Last Updated: July 1, 2026
Introduction
This document outlines how stone-quartz complies with the General Data Protection Regulation (GDPR) and explains the rights available to individuals whose personal data we process.
Legal Basis for Processing
We process personal data under the following legal bases:
- Consent: When you have given clear consent for us to process your personal data for specific purposes
- Contract: When processing is necessary to fulfill our contractual obligations to you (e.g., delivering programs you've registered for)
- Legal Obligation: When we must process your data to comply with legal requirements
- Legitimate Interests: When processing is necessary for our legitimate business interests, provided these don't override your rights and freedoms
Your Rights Under GDPR
Right to Access
You have the right to request copies of your personal data. We may charge a reasonable fee for additional copies or manifestly unfounded requests.
Right to Rectification
You have the right to request correction of any information you believe is inaccurate or completion of information you believe is incomplete.
Right to Erasure
You have the right to request deletion of your personal data under certain conditions, including:
- The data is no longer necessary for the purposes it was collected
- You withdraw consent and there is no other legal basis for processing
- You object to processing and there are no overriding legitimate grounds
- The data has been unlawfully processed
- Legal obligations require deletion
Right to Restrict Processing
You have the right to request restriction of processing your personal data under certain conditions:
- You contest the accuracy of the data
- Processing is unlawful but you oppose erasure
- We no longer need the data but you need it for legal claims
- You have objected to processing pending verification of legitimate grounds
Right to Object
You have the right to object to our processing of your personal data based on legitimate interests or for direct marketing purposes.
Right to Data Portability
You have the right to request transfer of your data to another organization or directly to you in a structured, commonly used, machine-readable format, where technically feasible.
Right to Withdraw Consent
When processing is based on consent, you have the right to withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.
Right to Lodge a Complaint
You have the right to lodge a complaint with a supervisory authority, particularly in your country of residence, workplace, or where an alleged infringement occurred.
How to Exercise Your Rights
To exercise any of these rights, please contact us at:
Email: [email protected]
We will respond to your request within one month. In complex cases, we may extend this period by two additional months and will inform you of the extension.
Data Protection Officer
For questions specifically related to data protection, you may contact our data protection officer at:
Email: [email protected]
International Data Transfers
When we transfer personal data outside the European Economic Area, we ensure appropriate safeguards are in place, including:
- Standard contractual clauses approved by the European Commission
- Adequacy decisions recognizing equivalent data protection in recipient countries
- Your explicit consent for specific transfers
Automated Decision-Making
We do not use automated decision-making or profiling that produces legal effects or similarly significantly affects individuals.
Data Retention
We retain personal data only as long as necessary for the purposes outlined in our Privacy Policy or as required by law. Specific retention periods depend on:
- The nature of the data
- The purposes for which it was collected
- Legal or regulatory requirements
- Legitimate business needs
Data Security Measures
We implement appropriate technical and organizational measures to ensure data security, including:
- Encryption of data in transit and at rest
- Regular security assessments and updates
- Access controls and authentication mechanisms
- Employee training on data protection
- Incident response procedures
Data Breach Notification
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. If the breach poses a high risk, we will also notify affected individuals without undue delay.
Children's Data
We do not knowingly process personal data of individuals under 16 years of age without parental consent. If you believe we have collected data from a child without appropriate consent, please contact us immediately.
Changes to This Document
We may update this GDPR compliance statement periodically to reflect changes in our practices or legal requirements. Significant changes will be communicated through our website and, where appropriate, directly to affected individuals.
Contact Information
For any questions regarding GDPR compliance or to exercise your rights:
stone-quartz
347 West Hastings Street
Vancouver, BC V6B 1H6
Canada
Email: [email protected]