Your GDPR Rights
Last Updated: January 15, 2026
If you are in the European Union (EU) or European Economic Area (EEA), you have specific rights under the General Data Protection Regulation (GDPR). This page explains these rights and how to exercise them.
1. Data Controller Information
Who Controls Your Data
Data Controller: echopl.com
Address: 56 Cedar Avenue, Jasper, AB T0E 1E0, Canada
Email: support@echopl.com
Response Time: Within 30 days of your request
2. Your Rights Under GDPR
The GDPR gives you powerful rights over your personal data. Here is a detailed explanation of each right:
Right to Access (Article 15)
You have the right to:
- Know if we process your data: We will confirm whether we hold any of your personal information
- Get a copy of your data: We will provide all personal data we have about you in a readable format
- Know the purposes: We will explain why we process your data
- Know the categories: We will list what types of data we have
- Know the recipients: We will tell you who we share your data with
- Know the retention period: We will explain how long we keep your data
- Know the source: If we did not collect data directly from you, we will tell you where we got it
Right to Correction (Article 16)
You have the right to:
- Fix inaccurate data: If any information about you is wrong, we will correct it
- Complete incomplete data: If we are missing information, you can provide it
- Update outdated information: If your details have changed, we will update our records
We will make corrections without undue delay and notify any third parties who received the incorrect data.
Right to Deletion / Right to be Forgotten (Article 17)
You can ask us to delete your personal data when:
- Data is no longer needed: We no longer need it for the original purpose
- You withdraw consent: You change your mind about permission you gave us
- You object to processing: You use your right to object and we have no overriding reason to continue
- Unlawful processing: We processed your data illegally
- Legal obligation: We must delete it to comply with law
- Child's data: Data was collected from a child for online services
We may refuse deletion if we need the data for legal claims, compliance, or public interest reasons.
Right to Restriction (Article 18)
You can ask us to limit how we use your data when:
- Accuracy is contested: While we verify if your data is correct
- Processing is unlawful: But you prefer restriction over deletion
- We no longer need it: But you need it for legal claims
- You have objected: While we consider your objection
When processing is restricted, we will only store the data. Any other use requires your consent.
Right to Data Portability (Article 20)
You have the right to:
- Receive your data: Get a copy of data you provided to us
- In a common format: We will give it in a structured, machine-readable format (like CSV or JSON)
- Transfer to another service: You can move your data to a different provider
- Direct transfer: Where possible, we will send your data directly to another controller
This right applies to data you gave us based on consent or contract, processed by automated means.
Right to Object (Article 21)
You can object to processing based on:
- Legitimate interests: If we process based on our legitimate interests, you can object. We must stop unless we show compelling reasons that override your interests
- Direct marketing: You can always object to marketing. We must stop immediately with no exceptions
- Research or statistics: You can object to processing for research or statistical purposes
Right Not to be Subject to Automated Decisions (Article 22)
You have the right to:
- Not be subject to automated decisions: Decisions that significantly affect you should not be made solely by machines
- Human review: You can ask for a person to review automated decisions
- Express your views: You can contest decisions and provide additional information
Note: Dream Home Coloring Book does not use automated decision-making that significantly affects users.
3. How to Exercise Your Rights
To exercise any of your GDPR rights:
- Send an email to: support@echopl.com
- Include in your email:
- Your full name
- Email address linked to your account
- Which right you want to exercise
- Any relevant details to help us find your data
- Verify your identity: We may ask for proof to protect your data from unauthorized access
- Receive our response: We will respond within 30 days. Complex requests may take up to 90 days with notice.
4. Withdrawing Consent
If we process your data based on consent, you can withdraw it at any time:
Cookie Consent
- Click the cookie settings link in the footer
- Adjust your preferences in the cookie modal
- Save your new settings
- Or clear cookies in your browser settings
Newsletter Consent
- Click "Unsubscribe" at the bottom of any newsletter
- Or email us at support@echopl.com
Marketing Consent
- Email us to opt out of all marketing
- Adjust notification settings in the app
Withdrawing consent does not affect processing that happened before you withdrew.
5. Managing Cookies
We use cookies on our website. You can control them in several ways:
Through Our Cookie Banner
- Accept All: Enables all cookies
- Reject Non-Essential: Only essential cookies remain
- Manage Settings: Choose which types to allow
Through Your Browser
Most browsers let you:
- Block all cookies
- Block third-party cookies only
- Clear existing cookies
- Set cookies to expire when you close the browser
Cookie Types We Use
- Essential: Required for the site to work. Cannot be disabled.
- Analytics: Help us understand site usage. You can disable these.
- Marketing: Used for relevant content. You can disable these.
6. Data We Collect
Here is what personal data we may hold about you:
- Contact Data: Name, email address
- Technical Data: IP address, device type, browser type
- Usage Data: Pages visited, features used, time on site
- Preference Data: Cookie settings, language choice
- Communication Data: Support requests, feedback
7. How Long We Keep Data
We keep different types of data for different periods:
- Account Data: Until you request deletion
- Support Requests: 3 years after resolution
- Analytics Data: 26 months
- Cookie Data: Up to 12 months
- Legal Records: As required by law (typically 7 years)
8. International Transfers
Your data may be transferred outside the EU/EEA. We protect these transfers through:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Data processing agreements with all vendors
- Regular review of vendor security practices
9. Your Right to Complain
If you are not happy with how we handle your data, you can:
- Contact us first: Email support@echopl.com. We want to resolve your concerns.
- Lodge a complaint: Contact your local data protection authority. A list of EU authorities is available at the European Data Protection Board website.
10. Children's Data
We do not knowingly collect data from children under 16 in the EU without parental consent. If you believe we have such data, contact us immediately and we will delete it.
11. Updates to This Page
We may update this GDPR information from time to time. Check the "Last Updated" date at the top. Significant changes will be communicated through our app or website.
12. Contact Us
For any GDPR-related questions or requests:
Data Protection Contact
Email: support@echopl.com
Subject Line: GDPR Request - [Your Name]
Address: 56 Cedar Avenue, Jasper, AB T0E 1E0, Canada
Response Time: Within 30 days
We are committed to protecting your privacy and will handle all requests with care and respect.