ThinSky Logo ThinSky Back to Home

GDPR & PIPEDA Compliance

Last Updated: December 3, 2025

GDPR Compliant
PIPEDA Compliant
SOC 2 Type II

Our Commitment to Data Protection

ThinSky is fully committed to protecting personal data in accordance with the General Data Protection Regulation (GDPR), Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), and other applicable privacy regulations. This page outlines our compliance practices and your rights under these frameworks.

GDPR Compliance

The General Data Protection Regulation applies to all organizations processing personal data of EU/EEA residents. ThinSky ensures GDPR compliance through:

Lawful Basis for Processing

Your GDPR Rights

Data Protection Measures

PIPEDA Compliance

The Personal Information Protection and Electronic Documents Act governs how private-sector organizations in Canada handle personal information. ThinSky adheres to PIPEDA's 10 Fair Information Principles:

The 10 PIPEDA Principles

  1. Accountability: We are responsible for personal information under our control
  2. Identifying Purposes: We identify why we collect information before or at the time of collection
  3. Consent: We obtain meaningful consent for collection, use, and disclosure
  4. Limiting Collection: We collect only what is necessary for identified purposes
  5. Limiting Use, Disclosure, and Retention: Information is used only for stated purposes and retained only as needed
  6. Accuracy: We keep personal information accurate, complete, and up-to-date
  7. Safeguards: We protect information with appropriate security measures
  8. Openness: We make our policies readily available
  9. Individual Access: Individuals can access their information and challenge its accuracy
  10. Challenging Compliance: Individuals can challenge our compliance with these principles

Your PIPEDA Rights

How We Protect Your Data

Technical Safeguards

Organizational Safeguards

International Data Transfers

When transferring personal data internationally, we ensure compliance through:

Data Processing Agreements

For clients using our managed services, we provide comprehensive Data Processing Agreements (DPAs) that include:

Exercising Your Rights

To exercise any of your data protection rights, please contact us:

Data Protection Officer

Email: dpo@thinsky.com

Privacy Inquiries: privacy@thinsky.com

Response Time: Within 30 days (or 72 hours for breach notifications)

Please include sufficient information to verify your identity and specify your request clearly.

Supervisory Authorities

If you believe your data protection rights have been violated, you may file a complaint with:

Helping You Achieve Compliance

Beyond our own compliance, ThinSky helps organizations achieve and maintain GDPR and PIPEDA compliance through:

Updates to This Page

We may update this compliance information as regulations evolve. Material changes will be communicated to clients and posted on our website. We encourage you to review this page periodically.