Fort Privacy Essentials
“Personal Data” means data which identifies a person or could identify a person, such as their name, contact details, purchase history or web browsing history. It applies to Personal Data that we collect, use and otherwise process in connection with your relationship with us as a customer, supplier, partner, investor, visitor to our website or prospective employee.
Every individual has a right to understand how their Personal Data is being used and to exercise control over it using data protection rights which are set out in the General Data Protection Regulation (“GDPR”). As data protection practitioners it is our business to ensure that:
- you know what Personal Data we collect from you
- you know what we are doing with your Personal Data
- you know that we will only use your Personal Data for the purposes set out in our Privacy Statement
- you understand your rights and can exercise control over your Personal Data
- we will not send you marketing emails if you do not want to receive them
- we will always ensure that we only share your Personal Data with third parties where absolutely necessary and only after thorough third-party due diligence
- we will ensure appropriate technical and organisational measure are in place to protect your Personal Data and keep it secure
You can access our full Privacy Statement here. In it we provide further information about what Personal Data we collect, what we use it for, why we collect your Personal Data and what our legal basis is, who we share it with and how long we retain it. We also provide detailed information about your rights in relation to your Personal Data. If you have further questions, please get in touch with us at [email protected]
If you wish to make a complaint in relation to the use of your Personal Data, you may contact the Irish Data Protection Commission at [email protected]
You will be notified of any material changes to our Privacy Statement.
1.1 - Who we are
Fort Privacy is a business-centric data protection service company, focused on developing various services and products to assist in compliance with the General Data Protection Regulation (“GDPR”) and applicable domestic data protection legislation.
1.2 - Controller / Processor
Under the GDPR, Fort Privacy acts as both a “controller” and a “processor” of Personal Data.
1.3 - Scope of this statement
This Privacy Statement covers the processing activities of Fort Privacy as a controller of Personal Data.
1.4 - Our commitment
We treat the handling of your Personal Data seriously and sensitively.
This Privacy Statement is a statement of our commitment to protect your data protection rights and sets out the legal basis on which any Personal Data we process will be used. It also lists your rights as a data subject.
2.1 - Categories of Individuals
This Privacy Statement applies to the following individuals:
- visitors to our website;
- business contact details of our partners, investors, customers and suppliers;
- those applying for jobs at Fort Privacy; and
- attendees at our webinars/events/conferences.
2.2 - Employees
Personal Data of employees of Fort Privacy is dealt with in a separate internal Employee Privacy Notice.
3.1 - Types of Personal Data
We require certain Personal Data in order to provide our services to you and to operate our business.
|Personal Data Type||Description|
|Contact & Identity Data||Name, Address, Email, Phone Number profession, company and department.|
|Communications Data||Personal Data included in communications with us over email, phone or letter.|
|Financial Data||Payment details|
|Recruitment Data||Identity data, CV data, References and application data|
|Web Data||Data on the type of device you are using, the device IP address, operating system, referral source, length of your visit, page views and website navigation paths, as well as information about the timing, frequency and pattern of your service use. This information is collected at an aggregate level and your identity data is not stored as part of this technical data.|
4.1 - Purposes
We process your Personal Data for the following purposes:
|Type of Personal Data||Purpose|
|Contact & Identity Data||
5.1 - Contract
Processing is lawful if it Is necessary for the performance of a contract.
We undertake the following processing under this heading:
- in order to contact you in connection with our products/services under the contract;
- to contact you regarding payments to and from you;
- to manage the service we provide to you; and
- to process payments to and from our business
5.2 - Consent
Where we process Personal Data with your consent, we will ensure that consent is specific, informed and unambiguous. You may withdraw consent for processing by sending an email to [email protected]
We sometimes process Personal Data on the basis of consent where we send you data protection related information as part of our newsletters or similar communications and for certain conferences, training and events that we organise.
5.3 - Legitimate Interests
We will only process Personal Data under this legal ground where we have assessed and verified that the legitimate interest pursued does not override your rights to privacy. Our legitimate interests include:
- our interest in providing the best service we can to our customers and growing our business
- our interest in conducting research and analytics on our products and services so that we can understand which services are most popular on our website
- our interest in obtaining payment for products and services provided
- our interest in protecting our intellectual property rights
- our interest in promoting and developing our business
- our interest in recruiting the best possible talent for our business
- our interest in ensuring the safety and security of users of our website and our products and services
5.4 - Compliance with Legal Obligations
We will process Personal Data where we have a legal obligation to do so.
6.1 - Business Partners, Investors, Customers & Service Providers
Will receive your Personal Data if:
- you have requested us to refer your details on;
- if we are collaborating on an event, training, conference or similar activity;
- in connection with, or during the negotiation of any investment, merger or sale of the business;
- we engage with marketing partners to market our products/services;
- we engage data analytics providers to develop our website;
- we need to engage with consultants, lawyers, accountants, insurers and other professional service providers; and
- if we require help to deliver our services to you including for example:
- CRM application suppliers;
- payment processors and facilitators; and
- IT and Cloud solution providers including back up and hosting of Personal Data.
