This website contains promotional content about travel and tourism services.

Introduction

Plateau-path is committed to protecting the privacy and rights of individuals in the European Economic Area (EEA) in accordance with the General Data Protection Regulation (GDPR). This page provides information specifically for EEA visitors about how we process your personal data.

Data Controller

For the purposes of the GDPR, the data controller is:

Plateau-path Heritage Tours
245 Water Street, Suite 302
Halifax, Nova Scotia B3J 1S2
Canada

Email: [email protected]

Legal Basis for Processing

We process personal data from EEA residents on the following legal bases:

Consent

When you submit an inquiry form or sign up for communications, you consent to our processing of your personal data for the stated purposes. You may withdraw consent at any time.

Contract Performance

When you book a tour with us, we process your personal data as necessary to perform our contract with you, including arranging tour logistics, communicating booking details, and processing payments.

Legitimate Interests

We may process certain data based on our legitimate business interests, such as improving our services, preventing fraud, and ensuring website security. These interests are balanced against your rights and freedoms.

Legal Obligations

We may process personal data when required to comply with applicable laws, such as tax reporting requirements or response to legal requests.

Your Rights Under GDPR

As a resident of the EEA, you have the following rights regarding your personal data:

Right of Access

You have the right to request a copy of the personal data we hold about you, along with information about how we process it.

Right to Rectification

You have the right to request that we correct any inaccurate or incomplete personal data we hold about you.

Right to Erasure

You have the right to request that we delete your personal data in certain circumstances, such as when the data is no longer necessary for the purpose for which it was collected.

Right to Restrict Processing

You have the right to request that we restrict the processing of your personal data in certain circumstances, such as when you contest the accuracy of the data.

Right to Data Portability

You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit that data to another controller.

Right to Object

You have the right to object to our processing of your personal data based on legitimate interests or for direct marketing purposes.

Rights Related to Automated Decision-Making

You have the right not to be subject to decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you. We do not currently engage in such automated decision-making.

Exercising Your Rights

To exercise any of your rights under GDPR, please contact us using the details above. We will respond to your request within one month. In complex cases, we may extend this period by up to two additional months, but we will inform you of any extension within the first month.

There is no fee for exercising your rights, unless your requests are manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse to act on the request.

International Data Transfers

As a Canadian organisation, your personal data may be transferred to and stored in Canada. Canada has been recognised by the European Commission as providing an adequate level of data protection under GDPR Article 45.

For transfers to third-party service providers in other countries, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission.

Data Retention

We retain personal data only for as long as necessary for the purposes for which it was collected:

Data Security

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, or destruction. These measures include encryption, access controls, and regular security assessments.

Data Breach Notification

In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay. We will also notify the relevant supervisory authority within 72 hours of becoming aware of such a breach.

Supervisory Authority

If you are not satisfied with our response to your request or believe we are processing your personal data unlawfully, you have the right to lodge a complaint with a supervisory authority in the EU member state of your residence, place of work, or place of the alleged infringement.

Updates to This Information

We may update this GDPR information from time to time. We encourage you to review this page periodically for any changes.

Additional Information

For more detailed information about our privacy practices, please see our Privacy Policy and Cookie Policy.