Your data protection rights under the General Data Protection Regulation
Comet Mink is committed to protecting the personal data of all individuals, including those residing in the European Economic Area (EEA). This page outlines how we comply with the General Data Protection Regulation (GDPR) and your rights under this regulation.
Comet Mink acts as the data controller for personal information collected through our website and services. Our contact details are:
Comet Mink
742 Riverside Drive
Whistler, BC V8E 0A1
Canada
[email protected]
We process personal data under the following legal bases:
If you are a resident of the EEA, you have the following rights regarding your personal data:
You have the right to request a copy of the personal data we hold about you and information about how we process it.
You have the right to request correction of any inaccurate personal data we hold about you.
You have the right to request deletion of your personal data in certain circumstances, such as when the data is no longer necessary for the purpose it was collected.
You have the right to request that we restrict processing of your personal data in certain circumstances, such as when you contest the accuracy of the data.
You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit it to another controller.
You have the right to object to processing of your personal data based on legitimate interests or for direct marketing purposes.
You have the right not to be subject to decisions based solely on automated processing, including profiling, that produces legal effects concerning you.
To exercise any of these rights, please contact us at [email protected]. We will respond to your request within one month. In certain circumstances, we may extend this period by two additional months if necessary.
There is no fee for exercising your rights, although we may charge a reasonable fee or refuse to comply with requests that are manifestly unfounded or excessive.
As a Canadian company, we may transfer personal data outside the EEA. When we do so, we ensure appropriate safeguards are in place, such as:
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by applicable laws. When personal data is no longer needed, we securely delete or anonymize it.
We implement appropriate technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure, or destruction. These measures include encryption, access controls, and regular security assessments.
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours. If the breach is likely to result in a high risk to you, we will also notify you directly.
If you believe we have not handled your personal data properly, you have the right to lodge a complaint with your local data protection authority. However, we encourage you to contact us first so we can address your concerns directly.
We may update this GDPR compliance information from time to time. Any changes will be posted on this page with an updated revision date.
For questions about GDPR compliance or to exercise your data protection rights, please contact our Data Protection Officer: