General Data Protection Regulation Compliance
Grand Spire is committed to compliance with the General Data Protection Regulation (GDPR) and respects the data protection rights of individuals in the European Economic Area (EEA), United Kingdom, and Switzerland.
Legal Basis for Processing
We process personal data only when we have a legal basis to do so. Our legal bases include:
- Consent: When you have given clear consent for us to process your personal data for specific purposes
- Contract: When processing is necessary to fulfill contractual obligations with you
- Legal obligation: When we must process data to comply with legal requirements
- Legitimate interests: When processing serves our legitimate business interests and does not override your rights and freedoms
Your GDPR Rights
Under GDPR, individuals have the following rights regarding their personal data:
Right of Access
You have the right to request confirmation of whether we process your personal data and to access that data. We will provide a copy of your personal data in a commonly used electronic format.
Right to Rectification
You may request correction of inaccurate or incomplete personal data we hold about you. We will make corrections within a reasonable timeframe.
Right to Erasure
You may request deletion of your personal data when it is no longer necessary for the purposes for which it was collected, when you withdraw consent, or when there is no overriding legitimate ground for continued processing.
Right to Restriction of Processing
You may request that we restrict processing of your personal data in certain circumstances, such as when you contest the accuracy of the data or object to processing.
Right to Data Portability
You have the right to receive personal data you provided to us in a structured, commonly used, machine-readable format and to transmit that data to another controller.
Right to Object
You may object to processing of your personal data based on legitimate interests or for direct marketing purposes. We will cease processing unless we demonstrate compelling legitimate grounds that override your interests.
Right to Withdraw Consent
Where processing is based on consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing conducted before withdrawal.
Right to Lodge a Complaint
You have the right to lodge a complaint with a supervisory authority in your jurisdiction if you believe our processing of your personal data violates GDPR.
Exercising Your Rights
To exercise any of these rights, please submit a request to [email protected]. Include sufficient information to allow us to verify your identity and specify which right you wish to exercise.
We will respond to your request without undue delay and within one month of receipt. In complex cases, we may extend this period by two additional months and will inform you of any such extension.
Data Controller Information
Grand Spire Research Consultancy is the data controller responsible for processing your personal data. Our contact information is:
Grand Spire Research Consultancy
1247 Bay Street, Suite 820
Toronto, ON M5R 2B4
Canada
Email: [email protected]
Data Processing Activities
We process personal data for the following purposes:
- Responding to inquiries and providing research services
- Managing client relationships and project delivery
- Improving our services and website functionality
- Complying with legal and regulatory obligations
Data Recipients
Personal data may be shared with:
- Service providers who assist in website operations, data storage, or business processes, under strict confidentiality agreements
- Legal and regulatory authorities when required by law
- Professional advisors such as lawyers and accountants, subject to confidentiality obligations
International Data Transfers
When we transfer personal data outside the EEA, we implement appropriate safeguards to ensure adequate protection, including:
- Standard Contractual Clauses approved by the European Commission
- Adequacy decisions recognizing equivalent data protection standards
- Other legally recognized transfer mechanisms
Data Retention
We retain personal data only as long as necessary for the purposes for which it was collected or as required by law. Retention periods vary based on:
- The nature of the data and purpose of processing
- Legal, regulatory, or contractual retention requirements
- Legitimate business needs such as dispute resolution
Automated Decision-Making
We do not engage in automated decision-making, including profiling, that produces legal effects or similarly significantly affects individuals.
Data Security
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- Encryption of personal data in transit and at rest
- Access controls limiting data access to authorized personnel
- Regular security assessments and updates
- Incident response procedures for data breaches
Data Breach Notification
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. If the breach poses a high risk, we will also notify affected individuals without undue delay.
Updates to This Policy
We may update this GDPR compliance information to reflect changes in our practices or legal requirements. Material changes will be communicated through our website with an updated effective date.
Contact and Questions
If you have questions about our GDPR compliance practices or wish to exercise your data protection rights, please contact us at [email protected].