GDPR Compliance
Last updated: October 2, 2026
Our Commitment to Data Protection
turquoise-cloud.com is committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR) and Canadian privacy laws, including the Personal Information Protection and Electronic Documents Act (PIPEDA).
Legal Basis for Processing
We process your personal data based on:
- Your consent when you submit forms or agree to communications
- Contractual necessity to provide services you have requested
- Legitimate business interests in improving our services
- Legal obligations we must fulfill
Your GDPR Rights
Under GDPR, you have the following rights regarding your personal data:
Right to Access
You can request confirmation of whether we process your personal data and obtain a copy of that data.
Right to Rectification
You can request correction of inaccurate or incomplete personal data.
Right to Erasure
You can request deletion of your personal data under certain circumstances, including when the data is no longer necessary for the purposes it was collected.
Right to Restriction of Processing
You can request that we limit how we use your personal data in specific situations.
Right to Data Portability
You can request to receive your personal data in a structured, commonly used, machine-readable format and transmit it to another controller.
Right to Object
You can object to processing of your personal data based on legitimate interests or for direct marketing purposes.
Rights Related to Automated Decision-Making
We do not use automated decision-making or profiling that produces legal effects or similarly significant effects.
Data Controller
The data controller responsible for your personal information is:
Turquoise-cloud
437 Wellington Street West
Toronto, ON M5V 1E7
Canada
[email protected]
Data Protection Officer
For questions related to data protection, you can contact our data protection contact at the address above.
International Data Transfers
Your personal data is processed and stored in Canada. We do not transfer personal data outside of Canada without appropriate safeguards.
Data Breach Notification
In the event of a data breach that poses a risk to your rights and freedoms, we will notify you and relevant supervisory authorities within 72 hours as required by GDPR.
How to Exercise Your Rights
To exercise any of your GDPR rights, please contact us at [email protected] with your request. We will respond within 30 days.
Please provide sufficient information to allow us to verify your identity and locate your data in our systems.
Right to Lodge a Complaint
If you believe we have not handled your personal data in accordance with GDPR, you have the right to lodge a complaint with:
- The Office of the Privacy Commissioner of Canada
- Your local data protection supervisory authority if you are in the EU
Data Retention Periods
We retain personal data only as long as necessary for the purposes outlined in our Privacy Policy:
- Consultation inquiries: 2 years from last contact
- Active project data: Duration of project plus 7 years
- Marketing communications: Until consent is withdrawn
- Website analytics: 24 months
Updates to This Statement
We may update this GDPR compliance statement to reflect changes in our practices or legal requirements. Check this page periodically for updates.