Our commitment to European data protection standards
The General Data Protection Regulation (GDPR) is a comprehensive data protection law that applies to organizations processing personal data of individuals in the European Union. Although Demonphary is based in Canada, we recognize the importance of GDPR compliance when serving clients with EU connections or processing data of EU residents.
This page outlines how we address GDPR requirements in our operations and the rights available to individuals whose data falls under GDPR jurisdiction.
Under GDPR, processing of personal data requires a valid legal basis. Depending on the context, we process personal data under one or more of the following grounds:
If your personal data is subject to GDPR, you have the following rights:
You may request confirmation of whether we process your personal data and, if so, access to that data along with information about how it is processed.
You may request correction of inaccurate personal data or completion of incomplete data we hold about you.
In certain circumstances, you may request deletion of your personal data. This right applies when data is no longer necessary for its original purpose, you withdraw consent, or data has been unlawfully processed.
You may request restriction of processing in specific situations, such as when you contest the accuracy of data or object to processing pending verification of legitimate grounds.
Where processing is based on consent or contract and carried out by automated means, you may request to receive your personal data in a structured, commonly used, machine-readable format.
You may object to processing based on legitimate interests or for direct marketing purposes. We will cease processing unless we demonstrate compelling legitimate grounds that override your interests.
You have the right not to be subject to decisions based solely on automated processing that significantly affect you, with certain exceptions. We do not currently make such automated decisions.
As a Canadian organization, data transfers from the EU to Canada benefit from the European Commission's adequacy decision recognizing Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) as providing adequate protection for personal data. Where necessary, we implement additional safeguards such as Standard Contractual Clauses approved by the European Commission.
While not legally required to appoint a Data Protection Officer, we maintain internal responsibility for data protection compliance. Privacy inquiries may be directed to our contact address below.
If you believe we have not adequately addressed your concerns, you have the right to lodge a complaint with a supervisory authority in the EU Member State of your habitual residence, place of work, or place of the alleged infringement.
We review and update our GDPR compliance practices regularly to reflect changes in regulations, guidance, and our operations. Material changes will be communicated through appropriate channels.
For questions about our GDPR compliance or to exercise your rights:
Demonphary
425 University Avenue, Suite 1200
Toronto, Ontario M5G 1T6
Canada
Email: [email protected]