GDPR Information
Last updated: June 18, 2026
This page provides information about your rights under the General Data Protection Regulation and how topaz-mist processes your personal data in compliance with GDPR requirements.
Data Controller
For the purposes of GDPR, topaz-mist is the data controller responsible for your personal information. Our contact details are provided at the end of this document.
Legal Basis for Processing
We process your personal data under the following legal bases:
- Consent: When you provide explicit consent for specific processing activities
- Contract: When processing is necessary to fulfill our contractual obligations
- Legitimate Interests: When we have a legitimate business interest that does not override your rights
- Legal Obligation: When we must process data to comply with legal requirements
Your Rights Under GDPR
You have the following rights regarding your personal data:
Right of Access
You have the right to request copies of your personal data that we hold.
Right to Rectification
You have the right to request correction of any information you believe is inaccurate or incomplete.
Right to Erasure
You have the right to request deletion of your personal data under certain conditions.
Right to Restrict Processing
You have the right to request that we restrict the processing of your personal data under certain conditions.
Right to Data Portability
You have the right to request transfer of your data to another organization or directly to you under certain conditions.
Right to Object
You have the right to object to our processing of your personal data under certain conditions.
Rights Related to Automated Decision Making
You have the right not to be subject to decisions based solely on automated processing, including profiling, which produce legal effects or similarly significantly affect you.
Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including:
- Providing services and responding to inquiries
- Complying with legal and regulatory requirements
- Resolving disputes and enforcing agreements
After this period, your data will be securely deleted or anonymized.
Data Security
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- Encryption of data in transit and at rest
- Regular security assessments and updates
- Access controls and authentication procedures
- Staff training on data protection principles
International Data Transfers
If we transfer your personal data outside the European Economic Area, we ensure appropriate safeguards are in place to protect your data in accordance with GDPR requirements.
Exercising Your Rights
To exercise any of your GDPR rights, please contact us at [email protected]. We will respond to your request within one month, though this period may be extended by two additional months where necessary, taking into account the complexity and number of requests.
Right to Lodge a Complaint
If you believe we have not handled your personal data in accordance with GDPR, you have the right to lodge a complaint with the relevant supervisory authority in your jurisdiction.
Changes to This Information
We may update this GDPR information to reflect changes in our practices or legal requirements. Significant changes will be communicated through appropriate channels.
Contact Us
For any questions about your GDPR rights or our data processing practices, please contact us at [email protected].