Our commitment to protecting your data under European regulation
Last updated: January 2024
fishgnomen is fully committed to compliance with the General Data Protection Regulation (GDPR) (EU) 2016/679. As a company based in Ireland and serving educational institutions throughout the European Union, we recognise the importance of data protection and privacy rights.
This page provides information about how we comply with GDPR requirements and how you can exercise your rights under this regulation.
fishgnomen acts as the data controller for personal data collected through our website and services. Our contact details are:
fishgnomen
Unit 12, Digital Hub
Thomas Street
Dublin 8, D08 TCV4
Ireland
Email: [email protected]
We process personal data under the following lawful bases as defined in Article 6 of the GDPR:
Where you have given clear consent for us to process your personal data for specific purposes, such as receiving marketing communications or newsletters.
Where processing is necessary for the performance of a contract to which you are a party, or to take steps at your request before entering into a contract.
Where processing is necessary for compliance with a legal obligation to which we are subject.
Where processing is necessary for the purposes of our legitimate interests, except where such interests are overridden by your interests or fundamental rights and freedoms.
The GDPR provides you with specific rights regarding your personal data. We are committed to facilitating the exercise of these rights:
You have the right to receive clear, transparent information about how we use your personal data. This is provided through our Privacy Policy and this GDPR page.
You have the right to obtain confirmation as to whether we are processing your personal data, and if so, to access that data along with supplementary information. We will respond to access requests within one month.
You have the right to have inaccurate personal data rectified without undue delay. You may also have incomplete personal data completed.
Also known as the "right to be forgotten", you may request deletion of your personal data in certain circumstances, such as when the data is no longer necessary for its original purpose.
You have the right to request restriction of processing in certain circumstances, such as when you contest the accuracy of the data.
You have the right to receive your personal data in a structured, commonly used and machine-readable format, and to transmit that data to another controller.
You have the right to object to processing based on legitimate interests or for direct marketing purposes.
You have the right not to be subject to decisions based solely on automated processing, including profiling, which produce legal or similarly significant effects.
To exercise any of your rights under GDPR, please contact us at [email protected]. We may need to verify your identity before processing your request. We will respond to your request within one month, though this period may be extended by a further two months for complex requests.
There is no charge for exercising your rights, except where requests are manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse to act on the request.
Where our processing activities are likely to result in a high risk to the rights and freedoms of individuals, we conduct Data Protection Impact Assessments (DPIAs) to identify and minimise data protection risks.
We have procedures in place to detect, report and investigate personal data breaches. Where a breach is likely to result in a risk to the rights and freedoms of individuals, we will notify the Data Protection Commission within 72 hours. Where the breach is likely to result in a high risk, we will also notify affected individuals without undue delay.
When we transfer personal data outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission or adequacy decisions.
Where we engage third-party processors to handle personal data on our behalf, we ensure appropriate Data Processing Agreements are in place that comply with Article 28 of the GDPR.
If you are not satisfied with how we handle your personal data or respond to your requests, you have the right to lodge a complaint with the supervisory authority in your country of residence or where you believe an infringement has occurred.
In Ireland, the supervisory authority is:
Data Protection Commission
21 Fitzwilliam Square South
Dublin 2, D02 RD28
Ireland
Website: www.dataprotection.ie
We may update this GDPR compliance information from time to time to reflect changes in our practices or legal requirements. We encourage you to review this page periodically.
If you have any questions about our GDPR compliance or wish to exercise your data protection rights, please contact us:
Email: [email protected]
Post: fishgnomen, Unit 12, Digital Hub, Thomas Street, Dublin 8, D08 TCV4, Ireland