Effective Date: October 3, 2026
Website: https://onyxda.com
Data Controller: Onyxda
Registered Address: 8 Ivy Bridge Dr, Stoney Creek, ON L8E 4A4, Canada
Privacy Officer & Contact: directors@onyxda.com
Onyxda ('Company', 'we', 'our', or 'us') respects the privacy rights of visitors, clients, and partners. This Privacy Policy details our operational practices regarding the collection, processing, storage, and transfer of personal data in compliance with the Personal Information Protection and Electronic Documents Act (PIPEDA – Canada), the General Data Protection Regulation (EU GDPR / German DSGVO), the UK GDPR / Data Protection Act 2018, and state-level consumer privacy laws in the United States (including CCPA / CPRA).
| Category | Information Collected | Legal Basis (GDPR Art. 6) |
|---|---|---|
| Identity & Business Contact | Full name, professional email address, company name, corporate title, billing physical address. | Performance of Contract (Art. 6(1)(b)) & Legitimate Interests (Art. 6(1)(f)) |
| Project & Technical Data | Project specifications, API integration keys, brand assets, ad account delegate access, audience criteria. | Contractual Performance (Art. 6(1)(b)) |
| Technical & Telemetry Data | IP address, browser type/version, operating system, referring URL, time stamp, device identifiers. | Legitimate Interests (Art. 6(1)(f)) & Security Compliance |
| Marketing & Inquiry Records | Form submissions, email communications, and direct inquiries sent to directors@onyxda.com. | Consent (Art. 6(1)(a)) & Legitimate Interests (Art. 6(1)(f)) |
Performance of Contract (Art. 6(1)(b)): Processing required to provide quotations, enter into contracts, and build commissioned software or marketing projects.
Legitimate Interests (Art. 6(1)(f)): Processing required to maintain web application security, prevent fraud, optimize platform performance, and manage legitimate B2B correspondence.
Compliance with Legal Obligations (Art. 6(1)(c)): Retaining financial, tax, and invoicing records pursuant to Canadian and international commercial accounting laws.
Consent (Art. 6(1)(a)): Processing based on affirmative consent, such as opting into analytics tracking or marketing communications.
Essential Cookies: Strictly required for website security, session navigation, and secure form delivery.
Performance & Analytics: Google Analytics or equivalent tools used to evaluate aggregate traffic patterns. In compliance with German and EU guidelines, IP masking/anonymization is applied.
Consent Controls: Visitors from the UK, Germany, and EU may decline non-essential cookies via browser settings or on-site consent prompts.
Onyxda is headquartered in Ontario, Canada, and utilizes secure cloud infrastructure located in Canada, the United States, and the UK. Under GDPR Article 45, Canada's commercial data protection regime (PIPEDA) is recognized by the European Commission as providing adequate data protection. For transfers involving non-adequate jurisdictions, Onyxda implements Standard Contractual Clauses (SCCs) and International Data Transfer Agreements (IDTAs) to ensure full data protection.
European Union (Germany / DSGVO) & United Kingdom: Under the GDPR / DSGVO and UK Data Protection Act, you possess the right of access (Art. 15), right to rectification (Art. 16), right to erasure (Art. 17), right to restriction (Art. 18), right to data portability (Art. 20), and right to object to processing (Art. 21). You also have the right to lodge a complaint with your competent supervisory authority (e.g., German Federal/State Data Protection Commissioners or the UK Information Commissioner's Office – ICO).
United States (California CCPA / CPRA & State Laws): Residents possess the right to know what personal data is collected, the right to request deletion of personal information, and the right to freedom from discrimination for exercising privacy rights. Onyxda DOES NOT sell or share personal data for cross-context behavioural advertising.
Canada (PIPEDA): Individuals have the right to request access to their personal information and request necessary corrections.
We maintain industry-standard physical, organizational, and electronic safeguards, including end-to-end SSL/TLS encryption for web communications, credential isolation, and restricted database access. No internet-based transmission is 100% impenetrable; clients must safeguard their own credentials.
To submit a verified Data Subject Access Request (DSAR), rectification request, or privacy inquiry, email our Data Protection Officer exclusively at:
Dedicated Privacy Email: directors@onyxda.com (Subject: Formal Data Subject Request / Privacy Inquiry)