GDPR Compliance
At Token tact Syntax, we take data privacy seriously. We are fully compliant with the General Data Protection Regulation (GDPR), which sets out obligations for organizations processing the personal data of individuals in the European Union and European Economic Area (EU/EEA). This page outlines how we handle your data lawfully, transparently, and securely.
1. Lawful Basis
We collect and process personal data under the following lawful bases as defined in Article 6 of the GDPR:
- Consent: When you explicitly agree to our use of your data (e.g., newsletter signup, optional analytics, marketing cookies).
- Contractual Necessity: To fulfill our obligations in providing you access to your course materials, progress tracking, billing, and certifications.
- Legitimate Interest: To improve our platform, communicate updates, detect fraud, and protect the integrity of our services — without overriding your fundamental rights.
2. Your Data Protection Rights
Under the GDPR, all individuals in the EU/EEA are entitled to the following rights:
- Right of Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Ask us to correct inaccurate or incomplete information.
- Right to Erasure: Request deletion of your data in certain circumstances ("right to be forgotten").
- Right to Restriction: Limit how we process your data under specific conditions.
- Right to Data Portability: Obtain and reuse your data across different services.
- Right to Object: Object to our processing of your data based on legitimate interests or direct marketing.
- Right to Withdraw Consent: Revoke your consent at any time where consent was the legal basis for processing.
To exercise any of these rights, please contact us using the details below. We will respond within 30 days, as required by law.
3. International Data Transfers
While Token tact Syntax is based in Canada, your data may be processed or stored on servers located in jurisdictions outside the EU/EEA. In such cases, we ensure appropriate safeguards are in place, including:
- Use of Standard Contractual Clauses (SCCs) approved by the European Commission;
- Ensuring data processors follow equivalent data protection standards;
- Implementing encryption and secure data transfer protocols.
We work only with third-party service providers that demonstrate GDPR compliance, such as cloud storage platforms, analytics tools, and payment gateways.
4. Data Security
We apply industry-standard technical and organizational measures to protect your personal information. These include HTTPS encryption, access controls, regular security audits, and data minimization principles. Our staff is trained in privacy awareness, and access to sensitive data is restricted.
5. Data Retention
We retain personal data only as long as necessary for the purposes stated. If your account becomes inactive for more than 18 months, we may contact you before scheduled deletion. Certain data may be retained longer if required by tax, regulatory, or legal obligations.
6. Contact
If you have any questions, concerns, or would like to submit a GDPR request, please contact our Data Protection Officer at:
Email:
support@ttsyntax.com
Mailing Address: Token tact Syntax, 320 Bay Street, Toronto, ON,
Canada
If you believe your rights under GDPR have been violated, you also have the right to lodge a complaint with your local Data Protection Authority (DPA).