×
GDPR Compliance Documentation
Last updated: December 2024
1. Our Commitment to GDPR Compliance
Journey Essence is committed to protecting your personal data and respecting your privacy rights under the General Data Protection Regulation (GDPR).
2. Data Controller Information
Data Controller: Journey Essence
Address: 1247 Wilshire Boulevard, Suite 302, Los Angeles, CA 90017, USA
Email: [email protected]
Phone: +1 (213) 555-7842
3. Lawful Basis for Processing
We process your personal data based on the following lawful bases:
- Consent: For marketing communications and optional services
- Legitimate Interest: For providing our core wellness services
- Contract: For fulfilling our service obligations
- Legal Obligation: When required by law
4. Your Rights Under GDPR
Right of Access (Article 15)
You have the right to obtain confirmation that your data is being processed and access to your personal data.
Right to Rectification (Article 16)
You have the right to have inaccurate personal data corrected or completed if incomplete.
Right to Erasure (Article 17)
You have the right to have your personal data erased under certain circumstances.
Right to Restrict Processing (Article 18)
You have the right to restrict the processing of your personal data under certain circumstances.
Right to Data Portability (Article 20)
You have the right to receive your personal data in a structured, commonly used format.
Right to Object (Article 21)
You have the right to object to processing based on legitimate interests or for direct marketing.
5. Data Protection Measures
We implement appropriate technical and organizational measures including:
- Encryption of personal data
- Regular security assessments
- Access controls and authentication
- Staff training on data protection
- Data breach response procedures
6. International Data Transfers
If we transfer your data outside the EU/EEA, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses or adequacy decisions.
7. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected or as required by law.
8. Exercising Your Rights
To exercise any of your rights under GDPR, please contact us using the information provided above. We will respond to your request within one month.
9. Complaints
You have the right to lodge a complaint with a supervisory authority if you believe your data protection rights have been violated.