Overview
The General Data Protection Regulation (GDPR) is a comprehensive data protection law that governs how organizations collect, store, and process personal data of individuals in the European Union and European Economic Area. While our business operates in Canada, we respect the principles of GDPR for all visitors to our website.
Data Controller
Modern Barber Lounge acts as the data controller for personal information collected through this website. This means we determine the purposes and means of processing your personal data.
Contact Information:
Email: [email protected]
Address: 847 Wellington Street West, Toronto, Ontario M5V 1G3, Canada
Legal Basis for Processing
We process personal data based on one or more of the following legal grounds:
- Consent: You have given clear consent for us to process your personal data for a specific purpose, such as receiving communications or submitting appointment requests.
- Contractual Necessity: Processing is necessary to fulfill a contract with you or to take steps at your request before entering into a contract.
- Legal Obligation: Processing is necessary to comply with applicable laws or regulations.
- Legitimate Interests: Processing is necessary for our legitimate business interests, provided these do not override your fundamental rights and freedoms.
Your Rights Under GDPR
If you are located in the EU or EEA, you have the following rights concerning your personal data:
Right to Access
You have the right to request a copy of the personal data we hold about you. We will provide this information free of charge within one month of receiving your request.
Right to Rectification
You have the right to request correction of any inaccurate personal data we hold about you. You may also request completion of incomplete data.
Right to Erasure
Also known as the "right to be forgotten," you may request deletion of your personal data under certain circumstances, including when the data is no longer necessary for the purpose it was collected.
Right to Restrict Processing
You have the right to request that we limit the processing of your personal data under certain conditions, such as when you contest the accuracy of the data.
Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, and machine-readable format. You may also request that we transfer this data directly to another controller where technically feasible.
Right to Object
You have the right to object to processing of your personal data based on legitimate interests or for direct marketing purposes. Upon objection, we will cease processing unless we demonstrate compelling legitimate grounds.
Rights Related to Automated Decision-Making
You have the right not to be subject to decisions based solely on automated processing, including profiling, that produce legal or similarly significant effects. We do not currently engage in automated decision-making of this nature.
Exercising Your Rights
To exercise any of these rights, please contact us using the information provided above. We will respond to your request within one month. This period may be extended by two additional months for complex requests, in which case we will inform you of the extension and reasons for it.
We may request verification of your identity before processing your request to ensure we are communicating with the correct individual.
Data Transfers
As our operations are based in Canada, personal data collected from EU/EEA residents may be transferred to and processed in Canada. Canada has been recognized by the European Commission as providing an adequate level of data protection under its Personal Information Protection and Electronic Documents Act (PIPEDA).
Data Security
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- Encryption of data in transit
- Regular security assessments
- Access controls limiting who can view personal data
- Staff training on data protection practices
Data Breach Notification
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. If the breach poses a high risk to you, we will also notify you directly without undue delay.
Complaints
If you believe that your data protection rights have been violated, you have the right to lodge a complaint with a supervisory authority in the EU member state of your residence, place of work, or place of the alleged infringement.
Updates to This Notice
We may update this GDPR compliance notice periodically. Changes will be posted on this page with an updated revision date.
Last updated: September 2026