Content on this site is promotional in nature Curating comfort for Irish homes since 2019

Last updated: January 2024

Our Commitment to GDPR

Reef Myth is committed to protecting your personal data and respecting your privacy rights. As a business operating in Ireland and the European Union, we comply with the General Data Protection Regulation (GDPR) and the Irish Data Protection Act 2018.

This page outlines how we meet our obligations under data protection law and explains your rights as a data subject.

Data Controller Information

For the purposes of data protection law, Reef Myth is the data controller responsible for your personal data.

Contact details:
Reef Myth
Unit 7, Harbour Business Park
Dun Laoghaire, Co. Dublin
A96 K2P8, Ireland
Email: [email protected]

Your Rights Under GDPR

The GDPR provides you with specific rights concerning your personal data. These include:

Right to Be Informed

You have the right to know how we collect and use your personal data. This information is provided in our Privacy Policy and this GDPR page.

Right of Access

You have the right to request a copy of the personal data we hold about you. This is commonly known as a "subject access request". We will respond to valid requests within one month.

Right to Rectification

If any personal data we hold about you is inaccurate or incomplete, you have the right to have it corrected. Please contact us if you believe we hold incorrect information.

Right to Erasure

Also known as the "right to be forgotten", you can request that we delete your personal data in certain circumstances, including:

  • When the data is no longer necessary for the purpose it was collected
  • When you withdraw consent (where consent was the legal basis)
  • When you object to processing and there are no overriding legitimate grounds
  • When the data has been unlawfully processed

Right to Restrict Processing

You can request that we limit how we use your personal data in certain circumstances, such as when you contest the accuracy of the data or when you have objected to our processing.

Right to Data Portability

Where we process your data based on consent or contract, and processing is automated, you have the right to receive your personal data in a structured, commonly used, machine-readable format.

Right to Object

You have the right to object to processing of your personal data where we rely on legitimate interests as our legal basis. We will stop processing unless we can demonstrate compelling legitimate grounds.

Rights Related to Automated Decision-Making

You have the right not to be subject to decisions based solely on automated processing, including profiling, that produce legal or similarly significant effects. We do not currently use automated decision-making in our services.

How We Process Your Data

Legal Bases for Processing

We only process personal data when we have a lawful basis to do so. The legal bases we rely on include:

  • Consent: Where you have given clear consent for us to process your data for a specific purpose
  • Contract: Where processing is necessary to perform a contract with you or take steps before entering into a contract
  • Legitimate Interests: Where processing is necessary for our legitimate interests and does not override your fundamental rights
  • Legal Obligation: Where we need to comply with a legal or regulatory obligation

Data Minimisation

We only collect personal data that is necessary for the purposes stated. We do not collect excessive data or hold data longer than needed.

Data Security

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, destruction, or damage. These measures are regularly reviewed and updated.

Exercising Your Rights

To exercise any of your rights under GDPR, please contact us at [email protected]. When making a request, please provide:

  • Your full name and contact details
  • A description of the right you wish to exercise
  • Any information that will help us identify your data

We may need to verify your identity before processing your request. We will respond to valid requests within one month. In complex cases, we may extend this by a further two months, but we will inform you if this is necessary.

Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected. Our standard retention periods are:

  • Consultation enquiries: 3 years after last contact
  • Client records: 7 years after service completion (for legal and accounting purposes)
  • Marketing data: Until consent is withdrawn

International Transfers

We primarily store and process data within the European Economic Area (EEA). If we transfer data outside the EEA, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission.

Data Breach Procedures

We have procedures in place to detect, investigate, and report personal data breaches. Where a breach is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay.

Complaints

If you are not satisfied with how we handle your personal data or respond to your requests, you have the right to lodge a complaint with the Data Protection Commission (DPC):

Data Protection Commission
21 Fitzwilliam Square South
Dublin 2, D02 RD28
Ireland
Website: www.dataprotection.ie

Updates to This Information

We may update this GDPR compliance information from time to time. Any significant changes will be communicated through our website.