We use cookies to enhance your browsing experience. By continuing to visit this site you agree to our use of cookies.

Maple Barber Studio
Information on this site is advertising in nature
  • Home
  • Services
  • About
  • Contact

GDPR Compliance Statement

Last updated: September 9, 2026

Introduction

Maple Barber Studio is committed to protecting the privacy and personal data of all individuals who interact with our website and services. While our primary operations are based in Canada, we recognize the importance of the General Data Protection Regulation (GDPR) for users located in the European Economic Area (EEA), the United Kingdom, and Switzerland.

This document outlines how we comply with GDPR principles and explains your rights regarding your personal data.

Data Controller

For the purposes of GDPR, the data controller is:

Maple Barber Studio
427 Queen Street West
Toronto, ON M5V 2A5
Canada
Email: [email protected]

Legal Basis for Processing

We process personal data only when we have a legal basis to do so. Our legal bases for processing include:

  • Consent: You have given clear consent for us to process your personal data for specific purposes, such as when you submit a booking request
  • Legitimate Interests: Processing is necessary for our legitimate interests, such as improving our services and website functionality, provided your rights do not override these interests
  • Legal Obligation: Processing is necessary to comply with legal requirements

Personal Data We Collect

We collect and process the following categories of personal data:

  • Identity Data: Your full name
  • Contact Data: Email address
  • Service Data: Information about the services you have requested or shown interest in
  • Technical Data: IP address, browser type, device information, and website usage data
  • Communication Data: Any additional notes or messages you provide through our booking form

How We Use Your Data

We use your personal data for the following purposes:

  • To process and manage your booking requests
  • To communicate with you about appointments and services
  • To improve our website and user experience
  • To respond to your inquiries and provide customer support
  • To comply with legal obligations

Your GDPR Rights

Under GDPR, you have the following rights regarding your personal data:

Right to Access

You have the right to request copies of your personal data. We may charge a reasonable fee if your request is clearly unfounded, repetitive, or excessive.

Right to Rectification

You have the right to request that we correct any information you believe is inaccurate or complete information you believe is incomplete.

Right to Erasure

You have the right to request that we erase your personal data under certain conditions, such as when the data is no longer necessary for the purposes for which it was collected.

Right to Restrict Processing

You have the right to request that we restrict the processing of your personal data under certain conditions.

Right to Object

You have the right to object to our processing of your personal data under certain conditions, particularly when processing is based on legitimate interests.

Right to Data Portability

You have the right to request that we transfer the data we have collected to another organization, or directly to you, under certain conditions.

Right to Withdraw Consent

Where we rely on your consent to process your personal data, you have the right to withdraw that consent at any time. This will not affect the lawfulness of processing based on consent before its withdrawal.

Exercising Your Rights

To exercise any of your GDPR rights, please contact us at [email protected]. We will respond to your request within one month, though this period may be extended by two additional months if your request is complex or we receive multiple requests.

When submitting a request, please provide sufficient information to allow us to verify your identity and locate your data in our systems.

Data Retention

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including any legal, accounting, or reporting requirements.

Booking and appointment data is typically retained for three years. Technical and usage data is generally retained for shorter periods depending on the specific purpose.

When determining retention periods, we consider the amount, nature, and sensitivity of the personal data, the potential risk from unauthorized use or disclosure, and applicable legal requirements.

Data Security

We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:

  • Encryption of data in transit and at rest where appropriate
  • Regular security assessments and updates
  • Access controls limiting who can view or use personal data
  • Staff training on data protection and security

International Data Transfers

Our servers and data storage facilities are located in Canada. If you are accessing our website from the EEA, UK, or Switzerland, please be aware that your personal data will be transferred to and processed in Canada.

Canada has been recognized by the European Commission as providing adequate protection for personal data, ensuring that your data receives a similar level of protection as under GDPR.

Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the appropriate supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR.

If the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay.

Third-Party Data Processing

We may engage third-party service providers to process personal data on our behalf. When we do so, we ensure that:

  • Processing is governed by a contract that meets GDPR requirements
  • The processor provides sufficient guarantees of appropriate security measures
  • The processor only processes data according to our documented instructions

Right to Lodge a Complaint

You have the right to lodge a complaint with a supervisory authority, particularly in the EU member state where you habitually reside, work, or where an alleged infringement of GDPR occurred.

For users in the UK, the relevant supervisory authority is the Information Commissioner's Office (ICO). For users in other EEA countries, please refer to your national data protection authority.

Children's Privacy

Our services are not directed to individuals under the age of 16. We do not knowingly collect personal data from children under 16 without parental consent. If we become aware that we have collected personal data from a child under 16 without appropriate consent, we will take steps to delete that information.

Changes to This Statement

We may update this GDPR compliance statement from time to time to reflect changes in our practices or applicable laws. We will notify you of any material changes by posting the updated statement on our website and updating the "Last updated" date.

Contact Information

If you have questions about our GDPR compliance or wish to exercise your data protection rights, please contact us at:

Maple Barber Studio
427 Queen Street West
Toronto, ON M5V 2A5
Canada
Email: [email protected]

Maple Barber Studio

Professional grooming services rooted in tradition and enhanced by modern techniques.

Quick Links

  • Services
  • About Us
  • Contact

Legal

  • Privacy Policy
  • Terms of Use
  • GDPR
  • Cookies Policy

Disclaimer

Results from our grooming services may vary based on individual hair type, texture, and maintenance habits. Our recommendations are based on professional experience but should not replace consultation with a dermatologist for specific scalp or skin conditions. Always inform your barber of any allergies or sensitivities before service begins.

© 2026 Maple Barber Studio. All rights reserved.