GDPR Privacy Notice
Last updated: 7/6/2026
This GDPR Privacy Notice provides detailed information about how BJORN Kreativ ("we," "us," or "our") processes personal data in accordance with the EU General Data Protection Regulation (GDPR) and other applicable data protection laws.
Quick Summary: We are committed to protecting your personal data and respecting your privacy rights under GDPR. You have significant control over your data, including the right to access, correct, delete, or transfer it at any time.
1. Data Controller Information
BJORN Kreativ acts as the data controller for the personal data we process about you. As the data controller, we determine the purposes and means of processing your personal data.
Contact Details:
BJORN Kreativ
151 15th Street
North Vancouver, BC V7L 0G9
Canada
Email: support@getbjorn.ai
Phone: 778-488-0418
Data Protection Officer (DPO): [If you have appointed a DPO, include their contact details here. DPOs are required for public authorities and organizations whose core activities involve regular and systematic monitoring or processing of special categories of data]
EU Representative: [If you're not established in the EU but process EU residents' data, you may need to appoint an EU representative under Article 27 GDPR]
2. Categories of Personal Data We Process
Identity and Contact Data
- Name, email address, postal address, telephone number
- Username, password, and other authentication credentials
- Profile information and preferences
- Communication preferences and marketing consent status
Technical and Usage Data
- IP address, browser type, device information
- Usage patterns, session data, and analytics information
- Cookies and similar tracking technologies data
- Location data (when permitted and necessary)
Transaction and Financial Data
- Payment information (processed securely by our payment providers)
- Transaction history and billing information
- Tax information where required by law
Content and Communication Data
- Content you create, upload, or share through our services
- Messages and communications you send to us
- Support tickets and customer service interactions
Special Categories of Personal Data
We do not intentionally collect special categories of personal data (such as health, biometric, or genetic data) unless specifically required for our services and with your explicit consent. [Modify this section if your business processes special categories of data]
3. Lawful Bases for Processing
We process your personal data only when we have a lawful basis under GDPR Article 6:
Consent (Article 6(1)(a))
We process data based on your consent for:
- Marketing communications and newsletters
- Non-essential cookies and tracking technologies
- Participation in surveys, research, or beta testing
- Sharing testimonials or case studies
Contract Performance (Article 6(1)(b))
We process data necessary to provide our services, including:
- Creating and managing your account
- Processing payments and delivering services
- Providing customer support
- Fulfilling our contractual obligations
Legal Obligation (Article 6(1)(c))
We process data to comply with legal requirements, such as:
- Tax and accounting obligations
- Regulatory reporting requirements
- Responding to lawful requests from authorities
- Maintaining records as required by law
Legitimate Interests (Article 6(1)(f))
We process data for legitimate business purposes, including:
- Improving our services and user experience
- Preventing fraud and ensuring security
- Business analytics and performance monitoring
- Protecting our legal rights and interests
Balancing Test: When relying on legitimate interests, we ensure our interests do not override your fundamental rights and freedoms. You have the right to object to processing based on legitimate interests.
4. Your Rights Under GDPR
You have comprehensive rights regarding your personal data. We are committed to facilitating the exercise of these rights:
Right of Access (Article 15)
You have the right to:
- Confirm whether we process your personal data
- Access your personal data and information about our processing
- Receive a copy of your data in a commonly used format
Right to Rectification (Article 16)
You have the right to:
- Correct inaccurate personal data
- Complete incomplete personal data
- Update outdated information
Right to Erasure/"Right to be Forgotten" (Article 17)
You have the right to request deletion of your personal data when:
- The data is no longer necessary for the original purpose
- You withdraw consent and there's no other lawful basis
- You object to processing and there are no overriding legitimate grounds
- The data has been unlawfully processed
- Deletion is required for compliance with legal obligations
Right to Restrict Processing (Article 18)
You have the right to restrict processing when:
- You contest the accuracy of personal data
- Processing is unlawful but you prefer restriction over deletion
- We no longer need the data but you need it for legal claims
- You've objected to processing pending verification of grounds
Right to Data Portability (Article 20)
You have the right to:
- Receive your data in a structured, commonly used format
- Transmit your data to another controller where technically feasible
- Have data transmitted directly between controllers when possible
Right to Object (Article 21)
You have the right to object to processing based on:
- Legitimate interests (unless we demonstrate compelling grounds)
- Direct marketing (including profiling for marketing)
- Scientific, historical research, or statistical purposes
Rights Related to Automated Decision-Making (Article 22)
You have rights regarding automated processing, including:
- Not to be subject to solely automated decision-making
- Human intervention in automated processes
- Explanation of automated decision logic
- Challenge automated decisions
How to Exercise Your Rights
To exercise any of these rights:
- Email: support@getbjorn.ai with "GDPR Request" in the subject line
- In Writing: Send a letter to our postal address above
Response Time: We will respond to your request within one month (extendable by two months for complex requests).
Identity Verification: We may require proof of identity to protect your data from unauthorized access.
