GDPR Compliance

Last updated: June 30, 2024

Missinglettr Ltd. (“we”, “us”, or “our”) is committed to protecting personal data and complying with applicable data protection laws, including the General Data Protection Regulation (EU) 2016/679 (“GDPR”) where it applies.

Does GDPR Apply to Missinglettr?

Although Missinglettr is based in Canada, GDPR may apply where we:

  • Provide services to individuals located in the European Economic Area (EEA)

  • Monitor or analyze behavior of users within the EEA

Where GDPR applies, we comply with its requirements.

Our Role

Depending on the context, Missinglettr may act as:

  • Data Controller — when we determine how and why personal data is processed

  • Data Processor — when we process data on behalf of our customers

Lawful Bases for Processing

Where required under GDPR, we rely on lawful bases including:

  • Consent

  • Contract performance

  • Legitimate interests

  • Legal obligations

International Data Transfers

Personal data may be transferred outside the EEA, including to Canada and the United States.

Where required, we implement appropriate safeguards, such as:

  • Standard Contractual Clauses (SCCs)

  • Contracts with service providers ensuring adequate protection

Your Rights Under GDPR

If GDPR applies, individuals have the right to:

  • Access their personal data

  • Correct inaccurate data

  • Request deletion (“right to be forgotten”)

  • Restrict or object to processing

  • Request data portability

  • Withdraw consent

To exercise these rights, contact: privacy@missinglettr.com

Data Processing Agreements (DPA)

We offer a Data Processing Agreement (DPA) for customers who require one to comply with GDPR.

To request a DPA, please contact: legal@missinglettr.com

Use of Aggregated and De-Identified Data

We may use aggregated and de-identified data derived from personal data.

Such data:

  • Does not identify any individual

  • Is not considered personal data under GDPR

This use is described in our Privacy Policy.

Security Measures

We implement appropriate technical and organizational measures to protect personal data, including:

  • Encryption in transit

  • Access controls

  • Secure infrastructure

Further details are available on our Security page.

Contact

If you have any questions about GDPR or your data:

privacy@missinglettr.com