Introduction

senvatrixbitca is committed to ensuring compliance with the General Data Protection Regulation (GDPR) for visitors and customers from the European Economic Area (EEA). This page outlines how we handle personal data in accordance with GDPR requirements and explains your rights under this regulation.

Data Controller

For the purposes of GDPR, senvatrixbitca acts as the data controller for personal data collected through our website and services. Our contact information is:

senvatrixbitca
250 University Avenue, Suite 400
Toronto, Ontario M5H 3E5
Canada

Email: [email protected]

Legal Basis for Processing

We process personal data only when we have a valid legal basis to do so. The legal bases we rely on include:

Consent

When you provide explicit consent for specific processing activities, such as subscribing to our newsletter or accepting non-essential cookies. You may withdraw your consent at any time.

Contractual Necessity

When processing is necessary to fulfill a contract with you, such as providing access to courses you have purchased or responding to service inquiries.

Legitimate Interests

When processing is necessary for our legitimate business interests, provided these do not override your fundamental rights and freedoms. Examples include fraud prevention, network security, and business analytics.

Legal Obligation

When we are required to process personal data to comply with applicable laws, such as tax regulations or responding to lawful requests from public authorities.

Your Rights Under GDPR

If you are located in the EEA, you have the following rights regarding your personal data:

Right of Access

You have the right to request a copy of the personal data we hold about you. We will provide this information within one month of your request, free of charge for the first request.

Right to Rectification

You have the right to request that we correct any inaccurate personal data or complete any incomplete data we hold about you.

Right to Erasure

Also known as the "right to be forgotten," you have the right to request that we delete your personal data in certain circumstances, such as when the data is no longer necessary for the purposes for which it was collected.

Right to Restrict Processing

You have the right to request that we limit how we use your personal data in certain circumstances, such as while we verify the accuracy of data you have contested.

Right to Data Portability

You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller without hindrance.

Right to Object

You have the right to object to processing of your personal data based on legitimate interests, including profiling. We will stop processing unless we can demonstrate compelling legitimate grounds.

Rights Related to Automated Decision Making

You have the right not to be subject to decisions based solely on automated processing, including profiling, that produce legal or similarly significant effects. We do not currently engage in such automated decision-making.

Exercising Your Rights

To exercise any of these rights, please contact us at [email protected]. We may request specific information to verify your identity before processing your request. We will respond to your request within one month, though this period may be extended by two additional months for complex requests.

International Data Transfers

As a Canadian organization, data we collect may be transferred to and processed in Canada. Canada has been recognized by the European Commission as providing an adequate level of data protection. For any transfers to countries without adequacy decisions, we implement appropriate safeguards such as Standard Contractual Clauses.

Data Retention

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including to satisfy legal, accounting, or reporting requirements. The specific retention period depends on the nature of the data and the purposes for processing.

Data Security

We implement appropriate technical and organizational measures to protect personal data against unauthorized or unlawful processing, accidental loss, destruction, or damage. These measures include encryption, access controls, and regular security assessments.

Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. If the breach is likely to result in a high risk to affected individuals, we will also notify those individuals directly.

Children's Data

Our services are not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us immediately.

Complaints

If you believe that your data protection rights have been violated, you have the right to lodge a complaint with a supervisory authority in the EU member state of your residence, place of work, or the place of the alleged violation.

Updates to This Information

We may update this GDPR compliance information from time to time to reflect changes in our practices or legal requirements. We encourage you to review this page periodically for the latest information.

Contact Our Privacy Team

For any questions or concerns about our GDPR compliance or data protection practices, please contact us at:

Email: [email protected]

We are committed to working with you to obtain a fair resolution of any complaint or concern about privacy.