Please read the following carefully to understand our use of your personal data.
1. Information we may collect from you
“Personal data” under Data Protection Law (including the EU General Data Protection Regulation 2016/679 (GDPR), the EU Privacy and Electronic Communications Directive 2002/58/EC, and all national implementing legislation) means any information about an individual from which that person can be identified. You can use our Site without being required to provide any personal data to us. We only collect personal data about you on the Site which you volunteer when you email us, by using our online forms, in order to deliver a service or product to you, or to send you newsletters or other information. In addition to the information you provide to us, we collect certain information when you visit our Site.
We collect and process the following types of personal data about you:
Identity Data including name, username or similar identifier, occupation and date of birth.
Contact Data including billing address, delivery address, email address and telephone numbers.
Transaction Data including details about payments from you and other details of products and services you have purchased from us. We do not store debit / credit card information.
Technical Data including internet protocol (IP) address, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform and other technology on the devices you use to access this Site.
Profile Data including your username and password (encrypted), purchases or orders made by you, your interests and preferences.
Usage Data including information about how you use our Site, products and services.
Marketing and Communications Data including your preferences in receiving marketing from us and your communication preferences.
We do not collect any Special Categories of Personal Data about you (this includes details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your health and genetic and biometric data). Nor do we collect any information about criminal convictions and offences.
If you do not provide the requested information, we will not be able to deliver our services or products to you or respond to you.
2. How we use personal data we collect
We will only use your personal data for the purposes and legal bases set out in the table below.
|Purpose(s) for Processing||Legal Basis for Processing|
|To register and create an account on our website.||The processing is necessary to enter and perform our contract with you|
|To manage our relationship with you, including processing your application to sign up for an event, processing your request for information, processing your donation or processing an online order and delivering the requested product to you||The processing is necessary to perform our contract with you to the extent you have requested to be contacted and to comply with our legal obligations, including tax and accounting rules.|
|For the prevention and detection of fraud, money laundering or other crimes||The processing is necessary for us to comply with legal and regulatory obligations|
|Sending newsletters or other direct marketing electronic communications||· The processing is necessary to perform our contract with you to the extent you have subscribed to such newsletters,
· You have provided your consent to receipt of direct marketing communications – which can withdraw at any time
· It is in our legitimate interests to send supporters information about fundraising events – you have the right to object to such communications at any time
|To customise your experience on the Site, or to serve you specific content that is relevant to you||The processing is necessary to support our legitimate interests in managing our organisation (to define types of customers for our products and services, to keep our Site updated and relevant, to develop our business and to inform our marketing strategy) provided such interests are not overridden by your interests and rights|
We will store your personal data only for as long as necessary for the purposes of providing access to our Site and related services to you; as required by law, and for the exercise or defence of legal claims.
3. Disclosure of your information
We may disclose your personal data to third parties who provide a service to us, including our Internet Service Provider who records data on our behalf and is bound by confidentiality provisions, or if we are under a duty to disclose or share your personal data in order to comply with any legal obligation, or where necessary for our legitimate business interests to protect the rights, property, or safety of The Hope Foundation, our supporters, or others. This includes exchanging information with other companies and organisations for the purposes of fraud protection and credit risk reduction.
4. Links to other sites
Our Site may, from time to time, contain links to and from other websites. If you follow a link to any of those websites, please note that those websites have their own privacy policies and we do not accept any responsibility or liability for those policies. Please check those policies before you submit any personal data to those websites.
5. Your rights
You have the right to request access to, rectification, or erasure of your personal data, or restriction of processing or object to processing of your personal data, as well as the right to data portability. To request access to your information visit or Subject Access Request Form. The following is a summary of your rights:
- The right of access enables you to receive a copy of your personal data.
- The right to rectification enables you to correct any inaccurate or incomplete personal data we hold about you.
- The right to erasure enables you to ask us to delete your personal data in certain circumstances, including where:
- It is no longer necessary for us to process your personal data;
- You consider the personal data is being unlawfully processed;
- You withdraw your consent (where the processing is based on consent);
- You object to the processing and there are no overriding legitimate grounds justifying the processing; or
- The personal data have to be erased to comply with a legal obligation.
We may refuse your request if the processing is necessary to comply with a legal obligation or for the establishment, exercise or defence of legal claims.
- The right to restrict processing enables you to ask us to halt the processing of your personal data in certain circumstances, including where:
- You contest the accuracy of your personal data;
- You consider the processing is unlawful, but you do not want your personal data erased;
- We no longer need the personal data but you require it for the establishment, exercise or defence of legal claims; or
- You have objected to the processing, and verification as to our overriding legitimate interests is pending.
We may continue to process your personal data:
- Where we have your consent to do so;
- For the establishment, exercise or defence of legal claims;
- The processing is necessary to protect the rights of other individuals or legal persons; or
- For important public interest reasons.
- The right to object enables you to object to us processing your personal data on the basis of our legitimate interests (or those of a third party). We will stop such processing unless we can demonstrate compelling legitimate grounds for the processing which override your interests or the processing is necessary for the establishment, exercise or defence of legal claims. You also have the right to object to us processing your personal data for direct marketing purposes.
- The right to data portability enables you to request us to transmit personal data that you have provided to us, to a third party without hindrance, or to give you a copy of it so that you can transmit it to a third party, where technically feasible. The right only applies where:
- The processing is carried out by automated means; and
- The processing is based on your consent or for the performance of a contract with you.
You have the right to lodge a complaint with the Data Protection Authority, in particular in the Member State of your residence, place of work or place of an alleged infringement, if you consider that the processing of your personal data infringes the GDPR.
If you wish to exercise any of these rights, please contact us (see Contact Us below). We will respond to your request within one month. That period may be extended by two further months where necessary, taking into account the complexity and number of requests. We will inform you of any such extension within one month of receipt of your request. We may request proof of identification to verify your request. We have the right to refuse your request for the reasons set out above, or if it is manifestly unfounded or excessive, or to the extent necessary for important objectives of public interest.
6. Security and where we store your personal data
We are committed to protecting the security of your personal data. We use a variety of security technologies and procedures to help protect your personal data from unauthorised access and use. As effective as modern security practices are, no physical or electronic security system is entirely secure. We cannot guarantee the complete security of our database, nor can we guarantee that information you supply will not be intercepted while being transmitted to us over the Internet. We have implemented strict internal guidelines to ensure that your privacy is safeguarded at every level of our organisation. We will continue to revise policies and implement additional security features as new technologies become available. Where we have given you a password which enables you to access certain parts of our Site, you are responsible for keeping that password confidential. We ask you not to share your password with anyone.
Although we will do our best to protect your personal data, we cannot guarantee the security of your personal data transmitted to our Site. Any transmission of personal data is at your own risk. Once we receive your personal data, we use appropriate security measures to seek to prevent unauthorised access or disclosure.
7. Changes to this Privacy Statement
We reserve the right to change this Privacy Statement from time to time at our sole discretion. If we make any changes, we will post those changes here and update the “Last Updated” date at the bottom of this Privacy Statement. However, if we make material changes to this Privacy Statement, we will notify you by means of a prominent notice on the Site prior to the change becoming effective. Please review this Privacy Statement periodically for updates.
8. Contact Us
Questions, comments, requests and complaints regarding this Privacy Statement and the personal data we hold are welcome and should be addressed to firstname.lastname@example.org or sent in writing to Data Protection Office, The Hope Foundation, Silverdale Grove, Ballinlough, Cork, Ireland. All requests will be dealt with promptly and efficiently.
Last Updated: 17/05/2018