General Data Protection Regulation Information
moon-puffin is committed to protecting your personal data and respecting your privacy rights under the General Data Protection Regulation (GDPR). This page outlines how we comply with GDPR requirements and your rights as a data subject.
We process your personal data only when we have a legal basis to do so. The legal bases we rely on include:
Under the GDPR, you have the following rights regarding your personal data:
You have the right to request copies of your personal data. We may charge a small fee for this service in cases of excessive or repetitive requests.
You have the right to request that we correct any information you believe is inaccurate or complete information you believe is incomplete.
You have the right to request that we erase your personal data, under certain conditions.
You have the right to request that we restrict the processing of your personal data, under certain conditions.
You have the right to object to our processing of your personal data, under certain conditions.
You have the right to request that we transfer the data we have collected to another organization, or directly to you, under certain conditions.
Where we rely on consent as the legal basis for processing your personal data, you have the right to withdraw that consent at any time.
If you wish to exercise any of your GDPR rights, please contact us at:
Email: [email protected]
We will respond to your request within one month of receiving it. In complex cases, we may extend this period by two additional months, and we will inform you of any such extension.
For questions specifically related to data protection and GDPR compliance, you can contact our Data Protection Officer at [email protected]
We are based in Canada and primarily serve Canadian customers. If we transfer your data outside of the European Economic Area, we ensure that appropriate safeguards are in place to protect your personal data in accordance with GDPR requirements.
We have implemented appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the relevant supervisory authority within 72 hours of becoming aware of the breach.
We do not use automated decision-making or profiling that produces legal effects or similarly significantly affects you.
If you believe we have not handled your personal data in accordance with GDPR, you have the right to lodge a complaint with a supervisory authority. In Canada, you can contact the Office of the Privacy Commissioner of Canada.
We may update this GDPR compliance page from time to time. Any changes will be posted on this page with an updated revision date.
For any questions or concerns regarding GDPR compliance or data protection:
Email: [email protected]
Address: 452 Wellington Street West, Toronto, ON M5V 1E3, Canada