General Data Protection Regulation (GDPR) Compliance
Last Updated: March 9, 2024
Domain ("we," "us," or "our") is committed to protecting the privacy and security of personal data in accordance with the General Data Protection Regulation (GDPR) and applicable data protection laws.
1. Data Controller Information
Domain acts as the data controller for personal data processed through our services.
Contact Information:
Domain
28830 Fraser Hwy, Abbotsford, BC V4X 1G8, Canada
Email: [email protected]
Phone: +15066348080
2. Legal Basis for Processing
We process personal data under the following legal bases:
Consent: Where you have provided explicit consent for specific processing activities.
Contractual Necessity: To fulfill our contractual obligations and deliver services you have requested.
Legitimate Interests: To improve our services, prevent fraud, and ensure system security.
Legal Obligation: To comply with applicable laws and regulations.
3. Personal Data We Collect
We collect and process the following categories of personal data:
Identity Data: Name, username, and similar identifiers.
Contact Data: Email address, telephone number, and physical address.
Financial Data: Payment information and transaction history related to our services.
Technical Data: IP address, browser type, device information, and usage patterns.
Profile Data: Preferences, feedback, and service customization settings.
Usage Data: Information about how you interact with our services.
4. How We Use Your Personal Data
We process personal data for the following purposes:
Service Delivery: To provide automated financial report generation and related services.
Account Management: To create and manage your account and subscriptions.
Communication: To respond to inquiries, provide support, and send service-related notifications.
Improvement and Development: To analyze usage patterns and enhance service quality.
Security: To protect against unauthorized access, fraud, and system abuse.
Compliance: To meet legal and regulatory requirements.
5. Data Sharing and Disclosure
We may share personal data with:
Service Providers: Third-party vendors who assist in delivering our services, including hosting, payment processing, and analytics.
Business Transfers: In connection with mergers, acquisitions, or asset sales, subject to confidentiality obligations.
Legal Requirements: When required by law, court order, or governmental authority.
Protection of Rights: To enforce our terms, protect our rights, and ensure user safety.
We do not sell personal data to third parties.
6. International Data Transfers
Your personal data may be transferred to and processed in countries outside your jurisdiction. When we transfer data internationally, we ensure appropriate safeguards are in place, including:
Standard Contractual Clauses: Approved by relevant data protection authorities.
Adequacy Decisions: Transfers to countries recognized as providing adequate data protection.
Explicit Consent: Where required, we obtain your consent for international transfers.
7. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes outlined in this policy, unless a longer retention period is required by law. Retention periods vary based on:
Account Activity: Data is retained while your account remains active.
Legal Obligations: We retain data to comply with tax, accounting, and legal requirements.
Dispute Resolution: Data may be retained to resolve disputes or enforce agreements.
Upon expiration of the retention period, personal data is securely deleted or anonymized.
8. Your Rights Under GDPR
You have the following rights regarding your personal data:
8.1 Right of Access
You have the right to request confirmation of whether we process your personal data and to obtain a copy of that data.
8.2 Right to Rectification
You may request correction of inaccurate or incomplete personal data.
8.3 Right to Erasure
You may request deletion of your personal data under certain circumstances, including when the data is no longer necessary for the purposes collected or when you withdraw consent.
8.4 Right to Restrict Processing
You may request limitation of processing activities in specific situations, such as when you contest data accuracy or object to processing.
8.5 Right to Data Portability
You have the right to receive your personal data in a structured, commonly used format and to transmit that data to another controller.
8.6 Right to Object
You may object to processing based on legitimate interests or for direct marketing purposes.
8.7 Right to Withdraw Consent
Where processing is based on consent, you may withdraw that consent at any time without affecting the lawfulness of processing prior to withdrawal.
8.8 Right to Lodge a Complaint
You have the right to lodge a complaint with a supervisory authority if you believe your data protection rights have been violated.
9. Exercising Your Rights
To exercise any of your rights, please contact us at:
Email: [email protected]
Phone: +15066348080
We will respond to your request within one month of receipt. In complex cases, we may extend this period by an additional two months and will notify you of any delay.
We may request additional information to verify your identity before processing requests involving personal data.
10. Security Measures
We implement appropriate technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure, or destruction. These measures include:
Encryption: Data is encrypted in transit and at rest using industry-standard protocols.
Access Controls: Strict access limitations ensure only authorized personnel can access personal data.
Security Monitoring: Continuous monitoring detects and responds to security threats.
Regular Audits: Periodic security assessments identify and address vulnerabilities.
Staff Training: Employees receive training on data protection principles and security practices.
11. Data Breach Notification
In the event of a data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. If the breach poses a high risk, we will also notify affected individuals without undue delay.
12. Automated Decision-Making and Profiling
Our services may use automated processing to generate financial reports and provide personalized recommendations. You have the right to:
Be Informed: Receive information about the logic involved in automated decision-making.
Human Intervention: Request human review of automated decisions that significantly affect you.
Contest Decisions: Challenge automated decisions and express your point of view.
13. Children's Privacy
Our services are not directed to individuals under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child without parental consent, we will take steps to delete that information promptly.
14. Cookies and Tracking Technologies
We use cookies and similar tracking technologies to enhance user experience and analyze service usage. You can manage cookie preferences through your browser settings. For detailed information, please refer to our Cookie Policy.
15. Third-Party Links
Our services may contain links to third-party websites or services. We are not responsible for the privacy practices of these external sites. We encourage you to review their privacy policies before providing personal data.
16. Changes to This Policy
We may update this GDPR Compliance Policy periodically to reflect changes in our practices or legal requirements. The "Last Updated" date at the top indicates when the policy was last revised. Continued use of our services after changes constitutes acceptance of the updated policy.
17. Data Protection Officer
For questions regarding data protection or to exercise your rights, you may contact our data protection contact:
Email: [email protected]
Address: 28830 Fraser Hwy, Abbotsford, BC V4X 1G8, Canada
18. Supervisory Authority
If you have concerns about how we handle your personal data, you have the right to lodge a complaint with your local data protection supervisory authority.
19. Consent
By using our services, you acknowledge that you have read and understood this GDPR Compliance Policy and consent to the collection, processing, and use of your personal data as described herein.
For questions, concerns, or requests related to GDPR compliance, please contact us at [email protected] or +15066348080.