Last Updated: September 9, 2026
The General Data Protection Regulation (GDPR) is a comprehensive data protection law that applies to organizations processing personal data of individuals in the European Union. While quiet-gorge is based in Canada, we respect the principles of GDPR and are committed to protecting the privacy rights of all our clients.
We process your personal data under the following legal bases:
You have the right to request access to the personal data we hold about you. We will provide you with a copy of your data in a commonly used electronic format.
If your personal information is inaccurate or incomplete, you have the right to request that we correct or complete it.
Also known as the "right to be forgotten," you can request deletion of your personal data when:
You can request that we limit how we use your personal data in certain circumstances, such as when you contest the accuracy of the data.
You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller.
You can object to processing of your personal data when:
Where processing is based on consent, you have the right to withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing based on consent before withdrawal.
You have the right to lodge a complaint with a supervisory authority if you believe your data protection rights have been violated.
For questions regarding GDPR compliance or to exercise your rights, please contact us at:
To exercise any of your GDPR rights, please send a written request to the email address above. Include:
We will respond to your request within 30 days. In complex cases, we may extend this period by an additional 60 days and will inform you of any such extension.
Your personal data is processed and stored in Canada. We implement appropriate safeguards to ensure your data receives an adequate level of protection when transferred internationally.
We implement technical and organizational measures to ensure a level of security appropriate to the risk, including:
In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify you without undue delay and no later than 72 hours after becoming aware of the breach.
We do not use automated decision-making or profiling that produces legal effects or similarly significantly affects you.
We may update this GDPR compliance statement to reflect changes in our practices or legal requirements. Material changes will be communicated through our website and, where appropriate, by email.