GDPR Compliance
Last Updated: January 15, 2024
Our Commitment to Data Protection
Merry Lotus is committed to protecting the privacy and personal data of all individuals, including those located in the European Economic Area (EEA). We comply with the General Data Protection Regulation (GDPR) and other applicable data protection laws.
Data Controller Information
For the purposes of GDPR, the data controller is:
Merry Lotus
245 Richmond Street West, Suite 400
Toronto, ON M5V 1W2
Canada
Email: [email protected]
Legal Basis for Processing
We process personal data under the following legal bases:
Consent
When you explicitly consent to the processing of your personal data for specific purposes, such as receiving communications from us or using certain features of our website.
Contract Performance
When processing is necessary to perform a contract with you or to take steps at your request before entering into a contract, such as providing our professional services.
Legitimate Interests
When processing is necessary for our legitimate interests, such as improving our services, preventing fraud, and ensuring website security, provided these interests are not overridden by your fundamental rights.
Legal Obligation
When processing is necessary to comply with our legal obligations.
Your Data Subject Rights
Under GDPR, you have the following rights regarding your personal data:
Right of Access
You have the right to request a copy of the personal data we hold about you. We will provide this information within one month of receiving your request.
Right to Rectification
You have the right to request that we correct any inaccurate personal data or complete any incomplete data we hold about you.
Right to Erasure (Right to be Forgotten)
You have the right to request that we delete your personal data in certain circumstances, including:
- When the data is no longer necessary for the purpose it was collected
- When you withdraw consent and there is no other legal basis for processing
- When you object to processing and there are no overriding legitimate grounds
- When the data has been unlawfully processed
Right to Restriction of Processing
You have the right to request that we restrict the processing of your personal data in certain circumstances, such as when you contest the accuracy of the data or when processing is unlawful but you oppose erasure.
Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller where technically feasible.
Right to Object
You have the right to object to the processing of your personal data based on legitimate interests or for direct marketing purposes. We will cease processing unless we have compelling legitimate grounds that override your interests.
Rights Related to Automated Decision-Making
You have the right not to be subject to decisions based solely on automated processing, including profiling, that produce legal effects or similarly significantly affect you.
Exercising Your Rights
To exercise any of your data subject rights, please contact us using the information below. We may need to verify your identity before processing your request. We will respond to your request within one month, although this period may be extended by two further months where necessary.
Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, comply with legal obligations, resolve disputes, and enforce our agreements. Retention periods vary based on the type of data and the purpose of processing.
International Data Transfers
As a Canadian company, we may transfer personal data outside the EEA. Canada has been recognized by the European Commission as providing an adequate level of data protection. For transfers to other jurisdictions, we implement appropriate safeguards such as standard contractual clauses.
Data Security
We implement appropriate technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure, or destruction. These measures include encryption, access controls, and regular security assessments.
Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. If the breach is likely to result in a high risk, we will also notify you directly.
Children's Data
Our services are not directed at individuals under 16 years of age. We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child without appropriate consent, we will delete that information.
Complaints
If you believe that your data protection rights have been violated, you have the right to lodge a complaint with a supervisory authority in the EU member state of your habitual residence, place of work, or place of the alleged infringement.
Updates to This Notice
We may update this GDPR compliance notice from time to time. We will notify you of any material changes by posting the updated notice on our website and updating the "Last Updated" date.
Contact Us
For any questions about this GDPR notice or to exercise your data subject rights, please contact us at:
Merry Lotus
245 Richmond Street West, Suite 400
Toronto, ON M5V 1W2
Canada
Email: [email protected]