No Fee: We do not charge fees for rights requests unless they are manifestly unfounded or excessive.
5. Data Retention Periods
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected:
Account and Service Data
- Active accounts: For the duration of your account plus 90 days after closure
- Service usage data: Up to 3 years for service improvement
- Support communications: 3 years after resolution
Financial and Transaction Data
- Payment records: 7 years for tax and legal compliance
- Tax-related information: As required by applicable tax laws
- Fraud prevention data: Up to 6 years or as required by law
Marketing and Communications
- Marketing consent: Until withdrawn or 2 years of inactivity
- Email communications: Until unsubscribed plus suppression list maintenance
- Analytics data: Anonymized data may be retained indefinitely
Legal and Compliance
- Legal claims: Until statute of limitations expires
- Regulatory requirements: As specified by applicable laws
- Investigation records: Until matter is resolved plus reasonable retention period
6. International Data Transfers
We may transfer your personal data outside the European Economic Area (EEA). When we do, we ensure adequate protection through:
Adequacy Decisions
We transfer data to countries that the European Commission has determined provide adequate protection for personal data.
Standard Contractual Clauses (SCCs)
We use EU-approved Standard Contractual Clauses to ensure appropriate safeguards for data transfers to countries without adequacy decisions.
Certification and Codes of Conduct
We work with service providers who participate in approved certification schemes or codes of conduct that ensure data protection.
Transfer Impact Assessments
We conduct Transfer Impact Assessments to evaluate the level of protection in destination countries and implement supplementary measures when necessary.
7. Data Security Measures
We implement appropriate technical and organizational measures to ensure data security:
Technical Measures
- Encryption of data in transit and at rest
- Access controls and authentication systems
- Regular security assessments and vulnerability testing
- Secure backup and disaster recovery procedures
- Network security and monitoring systems
Organizational Measures
- Staff training on data protection principles
- Data protection policies and procedures
- Regular compliance audits and reviews
- Incident response and breach notification procedures
- Vendor due diligence and contract management
8. Data Sharing and Recipients
We share personal data only when necessary and with appropriate safeguards:
Service Providers and Processors
We work with trusted third-party processors who:
- Process data only on our documented instructions
- Implement appropriate technical and organizational measures
- Are bound by contractual obligations equivalent to GDPR
- Assist with our GDPR compliance obligations
Legal Authorities and Compliance
We may share data with:
- Law enforcement agencies when required by law
- Regulatory authorities for compliance purposes
- Courts and legal representatives in legal proceedings
- Tax authorities as required by tax laws
Business Transfers
In case of merger, acquisition, or business transfer, we will:
- Notify you before your data is transferred
- Ensure the new controller respects this privacy notice
- Provide you with information about the new controller
9. Automated Decision-Making and Profiling
We do not engage in automated decision-making or profiling that produces legal or similarly significant effects.
10. Data Protection Impact Assessments (DPIAs)
We conduct DPIAs for high-risk processing activities, including:
- Systematic and extensive automated processing with profiling
- Large-scale processing of special categories of data
- Systematic monitoring of publicly accessible areas
- New technologies with potential privacy impact
11. Data Breach Notification
In case of a personal data breach, we will:
- Notify the supervisory authority within 72 hours (where required)
- Notify affected individuals without undue delay (where required)
- Document the breach and our response measures
- Implement measures to address the breach and prevent recurrence
12. Children's Data Protection
We are committed to protecting children's privacy:
- We do not knowingly process data of children under 16 without parental consent
- We implement age verification measures where appropriate
- We will delete children's data if collected without proper consent
- Parents can exercise rights on behalf of their children
13. Supervisory Authority and Complaints
You have the right to lodge a complaint with a supervisory authority if you believe our processing violates GDPR.
Lead Supervisory Authority: [If you have a main establishment in the EU, identify your lead supervisory authority]
Your Local Authority: You can also contact the supervisory authority in your EU country of residence, place of work, or where the alleged violation occurred.
Contact Before Complaining: We encourage you to contact us first so we can address your concerns directly.
14. Updates to This Notice
We may update this GDPR Privacy Notice to reflect changes in our processing or legal requirements. When we make changes:
- We will post the updated notice with a new effective date
- We will notify you of material changes via email or prominent website notice
- We will seek new consent where required by law
- We will maintain previous versions for reference
15. Contact Information for Data Protection Matters
For all data protection inquiries, rights requests, or complaints:
General Data Protection Inquiries:
Email: support@getbjorn.ai
Subject Line: "GDPR Inquiry"
Data Protection Officer:
We have not appointed a Data Protection Officer; direct all data-protection inquiries to support@getbjorn.ai.
Postal Address:
BJORN Kreativ
Attention: Data Protection Team
151 15th Street
North Vancouver, BC V7L 0G9
Canada
Response Time: We respond to GDPR-related inquiries within one month of receipt.
This GDPR Privacy Notice demonstrates our commitment to transparency and compliance with EU data protection law. We continuously review and update our practices to ensure ongoing compliance.