6.2 - Law Enforcement Officers, Data Protection Commission, Government Officials or similar parties
Will receive your Personal Data:
- if required by applicable law, regulation, operating agreement, legal process or governmental request, or where the disclosure is otherwise appropriate due to safety or similar concerns;
- if this is necessary for the purpose of enforcing the terms of any contract that we have entered into with you;
- in connection with, or during negotiations of, any merger, sale of company assets, consolidation or restructuring, financing, or acquisition of all or a portion of our business by or into another company;
- to protect our rights, property, or safety, or that of you or others. This includes exchanging information with other companies and organisations for the purposes of fraud protection.
Cookies enable us to store information about your preferences and therefore customise the website according to your individual interests. They are also used to monitor which parts of the website are the most popular to its visitors.
Please be aware that if you do disable cookies however, certain services on the website will not be available to you and your use and enjoyment of them will be impaired.
8.1 - Steps we take
We will take all steps reasonably necessary to ensure that Personal Data is treated securely in accordance with this Privacy Statement and the relevant law.
In particular, we have put in place appropriate physical, technical, and organisational procedures to safeguard and secure the Personal Data we process.
To protect the privacy and security of the Personal Data, we will also take reasonable steps to verify your identity before granting access to information as appropriate.
Once we have received your information, we will use strict procedures and security features to try to prevent unauthorised access.
We also use secure connections to protect Personal Data during its transmission using SSL (Secure Socket Layer) technology.
In the event that we use a third party processor (see Sharing of Personal Data) your Personal Data may be transferred outside of the European Union or EFTA States. We ensure that any such transfer is undertaken using legally compliant transfer mechanisms in compliance with the GDPR.
9.1 - Retention Periods
We retain certain transaction information for a period of 7 years for the purposes of regulatory, tax, insurance or other requirements.
You can request to have your Personal Data deleted. Fort Privacy will then delete Personal Data that is it not required to retain. We will restrict internal access to Personal Data that we are required to retain.
10.1 - Right of Access
You have the right to ask for all the information we have about you and the services you receive from us. When we receive a request from you in writing, we must give you access to everything we’ve recorded about you as well as details of the processing, the categories of Personal Data concerned and the recipients of the Personal Data.
We will provide the first copy of your Personal Data free of charge but we may charge you a reasonable fee for any additional copies.
We cannot give you access to a copy of your Personal Data if this would adversely affect the rights and freedoms of others.
10.2 - Right of Correction
If we have Personal Data about you that you believe to be inaccurate, you have the right to request correction of your Personal Data.
10.3 - Right to be Forgotten
In some circumstances you can ask for your Personal Data to be deleted, for example, where:
- your Personal Data is no longer needed for the purpose that it was collected in the first place;
- you have removed your consent for us to use your Personal Data (where there is no other legal reason us to use it);
- there is no legal reason for the use of your Personal Data;
- deleting the Personal Data is a legal requirement;
Where your Personal Data has been shared with others, we will do what we can to make sure those using your Personal Data comply with your request for erasure.
10.4 - Right of Restriction
When Personal Data is restricted it can’t be used other than to securely store the data and with your consent to handle legal claims and protect others, or where it’s for important public interests.
10.5 - Right to Data Portability
You have the right to ask for your Personal Data to be given back to you or another service provider of your choice in a commonly used format. This is called data portability.
This right only applies if we’re using your personal information under the lawful grounds of consent or pursuant to a contract and the processing is automated and not manual. It does not apply where it would adversely affect the rights and freedoms of others.
10.6 - Right to Object
You have the right to object to the processing of your Personal Data where processing is:
- on the grounds of public interest or legitimate interest including profiling based on these grounds;
- for direct marketing purposes.
10.7 - Rights Regarding Automated Decision Making
You have the right not to be subject to a decision based solely on automated processing, including profiling which has legal effects on you. This right shall not apply where the processing:
- is necessary for a contract you have entered into;
- is undertaken with your consent; or
- is authorised by law.
10.8 - Right to make a complaint
You have the right to lodge a complaint with a supervisory authority, in particular in the country where you reside, place of work or place of the alleged infringement if you consider that the processing of Personal Data infringes the GDPR.
The contact details for the Data Commission in Ireland are:
Email: [email protected]
Address: Canal House, Station Road, Portarlington, R32 AP23, County Laois
Tel Lo-Call: 1890 252 231
We will post any changes on the Website and when doing so will change the updated date at the top of this Privacy Statement.
In some cases, we may provide you with additional notice of changes to this Privacy Statement, such as via email.
We will always provide you with such additional notice well in advance of the changes taking effect where we consider the changes to be material.