BJÖRN

GDPR Privacy Notice

Last updated: 7/6/2026

This GDPR Privacy Notice provides detailed information about how BJORN Kreativ ("we," "us," or "our") processes personal data in accordance with the EU General Data Protection Regulation (GDPR) and other applicable data protection laws.

Quick Summary: We are committed to protecting your personal data and respecting your privacy rights under GDPR. You have significant control over your data, including the right to access, correct, delete, or transfer it at any time.

1. Data Controller Information

BJORN Kreativ acts as the data controller for the personal data we process about you. As the data controller, we determine the purposes and means of processing your personal data.

Contact Details:
BJORN Kreativ
151 15th Street
North Vancouver, BC V7L 0G9
Canada
Email: support@getbjorn.ai
Phone: 778-488-0418

Data Protection Officer (DPO): [If you have appointed a DPO, include their contact details here. DPOs are required for public authorities and organizations whose core activities involve regular and systematic monitoring or processing of special categories of data]

EU Representative: [If you're not established in the EU but process EU residents' data, you may need to appoint an EU representative under Article 27 GDPR]

2. Categories of Personal Data We Process

Identity and Contact Data

Technical and Usage Data

Transaction and Financial Data

Content and Communication Data

Special Categories of Personal Data

We do not intentionally collect special categories of personal data (such as health, biometric, or genetic data) unless specifically required for our services and with your explicit consent. [Modify this section if your business processes special categories of data]

3. Lawful Bases for Processing

We process your personal data only when we have a lawful basis under GDPR Article 6:

Consent (Article 6(1)(a))

We process data based on your consent for:

Contract Performance (Article 6(1)(b))

We process data necessary to provide our services, including:

Legal Obligation (Article 6(1)(c))

We process data to comply with legal requirements, such as:

Legitimate Interests (Article 6(1)(f))

We process data for legitimate business purposes, including:

Balancing Test: When relying on legitimate interests, we ensure our interests do not override your fundamental rights and freedoms. You have the right to object to processing based on legitimate interests.

4. Your Rights Under GDPR

You have comprehensive rights regarding your personal data. We are committed to facilitating the exercise of these rights:

Right of Access (Article 15)

You have the right to:

Right to Rectification (Article 16)

You have the right to:

Right to Erasure/"Right to be Forgotten" (Article 17)

You have the right to request deletion of your personal data when:

Right to Restrict Processing (Article 18)

You have the right to restrict processing when:

Right to Data Portability (Article 20)

You have the right to:

Right to Object (Article 21)

You have the right to object to processing based on:

Rights Related to Automated Decision-Making (Article 22)

You have rights regarding automated processing, including:

How to Exercise Your Rights

To exercise any of these rights:

Response Time: We will respond to your request within one month (extendable by two months for complex requests).

Identity Verification: We may require proof of identity to protect your data from unauthorized access.

No Fee: We do not charge fees for rights requests unless they are manifestly unfounded or excessive.

5. Data Retention Periods

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected:

Account and Service Data

Financial and Transaction Data

Marketing and Communications

Legal and Compliance

6. International Data Transfers

We may transfer your personal data outside the European Economic Area (EEA). When we do, we ensure adequate protection through:

Adequacy Decisions

We transfer data to countries that the European Commission has determined provide adequate protection for personal data.

Standard Contractual Clauses (SCCs)

We use EU-approved Standard Contractual Clauses to ensure appropriate safeguards for data transfers to countries without adequacy decisions.

Certification and Codes of Conduct

We work with service providers who participate in approved certification schemes or codes of conduct that ensure data protection.

Transfer Impact Assessments

We conduct Transfer Impact Assessments to evaluate the level of protection in destination countries and implement supplementary measures when necessary.

7. Data Security Measures

We implement appropriate technical and organizational measures to ensure data security:

Technical Measures

Organizational Measures

8. Data Sharing and Recipients

We share personal data only when necessary and with appropriate safeguards:

Service Providers and Processors

We work with trusted third-party processors who:

Legal Authorities and Compliance

We may share data with:

Business Transfers

In case of merger, acquisition, or business transfer, we will:

9. Automated Decision-Making and Profiling

We do not engage in automated decision-making or profiling that produces legal or similarly significant effects.

10. Data Protection Impact Assessments (DPIAs)

We conduct DPIAs for high-risk processing activities, including:

11. Data Breach Notification

In case of a personal data breach, we will:

12. Children's Data Protection

We are committed to protecting children's privacy:

13. Supervisory Authority and Complaints

You have the right to lodge a complaint with a supervisory authority if you believe our processing violates GDPR.

Lead Supervisory Authority: [If you have a main establishment in the EU, identify your lead supervisory authority]

Your Local Authority: You can also contact the supervisory authority in your EU country of residence, place of work, or where the alleged violation occurred.

Contact Before Complaining: We encourage you to contact us first so we can address your concerns directly.

14. Updates to This Notice

We may update this GDPR Privacy Notice to reflect changes in our processing or legal requirements. When we make changes:

15. Contact Information for Data Protection Matters

For all data protection inquiries, rights requests, or complaints:

General Data Protection Inquiries:
Email: support@getbjorn.ai
Subject Line: "GDPR Inquiry"

Data Protection Officer:
We have not appointed a Data Protection Officer; direct all data-protection inquiries to support@getbjorn.ai.

Postal Address:
BJORN Kreativ
Attention: Data Protection Team
151 15th Street
North Vancouver, BC V7L 0G9
Canada

Response Time: We respond to GDPR-related inquiries within one month of receipt.

This GDPR Privacy Notice demonstrates our commitment to transparency and compliance with EU data protection law. We continuously review and update our practices to ensure ongoing compliance.

BJORN Kreativ · 151 15th Street, North Vancouver, BC, V7L 0G9, Canada