GDPR Compliance
Last updated: September 16, 2026
General Data Protection Regulation
While Violet-river operates in Canada, we recognize that some visitors and clients may be located in the European Economic Area. We are committed to protecting personal data in accordance with GDPR principles.
Legal Basis for Processing
We process personal data based on the following legal grounds:
- Consent: When you submit inquiries through our forms, you provide explicit consent for us to process your information to respond to your request
- Legitimate Interests: We process certain data for legitimate business interests, such as website analytics and security
- Legal Obligation: We may process data to comply with legal requirements
Your Rights Under GDPR
If you are located in the EEA, you have the following rights regarding your personal data:
Right of Access
You can request confirmation of whether we process your personal data and obtain a copy of that data.
Right to Rectification
You can request correction of inaccurate or incomplete personal data.
Right to Erasure
You can request deletion of your personal data under certain circumstances, such as when the data is no longer necessary for the purposes for which it was collected.
Right to Restriction of Processing
You can request that we limit how we use your personal data in specific situations.
Right to Data Portability
You can request to receive your personal data in a structured, commonly used format and have it transmitted to another controller.
Right to Object
You can object to processing of your personal data based on legitimate interests.
Right to Withdraw Consent
Where processing is based on consent, you have the right to withdraw that consent at any time.
Right to Lodge a Complaint
You have the right to lodge a complaint with a supervisory authority in your jurisdiction if you believe we have not complied with data protection requirements.
Exercising Your Rights
To exercise any of these rights, contact us at:
Email: [email protected]
Subject line: GDPR Data Subject Request
We will respond to your request within one month of receipt. In complex cases, we may extend this period by an additional two months and will inform you of any such extension.
Data Protection Officer
For questions specifically related to data protection and GDPR compliance, you may contact our designated privacy coordinator at [email protected]
International Data Transfers
Our servers and business operations are located in Canada. If you are located in the EEA, your personal data will be transferred to Canada. We ensure appropriate safeguards are in place for such transfers.
Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, typically three years for inquiry records. After this period, data is securely deleted unless retention is required by law.
Security Measures
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- Encryption of data in transit
- Access controls and authentication
- Regular security assessments
- Staff training on data protection
Changes to This Statement
We may update this GDPR compliance statement periodically. Material changes will be communicated through this website with an updated revision date.