GDPR & PIPEDA Compliance

MarketXYGDPR & PIPEDA Compliance
Effective: April 14, 2026MarketXY.com — AllHeart Web Inc.
Plain-English Summary — MarketXY complies with GDPR for EU/UK users and PIPEDA for Canadian users. You have full rights to access, correct, and delete your data. A DPA is available for B2B customers who require one.
✓ GDPR compliant✓ PIPEDA compliant✓ DPA available on request✓ 30-day rights responseℹ SCCs used for international transfers

This Compliance Statement explains how AllHeart Web Inc. ("MarketXY") meets its obligations under the General Data Protection Regulation (GDPR) — applicable to users in the European Union and United Kingdom — and the Personal Information Protection and Electronic Documents Act (PIPEDA) — applicable to users in Canada. Both frameworks are addressed in this unified document.

Section 01

Overview

MarketXY processes personal data in two primary contexts:

B2C / User data
Data collected directly from registered users — account information, usage logs, billing data, and support communications. MarketXY acts as a Data Controller for this data.
WHOIS / third-party data
Registrant contact information that appears in publicly available WHOIS records and other public sources, processed as part of MarketXY's domain intelligence services. MarketXY processes this data under a legitimate interests basis.
Customer-submitted data
Personal data submitted by enterprise customers through integrations, CRM enrichment, or API calls. For this data, MarketXY acts as a Data Processor on behalf of the customer as Data Controller.
Section 02

GDPR — EU & UK Compliance

MarketXY processes the personal data of EU and UK residents in accordance with the General Data Protection Regulation (EU) 2016/679 and the UK GDPR (as retained by the UK Data Protection Act 2018).

Legal Bases We Rely On

Processing ActivityLegal BasisGDPR Article
Providing subscription ServicesPerformance of a contractArt. 6(1)(b)
Processing payments & invoicingPerformance of a contractArt. 6(1)(b)
Tax & accounting complianceLegal obligationArt. 6(1)(c)
Platform security & fraud preventionLegitimate interestsArt. 6(1)(f)
Platform analytics & improvementLegitimate interestsArt. 6(1)(f)
Marketing communicationsConsent or Legitimate interestsArt. 6(1)(a)/(f)
WHOIS data processingLegitimate interestsArt. 6(1)(f)
Processing customer-submitted dataData Processing Agreement (processor)Art. 28

Data Minimisation

We collect only the personal data necessary for the identified purpose. Data collection practices are reviewed periodically to ensure they remain proportionate and limited to what is necessary.

Retention

Personal data is retained only for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable law. See our Privacy Policy for specific retention periods by data category.

Section 03

Your GDPR Rights

If you are in the EU, EEA, or UK, you have the following rights under GDPR. To exercise any of these rights, contact [email protected]. We will respond within 30 days (which may be extended to 60 days in complex cases, with notice).

RightWhat It Means
Right of Access (Art. 15)Request a copy of the personal data we hold about you, and information about how it is processed
Right to Rectification (Art. 16)Request correction of inaccurate or incomplete personal data
Right to Erasure (Art. 17)Request deletion of your personal data, subject to legal retention obligations
Right to Restriction (Art. 18)Request that we restrict processing of your data in certain circumstances
Right to Portability (Art. 20)Receive your personal data in a structured, machine-readable format and transfer it to another controller
Right to Object (Art. 21)Object to processing based on legitimate interests, including profiling and direct marketing
Right to Withdraw Consent (Art. 7)Withdraw consent at any time where processing is consent-based, without affecting prior processing
Right Not to Be Subject to Automated Decisions (Art. 22)Not be subject to solely automated decisions that produce significant legal effects, without human review
Section 04

Data Processing Agreement (DPA)

Where MarketXY acts as a Data Processor on behalf of an enterprise customer (as Data Controller), a Data Processing Agreement (DPA) is required under Article 28 of the GDPR. The DPA sets out the nature, purpose, and duration of the processing, the types of personal data involved, and the obligations of each party.

Requesting a DPA

Enterprise customers who qualify as Data Controllers may request a DPA by emailing [email protected]. We will respond within 5 business days. Failure to enter into a DPA where legally required constitutes a material breach of the Terms of Use.

Subprocessors

MarketXY uses a limited number of authorised subprocessors to provide the Services, including cloud infrastructure, payment processing, email delivery, and support platforms. A current list of subprocessors is available upon request. We ensure all subprocessors are bound by data protection agreements equivalent to the DPA.

