Effective Date: January 1, 2026
Introduction
The General Data Protection Regulation (GDPR) is a European Union regulation that establishes comprehensive data protection requirements for organizations processing personal data of EU residents. Although Hollow-falcon is based in Canada, we respect the privacy rights of all website visitors and service users, including those in the European Union.
This page outlines how we comply with GDPR principles and describes the rights available to EU residents regarding their personal data.
Legal Basis for Processing
We process personal data only when we have a lawful basis to do so. The legal bases we rely on include:
Consent
When you submit program booking requests, subscribe to communications, or accept cookies, you provide explicit consent for us to process your personal data for the specified purposes. You may withdraw consent at any time.
Contract Performance
When you book a heritage program, we process your personal data as necessary to fulfill our contractual obligations, including confirming reservations, providing program information, and coordinating logistics.
Legitimate Interests
We process certain data based on our legitimate business interests, such as improving website functionality, analyzing user behavior to enhance services, and preventing fraud. These interests are balanced against your privacy rights.
Legal Obligations
In some cases, we process data to comply with legal requirements, such as tax reporting, record-keeping obligations, or responding to lawful requests from authorities.
Your GDPR Rights
Under GDPR, individuals in the European Union have the following rights regarding their personal data:
Right to Access
You have the right to request confirmation of whether we are processing your personal data and to receive a copy of that data. We will provide this information in a commonly used electronic format.
Right to Rectification
If your personal data is inaccurate or incomplete, you have the right to request correction. We will update your information promptly upon verification.
Right to Erasure (Right to be Forgotten)
You may request deletion of your personal data when it is no longer necessary for the purposes for which it was collected, when you withdraw consent, or when you object to processing. This right is subject to legal retention requirements.
Right to Restriction of Processing
You may request that we limit how we use your data in certain circumstances, such as when you contest the accuracy of the data or object to processing while we verify your request.
Right to Data Portability
You have the right to receive your personal data in a structured, machine-readable format and to transmit that data to another controller without hindrance.
Right to Object
You may object to processing of your personal data based on legitimate interests or for direct marketing purposes. We will cease such processing unless we demonstrate compelling legitimate grounds that override your interests.
Right Not to Be Subject to Automated Decision-Making
You have the right not to be subject to decisions based solely on automated processing that produce legal effects or similarly significantly affect you. Hollow-falcon does not engage in automated decision-making with legal or significant effects.
How to Exercise Your Rights
To exercise any of your GDPR rights, please contact us using the information provided at the end of this page. Your request should include:
- Your full name and contact information
- Description of the right you wish to exercise
- Specific details about your request
- Proof of identity (to prevent unauthorized disclosure)
We will respond to your request within one month. In complex cases, we may extend this period by an additional two months and will inform you of the extension and reasons for delay.
Data Processing Details
Categories of Personal Data
We process the following categories of personal data:
- Identity data (name, contact details)
- Communication data (email correspondence, booking requests)
- Technical data (IP address, browser information, device identifiers)
- Usage data (pages visited, navigation patterns, time spent on site)
Data Retention Periods
We retain personal data for different periods depending on the purpose:
- Program booking records: 3 years following program completion
- Marketing consent records: Until consent is withdrawn, plus 1 year
- Website analytics: Anonymized after 14 months
- Legal compliance records: As required by applicable law
International Data Transfers
As a Canadian organization, we may transfer your data outside the European Economic Area. When we do so, we ensure appropriate safeguards are in place, such as standard contractual clauses approved by the European Commission.
Data Security Measures
We implement technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure, or destruction:
- Encryption of data in transit using SSL/TLS protocols
- Access controls limiting data access to authorized personnel
- Regular security assessments and updates
- Staff training on data protection obligations
- Incident response procedures for data breaches
Data Breach Notification
In the event of a data breach that poses a risk to your rights and freedoms, we will notify you within 72 hours of becoming aware of the breach. The notification will describe the nature of the breach, likely consequences, and measures taken to address the breach and mitigate harm.
Third-Party Data Processors
We engage third-party service providers who process personal data on our behalf. These processors are contractually bound to:
- Process data only according to our documented instructions
- Implement appropriate security measures
- Maintain confidentiality
- Assist with fulfilling data subject rights requests
- Delete or return data upon termination of services
Children's Data
We do not knowingly collect or process personal data of individuals under 16 years of age without parental consent. If we become aware that we have collected data from a child without appropriate consent, we will delete that information promptly.
Updates to This Notice
We may update this GDPR compliance notice to reflect changes in our practices or legal requirements. Material changes will be communicated through prominent website notice or direct communication to affected individuals.
Right to Lodge a Complaint
If you believe your data protection rights have been violated, you have the right to lodge a complaint with a supervisory authority in the EU member state of your habitual residence, place of work, or place of the alleged infringement.
We encourage you to contact us first so we can address your concerns directly.
Contact Information
For questions about our GDPR compliance or to exercise your data protection rights, contact:
Hollow-falcon
Data Protection Inquiries
347 Water Street
Halifax, Nova Scotia B3J 1S9
Canada
Email: [email protected]
Please include "GDPR Request" in the subject line of your email to ensure prompt handling.