Information on this site is advertising in nature [email protected]

Our Commitment to GDPR

Sprout Lark is committed to ensuring the security and protection of the personal information that we process, and to provide a compliant and consistent approach to data protection. We have implemented processes and procedures to meet the requirements of the General Data Protection Regulation (GDPR).

This page outlines how we comply with GDPR requirements and explains your rights regarding your personal data.

Legal Basis for Processing

We process personal data under the following lawful bases as defined by GDPR:

  • Consent: Where you have given clear consent for us to process your personal data for a specific purpose.
  • Contract: Where processing is necessary for a contract we have with you, or because you have asked us to take specific steps before entering into a contract.
  • Legal obligation: Where processing is necessary for us to comply with the law.
  • Legitimate interests: Where processing is necessary for our legitimate interests or the legitimate interests of a third party, unless there is a good reason to protect your personal data which overrides those legitimate interests.

Your Rights Under GDPR

Under the GDPR, you have the following rights regarding your personal data:

Right to Access

You have the right to request a copy of the personal data we hold about you. We will provide this information free of charge within one month of receiving your request.

Right to Rectification

You have the right to request that we correct any personal data that is inaccurate or incomplete.

Right to Erasure

You have the right to request that we delete your personal data in certain circumstances, such as when the data is no longer necessary for the purpose for which it was collected.

Right to Restrict Processing

You have the right to request that we restrict the processing of your personal data in certain circumstances, such as when you contest the accuracy of the data.

Right to Data Portability

You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller.

Right to Object

You have the right to object to processing of your personal data based on legitimate interests or for direct marketing purposes.

Rights Related to Automated Decision-Making

You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you.

How to Exercise Your Rights

To exercise any of your rights under GDPR, please contact us at:

  • Email: [email protected]
  • Address: 250 University Avenue, Suite 400, Toronto, ON M5H 3E5, Canada

We will respond to your request within one month. In some cases, we may need to verify your identity before processing your request.

Data Protection Measures

We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:

  • Encryption of personal data where appropriate
  • Regular testing and evaluation of our security measures
  • Staff training on data protection and security
  • Access controls to limit who can access personal data
  • Secure data storage and transmission protocols

Data Transfers

When we transfer personal data outside of the European Economic Area (EEA), we ensure that adequate safeguards are in place to protect your data. These safeguards may include:

  • Standard contractual clauses approved by the European Commission
  • Binding corporate rules
  • Transfer to countries with an adequacy decision

Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly.

Data Protection Officer

For any questions regarding our GDPR compliance or data protection practices, please contact us at [email protected].

Supervisory Authority

If you are located in the European Union and believe that your data protection rights have been violated, you have the right to lodge a complaint with a supervisory authority in the EU member state of your habitual residence, place of work, or place of the alleged infringement.

Updates to This Notice

We may update this GDPR compliance notice from time to time. Any changes will be posted on this page with an updated revision date.

Contact Information

For any questions about GDPR or our data protection practices, please contact:

Sprout Lark
250 University Avenue, Suite 400
Toronto, ON M5H 3E5
Canada
[email protected]