GDPR Compliance
We're a Canadian company that serves EU customers, so GDPR + PIPEDA + UK-GDPR all apply. Here's what that means in practice.
Lawful basis
Contract (we provide hosting), consent (marketing), legal obligation (tax, court orders), legitimate interest (fraud prevention).
Your rights
Access, rectification, erasure, restriction, portability, objection, withdrawal of consent. Exercise from Settings → Privacy or by emailing [email protected].
Data Processing Agreement
EU customers receive a GDPR Article 28 DPA auto-attached at signup. Available on request for any account.
Sub-processors
Full list at /legal/subprocessors. We notify you 30 days before adding any new sub-processor.
International transfers
Standard Contractual Clauses for all transfers outside the EEA. EU customer data lives in AMS1 or FRA1 by default.
Data Protection Officer
Reachable at [email protected] · also our Canadian Privacy Officer for PIPEDA matters.
Supervisory authority
You may lodge a complaint with your local DPA. For Canadian customers: the Office of the Privacy Commissioner of Canada.