Last Updated: December 28, 2025
What Is GDPR and Who Does It Apply To?
The General Data Protection Regulation (GDPR) is a comprehensive data protection law enacted by the European Union that came into effect on May 25, 2018. GDPR establishes strict requirements for how organizations collect, process, store, and protect personal data of individuals located in the European Union (EU) and European Economic Area (EEA).
This GDPR Compliance Statement applies to all visitors to radiotrailblazers.ca who are located in the EU or EEA at the time they access our website. According to GDPR Article 3, the regulation applies to any organization that offers goods or services to individuals in the EU, regardless of where the organization is based. As an informational website about Balkan mail order brides that is accessible to EU residents, we are committed to GDPR compliance.
Our Role Under GDPR
Radiotrailblazers.ca operates as a data controller for the limited personal data we collect through website analytics and user interactions. A data controller is the entity that determines the purposes and means of processing personal data. We do not operate as a marriage broker or dating agency-we are an informational resource that earns affiliate commissions from recommended dating platforms.
When you click through to third-party dating sites we recommend, those platforms become independent data controllers responsible for their own GDPR compliance. We encourage you to review the privacy policies of any external services you choose to use.
What Are the Legal Bases for Processing Your Data?
Under GDPR Article 6, all processing of personal data must have a lawful basis. Radiotrailblazers.ca processes visitor data under the following legal bases:
Legitimate Interest (Article 6(1)(f))
We process certain data based on our legitimate interest in operating and improving our website. According to GDPR recital 47, legitimate interests may include understanding how visitors use our site to improve content quality and user experience. This includes:
- Website analytics and traffic measurement to understand which pages are most helpful to visitors
- Technical data necessary for website functionality, security, and performance optimization
- Affiliate link tracking to measure which dating platforms visitors find most relevant
We have conducted a legitimate interest assessment and determined that these processing activities do not override your fundamental rights and freedoms, as the data collected is minimal and non-sensitive in nature.
Consent (Article 6(1)(a))
Where required, we obtain your explicit consent before processing personal data. This applies to:
- Non-essential cookies and tracking technologies (marketing and analytics cookies)
- Newsletter subscriptions, if we offer such services in the future
- Any voluntary information you provide through contact forms or surveys
You have the right to withdraw consent at any time by adjusting your cookie preferences or contacting us. Withdrawing consent does not affect the lawfulness of processing based on consent before its withdrawal.
What Data Subject Rights Do You Have?
Under GDPR Chapter III, individuals in the EU have comprehensive rights regarding their personal data. Radiotrailblazers.ca respects and facilitates the exercise of all applicable data subject rights:
Right of Access (Article 15)
You have the right to obtain confirmation as to whether we are processing your personal data and, if so, to access that data along with information about how we use it. This includes the right to receive a copy of your personal data undergoing processing.
Right to Rectification (Article 16)
If personal data we hold about you is inaccurate or incomplete, you have the right to request that we correct or complete it without undue delay. Given the minimal personal data we collect (primarily analytics), rectification requests are rare but will be honored.
Right to Erasure / "Right to Be Forgotten" (Article 17)
You have the right to request deletion of your personal data in certain circumstances, including when:
- The data is no longer necessary for the purposes for which it was collected
- You withdraw consent and there is no other legal ground for processing
- You object to processing and there are no overriding legitimate grounds
- The data has been unlawfully processed
Please note that this right is not absolute-we may retain certain data where legal obligations require us to do so.
Right to Restriction of Processing (Article 18)
In certain circumstances, you can request that we restrict how we process your personal data. When processing is restricted, we can store the data but not use it. This right applies when you contest the accuracy of data, when processing is unlawful but you prefer restriction to erasure, or when you need the data for legal claims.
Right to Data Portability (Article 20)
Where technically feasible and where processing is based on consent or contract, you have the right to receive your personal data in a structured, commonly used, and machine-readable format. You also have the right to transmit that data to another controller without hindrance.
Right to Object (Article 21)
According to GDPR Article 21, you have the right to object to processing based on legitimate interests. You may object to:
- Processing for direct marketing purposes (we will cease immediately)
- Processing based on legitimate interests (we must demonstrate compelling grounds that override your interests)
- Profiling and automated decision-making (though we do not engage in automated individual decision-making)
Rights Related to Automated Decision-Making (Article 22)
You have the right not to be subject to decisions based solely on automated processing, including profiling, which produces legal effects or similarly significantly affects you. Radiotrailblazers.ca does not engage in automated decision-making or profiling that would trigger these protections.
How Do We Transfer Data Outside the EU?
Radiotrailblazers.ca may use third-party service providers (such as analytics platforms, hosting services, and content delivery networks) that process data in countries outside the European Union and European Economic Area. According to GDPR Chapter V, any transfer of personal data to third countries must be subject to appropriate safeguards.
