Your data protection rights under the General Data Protection Regulation
Last updated: January 2024
Reef Myth is committed to protecting your personal data and respecting your privacy rights. As a business operating in Ireland and the European Union, we comply with the General Data Protection Regulation (GDPR) and the Irish Data Protection Act 2018.
This page outlines how we meet our obligations under data protection law and explains your rights as a data subject.
For the purposes of data protection law, Reef Myth is the data controller responsible for your personal data.
Contact details:
Reef Myth
Unit 7, Harbour Business Park
Dun Laoghaire, Co. Dublin
A96 K2P8, Ireland
Email: [email protected]
The GDPR provides you with specific rights concerning your personal data. These include:
You have the right to know how we collect and use your personal data. This information is provided in our Privacy Policy and this GDPR page.
You have the right to request a copy of the personal data we hold about you. This is commonly known as a "subject access request". We will respond to valid requests within one month.
If any personal data we hold about you is inaccurate or incomplete, you have the right to have it corrected. Please contact us if you believe we hold incorrect information.
Also known as the "right to be forgotten", you can request that we delete your personal data in certain circumstances, including:
You can request that we limit how we use your personal data in certain circumstances, such as when you contest the accuracy of the data or when you have objected to our processing.
Where we process your data based on consent or contract, and processing is automated, you have the right to receive your personal data in a structured, commonly used, machine-readable format.
You have the right to object to processing of your personal data where we rely on legitimate interests as our legal basis. We will stop processing unless we can demonstrate compelling legitimate grounds.
You have the right not to be subject to decisions based solely on automated processing, including profiling, that produce legal or similarly significant effects. We do not currently use automated decision-making in our services.
We only process personal data when we have a lawful basis to do so. The legal bases we rely on include:
We only collect personal data that is necessary for the purposes stated. We do not collect excessive data or hold data longer than needed.
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, destruction, or damage. These measures are regularly reviewed and updated.
To exercise any of your rights under GDPR, please contact us at [email protected]. When making a request, please provide:
We may need to verify your identity before processing your request. We will respond to valid requests within one month. In complex cases, we may extend this by a further two months, but we will inform you if this is necessary.
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected. Our standard retention periods are:
We primarily store and process data within the European Economic Area (EEA). If we transfer data outside the EEA, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission.
We have procedures in place to detect, investigate, and report personal data breaches. Where a breach is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay.
If you are not satisfied with how we handle your personal data or respond to your requests, you have the right to lodge a complaint with the Data Protection Commission (DPC):
Data Protection Commission
21 Fitzwilliam Square South
Dublin 2, D02 RD28
Ireland
Website: www.dataprotection.ie
We may update this GDPR compliance information from time to time. Any significant changes will be communicated through our website.