Last Updated: June 25, 2026
Cedar Kestrel is committed to protecting your personal data in accordance with the General Data Protection Regulation. This page outlines how we comply with GDPR requirements and your rights under this regulation.
We process your personal data based on one or more of the following legal grounds:
As a data subject under GDPR, you have the following rights:
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including any legal, accounting, or reporting requirements. When data is no longer needed, we securely delete or anonymize it.
If we transfer your personal data outside the European Economic Area, we ensure appropriate safeguards are in place to protect your data in accordance with GDPR requirements, such as standard contractual clauses approved by the European Commission.
For questions about how we handle your personal data or to exercise your GDPR rights, you can contact us at [email protected].
To exercise any of your rights under GDPR, please contact us with your request. We will respond within one month of receiving your request. In complex cases, we may extend this period by an additional two months, and we will inform you of any such extension.
If you believe we have not handled your personal data in accordance with GDPR, you have the right to lodge a complaint with your local data protection authority.
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. If the breach poses a high risk, we will also notify affected individuals without undue delay.