Where we transfer data internationally, we ensure compliance through one or more of the following mechanisms:
- Adequacy Decisions: We may transfer data to countries that the European Commission has determined provide an adequate level of protection (GDPR Article 45)
- Standard Contractual Clauses: Where adequacy decisions do not exist, we use Standard Contractual Clauses approved by the European Commission (GDPR Article 46)
- Privacy Shield Successors: For U.S.-based service providers, we verify participation in successor frameworks or alternative safeguards following the invalidation of Privacy Shield
Our primary service providers include analytics platforms and hosting infrastructure. We conduct due diligence to ensure these providers maintain GDPR-compliant data protection standards and have implemented appropriate technical and organizational measures.
What Security Measures Do We Implement?
Under GDPR Article 32, we are required to implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk. Radiotrailblazers.ca takes data security seriously and has implemented the following measures:
Technical Security Measures
- Encryption: HTTPS/TLS encryption for all data transmitted between your browser and our servers
- Access Controls: Restricted access to any stored data, with authentication required for administrative functions
- Data Minimization: We collect only the minimum data necessary for website operation and analytics
- Secure Hosting: Our hosting infrastructure is maintained by reputable providers with ISO 27001 certification and GDPR compliance
Organizational Security Measures
- Data Protection Policies: Internal policies governing data handling, retention, and deletion
- Vendor Management: Due diligence and contractual safeguards with third-party processors
- Incident Response: Procedures for detecting, investigating, and responding to data breaches in accordance with GDPR Article 33 (72-hour notification requirement)
- Regular Reviews: Periodic assessment of security measures and updating as needed to address evolving threats
While we implement robust security measures, no internet-based service can guarantee absolute security. We encourage users to take their own precautions, such as using secure internet connections and keeping devices updated with security patches.
How Long Do We Retain Your Data?
According to GDPR Article 5(1)(e), personal data must be kept only for as long as necessary for the purposes for which it is processed. Our data retention practices include:
- Analytics Data: Aggregated and anonymized analytics data may be retained indefinitely as it no longer constitutes personal data
- Cookie Data: Cookies expire according to the timeframes specified in our Cookie Policy, typically ranging from session-based to 24 months
- Contact Form Data: Any information submitted through contact forms is retained only as long as necessary to respond to inquiries (typically 12 months maximum)
- Legal Obligations: Data may be retained longer where required by applicable law or to defend legal claims
How Can You Exercise Your Rights?
Exercising your GDPR rights is straightforward. Under GDPR Article 12, we are required to respond to data subject requests without undue delay and within one month of receipt (extendable by two additional months for complex requests).
Submitting a Request
To exercise any of your data subject rights, please contact us through our Contact page. When submitting a request, please include:
- Which right(s) you wish to exercise (access, erasure, rectification, etc.)
- Any identifying information that will help us locate your data (IP address range, approximate dates of visits, etc.)
- Proof of identity to verify you are the data subject (to prevent unauthorized disclosure)
Response Timeframes
We will acknowledge your request within 72 hours and provide a substantive response within one month. For complex or voluminous requests, we may extend this period by two additional months and will notify you of the extension and reasons within the first month.
No Fee for Requests
According to GDPR Article 12(5), we do not charge a fee for processing data subject requests unless they are manifestly unfounded, excessive, or repetitive. In such cases, we may charge a reasonable fee based on administrative costs or refuse to act on the request.
Right to Lodge a Complaint
Under GDPR Article 77, you have the right to lodge a complaint with a supervisory authority, particularly in the EU member state where you reside, work, or where an alleged infringement occurred. You can find your local data protection authority through the European Data Protection Board website.
Additional Resources and Related Policies
This GDPR Compliance Statement should be read in conjunction with our other privacy-related documents:
- Privacy Policy - Comprehensive overview of how we collect, use, and protect information
- Cookie Policy - Detailed explanation of cookies we use and how to manage preferences
- Terms of Service - Legal terms governing use of our website
- Affiliate Disclosure - Transparency about affiliate relationships and commissions
Updates to This Statement
We may update this GDPR Compliance Statement periodically to reflect changes in our practices, legal requirements, or regulatory guidance. When we make material changes, we will update the "Last Updated" date at the top of this page. For significant changes affecting your rights, we will provide prominent notice on our website or, where we have contact information, direct notification.
We encourage you to review this statement periodically to stay informed about how we protect your data and facilitate your GDPR rights.
Contact Us About GDPR Compliance
If you have questions about this GDPR Compliance Statement, wish to exercise your data subject rights, or have concerns about how we handle EU visitor data, please reach out through our Contact page.
We are committed to responding promptly and transparently to all GDPR-related inquiries and working with EU data protection authorities to resolve any concerns.