Last Updated: September 9, 2026
General Data Protection Regulation Information
Modern Barber Studio is committed to protecting your privacy and ensuring compliance with the General Data Protection Regulation. This page provides detailed information about your rights and how we handle your personal data in accordance with GDPR requirements.
Data Controller
For the purposes of GDPR, the data controller is:
Modern Barber Studio
342 Heritage Avenue
Toronto, Ontario M5R 2K8
Canada
Email: [email protected]
Your Rights Under GDPR
If you are a resident of the European Economic Area, you have specific data protection rights under GDPR. These include:
Right to Access
You have the right to request copies of your personal data. We may charge a reasonable fee for multiple copies or manifestly unfounded requests. We will respond to your request within one month of receipt.
Right to Rectification
You have the right to request correction of any information you believe is inaccurate or incomplete. We will make reasonable efforts to verify the accuracy of updated information.
Right to Erasure
You have the right to request deletion of your personal data under certain conditions, including:
- The data is no longer necessary for the purposes it was collected
- You withdraw consent on which processing is based
- You object to processing and there are no overriding legitimate grounds
- The data has been unlawfully processed
- The data must be erased to comply with legal obligations
Please note that we may need to retain certain information for legal or administrative purposes.
Right to Restrict Processing
You have the right to request restriction of processing your personal data under the following circumstances:
- You contest the accuracy of the data while we verify its accuracy
- Processing is unlawful but you prefer restriction over erasure
- We no longer need the data but you require it for legal claims
- You have objected to processing pending verification of legitimate grounds
Right to Data Portability
You have the right to request transfer of your data to another organization or directly to you in a structured, commonly used, and machine-readable format. This right applies when processing is based on consent or contract and is carried out by automated means.
Right to Object
You have the right to object to processing of your personal data where we rely on legitimate interests as the legal basis. We will stop processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or for establishment, exercise, or defense of legal claims.
Right to Withdraw Consent
Where processing is based on your consent, you have the right to withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing conducted prior to withdrawal.
Right to Lodge a Complaint
You have the right to lodge a complaint with a supervisory authority, particularly in the EU member state of your habitual residence, place of work, or place of alleged infringement if you believe your data protection rights have been violated.
How to Exercise Your Rights
To exercise any of your GDPR rights, please contact us using the following information:
Email: [email protected]
Please include the following in your request:
- Your full name and contact information
- Description of the specific right you wish to exercise
- Any relevant details to help us locate your information
- Proof of identity for security purposes
We will respond to your request within one month. In complex cases, we may extend this period by two additional months and will inform you of the extension and reasons for delay.
Legal Bases for Processing
We process personal data based on the following legal grounds:
- Consent: You have given clear consent for us to process your personal data for specific purposes
- Contract: Processing is necessary for performance of a contract with you or to take steps at your request before entering into a contract
- Legal Obligation: Processing is necessary for compliance with legal obligations to which we are subject
- Legitimate Interests: Processing is necessary for our legitimate interests or those of a third party, provided these interests do not override your fundamental rights and freedoms
International Data Transfers
We may transfer your personal data outside the European Economic Area. When we do so, we ensure appropriate safeguards are in place, including:
- Standard contractual clauses approved by the European Commission
- Transfer to countries deemed to provide adequate protection
- Binding corporate rules where applicable
- Your explicit consent after being informed of potential risks
Data Retention Periods
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including legal, accounting, or reporting requirements. Specific retention periods include:
- Appointment and service records: 3 years from last service
- Marketing communications: Until you unsubscribe or request deletion
- Financial records: As required by applicable tax and accounting laws
- Website analytics data: 26 months
Automated Decision-Making
We do not use automated decision-making or profiling that produces legal effects or similarly significant effects on individuals.
Data Protection Officer
While we are not required to appoint a Data Protection Officer, we take data protection seriously. For data protection inquiries, please contact us at [email protected].
Security Measures
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- Encryption of personal data in transit and at rest
- Regular security assessments and updates
- Access controls and authentication mechanisms
- Employee training on data protection principles
- Incident response procedures
Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you without undue delay. We will also notify the relevant supervisory authority within 72 hours of becoming aware of the breach, unless the breach is unlikely to result in risk to individuals.
Children's Data
We do not knowingly process personal data of children under 16 without parental consent. If we become aware that we have collected data from a child without appropriate consent, we will take steps to delete that information promptly.
Updates to This Information
We may update this GDPR compliance information from time to time. Any changes will be posted on this page with an updated revision date. We encourage you to review this page periodically to stay informed about how we protect your data.
Contact and Questions
If you have questions about our GDPR compliance or data protection practices, please contact us at [email protected]. We are committed to working with you to resolve any concerns about your privacy.