Privacy Policy
The company SOOA (hereinafter referred to as "SOOA" or "we") attaches great importance to the protection of your personal data and, more generally, to your privacy.
In the course of operating the Website www.sooa.com (the "Website"), SOOA may collect and process personal data about you. This Privacy Policy describes how we handle your personal data when you use the Website.
All your personal data is processed by us in accordance with applicable Canadian privacy laws, in particular the Personal Information Protection and Electronic Documents Act (PIPEDA) and any relevant provincial legislation. The processing operations and their purposes are specified in the table at the end of this Privacy Policy.
Who processes your personal data?
Your personal data is processed under the responsibility of SOOA, a simplified joint stock company with a single shareholder, having its registered office in Toronto, Canada. In accordance with applicable laws, SOOA is responsible for the processing described in this Privacy Policy.
What categories of personal data do we collect and for what purpose(s)?
We only process your personal data if required to:
-
Perform a contract to which you are a party (e.g., process your orders);
-
Pursue our legitimate business interests;
-
Comply with legal obligations;
-
Or based on your consent for specific purposes.
The specific categories of data collected and the corresponding purposes are detailed in the table at the end of this Privacy Policy.
Mandatory fields are marked with an asterisk (*). If you do not provide the required data, you may not be able to access certain services or features.
For information on our use of cookies, please see our Cookie Policy.
Who has access to your personal data?
Within SOOA, only those employees or service providers who need access for the stated purposes will handle your personal data.
We may disclose data to third-party processors located in Canada or other countries. Any cross-border transfers of personal data are governed by contractual or other appropriate safeguards to ensure adequate protection.
How long do we keep personal data?
We retain your personal data only as long as necessary for the purposes for which it was collected and to meet legal requirements. Retention periods for each processing operation are specified in the table below.
How is your personal data protected?
We implement physical, technical and organizational measures to protect your personal data against unauthorized access, disclosure, alteration or destruction.
What are your rights?
Under PIPEDA, you have the right to:
-
Access your personal data and obtain information about how we process it.
-
Request corrections to your personal data if it is inaccurate or incomplete.
-
Withdraw your consent at any time, where processing is based on consent.
-
Request deletion or anonymization of your data when no longer needed.
-
Object to or limit processing based on legitimate interests.
-
Obtain a copy of your data in a structured, machine-readable format and transmit it to another organization (data portability).
To exercise your rights, please contact us using the details below. We will respond within the timeframes required by law.
Changes to this Privacy Policy
We may update this Privacy Policy from time to time. We will post the updated version on our Website and, where appropriate, notify you by email.
Contact Us
If you have any questions or wish to exercise your rights, you can contact us:
-
By email: contact@sooa.com
-
By post: SOOA, Legal Department, Toronto, Canada
If you are not satisfied with our response, you can file a complaint with the Office of the Privacy Commissioner of Canada:
-
By post:
Office of the Privacy Commissioner of Canada
30 Victoria Street
Gatineau, Quebec K1A 1H3 -
By phone: 1‑800‑282‑1376
-
Via website: https://www.priv.gc.ca
Table of processing operations, purposes, data categories, recipients, and retention periods
Processing purpose | Data categories | Recipients | Retention period |
---|---|---|---|
Order processing | Name, address, email, purchase history | Payment processor, shipping provider | 7 years from order completion |
Marketing communications | Email, preferences | Email service provider | Until withdrawal of consent |
Account management | Name, email, login credentials | Internal IT systems | For the duration of your account |
Customer support | Name, email, support tickets | Support platform provider | 2 years after last contact |
Legal and compliance | Any personal data required for legal obligations | Legal advisors, courts | As required by law |