1. Scope and privacy framework
This Privacy Policy explains how Selquorianwhiteatelier Inc. ("Selquorianwhiteatelier", "we", "us" or "our") collects, uses, discloses, retains and protects personal information when you visit trevoriangrandmanor.com, contact the atelier, request a consultation, enquire about designer collections or runway services, or otherwise interact with us. We operate in Canada. Depending on the circumstances, our privacy obligations may include the Personal Information Protection and Electronic Documents Act (PIPEDA), substantially similar provincial private-sector privacy legislation where applicable, Canada's Anti-Spam Legislation (CASL) for commercial electronic messages, and the EU General Data Protection Regulation (GDPR) where its territorial scope applies. If a provincial law applies instead of PIPEDA to a particular activity, we will follow that law to the extent required.
2. Privacy accountability and contact
We are responsible for personal information under our control and use reasonable administrative, technical and organizational measures to support compliance. Questions, access requests, correction requests, consent withdrawals and privacy complaints may be sent to info@selquorianwhiteatelier.com. Our site-facing legal identity and mailing address are shown below and are loaded from the local adress.json file so they can be maintained consistently across the website.
Legal entity: Selquorianwhiteatelier Inc.
Mailing address: 123 Fashion Way, Toronto, Ontario, M5V 1M4, Canada
3. Personal information we may collect
Depending on how you interact with the website, we may collect information you provide directly, such as your name, email address, telephone number, message content, consultation preferences, clothing or styling preferences you choose to disclose, appointment-related information, and correspondence history. We may also process limited technical information generated when the site is accessed, such as IP address, browser type, operating system, device category, referring page, approximate region derived from network information, timestamps, and security or diagnostic logs. We do not ask the public contact form for payment card details, government identifiers, health information or other unnecessary sensitive information.
4. Purposes for collection, use and disclosure
We process personal information only for identified and reasonable purposes. These may include responding to enquiries; arranging consultations; preparing or discussing bespoke design services; providing requested information about collections, runway work or other services; maintaining records of communications; operating, securing and troubleshooting the website; detecting misuse or fraud; meeting legal, accounting, insurance or dispute-resolution obligations; protecting the rights, safety and property of clients, personnel and the public; and sending marketing communications where permitted by law. We do not sell personal information.
5. Consent and meaningful choice under Canadian law
Where consent is the appropriate basis, we seek consent in a form appropriate to the sensitivity of the information and the reasonable expectations of the individual. We aim to explain the nature, purpose and consequences of collection, use or disclosure in understandable language. Consent may be express or implied where legally permitted. You may withdraw consent, subject to legal or contractual restrictions and reasonable notice. Withdrawal does not invalidate processing already carried out lawfully and may affect our ability to provide a requested service where the information is necessary for that service.
6. GDPR legal bases where applicable
Where the GDPR applies, we rely on one or more lawful bases under Article 6: your consent; steps taken at your request before entering into a contract or performance of a contract; compliance with a legal obligation; protection of vital interests in exceptional circumstances; or our legitimate interests, provided those interests are not overridden by your rights and freedoms. Legitimate interests may include responding to business enquiries, securing our systems, preventing abuse, maintaining records, and improving service operations. If we ever need to process special-category data under Article 9, we will do so only where a specific Article 9 condition applies and only to the extent necessary.
7. Cookies and similar technologies
This site is designed to operate with a minimal cookie footprint. Essential storage or cookies may be used where required for core functionality, security or user preferences. Optional analytics, advertising or profiling technologies should not be activated without an appropriate consent mechanism where consent is legally required. More detail appears in our Cookie Policy. Browser controls can also be used to delete or block cookies, although strictly necessary functionality may be affected.
8. Marketing and CASL
We send commercial electronic messages only where we have a lawful basis to do so. Where CASL requires consent, the message will identify the sender and provide a functional unsubscribe mechanism. We will process valid unsubscribe requests as required by law. Withdrawing from marketing does not prevent service, transactional, safety or legal communications that are otherwise permitted.
