Last Updated: August 17, 2026
This page outlines how we comply with the General Data Protection Regulation and your rights under this regulation.
We process personal data under the following legal bases:
quiet-atoll operates as the data controller for personal information collected through this website. We determine the purposes and means of processing your personal data.
Contact for data protection matters: [email protected]
You have the right to request confirmation of whether we process your personal data and to obtain a copy of that data.
You may request correction of inaccurate personal data or completion of incomplete data.
You can request deletion of your personal data when it is no longer necessary for the purposes for which it was collected, or when you withdraw consent.
Under certain circumstances, you can request that we limit how we use your personal data.
You have the right to receive your personal data in a structured, commonly used, and machine-readable format.
You may object to processing of your personal data based on legitimate interests.
Where processing is based on consent, you have the right to withdraw that consent at any time.
To exercise any of your GDPR rights, send a request to [email protected] with the subject line "GDPR Request." Include:
We will respond to your request within 30 days. In complex cases, this period may be extended by an additional 60 days, and you will be informed of any extension.
Your personal data is stored on servers located in Canada. We do not transfer personal data outside of Canada except when necessary for service delivery, and only with appropriate safeguards in place.
We do not use automated decision-making or profiling processes that produce legal effects or similarly significant effects on individuals.
In the event of a data breach that poses a risk to your rights and freedoms, we will notify you without undue delay and, where required, report the breach to the relevant supervisory authority within 72 hours.
You have the right to lodge a complaint with a data protection supervisory authority if you believe your rights under GDPR have been violated.
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
We do not knowingly process personal data of individuals under 16 years of age. If we become aware that we have collected such data, we will delete it promptly.