Data Protection Policy

At Harmony Appliance Repair BC, we are committed to protecting your personal data and ensuring its security. This policy outlines our approach to data protection and the measures we take to safeguard your information.

Our Data Protection Principles

We adhere to the following principles when processing personal data:

  • Lawfulness, fairness, and transparency
  • Purpose limitation
  • Data minimization
  • Accuracy
  • Storage limitation
  • Integrity and confidentiality
  • Accountability

Security Measures

We implement appropriate technical and organizational measures to ensure the security of your personal data, including:

  • Encryption of data in transit and at rest
  • Access controls and authentication
  • Regular security assessments
  • Staff training on data protection
  • Incident response procedures

Data Processing Activities

We maintain records of our data processing activities, including:

  • Categories of personal data processed
  • Purposes of processing
  • Categories of recipients
  • Retention periods
  • Security measures

International Data Transfers

When we transfer personal data outside of Canada, we ensure appropriate safeguards are in place through:

  • Standard contractual clauses
  • Adequacy decisions
  • Binding corporate rules

Data Protection Impact Assessments

We conduct Data Protection Impact Assessments (DPIAs) for high-risk processing activities to:

  • Identify and assess risks
  • Implement mitigation measures
  • Ensure compliance with data protection laws

Data Subject Rights

We respect and facilitate the exercise of data subject rights. Learn more about your rights and how to exercise them on our GDPR Rights page.

Data Processors

We carefully select and monitor our data processors to ensure they provide sufficient guarantees to implement appropriate technical and organizational measures. View our current list of Data Processors.

Data Breaches

We have procedures in place to detect, report, and investigate personal data breaches. In case of a breach that is likely to result in a risk to your rights and freedoms, we will:

  • Notify the relevant supervisory authority within 72 hours
  • Inform affected individuals without undue delay
  • Document the breach and remedial actions taken

Training and Awareness

We provide regular training to our staff on:

  • Data protection principles
  • Security measures
  • Breach reporting procedures
  • Handling data subject requests

Contact Information

For any questions about our data protection practices or to exercise your rights, please: