GDPR Compliance
Your data protection rights
Our Commitment to Data Protection
Surname Mosaic is committed to protecting your personal data and respecting your privacy. This page outlines how we comply with data protection regulations and explains your rights regarding your personal information.
Data Controller
Surname Mosaic acts as the data controller for personal information collected through this website. We determine the purposes and means of processing your personal data and are responsible for ensuring compliance with applicable data protection laws.
Legal Basis for Processing
We process your personal data based on the following legal grounds:
- Consent: When you explicitly agree to the processing of your data for specific purposes
- Contract: When processing is necessary to fulfill a contract with you, such as booking an appointment
- Legitimate Interest: When we have a legitimate business interest that does not override your rights
- Legal Obligation: When processing is required to comply with legal requirements
Your Rights Under GDPR
You have the following rights regarding your personal data:
Right of Access: You have the right to request a copy of the personal data we hold about you.
Right to Rectification: You have the right to request that we correct any inaccurate or incomplete personal data.
Right to Erasure: You have the right to request that we delete your personal data, subject to certain conditions.
Right to Restrict Processing: You have the right to request that we limit the processing of your personal data in certain circumstances.
Right to Data Portability: You have the right to receive your personal data in a structured, commonly used, and machine-readable format.
Right to Object: You have the right to object to the processing of your personal data for certain purposes, including direct marketing.
Right to Withdraw Consent: Where processing is based on consent, you have the right to withdraw that consent at any time.
Data Transfers
We primarily process data within Canada. If any data is transferred outside of Canada or the European Economic Area, we ensure appropriate safeguards are in place to protect your personal information.
Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by law. When data is no longer needed, we securely delete or anonymize it.
Security Measures
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- Encryption of data in transit and at rest where appropriate
- Regular assessment and evaluation of security measures
- Access controls to limit who can access personal data
- Staff training on data protection practices
Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority and, where required, affected individuals without undue delay.
Exercising Your Rights
To exercise any of your rights, please contact us at [email protected]. We will respond to your request within one month, though this period may be extended in complex cases.
Complaints
If you believe that your data protection rights have been violated, you have the right to lodge a complaint with the Office of the Privacy Commissioner of Canada or your local data protection authority.