Last Updated: January 1, 2026
snow-saga is committed to compliance with the General Data Protection Regulation (GDPR) and protecting the privacy rights of individuals in the European Economic Area. This document outlines how we fulfill our obligations under GDPR.
We process personal data based on the following legal grounds:
GDPR provides comprehensive rights regarding your personal data:
You have the right to obtain confirmation about whether we process your personal data and, if so, to access that data along with information about how it is processed.
You can request correction of inaccurate personal data and completion of incomplete data.
Under certain circumstances, you have the right to request deletion of your personal data, including when:
You can request that we restrict processing of your personal data when:
Where processing is based on consent or contract and carried out by automated means, you have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit it to another controller.
You have the right to object to processing based on legitimate interests or for direct marketing purposes. We will cease processing unless we demonstrate compelling legitimate grounds that override your interests.
You have the right not to be subject to decisions based solely on automated processing, including profiling, that produce legal effects or similarly significantly affect you. We do not engage in automated decision-making with legal or significant effects.
To exercise any of your GDPR rights, contact us at [email protected]. Please include:
We will respond to requests within one month. In complex cases, this period may be extended by two additional months, and we will inform you of any such extension.
For questions about our GDPR compliance or data protection practices, contact our data protection representative at [email protected].
Personal data is processed and stored within the European Economic Area. If data must be transferred outside the EEA, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission.
In the event of a data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. If the breach poses a high risk, we will also notify affected individuals without undue delay.
You have the right to lodge a complaint with a supervisory authority, particularly in the EU member state where you reside, work, or where an alleged infringement occurred.
In Ireland, the supervisory authority is:
Data Protection Commission
21 Fitzwilliam Square South
Dublin 2, D02 RD28, Ireland
Website: www.dataprotection.ie
We retain personal data only as long as necessary for the purposes outlined in our Privacy Policy or as required by law. Retention periods vary based on:
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including: