Information about data protection rights under EU regulations
Last updated: January 2024
The General Data Protection Regulation (GDPR) is a regulation in EU law on data protection and privacy for all individuals within the European Union and the European Economic Area. Although canopy-lemur is based in South Africa, we are committed to protecting the privacy rights of all our users, including those from the EU.
canopy-lemur acts as the data controller for personal information collected through our website and services. We determine the purposes and means of processing personal data.
Contact Details:
canopy-lemur
42 Airport Road
Kempton Park, 1619
Gauteng, South Africa
Email: [email protected]
We process personal data on the following legal grounds:
Processing is necessary to fulfil our contract with you when you book a transfer service. This includes:
Processing based on our legitimate business interests, balanced against your rights:
Where we rely on consent for processing, you have the right to withdraw that consent at any time. This applies to:
Processing necessary to comply with legal requirements, such as:
If you are an EU resident, you have the following rights regarding your personal data:
You have the right to request a copy of the personal data we hold about you. We will provide this information free of charge within one month of your request.
You have the right to request correction of any inaccurate or incomplete personal data we hold about you.
Also known as the "right to be forgotten", you can request deletion of your personal data when:
You can request that we limit how we use your data while:
You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit that data to another controller.
You have the right to object to processing based on legitimate interests, including profiling. We will stop processing unless we can demonstrate compelling legitimate grounds.
You have the right not to be subject to decisions based solely on automated processing that significantly affect you. We do not currently use automated decision-making systems for significant decisions.
As a South African company, data may be transferred outside the European Economic Area. When this occurs, we ensure appropriate safeguards are in place, including:
We retain personal data only as long as necessary for the purposes for which it was collected:
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
To exercise any of your GDPR rights, please contact us at [email protected]. We may need to verify your identity before processing your request. We will respond within one month, though this may be extended for complex requests.
If you believe your data protection rights have been violated, you have the right to lodge a complaint with a supervisory authority in your EU member state of residence, place of work, or place of the alleged infringement.
We may update this GDPR notice periodically. We encourage you to review this page regularly for any changes.