Your draft did mention European laws in spirit, but it didn’t explicitly name or properly comply with the GDPR (General Data Protection Regulation), which is the massive privacy law governing the European Union (EU) and the UK.

Even though your business is physically in Ontario, the GDPR applies to you if a single person living in Europe visits your website and takes your quiz. There are two major things we need to fix to make you European-compliant:

  1. The Policy Itself: We need to explicitly state the rights that European citizens have (like the “Right to be Forgotten”).

  2. How Your Quiz Works (Crucial Marketing Warning): Under GDPR, you cannot automatically force European users onto your newsletter just because they took a free quiz. Consent to get quiz results must be separate from consent to get marketing emails.

Below is your fully updated, GDPR-compliant privacy policy, followed by a quick tip on how to set up your quiz sign-up box so you don’t get into legal trouble.


PRIVACY POLICY

Last updated: May 20, 2026

1. General

This privacy policy governs the manner in which Demystifying Your Gut collects, uses, maintains, and discloses information collected from users (each, a “User”) of the website www.demystifyingyourgut.com (“Site”). This privacy policy applies to the Site and all products and services offered by Demystifying Your Gut.

We are committed to protecting your privacy. Depending on where you reside, your data is protected by specific regional frameworks:

  • Canada: The Personal Information Protection and Electronic Documents Act (PIPEDA) and Canada’s Anti-Spam Legislation (CASL).

  • United States: The California Online Privacy Protection Act (CalOPPA) and relevant state laws.

  • European Union / United Kingdom: The General Data Protection Regulation (GDPR / UK GDPR).


2. Personal Information We Collect

We collect personal information from Users in a variety of ways, including, but not limited to, when Users visit our site, take our free quiz, or subscribe to our newsletter.

  • Quiz & Newsletter Signup: To provide you with your quiz results and add you to our mailing list, we may collect your name and email address.

  • Voluntary Submission: We only collect personal information if you voluntarily submit it to us. You can always refuse to supply this information, though it may prevent you from receiving your quiz results.


3. Legal Basis for Processing (GDPR Requirement)

If you reside in the European Economic Area (EEA) or the UK, we process your personal data under the following legal bases:

  • Consent: You have given us clear consent to process your personal data for a specific purpose (e.g., signing up for our newsletter or receiving quiz results).

  • Legitimate Interests: Processing is necessary for our legitimate business interests, provided those interests do not override your fundamental rights (e.g., website analytics and improving our content).


4. How We Use Your Information

Demystifying Your Gut may collect and use Users’ personal information for the following purposes:

  • To deliver quiz results: To provide you with the specific insights generated by our free quiz.

  • To send periodic emails: If you have opted-in, we use your email address to send you updates, health/gut-related tips, educational content, and/or information regarding products and services.

  • To improve our Site: We may use feedback you provide to improve our products and services.


5. How We Protect and Retain Your Information

We adopt appropriate data collection, storage, and processing practices and security measures to protect against unauthorized access, alteration, disclosure, or destruction of your personal information.

  • Our website is scanned on a regular basis for security holes and malware.

  • Your personal information is contained behind secured networks and is only accessible by a limited number of persons with special access rights who are required to keep the information confidential.

  • All digital interactions are secured via Secure Socket Layer (SSL) technology.

  • Data Retention: We will retain your personal data only for as long as is necessary for the purposes set out in this privacy policy, or until you request its deletion.


6. Use of Cookies

We do not use cookies for tracking purposes. You can choose to turn off all cookies through your browser settings. If you disable cookies, some features that make your site experience more efficient may be disabled.


7. Third-Party Disclosure

We do not sell, trade, or rent Users’ personal identification information to others.

  • Service Providers: We may use trusted third-party service providers (such as our email marketing platform) to help us operate our business and the Site, such as sending out newsletters. We share your information with these third parties solely for those limited purposes, and they are contractually bound to comply with international data privacy laws.

  • Legal Compliance: We will disclose personal information if required to do so by law.


8. Your Data Protection Rights (GDPR & International)

Regardless of where you live, but specifically if you are located in the European Union (EU), United Kingdom (UK), or California (US), you have the following rights regarding your data:

  • The Right to Access / Portability: You have the right to request copies of your personal data or ask us to transfer it to another organization.

  • The Right to Rectification: You have the right to request that we correct any information you believe is inaccurate.

  • The Right to Erasure (“Right to be Forgotten”): You have the right to request that we erase your personal data from our systems.

  • The Right to Object / Withdraw Consent: You have the right to object to our processing of your data or withdraw your consent to email marketing at any time.

To exercise any of these rights, please contact us at demystifyingyourgut@gmail.com. We will respond to your request within 30 days.


9. Data Breach Notification

In the event of a data breach involving your personal information, we will take swift action in accordance with PIPEDA and GDPR guidelines:

  • We will notify affected users via email within 1 business day (well within the GDPR’s 72-hour requirement) of identifying the breach.

  • We will place a notification on our Site within 1 business day.


10. Anti-Spam Compliance (CASL & CAN-SPAM)

In accordance with Canadian (CASL) and US (CAN-SPAM) laws, we agree to the following:

  • We will never use false or misleading subjects or email addresses.

  • We will include a clear, functional “Unsubscribe” link at the bottom of every marketing email we send.

  • We will honor opt-out/unsubscribe requests promptly.

If at any time you would like to unsubscribe, simply click the link at the bottom of our emails or email us directly at demystifyingyourgut@gmail.com, and you will be removed immediately.


11. Contacting Us

If there are any questions regarding this privacy policy, you may contact us using the information below:

Brand Name: Demystifying Your Gut

Website: www.demystifyingyourgut.com

Location: Ontario, Canada

Email: demystifyingyourgut@gmail.com