GDPR Compliance
Last updated: September 17, 2026
General Data Protection Regulation
Maple & Iron Grooming Co. is committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR) and applicable data protection laws. This document outlines how we comply with GDPR requirements.
Legal Basis for Processing
We process your personal data on the following legal grounds:
- Consent: When you provide explicit consent for specific processing activities
- Contract: To fulfill our service obligations when you book an appointment
- Legitimate Interest: To operate and improve our business services
- Legal Obligation: To comply with applicable laws and regulations
Your GDPR Rights
Under the GDPR, you have the following rights regarding your personal data:
- Right of Access: Request a copy of the personal data we hold about you
- Right to Rectification: Request correction of inaccurate or incomplete data
- Right to Erasure: Request deletion of your personal data under certain circumstances
- Right to Restriction: Request limitation of processing in specific situations
- Right to Data Portability: Receive your data in a structured, commonly used format
- Right to Object: Object to processing based on legitimate interests
- Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent
Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes outlined in our Privacy Policy, or as required by law. Booking information is typically retained for business records and may be kept for up to seven years.
Data Processing
We process personal data in the following ways:
- Appointment booking and management
- Client communication via email
- Service improvement and business analytics
- Marketing communications with your consent
International Data Transfers
Your personal data is processed and stored within Canada. If data is transferred outside of this jurisdiction, we ensure appropriate safeguards are in place to protect your information.
Data Security Measures
We implement appropriate technical and organizational security measures, including:
- Encryption of data in transit and at rest
- Access controls and authentication procedures
- Regular security assessments and updates
- Staff training on data protection practices
Exercising Your Rights
To exercise any of your GDPR rights, please contact us at [email protected]. We will respond to your request within 30 days as required by law.
Complaints
If you believe we have not handled your personal data in accordance with GDPR, you have the right to lodge a complaint with your local data protection authority.
Contact Information
For questions regarding GDPR compliance or to exercise your rights, contact us at [email protected]