Information on this site is advertising in nature.

Our Commitment to GDPR

willow bridge is committed to complying with the General Data Protection Regulation (GDPR) when processing personal data of individuals located in the European Economic Area (EEA). This page explains how we handle your data in accordance with GDPR requirements.

Data Controller

For the purposes of GDPR, willow bridge acts as the data controller for personal data collected through this website. Our contact information:

willow bridge
180 John Street, Suite 402
Toronto, Ontario M5T 1X5
Canada
Email: [email protected]

Legal Basis for Processing

We process personal data under the following legal bases:

Your Rights Under GDPR

If you are located in the EEA, you have the following rights regarding your personal data:

Exercising Your Rights

To exercise any of your GDPR rights, please contact us at [email protected]. We will respond to your request within one month. In complex cases or if we receive a high volume of requests, we may extend this period by an additional two months, in which case we will inform you of the extension.

We may ask you to verify your identity before processing your request. There is generally no fee for exercising your rights, although we may charge a reasonable fee for manifestly unfounded or excessive requests.

Data Transfers

As willow bridge is based in Canada, your personal data may be transferred to and processed in Canada. Canada has been recognized by the European Commission as providing an adequate level of data protection. Where we transfer data to other countries, we ensure appropriate safeguards are in place, such as standard contractual clauses approved by the European Commission.

Data Retention

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected. The specific retention period depends on the nature of the data and our legal obligations. Contact form submissions are typically retained for 24 months unless you request earlier deletion.

Data Security

We implement appropriate technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure, or destruction. These measures include encryption, access controls, and regular security assessments.

Data Breach Notification

In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. If the breach poses a high risk to you, we will also notify you directly.

Supervisory Authority

If you believe we have not handled your personal data appropriately, you have the right to lodge a complaint with a supervisory authority in your country of residence. A list of EEA supervisory authorities is available on the European Data Protection Board website.

Updates to This Information

We may update this GDPR compliance information from time to time. Any significant changes will be communicated through our website.

Contact Us

For questions about GDPR compliance or to exercise your rights, please contact us at:

Email: [email protected]