GDPR Compliance
Last updated: June 2, 2026
1. Our Commitment to GDPR
Puffin Leaf Knowledge Systems is committed to compliance with the General Data Protection Regulation (GDPR) and respecting the data protection rights of individuals in the European Economic Area (EEA).
2. Legal Basis for Processing
We process your personal data based on the following legal grounds:
- Consent: You have given clear consent for us to process your personal data for specific purposes
- Contract: Processing is necessary to fulfill our contract with you
- Legal obligation: Processing is necessary to comply with the law
- Legitimate interests: Processing is necessary for our legitimate business interests, provided these do not override your rights
3. Your GDPR Rights
Under GDPR, you have the following rights:
3.1 Right to Access
You have the right to request copies of your personal data.
3.2 Right to Rectification
You have the right to request correction of inaccurate or incomplete personal data.
3.3 Right to Erasure
You have the right to request deletion of your personal data under certain conditions.
3.4 Right to Restrict Processing
You have the right to request restriction of processing your personal data under certain conditions.
3.5 Right to Data Portability
You have the right to request transfer of your data to another organization or directly to you.
3.6 Right to Object
You have the right to object to our processing of your personal data under certain conditions.
3.7 Rights Related to Automated Decision-Making
You have the right not to be subject to decisions based solely on automated processing, including profiling.
4. How to Exercise Your Rights
To exercise any of your GDPR rights, please contact us at:
Email: [email protected]
We will respond to your request within one month of receipt. In complex cases, this may be extended by two additional months.
5. Data Protection Officer
For questions about our GDPR compliance or to exercise your rights, you may contact our Data Protection Officer:
Email: [email protected]
Address: 438 Queen Street West, Suite 201, Toronto, ON M5V 2A8, Canada
6. Data Security Measures
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- Encryption of personal data in transit and at rest
- Regular security assessments and audits
- Access controls and authentication mechanisms
- Employee training on data protection
- Incident response procedures
7. Data Breach Notification
In the event of a data breach that poses a risk to your rights and freedoms, we will notify you and the relevant supervisory authority within 72 hours of becoming aware of the breach.
8. International Data Transfers
When we transfer your data outside the EEA, we ensure appropriate safeguards are in place, such as:
- Standard contractual clauses approved by the European Commission
- Adequacy decisions confirming adequate protection in the recipient country
- Binding corporate rules where applicable
9. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, unless a longer retention period is required by law.
10. Third-Party Processors
We work with third-party service providers who process data on our behalf. All processors are contractually bound to GDPR compliance and appropriate security measures.
11. Children's Data
Our services are not directed at children under 16. We do not knowingly collect or process personal data from children under 16 without parental consent.
12. Right to Lodge a Complaint
You have the right to lodge a complaint with a supervisory authority, particularly in the EU member state where you reside, work, or where an alleged infringement occurred.
13. Updates to This Statement
We may update this GDPR compliance statement from time to time. Significant changes will be communicated to you via email or prominent notice on our website.
14. Contact Information
For any questions about our GDPR compliance practices:
Email: [email protected]
Address: 438 Queen Street West, Suite 201, Toronto, ON M5V 2A8, Canada