GDPR Compliance
Your data protection rights under the General Data Protection Regulation
Last updated: January 2024
About This Notice
This page provides information about how gentle savanna complies with the General Data Protection Regulation (GDPR) for individuals located in the European Economic Area (EEA). The GDPR is a regulation that strengthens and unifies data protection for individuals within the European Union.
If you are a resident of the EEA, you have certain data protection rights. gentle savanna aims to take reasonable steps to allow you to correct, amend, delete, or limit the use of your personal data.
Data Controller
gentle savanna is the data controller responsible for your personal data collected through our website and services.
Contact information:
Email: [email protected]
Address: 2847 Maple Grove Boulevard, Suite 450, Vancouver, BC V6K 3M9, Canada
Legal Basis for Processing
Under the GDPR, we must have a legal basis for processing your personal data. We rely on the following legal bases:
- Consent: You have given clear consent for us to process your personal data for a specific purpose.
- Contract: Processing is necessary for a contract we have with you or because you have asked us to take specific steps before entering into a contract.
- Legal Obligation: Processing is necessary for us to comply with the law.
- Legitimate Interests: Processing is necessary for our legitimate interests or the legitimate interests of a third party, unless there is a good reason to protect your personal data that overrides those legitimate interests.
Your Rights Under GDPR
If you are a resident of the EEA, you have the following data protection rights:
Right to Access
You have the right to request copies of your personal data. We may charge a small fee for this service in certain circumstances.
Right to Rectification
You have the right to request that we correct any information you believe is inaccurate. You also have the right to request that we complete information you believe is incomplete.
Right to Erasure
You have the right to request that we erase your personal data, under certain conditions. This right is not absolute and may be limited by our legal obligations or legitimate business needs.
Right to Restrict Processing
You have the right to request that we restrict the processing of your personal data, under certain conditions.
Right to Object to Processing
You have the right to object to our processing of your personal data, under certain conditions, particularly where we process your data for direct marketing purposes or based on our legitimate interests.
Right to Data Portability
You have the right to request that we transfer the data we have collected to another organization, or directly to you, under certain conditions.
Right to Withdraw Consent
Where we rely on consent as the legal basis for processing your personal data, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
How to Exercise Your Rights
To exercise any of these rights, please contact us using the contact information provided above. We will respond to your request within one month of receipt. If your request is complex or you have made multiple requests, we may extend this period by two months, in which case we will inform you of the extension.
We may need to verify your identity before processing your request. If we cannot verify your identity, we may request additional information.
International Data Transfers
Your personal data may be transferred to and processed in countries outside the EEA. When we transfer your data outside the EEA, we ensure appropriate safeguards are in place, such as:
- Standard contractual clauses approved by the European Commission
- Transfers to countries that have been deemed to provide an adequate level of data protection by the European Commission
- Other legally recognized transfer mechanisms
Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including to satisfy legal, accounting, or reporting requirements. The retention period depends on the nature of the data and the purposes for which it is processed.
Data Security
We have implemented appropriate technical and organizational security measures designed to protect the security of any personal data we process. However, please note that no electronic transmission or storage of information is completely secure, and we cannot guarantee absolute security.
Automated Decision-Making
We do not use automated decision-making, including profiling, in a way that produces legal effects concerning you or similarly significantly affects you without human involvement.
Supervisory Authority
If you are a resident of the EEA and believe we are unlawfully processing your personal data, you have the right to lodge a complaint with your local data protection supervisory authority. You can find the contact details for data protection authorities in the EEA at the European Data Protection Board website.
Changes to This Notice
We may update this GDPR notice from time to time. The updated version will be indicated by an updated "Last updated" date. We encourage you to review this notice periodically to stay informed about how we are protecting your information in compliance with GDPR.
Contact Us
If you have questions about our GDPR compliance or wish to exercise your data protection rights, please contact us at:
Email: [email protected]
Address: 2847 Maple Grove Boulevard, Suite 450, Vancouver, BC V6K 3M9, Canada