Your rights under the General Data Protection Regulation
Last Updated: September 2026
Timberline Barber Lounge is committed to protecting the privacy and personal data of all individuals, including those located in the European Economic Area (EEA). This page outlines our compliance with the General Data Protection Regulation (GDPR) and explains your rights under this regulation.
Timberline Barber Lounge acts as the data controller for personal information collected through our website and services. Our contact details are:
Email: [email protected]
Address: 247 Maple Street, Toronto, ON M5V 2K1, Canada
We process personal data under the following legal bases:
Under the GDPR, you have the following rights regarding your personal data:
You have the right to request a copy of the personal data we hold about you. We will provide this information within 30 days of receiving a valid request.
You have the right to request that we correct any inaccurate personal data we hold about you without undue delay.
You have the right to request the deletion of your personal data when it is no longer necessary for the purposes for which it was collected, when you withdraw consent, or when the data has been unlawfully processed.
You have the right to request that we limit how we use your personal data in certain circumstances, such as when you contest the accuracy of the data.
You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit it to another controller.
You have the right to object to the processing of your personal data for direct marketing purposes or when processing is based on legitimate interests.
Where we process your data based on consent, you have the right to withdraw that consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by applicable laws. Booking request information is typically retained for up to two years for business record purposes, after which it is securely deleted.
As we are based in Canada, your data may be processed outside the EEA. Canada has been recognized by the European Commission as providing an adequate level of data protection. Where we transfer data to other countries, we ensure appropriate safeguards are in place.
We implement appropriate technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure, or destruction. These measures include secure data storage, access controls, and regular security assessments.
To exercise any of your GDPR rights, please contact us at [email protected]. We will respond to your request within 30 days. We may request verification of your identity before processing your request.
If you believe your data protection rights have been violated, you have the right to lodge a complaint with your local supervisory authority. We encourage you to contact us first so we can address your concerns directly.
We may update this GDPR notice periodically to reflect changes in our practices or legal requirements. The date at the top of this page indicates when it was last revised.