Home
KSystems Group

GDPR Statement

Effective date: 16 August 2026  ·  Last updated: 16 August 2026

How KSystems Group meets its obligations under the EU and UK General Data Protection Regulation, as both a controller and a processor.

Our commitment

KSystems Group supports clients whose people, customers, and operations fall within the scope of the EU and UK General Data Protection Regulation. Where the GDPR applies to information we handle, we meet its requirements — and we help our clients meet theirs.

This statement summarises how we approach the GDPR. It supplements our Privacy Policy, which describes our handling of personal information generally.

Controller and processor roles

Our role under the GDPR depends on the context:

  • We act as a controller for information we collect for our own purposes — website enquiries, client and supplier contacts, marketing, and recruitment.
  • We act as a processor when we handle personal information inside a client’s environment while delivering services. In that role we act only on the client’s documented instructions.

Lawful basis

Where we act as a controller we rely on one of the following: performance of a contract; our legitimate interests in operating, promoting, and securing our business, assessed against your rights and freedoms; compliance with a legal obligation; or consent, which you may withdraw at any time without affecting processing already carried out.

Data processing agreements

Where we process personal information on a client’s behalf, we enter into a written data processing agreement that sets out the subject matter and duration of the processing, its nature and purpose, the categories of data and data subjects, and the obligations of each party — as required by Article 28.

We do not engage a sub-processor without the client’s authorisation, and we impose equivalent data-protection obligations on any sub-processor we use.

Your rights as a data subject

If the GDPR applies to you, you have the right to access your personal data; to have inaccurate data corrected; to have data erased where we have no continuing grounds to keep it; to restrict or object to processing; to receive your data in a portable format; and to withdraw consent.

Send requests to the contact address below. We respond within one month, which may be extended by two further months for complex requests — we will tell you if that applies. There is no fee for a request unless it is manifestly unfounded or excessive.

Where we hold the data as a processor on a client’s behalf, we will refer your request to that client, who is the controller, and support them in responding.

International transfers

KSystems Group is established in Canada. Where personal data is transferred from the European Economic Area or the United Kingdom to us or to our service providers, we rely on an appropriate transfer mechanism — including the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum where required, together with a transfer risk assessment and supplementary technical measures such as encryption in transit and at rest.

Canada benefits from a partial adequacy decision of the European Commission in respect of organisations subject to PIPEDA.

Security measures

We apply technical and organisational measures appropriate to the risk, as required by Article 32. These include identity-first access control with multi-factor authentication, least-privilege permissions, encryption of data in transit and at rest, network segmentation, centralised logging and monitoring, vulnerability management, secure development practices, and staff training on data protection and information security.

Personal data breaches

We maintain an incident response process covering detection, containment, assessment, and notification. Where we act as a controller and a breach is likely to result in a risk to individuals, we notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it, and we inform affected individuals where the risk is high.

Where we act as a processor, we notify the client controller without undue delay after becoming aware of a breach and assist them with their own notification obligations.

Records and accountability

We maintain records of processing activities, apply data protection by design and by default, limit collection to what is necessary, and review our practices periodically. Where a proposed processing activity is likely to result in a high risk to individuals, we carry out a data protection impact assessment before proceeding.

Retention

We keep personal data only for as long as necessary for the purpose it was collected and to meet legal and contractual obligations. Data held on behalf of a client is returned or deleted at the end of the engagement in accordance with the data processing agreement.

Contact and complaints

To exercise your rights, to request a data processing agreement, or to raise a data protection concern, contact:

KSystems Group
Email: info@ksystemsgroup.com
Telephone: +1 587 883 3111

You also have the right to lodge a complaint with your local supervisory authority in the EEA or with the Information Commissioner’s Office in the UK. We would welcome the chance to address your concern first.