GDPR Compliance
Last Updated: May 29, 2026
Our Commitment to GDPR
The General Data Protection Regulation (GDPR) is a comprehensive data protection law that applies to organizations processing personal data of individuals in the European Economic Area (EEA). Although zyra-harbor is based in Canada, we are committed to GDPR principles and extend these protections to all our users regardless of location.
Data Controller Information
For the purposes of GDPR, zyra-harbor acts as the data controller for personal information collected through our website and services.
Contact Information:
zyra-harbor
142 Wellington Street West, Suite 708
Toronto, ON M5J 1H8
Canada
Email: [email protected]
Your Rights Under GDPR
As a data subject, you have the following rights:
1. Right to Access
You have the right to request confirmation of whether we process your personal data and to obtain a copy of that data along with supplementary information about how we process it.
2. Right to Rectification
You may request correction of inaccurate personal data and completion of incomplete personal data we hold about you.
3. Right to Erasure (Right to be Forgotten)
You may request deletion of your personal data when:
- The data is no longer necessary for the purposes it was collected
- You withdraw consent and there is no other legal ground for processing
- You object to processing and there are no overriding legitimate grounds
- The data has been unlawfully processed
- Deletion is required for compliance with a legal obligation
4. Right to Restriction of Processing
You may request restriction of processing when:
- You contest the accuracy of your personal data
- Processing is unlawful but you oppose erasure
- We no longer need the data but you need it for legal claims
- You have objected to processing pending verification of legitimate grounds
5. Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller.
6. Right to Object
You may object to processing of your personal data based on legitimate interests or for direct marketing purposes. We will cease processing unless we demonstrate compelling legitimate grounds that override your interests.
7. Right to Withdraw Consent
Where we process your data based on consent, you have the right to withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.
8. Right to Lodge a Complaint
You have the right to lodge a complaint with a supervisory authority, particularly in the EEA member state of your residence, workplace, or where an alleged infringement occurred.
How to Exercise Your Rights
To exercise any of these rights, please contact us at:
Email: [email protected]
We will respond to your request within one month of receipt. In complex cases, we may extend this period by two additional months and will inform you of any such extension.
Legal Basis for Processing
We process personal data under the following legal bases:
- Consent: You have given clear consent for us to process your personal data for specific purposes
- Contract: Processing is necessary for a contract we have with you, or because you have asked us to take specific steps before entering into a contract
- Legal Obligation: Processing is necessary for us to comply with the law
- Legitimate Interests: Processing is necessary for our legitimate interests or the legitimate interests of a third party, provided your interests and fundamental rights do not override those interests
Data Protection Measures
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- Encryption of personal data in transit and at rest
- Regular security assessments and updates
- Access controls and authentication mechanisms
- Staff training on data protection principles
- Incident response procedures
Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you without undue delay. We will also notify the relevant supervisory authority within 72 hours of becoming aware of the breach, where feasible.
International Data Transfers
When we transfer personal data outside the EEA, we ensure appropriate safeguards are in place, such as:
- Standard contractual clauses approved by the European Commission
- Transfers to countries with adequacy decisions
- Other legally approved transfer mechanisms
Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including legal, accounting, or reporting requirements. Retention periods vary depending on the type of data and purpose of processing.
Automated Decision-Making
We do not use automated decision-making or profiling that produces legal effects or similarly significantly affects you.
Third-Party Data Processors
We work with third-party service providers who process personal data on our behalf. We ensure these processors:
- Provide sufficient guarantees of technical and organizational security measures
- Process data only on our documented instructions
- Maintain confidentiality of personal data
- Comply with GDPR requirements
Updates to This Statement
We may update this GDPR compliance statement to reflect changes in our practices or legal requirements. We will notify you of any material changes and update the "Last Updated" date.
Contact Information
For questions about our GDPR compliance or to exercise your rights, contact:
Email: [email protected]
Address: 142 Wellington Street West, Suite 708, Toronto, ON M5J 1H8, Canada