9. Service providers and disclosures
We may use carefully selected service providers for functions such as hosting, website security, communications, professional advice, bookkeeping, or technical support. Providers are expected to handle personal information only for authorized purposes and with safeguards appropriate to the sensitivity of the data. We may disclose information where required or permitted by law, including to comply with lawful process, enforce rights, investigate suspected misconduct, protect safety, or complete a corporate reorganization subject to applicable legal requirements. We do not authorize third parties to use our client information for their own unrelated marketing merely because they provide a service to us.
10. International and cross-border processing
Some service providers may process information outside your province or outside Canada. Personal information processed in another jurisdiction may be subject to the laws and lawful access regimes of that jurisdiction. Where the GDPR applies to a transfer from the European Economic Area to a country that is not covered by an applicable adequacy mechanism for the relevant transfer, we use a legally recognized transfer mechanism where required, such as appropriate contractual safeguards, together with supplementary measures where appropriate.
11. Retention and disposal
We retain personal information only for as long as reasonably necessary for the purposes identified, to provide requested services, to meet legal or accounting requirements, to establish or defend legal claims, and to maintain appropriate business records. Retention periods vary by record type, sensitivity and legal context. When information is no longer required, we take reasonable steps to securely delete, anonymize or destroy it, subject to backup cycles and lawful retention obligations.
12. Safeguards and breach response
We use safeguards proportionate to the sensitivity and volume of information, which may include access controls, least-privilege practices, secure configuration, software updates, backup controls, staff confidentiality expectations, vendor diligence and incident-response procedures. No internet transmission or storage system can be guaranteed absolutely secure. Where a breach of security safeguards creates legal notification or record-keeping obligations, we will assess and respond to the incident in accordance with applicable law.
13. Accuracy, access and correction
We take reasonable steps to keep personal information accurate, complete and up to date where it is used to make decisions affecting an individual. Subject to applicable exceptions, you may request access to personal information we hold about you and request correction of inaccurate information. We may need to verify identity before fulfilling a request and may redact information that we are legally required or permitted to withhold, including information relating to another person, privileged material, confidential commercial information or information whose disclosure would create a serious safety risk.
14. GDPR data-subject rights
Where the GDPR applies, you may have the right to request access, rectification, erasure, restriction of processing, data portability, and to object to processing based on legitimate interests or to direct marketing. Where processing is based on consent, you may withdraw consent at any time. You also have the right to lodge a complaint with a competent supervisory authority. Rights are not absolute; statutory conditions, exemptions and verification requirements may apply. We do not intend to make decisions producing legal or similarly significant effects about website visitors solely through automated processing.
15. Children and minors
The public website is not designed to solicit personal information from children. If a minor contacts us, we limit collection and use to what is appropriate for the request and applicable law. Parents or legal guardians who believe a child has provided personal information inappropriately may contact us so that we can assess and, where appropriate, delete or restrict the information.
16. Third-party links
The website may contain links that take you to a third-party site or service. A third party's privacy practices are governed by its own notices and terms, not this policy. We recommend reviewing those notices before providing personal information. A link does not by itself mean that we control or endorse a third party's privacy practices.
17. Complaints and regulatory contacts
Please contact us first if you have a privacy concern so we can investigate and respond. Individuals in Canada may also have the right to complain to the Office of the Privacy Commissioner of Canada or, where applicable, a provincial privacy regulator. Individuals protected by the GDPR may lodge a complaint with the competent data protection authority in the EEA or other applicable supervisory authority. Nothing in this policy limits any statutory complaint or remedy.
18. Changes to this Privacy Policy
We may update this policy to reflect changes in our operations, technology or legal obligations. The version posted on this page is the current website version. Material changes will be presented in an appropriate manner having regard to their significance. We will not retroactively expand the use of personal information in a way that requires new consent without obtaining that consent where the law requires it.