Our Commitment to GDPR
We are committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR) and applicable Irish data protection legislation. This page explains how we comply with GDPR requirements and what rights you have regarding your personal information.
Data Controller
For the purposes of GDPR, the data controller is:
fern-myth
42 Merrion Square East
Dublin 2, D02 XF86
Ireland
Email: [email protected]
Lawful Basis for Processing
We process personal data only when we have a lawful basis to do so. Our lawful bases include:
Consent
When you provide explicit consent by submitting forms, accepting cookies, or agreeing to communications. You may withdraw consent at any time by contacting us.
Contract
When processing is necessary to fulfill a contract with you or take steps before entering into a contract, such as providing requested services or responding to service inquiries.
Legitimate Interests
When we have legitimate business interests that do not override your rights and freedoms, such as:
- Improving our website and services
- Understanding how visitors use our site
- Communicating about services you have expressed interest in
- Protecting against fraud or security threats
Legal Obligation
When processing is required to comply with legal requirements, such as tax, accounting, or regulatory obligations.
Your GDPR Rights
Right to Access
You have the right to request confirmation of whether we process your personal data and to obtain a copy of that data. We will provide this information in a commonly used electronic format.
Right to Rectification
If personal data we hold about you is inaccurate or incomplete, you have the right to request correction. We will update records promptly upon verification.
Right to Erasure
You may request deletion of your personal data when:
- The data is no longer necessary for the purposes it was collected
- You withdraw consent and no other lawful basis exists
- You object to processing and no overriding legitimate grounds exist
- The data has been unlawfully processed
- Erasure is required to comply with legal obligations
Note that we may retain certain information when legally required or when legitimate interests necessitate retention.
Right to Restriction of Processing
You may request that we limit how we use your data when:
- You contest the accuracy of the data
- Processing is unlawful but you prefer restriction over erasure
- We no longer need the data but you require it for legal claims
- You have objected to processing pending verification of legitimate grounds
Right to Data Portability
You have the right to receive personal data you provided to us in a structured, commonly used, machine-readable format. You may request that we transmit this data directly to another controller where technically feasible.
Right to Object
You may object to processing of your personal data when:
- Processing is based on legitimate interests or public interest
- Data is used for direct marketing purposes
- Data is processed for scientific, historical research, or statistical purposes
Upon receiving an objection, we will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.
Right Not to Be Subject to Automated Decision-Making
You have the right not to be subject to decisions based solely on automated processing, including profiling, that produce legal effects or similarly significantly affect you. We do not engage in automated decision-making that would trigger this right.
Right to Withdraw Consent
Where processing is based on consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing conducted before withdrawal.
How to Exercise Your Rights
To exercise any of these rights, contact us at [email protected] with the following information:
- Your full name and contact information
- Specific right you wish to exercise
- Details of your request
- Any relevant dates or interactions
We will respond to verified requests within one month. If your request is complex or we receive multiple requests, we may extend this period by two additional months and will inform you of the extension.
Data Protection Measures
We implement appropriate technical and organizational security measures to protect personal data, including:
- Encryption of data in transit and at rest
- Access controls limiting who can view personal data
- Regular security assessments and updates
- Staff training on data protection requirements
- Data processing agreements with third-party service providers
Data Breach Notification
In the event of a personal data breach that poses risks to your rights and freedoms, we will notify you without undue delay as required by GDPR. We will also notify the Data Protection Commission within 72 hours of becoming aware of the breach.
International Data Transfers
When we transfer personal data outside the European Economic Area, we ensure appropriate safeguards are in place, such as:
- Standard contractual clauses approved by the European Commission
- Adequacy decisions by the European Commission
- Binding corporate rules
Data Retention
We retain personal data only as long as necessary for the purposes outlined or as required by law. Retention periods vary based on data type and purpose:
- Marketing inquiries: 2 years from last contact
- Client contracts and communications: 7 years after contract completion
- Website analytics: 26 months
- Cookie data: as specified in cookie settings
Children's Data
Our services are not directed to children under 18. We do not knowingly collect or process data from individuals under 18 years of age. If we become aware such data has been collected, we will delete it promptly.
Complaints
If you believe we have not handled your personal data appropriately or wish to lodge a complaint, you may contact:
Data Protection Commission
21 Fitzwilliam Square South
Dublin 2, D02 RD28
Ireland
Phone: +353 57 868 4800
Website: dataprotection.ie
Updates to This Information
We may update this GDPR compliance information to reflect changes in our practices or legal requirements. Material changes will be communicated through prominent notices on our website.
Contact for GDPR Matters
For questions about GDPR compliance or to exercise your rights, contact us at:
Email: [email protected]
Address: 42 Merrion Square East, Dublin 2, D02 XF86, Ireland