1. Who We Are
This Privacy Policy applies to the website khakryonxap.world (the "Site") operated by Khakryonxap (the "Company", "we", "us", or "our").
We act as the organization responsible for personal information collected through this Site (for individuals in the European Economic Area, as data controller under the GDPR). Our contact details are provided at the end of this policy.
Canadian privacy framework: We collect, use, and disclose personal information in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA), Canada, and, where applicable, the Personal Information Protection Act (PIPA) of Alberta, and other provincial laws that may apply depending on your location. If you are in Quebec, the Act respecting the protection of personal information in the private sector (Law 25) may also apply to certain aspects of our practices; we will provide information and obtain consent as required by that law where it applies.
2. What Personal Data We Collect
We may collect the following categories of personal data:
- Contact information: full name, email address, and telephone number (if provided) when you complete our order form.
- Order information: the content of any message or note submitted alongside an order.
- Technical data: IP address, browser type and version, device type, operating system, pages visited, time and date of visit, and referring URL, collected automatically via server logs and analytics tools (where consent is given).
- Cookie and preference data: your cookie consent choices, stored in your browser's local storage.
We do not collect payment card details directly. Any payment processing is handled by a certified payment provider.
3. How We Use Your Personal Data
We use personal data for the following purposes:
- Order fulfilment: to process and deliver your order, and to communicate with you about its status.
- Customer service: to respond to your enquiries and provide support.
- Legal compliance: to fulfil our obligations under applicable law, including consumer protection, tax, and accounting requirements.
- Site improvement: to understand how the Site is used and to improve its functionality and content, where analytics consent has been granted.
- Marketing communications: to send relevant promotional information, only where you have provided explicit consent.
4. Legal Basis for Processing
Under the General Data Protection Regulation (GDPR), where it applies, and under Canadian privacy principles (PIPEDA and applicable provincial statutes), we rely on the following:
- Contract performance: processing your order and communicating about it.
- Legal obligation: retaining transaction records as required by law.
- Legitimate interests: preventing fraud, improving website security, and analysing site usage (where not overridden by your rights).
- Consent: for marketing communications, analytics cookies, and marketing cookies. You may withdraw consent at any time. Under PIPEDA, consent must be meaningful; we only collect, use, or disclose personal information for purposes a reasonable person would consider appropriate in the circumstances.
Canada’s ten principles (PIPEDA summary): We are accountable for personal information under our control; we identify purposes at or before collection; we obtain consent (express or implied as appropriate); we limit collection, use, disclosure, and retention to what is necessary; we keep information accurate; we use appropriate safeguards; we are open about our practices; we give individuals access to their information; and we allow individuals to challenge compliance by contacting us.
5. Data Retention
We retain personal data only for as long as necessary for the purposes described in this policy:
- Order and transaction records: 7 years, to comply with accounting and tax obligations.
- Customer communications: 2 years from the date of last contact.
- Technical/analytics data: up to 26 months from the date of collection.
- Marketing consent records: until consent is withdrawn, plus 1 year for audit purposes.
Upon expiry of the applicable retention period, personal data is securely deleted or irreversibly anonymised.
6. Who We Share Your Data With
We do not sell, rent, or trade your personal data. We may share it with trusted third parties only where necessary:
- Delivery and logistics partners: to fulfil and track your order.
- Payment processors: to handle secure payment transactions.
- Email service providers: to send order confirmations and customer communications.
- Analytics providers: only where you have consented to analytics cookies.
- Legal and regulatory authorities: where required by law or legitimate legal process.
All third-party processors are required to handle personal data in accordance with our instructions, applicable law (including PIPEDA and, where relevant, GDPR), and to implement appropriate security measures.
7. International Data Transfers
Some of our third-party service providers may process data outside the European Economic Area (EEA) or Canada. Where such transfers occur, we implement appropriate safeguards, including Standard Contractual Clauses (SCCs) approved by the European Commission, to ensure your data receives an equivalent level of protection.
Where personal information is transferred to a service provider in another country, we use contractual or other means to provide a comparable level of protection while the information is being processed by that third party, as required under PIPEDA and applicable provincial law.
8. Your Rights
Subject to applicable law, you have the following rights regarding your personal data:
- Right of access: to request a copy of the personal data we hold about you.
- Right to rectification: to request correction of inaccurate or incomplete data.
- Right to erasure: to request deletion of your personal data, subject to legal retention requirements.
- Right to restriction: to request that we limit the processing of your data in certain circumstances.
- Right to data portability: to receive your personal data in a structured, machine-readable format (where applicable under GDPR).
- Right to object: to object to processing based on legitimate interests or for marketing purposes.
- Right to withdraw consent: where processing is based on consent, to withdraw it at any time without affecting prior processing.
Canada: Under PIPEDA, you may request access to your personal information and challenge its accuracy and completeness. You may also ask how we use your information and to whom it has been disclosed (subject to limited exceptions prescribed by law). We will respond to access requests within a reasonable time and, for formal requests, generally within 30 days unless an extension is permitted by law.
Complaints: If you are not satisfied with our response, you may file a complaint with the Office of the Privacy Commissioner of Canada (OPC) at priv.gc.ca. If you are in Alberta, you may contact the Office of the Information and Privacy Commissioner of Alberta. Quebec residents may contact the Commission d’accès à l’information du Québec. If you are in the EEA, you may lodge a complaint with your local supervisory authority.
Commercial electronic messages (CASL): We only send promotional emails where you have given express consent or as otherwise permitted under Canada’s Anti-Spam Legislation (CASL). Every marketing message includes an unsubscribe mechanism. You may withdraw consent to marketing at any time.
9. Cookies
We use cookies and similar technologies on this Site. For full details of the cookies we use, their purpose, and how to manage your preferences, please see our Cookie Policy.
10. Security Measures
We implement technical and organisational measures to protect your personal data against unauthorised access, loss, or disclosure. These include:
- HTTPS encryption for all data transmitted through the Site.
- Access controls limiting employee access to personal data on a need-to-know basis.
- Regular security assessments and updates to our systems.
- Data processing agreements with all third-party processors.
While we take all reasonable steps to protect your data, no transmission over the internet is completely secure. We cannot guarantee absolute security.
11. Children's Privacy
This Site is not directed at individuals under the age of 18. We do not knowingly collect personal data from minors. In Canada, we do not knowingly collect personal information from individuals under the age of majority in their province or territory of residence for commercial purposes without appropriate parental or guardian consent where required by law. If you believe a minor has submitted data through this Site, please contact us and we will arrange for its deletion.
12. Changes to This Policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top of this page will reflect any changes. Where changes are material, we will notify you by email or by a prominent notice on the Site.
Contact Us
Khakryonxap
125 Loutit St, Fort Chipewyan, AB T0P 1B0, Canada
Email: correspondence@khakryonxap.world
Website: khakryonxap.world