v3.0 · EU + UK customers

GDPR Compliance

We're a Canadian company that serves EU customers, so GDPR + PIPEDA + UK-GDPR all apply. Here's what that means in practice.

01

Lawful basis

Contract (we provide hosting), consent (marketing), legal obligation (tax, court orders), legitimate interest (fraud prevention).

02

Your rights

Access, rectification, erasure, restriction, portability, objection, withdrawal of consent. Exercise from Settings → Privacy or by emailing [email protected].

03

Data Processing Agreement

EU customers receive a GDPR Article 28 DPA auto-attached at signup. Available on request for any account.

04

Sub-processors

Full list at /legal/subprocessors. We notify you 30 days before adding any new sub-processor.

05

International transfers

Standard Contractual Clauses for all transfers outside the EEA. EU customer data lives in AMS1 or FRA1 by default.

06

Data Protection Officer

Reachable at [email protected] · also our Canadian Privacy Officer for PIPEDA matters.

07

Supervisory authority

You may lodge a complaint with your local DPA. For Canadian customers: the Office of the Privacy Commissioner of Canada.