banff, Alberta T1L 1A3
Canada
Email: [email protected]
If you are an EU resident, you have the following rights regarding your personal data:
You may request confirmation of whether we process your personal data and obtain a copy of that data in a structured, commonly used format.
You may request correction of inaccurate personal data and completion of incomplete data.
Under certain circumstances, you may request deletion of your personal data. This right is not absolute and may be limited by legal retention obligations.
You may request that we limit how we use your personal data in specific situations, such as when you contest the accuracy of the data or object to processing.
You may request transfer of your personal data to another service provider in a machine-readable format, where technically feasible.
You may object to processing based on legitimate interests or for direct marketing purposes. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests.
Where processing is based on consent, you may withdraw that consent at any time. This does not affect the lawfulness of processing that occurred before withdrawal.
We do not use automated decision-making or profiling that produces legal effects or similarly significant impacts on individuals.
Your personal data is processed and stored in Canada. When we transfer data from the EU to Canada, we rely on the European Commission's adequacy decision or implement appropriate safeguards such as standard contractual clauses.
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected:
We implement technical and organizational measures to protect personal data against unauthorized access, accidental loss, destruction, or damage. These measures include encryption, access controls, regular security assessments, and staff training on data protection obligations.
In the event of a data breach that poses a risk to your rights and freedoms, we will notify you and relevant supervisory authorities within 72 hours of becoming aware of the breach, as required by GDPR.
To exercise any of the rights described above, please contact us at [email protected] with your request. We will respond within one month of receiving your request. In complex cases, we may extend this period by an additional two months and will inform you of any such extension.
If you believe our processing of your personal data violates GDPR, you have the right to lodge a complaint with your local data protection authority in the EU.
We regularly review our data protection practices to ensure ongoing compliance with GDPR requirements. Significant changes to our processing activities or this notice will be communicated to affected individuals.