We use cookies to enhance your browsing experience and analyze site traffic. By continuing to use this site, you consent to our use of cookies.

sapphire-birch
Commercial Information
  • Home
  • Services
  • About
  • Contact

GDPR Compliance

Last Updated: June 16, 2026

Our Commitment to GDPR

sapphire-birch is committed to compliance with the General Data Protection Regulation (GDPR) and respecting the privacy rights of individuals in the European Economic Area (EEA). This page outlines how we meet our obligations under GDPR.

Data Controller

For the purposes of GDPR, sapphire-birch is the data controller responsible for your personal information. Our contact details are:

sapphire-birch
142 King Street West
Toronto, ON M5H 1J5
Canada
Email: [email protected]

Legal Basis for Processing

We process personal data only when we have a lawful basis to do so under GDPR Article 6:

  • Consent (Article 6(1)(a)): When you have given clear, affirmative consent for us to process your personal data for specific purposes
  • Contract (Article 6(1)(b)): When processing is necessary to perform a contract with you or to take steps at your request before entering into a contract
  • Legal Obligation (Article 6(1)(c)): When we must process your data to comply with legal requirements
  • Legitimate Interests (Article 6(1)(f)): When processing is necessary for our legitimate business interests, provided these do not override your fundamental rights and freedoms

Your Rights Under GDPR

As an individual in the EEA, you have the following rights regarding your personal data:

Right to Access (Article 15)

You have the right to request confirmation of whether we are processing your personal data and, if so, to access that data along with certain information about how it is being processed.

Right to Rectification (Article 16)

You have the right to request correction of inaccurate personal data and to have incomplete personal data completed.

Right to Erasure (Article 17)

You have the right to request deletion of your personal data in certain circumstances, including when:

  • The data is no longer necessary for the purposes for which it was collected
  • You withdraw consent and there is no other legal basis for processing
  • You object to processing and there are no overriding legitimate grounds
  • The data has been unlawfully processed

Right to Restriction of Processing (Article 18)

You have the right to request restriction of processing in certain situations, such as when you contest the accuracy of the data or object to processing.

Right to Data Portability (Article 20)

You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller where technically feasible.

Right to Object (Article 21)

You have the right to object to processing based on legitimate interests or for direct marketing purposes. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests.

Rights Related to Automated Decision-Making (Article 22)

You have the right not to be subject to decisions based solely on automated processing, including profiling, which produces legal effects or similarly significantly affects you. We do not currently engage in automated decision-making of this nature.

Exercising Your Rights

To exercise any of your rights under GDPR, please contact us at [email protected] with:

  • Your full name and contact information
  • A clear description of the right you wish to exercise
  • Any relevant details to help us locate your information

We will respond to your request within one month, though this period may be extended by two additional months where necessary, considering the complexity and number of requests. We will inform you of any such extension within the initial one-month period.

Data Protection Principles

We adhere to the GDPR data protection principles, ensuring that personal data is:

  • Processed lawfully, fairly, and transparently
  • Collected for specified, explicit, and legitimate purposes
  • Adequate, relevant, and limited to what is necessary
  • Accurate and kept up to date
  • Kept only as long as necessary
  • Processed securely with appropriate technical and organizational measures

International Data Transfers

When we transfer personal data outside the EEA, we ensure appropriate safeguards are in place, such as:

  • Standard Contractual Clauses approved by the European Commission
  • Transfers to countries with adequacy decisions
  • Other legally approved transfer mechanisms

Data Security

We implement appropriate technical and organizational security measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. These measures include:

  • Encryption of data in transit and at rest
  • Access controls and authentication requirements
  • Regular security assessments and updates
  • Staff training on data protection

Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you without undue delay. We will also notify the relevant supervisory authority within 72 hours of becoming aware of the breach, where feasible.

Right to Lodge a Complaint

You have the right to lodge a complaint with a supervisory authority, particularly in the EEA member state of your habitual residence, place of work, or place of the alleged infringement, if you believe our processing of your personal data violates GDPR.

Data Retention

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including legal, accounting, or reporting requirements. Retention periods vary depending on the type of data and the purpose of processing:

  • Inquiry and consultation data: Retained for 3 years after last contact
  • Client project data: Retained for 7 years after project completion for legal and professional obligations
  • Marketing communications data: Retained until consent is withdrawn

Children's Data

We do not knowingly process personal data of children under 16 years of age. If we become aware that we have collected data from a child, we will take steps to delete it promptly.

Updates to This Page

We may update this GDPR compliance information from time to time to reflect changes in our practices or legal requirements. Significant changes will be communicated through our website.

Contact Us

For questions about our GDPR compliance or to exercise your rights, please contact us at [email protected].

sapphire-birch

Revealing the hidden geography of business decisions since 2019.

Legal

  • Privacy Policy
  • Terms of Use
  • GDPR
  • Cookie Policy

Reach Us

[email protected]

Toronto, Ontario, Canada

© 2026 sapphire-birch. All rights reserved.