Section 05

International Data Transfers

MarketXY is operated by AllHeart Web Inc. and may transfer personal data to countries outside the EEA or UK, including Canada and the United States. Where such transfers occur, we rely on one or more of the following safeguards:

  • Standard Contractual Clauses (SCCs): the European Commission's approved SCCs (2021/914) are incorporated into our DPA and service agreements for transfers to non-adequate countries
  • UK International Data Transfer Agreements (IDTAs): used for transfers from the UK where SCCs are not applicable
  • Adequacy decisions: Canada (PIPEDA) has an adequacy decision from the European Commission; transfers to Canada are therefore permitted without additional safeguards
  • Binding Corporate Rules (BCRs): evaluated on a case-by-case basis for specific enterprise arrangements
Section 06

PIPEDA — Canadian Compliance

MarketXY complies with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) for the collection, use, and disclosure of personal information in the course of commercial activities involving Canadian residents.

Our PIPEDA compliance is built around PIPEDA's Ten Fair Information Principles:

1. Accountability
AllHeart Web Inc. is responsible for personal information under our control. Our Privacy Officer oversees PIPEDA compliance.
2. Identifying Purposes
We identify the purposes for which personal information is collected before or at the time of collection.
3. Consent
We obtain meaningful consent for collection, use, and disclosure of personal information, with limited exceptions.
4. Limiting Collection
We collect only the information necessary for identified purposes.
5. Limiting Use, Disclosure & Retention
Personal information is used or disclosed only for the purpose it was collected, and retained only as long as necessary.
6. Accuracy
We keep personal information as accurate, complete, and up-to-date as necessary.
7. Safeguards
We protect personal information with security measures appropriate to the sensitivity of the information.
8. Openness
We make our privacy practices readily available through this Policy and our Privacy Policy.
9. Individual Access
Individuals may request access to their personal information and challenge its accuracy.
10. Challenging Compliance
Individuals may challenge our compliance with PIPEDA principles via our Privacy Officer.
Section 07

Your PIPEDA Rights

Canadian residents have the following rights under PIPEDA. To exercise these rights, contact our Privacy Officer at [email protected]. We respond within 30 days.

  • Right of Access: request access to the personal information we hold about you and how it is used
  • Right to Correction: request correction of any inaccurate personal information
  • Right to Withdraw Consent: withdraw consent for collection, use, or disclosure at any time, subject to legal or contractual restrictions
  • Right to Challenge Compliance: challenge our compliance with PIPEDA principles; complaints will be investigated and responded to in writing
  • Right to Complain: file a complaint with the Office of the Privacy Commissioner of Canada (OPC) at priv.gc.ca if you are not satisfied with our response
Section 08

Data Breach Notification

GDPR Obligations

In the event of a personal data breach that poses a risk to the rights and freedoms of EU/UK individuals, MarketXY will:

  • Notify the relevant supervisory authority within 72 hours of becoming aware of the breach (where feasible)
  • Notify affected individuals without undue delay if the breach poses a high risk to their rights and freedoms
  • Maintain internal records of all breaches, including those that do not require notification

PIPEDA Obligations

For breaches involving Canadian residents, MarketXY will comply with PIPEDA's mandatory breach reporting requirements by:

  • Reporting breaches that pose a real risk of significant harm to the OPC as soon as feasible
  • Notifying affected individuals of such breaches directly
  • Maintaining records of all breaches for a minimum of 24 months
If you suspect a data breach involving your MarketXY account or data, contact [email protected] immediately.
Section 09

Data Protection Officer

MarketXY has designated a Privacy Officer responsible for overseeing compliance with GDPR, PIPEDA, and this Compliance Statement. The Privacy Officer reviews data processing activities, handles data rights requests, responds to regulatory enquiries, and conducts periodic compliance audits.

To contact the Privacy Officer: [email protected] — or by post to: Privacy Officer, AllHeart Web Inc., [Registered Address].

Section 10

Complaints & Supervisory Authorities

If you are not satisfied with how we have handled your data rights request or privacy complaint, you have the right to lodge a complaint with the appropriate supervisory authority:

JurisdictionAuthorityContact
European UnionYour local EU Data Protection Authority (DPA) — list at edpb.europa.euedpb.europa.eu
United KingdomInformation Commissioner's Office (ICO)ico.org.uk
CanadaOffice of the Privacy Commissioner of Canada (OPC)priv.gc.ca
All regionsMarketXY Privacy Officer (first-instance complaints)[email protected]
Questions about this policy?
Contact us at [email protected] — we respond within 2 business days.