GDPR Compliance Policy

Effective Date: April 29, 2025

1. Introduction

ITLawSecure is committed to ensuring the privacy and protection of personal data in compliance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”). This policy outlines how we process, store, and protect personal data collected from individuals located in the European Union and European Economic Area (EEA).

2. Who We Are

ITLawSecure is a legal services provider based in Ontario, Canada, offering legal support for technology companies. Our data processing is handled in accordance with GDPR Article 27, and we serve clients across Canada and the EU.

3. What Data We Collect

We collect the following categories of personal data from EU/EEA users:

  • Name, email address, company name, and phone number
  • IP address and browser/device data (cookies)
  • Message content submitted via contact forms

4. Legal Basis for Processing

We process personal data based on the following lawful grounds under Article 6 of the GDPR:

  • Consent — where you explicitly agree (e.g., via form checkboxes)
  • Contract — for delivering legal services or preparing proposals
  • Legal obligation — for recordkeeping or compliance
  • Legitimate interest — such as maintaining website security and communication

5. Your Rights Under GDPR

As an EU/EEA resident, you have the right to:

  • Access and obtain a copy of your personal data
  • Correct inaccurate or incomplete data
  • Request erasure (“right to be forgotten”)
  • Restrict or object to data processing
  • Data portability
  • Withdraw consent at any time
  • Lodge a complaint with a supervisory authority in your country

6. Data Transfers

Your data may be stored or processed on servers located outside the EU, including in Canada and the United States. We ensure that all third-party service providers maintain GDPR-compliant safeguards (such as Standard Contractual Clauses or equivalent mechanisms).

7. Data Security

We implement appropriate technical and organizational measures to secure personal data, including:

  • SSL encryption for data transmission
  • Access controls and staff confidentiality agreements
  • Data minimization and retention policies

8. Data Retention

We retain personal data for as long as needed to fulfill the purpose for which it was collected, or to comply with legal and regulatory obligations. Users may request deletion of their data at any time.

9. Contact Information

If you have questions or would like to exercise your GDPR rights, please contact:

  • Data Controller: ITLawSecure
  • Email: contact@itlawsecure.com
  • Phone: +1 807-547-1449
  • Address: 4483 Nelson Street, Keewatin, ON P0X 1C0, Canada
  • Business Number (BN): 796437582RC0001

10. Updates to This Policy

We reserve the right to update this GDPR Policy at any time. Changes will be posted on this page and marked with the effective date.