Last Updated: September 2026
Atoll-sage is committed to protecting the personal data of all individuals, including those residing in the European Economic Area (EEA). We comply with the General Data Protection Regulation (GDPR) and provide the following information about how we handle your data.
For the purposes of GDPR, Atoll-sage acts as the data controller for personal information collected through this website.
Contact:
Atoll-sage
247 Market Street
Toronto, ON M5V 2K8
Canada
Email: [email protected]
We process personal data under the following lawful bases:
If you are located in the EEA, you have the following rights regarding your personal data:
You may request a copy of the personal data we hold about you. We will provide this information within 30 days of receiving your request.
You have the right to request correction of any inaccurate or incomplete personal data we hold about you.
Also known as the "right to be forgotten," you may request deletion of your personal data under certain circumstances, such as when the data is no longer necessary for its original purpose.
You may request that we limit how we use your personal data while we address your concerns or verify information accuracy.
You may request a machine-readable copy of your personal data to transfer to another service provider.
You have the right to object to processing based on legitimate interests or for direct marketing purposes.
Where we rely on consent for processing, you may withdraw that consent at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, please contact us using the information provided above. We will respond to your request within 30 days. In certain circumstances, we may need to verify your identity before processing your request.
As a Canadian organization, data may be transferred outside the EEA. When such transfers occur, we ensure appropriate safeguards are in place, including standard contractual clauses approved by regulatory authorities.
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by law. Specific retention periods vary based on the type of data and its purpose.
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including encryption, access controls, and regular security assessments.
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours. If the breach is likely to result in high risk, we will also notify affected individuals directly.
If you believe we have not handled your personal data appropriately, you have the right to lodge a complaint with your local data protection authority. We encourage you to contact us first so we can address your concerns directly.
We may update this GDPR compliance information periodically to reflect changes in our practices or legal requirements. The current version will always be available on this page.