Our Commitment to GDPR Compliance

Vivid Spire is committed to protecting the privacy and security of personal data in compliance with the General Data Protection Regulation (GDPR). This page outlines how we process personal data of individuals in the European Economic Area (EEA) and the United Kingdom, and explains your rights under GDPR.

Data Controller

Vivid Spire acts as the data controller for personal information collected through our website and services. Our contact details are:

Vivid Spire
245 King Street West, Suite 1200
Toronto, ON M5V 1J2
Canada
Email: [email protected]

Legal Basis for Processing

We process personal data under the following legal bases:

Your Rights Under GDPR

As a data subject under GDPR, you have the following rights:

Right of Access

You have the right to obtain confirmation as to whether we process your personal data and, if so, to request access to that data along with information about how it is processed.

Right to Rectification

You have the right to request correction of inaccurate personal data and to have incomplete data completed.

Right to Erasure

You have the right to request deletion of your personal data in certain circumstances, including when the data is no longer necessary for the purposes for which it was collected, or when you withdraw consent.

Right to Restrict Processing

You have the right to request restriction of processing in certain circumstances, such as when you contest the accuracy of the data or when processing is unlawful.

Right to Data Portability

You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller.

Right to Object

You have the right to object to processing based on legitimate interests or for direct marketing purposes.

Rights Related to Automated Decision-Making

You have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects. Vivid Spire does not use automated decision-making in relation to our services.

International Data Transfers

As Vivid Spire is based in Canada, personal data may be transferred outside the EEA. Canada has been recognised by the European Commission as providing an adequate level of data protection. For transfers to other countries, we implement appropriate safeguards such as Standard Contractual Clauses.

Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected. Retention periods vary depending on the type of data and its purpose. When data is no longer needed, it is securely deleted or anonymised.

Security Measures

We implement appropriate technical and organisational measures to protect personal data, including:

Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours. If the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly.

Exercising Your Rights

To exercise any of your rights under GDPR, please contact us at [email protected]. We will respond to your request within one month of receipt. If your request is complex or we receive numerous requests, we may extend this period by a further two months, in which case we will inform you of the extension.

There is no fee for exercising your rights, though we may charge a reasonable fee for manifestly unfounded or excessive requests.

Right to Lodge a Complaint

If you believe that our processing of your personal data violates GDPR, you have the right to lodge a complaint with a supervisory authority in the EU member state of your habitual residence, place of work, or place of the alleged infringement.

Updates to This Notice

We may update this GDPR notice from time to time. The current version will always be available on this page with the effective date noted.

Last updated: June 2026