This website contains promotional content about our services

GDPR Compliance

Information about how we comply with the General Data Protection Regulation.

Last updated: September 2024

Our Commitment to GDPR

stone-panther is committed to protecting the privacy and security of personal data in accordance with the General Data Protection Regulation (GDPR). This page outlines how we comply with GDPR requirements and explains the rights available to individuals whose data we process.

Data Controller Information

For the purposes of GDPR, stone-panther acts as a data controller for personal information collected through our website and services. Our contact details are:

stone-panther
1055 West Hastings Street, Suite 1400
Vancouver, BC V6E 2E9
Canada
Email: [email protected]

Legal Basis for Processing

We process personal data under the following legal bases as defined by GDPR:

Your Rights Under GDPR

If you are located in the European Economic Area (EEA), you have certain rights regarding your personal data:

Exercising Your Rights

To exercise any of these rights, please contact us at [email protected]. We will respond to your request within one month, though this period may be extended by two further months where necessary, taking into account the complexity and number of requests.

We may request specific information from you to help us confirm your identity and ensure your right to access your personal data or exercise any of your other rights.

Data Transfers

When we transfer personal data outside of the EEA, we ensure appropriate safeguards are in place to protect your data, including:

Data Retention

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including to satisfy any legal, accounting, or reporting requirements. The retention period may vary depending on the context of the processing and our legal obligations.

Data Security

We have implemented appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:

Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, where feasible. If the breach is likely to result in a high risk to individuals, we will also notify the affected individuals without undue delay.

Complaints

If you have concerns about our data processing practices, you have the right to lodge a complaint with a supervisory authority. We would, however, appreciate the opportunity to address your concerns before you approach the supervisory authority, so please contact us in the first instance.

Changes to This Notice

We may update this GDPR notice from time to time. We will notify you of any significant changes by posting the updated notice on our website and updating the "Last updated" date.