Stellar Niche
  • Home
  • About
  • Services
  • Contact

GDPR Compliance

Last Updated: April 10, 2026

Introduction

Stellar Niche is committed to protecting the privacy rights of individuals in the European Economic Area (EEA), United Kingdom, and Switzerland. This document explains how we comply with the General Data Protection Regulation (GDPR) and your rights under this legislation.

While Stellar Niche operates from Canada, we recognize and respect the privacy rights of all visitors to our website, including those from regions covered by GDPR.

Data Controller Information

For the purposes of GDPR, Stellar Niche is the data controller responsible for your personal information.

Stellar Niche
347 Wilderness Trail
Canmore, Alberta T1W 2E8
Canada
Email: [email protected]

Legal Basis for Processing

We process your personal data based on the following legal grounds:

Contract Performance

When you book an expedition with us, we process your information to fulfill our contractual obligations, including trip organization, communication, and service delivery.

Legitimate Interests

We process certain data based on legitimate business interests, such as improving our services, analyzing website usage, and maintaining business records. We balance these interests against your rights and only proceed when our interests do not override your fundamental rights.

Consent

For marketing communications and certain cookie uses, we rely on your explicit consent. You may withdraw this consent at any time without affecting the lawfulness of processing based on consent before withdrawal.

Legal Obligations

Some data processing is necessary to comply with legal requirements, such as tax regulations, safety reporting, or responding to lawful requests from authorities.

Your GDPR Rights

Under GDPR, you have comprehensive rights regarding your personal data:

Right to Access

You can request confirmation of whether we process your personal data and obtain a copy of that data. We will provide this information in a commonly used electronic format.

Right to Rectification

You may request correction of inaccurate personal data or completion of incomplete information. We will make corrections promptly and notify any third parties who received the data.

Right to Erasure

In certain circumstances, you can request deletion of your personal data. This right applies when data is no longer necessary for its original purpose, when you withdraw consent, or when processing is unlawful. Note that legal retention requirements may prevent immediate deletion in some cases.

Right to Restriction of Processing

You can request that we limit how we use your data while we verify accuracy, assess legitimate grounds for processing, or when you need the data preserved for legal claims.

Right to Data Portability

For data provided based on consent or contract, you can receive your information in a structured, machine-readable format and transmit it to another controller where technically feasible.

Right to Object

You may object to processing based on legitimate interests or for direct marketing purposes. We will cease processing unless we demonstrate compelling legitimate grounds that override your interests.

Rights Related to Automated Decision-Making

We do not use automated decision-making or profiling that produces legal effects or similarly significantly affects you. Any data analysis we conduct is used only to improve service quality and website functionality.

Exercising Your Rights

To exercise any of these rights, contact us at [email protected] with your request. Please include sufficient information to identify you and specify which right you wish to exercise.

We will respond within one month of receiving your request. In complex cases, we may extend this period by two additional months and will inform you of any such extension.

We do not charge fees for most requests. However, if your request is manifestly unfounded, excessive, or repetitive, we may charge a reasonable administrative fee or refuse to act on the request.

Data Collection and Use

Information We Collect

We collect only data necessary for our business purposes:

  • Contact information for communication and booking management
  • Health and dietary information relevant to wilderness safety
  • Payment details for transaction processing
  • Website usage data to improve user experience
  • Emergency contact information for participant safety

Data Minimization

We adhere to the principle of data minimization, collecting only what is adequate, relevant, and limited to what is necessary for specified purposes. We do not collect excessive or unnecessary personal information.

Data Sharing and Transfers

Third-Party Processors

We engage carefully selected third-party service providers who process personal data on our behalf. These processors are contractually obligated to implement appropriate security measures and process data only according to our instructions.

International Data Transfers

Your personal data may be transferred to and processed in Canada, which is not subject to an adequacy decision by the European Commission. When we transfer your data outside the EEA, we implement appropriate safeguards such as:

  • Standard contractual clauses approved by the European Commission
  • Ensuring processors in third countries have adequate data protection measures
  • Obtaining your explicit consent when required

Data Security

We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:

  • Encryption of personal data in transit and at rest
  • Regular security assessments and penetration testing
  • Access controls limiting data access to authorized personnel
  • Employee training on data protection principles
  • Incident response procedures for potential data breaches

Data Retention

We retain personal data only as long as necessary for the purposes for which it was collected or as required by law. Our retention periods are based on:

  • Business need and operational requirements
  • Legal and regulatory obligations
  • Potential legal claims and statute of limitations

When data is no longer needed, we securely delete or anonymize it to prevent unauthorized access or use.

Data Breach Notification

In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify you without undue delay. We will also notify relevant supervisory authorities within 72 hours of becoming aware of the breach, as required by GDPR.

Breach notifications will include the nature of the breach, likely consequences, measures taken or proposed to address the breach, and contact information for further inquiries.

Cookies and Tracking

Our website uses cookies and similar technologies. We obtain your consent before placing non-essential cookies on your device. You can manage cookie preferences through our cookie banner or browser settings.

For detailed information about our cookie practices, please review our Cookies Policy.

Children's Data

We do not knowingly collect or process personal data from children under sixteen without parental or guardian consent. If we become aware that we have inadvertently collected such data, we will take steps to delete it promptly.

Right to Lodge a Complaint

If you believe we have not handled your personal data in accordance with GDPR, you have the right to lodge a complaint with a supervisory authority in your country of residence, place of work, or where an alleged infringement occurred.

We encourage you to contact us first so we can attempt to resolve any concerns directly. However, this does not affect your right to approach a supervisory authority.

Updates to GDPR Compliance

We regularly review and update our data protection practices to ensure ongoing GDPR compliance. Changes to this document will be reflected in the "Last Updated" date above.

Significant changes will be communicated through our website or direct notification if you have an ongoing relationship with us.

Contact Us

For questions about our GDPR compliance, to exercise your rights, or to raise concerns about data processing, please contact:

Email: [email protected]
Mail: Stellar Niche, 347 Wilderness Trail, Canmore, Alberta T1W 2E8, Canada

We are committed to working with you to resolve any privacy concerns in a timely and respectful manner.

Stellar Niche

Guiding authentic wilderness experiences across Canada's most remarkable landscapes.

Quick Links

  • About
  • Services
  • Contact

Legal

  • Privacy Policy
  • GDPR
  • Cookies Policy
  • Terms of Use

© 2026 Stellar Niche. All rights reserved.