We use cookies to enhance your browsing experience and analyze site traffic. By continuing to use this site, you consent to our use of cookies.

Cypress Leap
Home About Programs Contact Advertising Content

GDPR Compliance

Last updated: September 22, 2026

Introduction

Cypress Leap is committed to protecting the privacy and personal data of individuals in the European Economic Area (EEA) in accordance with the General Data Protection Regulation (GDPR). This page explains how we comply with GDPR requirements and outlines your rights as a data subject.

Legal Basis for Processing

We process your personal data based on the following legal grounds:

  • Consent: You have given explicit consent for processing your data for specific purposes
  • Contract: Processing is necessary to fulfill our contractual obligations to provide educational services
  • Legal Obligation: Processing is required to comply with legal requirements
  • Legitimate Interest: Processing is necessary for our legitimate business interests, such as improving services and preventing fraud

Your GDPR Rights

Under GDPR, you have the following rights regarding your personal data:

Right to Access

You have the right to request access to your personal data and receive information about how we process it.

Right to Rectification

You can request correction of inaccurate or incomplete personal data we hold about you.

Right to Erasure

Also known as the "right to be forgotten," you can request deletion of your personal data in certain circumstances, such as when it is no longer necessary for the purposes for which it was collected.

Right to Restriction of Processing

You can request that we limit the processing of your personal data in specific situations, such as when you contest the accuracy of the data.

Right to Data Portability

You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit it to another controller.

Right to Object

You can object to the processing of your personal data based on legitimate interests or for direct marketing purposes.

Right to Withdraw Consent

Where processing is based on your consent, you have the right to withdraw that consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.

Right to Lodge a Complaint

You have the right to lodge a complaint with a supervisory authority if you believe our processing of your personal data violates GDPR.

Data Protection Officer

For questions or concerns regarding GDPR compliance or to exercise your rights, you may contact us at:

Email: [email protected]
Address: 1247 Burrard Street, Vancouver, BC V6Z 1Z4, Canada

Data Processing Activities

Categories of Personal Data

We process the following categories of personal data:

  • Identity data (name, username)
  • Contact data (email address, physical address)
  • Technical data (IP address, browser type, device information)
  • Usage data (how you interact with our website and services)
  • Educational data (learning progress, assessment results)
  • Payment data (transaction information)

Data Retention

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, comply with legal obligations, resolve disputes, and enforce our agreements. Specific retention periods vary based on the type of data and the purpose of processing.

International Data Transfers

When transferring personal data outside the EEA, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission or other legally recognized transfer mechanisms.

Security Measures

We implement appropriate technical and organizational security measures to protect your personal data against unauthorized or unlawful processing, accidental loss, destruction, or damage. These measures include:

  • Encryption of data in transit and at rest
  • Access controls and authentication procedures
  • Regular security assessments and audits
  • Employee training on data protection
  • Incident response procedures

Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. If the breach poses a high risk, we will also notify affected individuals without undue delay.

Third-Party Processors

We work with third-party service providers who process personal data on our behalf. We ensure these processors comply with GDPR requirements through contractual agreements that specify their data protection obligations.

Exercising Your Rights

To exercise any of your GDPR rights, please submit a request to [email protected]. We will respond to your request within one month, though this period may be extended by two additional months in complex cases. We will inform you of any such extension and the reasons for it.

We may request specific information from you to verify your identity before processing your request.

Updates to This Policy

We may update this GDPR compliance information from time to time. Any changes will be posted on this page with an updated revision date.

Cypress Leap

Empowering learners to communicate across cultures through personalized online language education.

Programs

  • All Programs
  • Our Approach
  • Get Started

Legal

  • Privacy Policy
  • Terms of Use
  • GDPR
  • Cookies Policy

Contact

[email protected]

© 2026 Cypress Leap. All rights reserved.