GDPR Compliance
Last updated: September 10, 2026
This page explains how spry-sequoia complies with the General Data Protection Regulation (GDPR) and outlines your rights as a data subject.
Data Controller
For the purposes of GDPR, spry-sequoia acts as the data controller for personal information collected through our website and services.
Contact information:
Email: [email protected]
Address: 127 Wellington Street West, Toronto, Ontario M5J 1H6, Canada
Legal Basis for Processing
We process your personal data under the following legal bases:
- Consent: When you provide explicit consent for specific processing activities
- Contract: When processing is necessary to fulfill our service agreement with you
- Legitimate interests: When we have legitimate business interests that do not override your rights
- Legal obligation: When required by law
Your Rights Under GDPR
If you are located in the European Economic Area, you have the following rights:
Right to Access
You have the right to request access to the personal data we hold about you and receive a copy of that data.
Right to Rectification
You have the right to request correction of inaccurate or incomplete personal data.
Right to Erasure
You have the right to request deletion of your personal data under certain circumstances, such as when the data is no longer necessary for the purposes for which it was collected.
Right to Restriction of Processing
You have the right to request that we limit the processing of your personal data in specific situations.
Right to Data Portability
You have the right to receive your personal data in a structured, commonly used format and transmit it to another controller.
Right to Object
You have the right to object to processing of your personal data based on legitimate interests or for direct marketing purposes.
Right to Withdraw Consent
Where processing is based on consent, you have the right to withdraw that consent at any time.
How to Exercise Your Rights
To exercise any of your GDPR rights, please contact us at [email protected]. We will respond to your request within 30 days.
You also have the right to lodge a complaint with a supervisory authority if you believe our processing of your personal data violates GDPR.
Data Protection Measures
We implement appropriate technical and organizational security measures to protect your personal data, including:
- Encryption of data in transit and at rest
- Access controls and authentication
- Regular security assessments
- Staff training on data protection
- Secure data storage and backup procedures
Data Transfers
We are based in Canada. If you are accessing our services from the European Economic Area, please be aware that your data may be transferred to and processed in Canada. We ensure appropriate safeguards are in place for such transfers.
Data Retention
We retain personal data only as long as necessary for the purposes outlined in our Privacy Policy or as required by law. When data is no longer needed, we securely delete or anonymize it.
Children's Data
We do not knowingly collect or process personal data from individuals under 16 years of age. If we become aware that we have collected such data, we will take steps to delete it promptly.
Updates to This Statement
We may update this GDPR compliance statement from time to time. Changes will be posted on this page with an updated date.
Contact Us
If you have questions about our GDPR compliance or wish to exercise your rights, please contact us at [email protected].