witty-threads
Home About Services Contact

GDPR Compliance

Last Updated: May 29, 2026

witty-threads is committed to protecting the privacy and data rights of all individuals, including those protected under the European Union's General Data Protection Regulation (GDPR). This page outlines our GDPR compliance measures and your rights under this regulation.

Our Commitment to GDPR

Although witty-threads is based in Canada, we recognize and respect the data protection rights of individuals in the European Economic Area (EEA) and process their personal data in accordance with GDPR requirements when applicable.

Lawful Bases for Processing

We process personal data under the following lawful bases as defined by GDPR:

Consent

When you submit an inquiry or reservation form, you provide consent for us to process your personal data for the purposes stated at the time of collection. You may withdraw consent at any time by contacting us.

Contractual Necessity

When you purchase our services, we process your data as necessary to fulfill our contractual obligations, including delivering route materials, scheduling sessions, and providing customer support.

Legitimate Interests

We may process data based on our legitimate business interests, such as improving our services, preventing fraud, and ensuring website security. We balance these interests against your fundamental rights and freedoms.

Legal Obligations

We may process data when required to comply with legal obligations, such as tax regulations and accounting requirements.

Your Rights Under GDPR

If you are located in the EEA, you have the following rights regarding your personal data:

Right to Access

You have the right to request a copy of the personal data we hold about you. We will provide this information within 30 days of receiving a valid request.

Right to Rectification

You have the right to request that we correct any inaccurate or incomplete personal data we hold about you.

Right to Erasure (Right to be Forgotten)

You have the right to request that we delete your personal data in certain circumstances, including:

  • When the data is no longer necessary for the purpose it was collected
  • When you withdraw consent and no other legal basis exists
  • When you object to processing and there are no overriding legitimate grounds
  • When the data has been unlawfully processed

Right to Restrict Processing

You have the right to request that we limit how we use your personal data in certain circumstances, such as when you contest the accuracy of the data or object to processing.

Right to Data Portability

You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit that data to another controller without hindrance.

Right to Object

You have the right to object to processing of your personal data based on legitimate interests or for direct marketing purposes. We will cease processing unless we demonstrate compelling legitimate grounds that override your interests.

Rights Related to Automated Decision-Making

You have the right not to be subject to decisions based solely on automated processing, including profiling, that produce legal or similarly significant effects. We do not currently engage in such automated decision-making.

International Data Transfers

As a Canadian company, your data may be transferred to and processed in Canada. Canada has been recognized by the European Commission as providing an adequate level of data protection. We ensure that any international transfers of personal data comply with GDPR requirements through appropriate safeguards.

Data Retention

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including:

  • Active customer data: Duration of customer relationship plus 3 years
  • Marketing data: Until consent is withdrawn or 2 years of inactivity
  • Transaction records: 7 years as required by tax regulations

Data Security

We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:

  • Encryption of data in transit and at rest
  • Regular security assessments
  • Access controls and authentication measures
  • Employee training on data protection
  • Incident response procedures

Data Protection Officer

While we are not required to appoint a Data Protection Officer under GDPR, we have designated a privacy contact who can address your questions and concerns regarding data protection.

Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. If the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay.

Children's Data

Our services are not directed to individuals under 18 years of age. We do not knowingly collect personal data from children. If we learn that we have collected personal data from a child, we will take steps to delete that information promptly.

Exercising Your Rights

To exercise any of your rights under GDPR, please contact us using the information below. We may need to verify your identity before processing your request. We will respond to all legitimate requests within 30 days.

Complaints

If you believe that we have not handled your personal data properly or have infringed your rights, you have the right to lodge a complaint with a supervisory authority in the EU member state of your habitual residence, place of work, or place of the alleged infringement.

Contact Us

For questions about GDPR compliance or to exercise your data protection rights, please contact us at:

witty-threads
Data Protection Contact
1847 Queen Street West, Suite 302
Toronto, Ontario M6R 1A7
Canada
Email: [email protected]

We will make every effort to respond to your inquiries promptly and to address any concerns you may have regarding our data protection practices.

witty-threads

Walking routes for leaders who think deeply.

Home About Services Contact
Privacy Policy Terms of Use Cookies Policy GDPR
© 2026 witty-threads. All rights reserved.

We use cookies to enhance your experience. By continuing to visit this site you agree to our use of cookies. Learn more