This content is advertising

Last updated: January 2024

Our Commitment to GDPR

fishgnomen is fully committed to compliance with the General Data Protection Regulation (GDPR) (EU) 2016/679. As a company based in Ireland and serving educational institutions throughout the European Union, we recognise the importance of data protection and privacy rights.

This page provides information about how we comply with GDPR requirements and how you can exercise your rights under this regulation.

Data Controller Information

fishgnomen acts as the data controller for personal data collected through our website and services. Our contact details are:

fishgnomen
Unit 12, Digital Hub
Thomas Street
Dublin 8, D08 TCV4
Ireland

Email: [email protected]

Lawful Basis for Processing

We process personal data under the following lawful bases as defined in Article 6 of the GDPR:

Consent (Article 6(1)(a))

Where you have given clear consent for us to process your personal data for specific purposes, such as receiving marketing communications or newsletters.

Contract (Article 6(1)(b))

Where processing is necessary for the performance of a contract to which you are a party, or to take steps at your request before entering into a contract.

Legal Obligation (Article 6(1)(c))

Where processing is necessary for compliance with a legal obligation to which we are subject.

Legitimate Interests (Article 6(1)(f))

Where processing is necessary for the purposes of our legitimate interests, except where such interests are overridden by your interests or fundamental rights and freedoms.

Your Rights Under GDPR

The GDPR provides you with specific rights regarding your personal data. We are committed to facilitating the exercise of these rights:

Right to be Informed (Articles 13-14)

You have the right to receive clear, transparent information about how we use your personal data. This is provided through our Privacy Policy and this GDPR page.

Right of Access (Article 15)

You have the right to obtain confirmation as to whether we are processing your personal data, and if so, to access that data along with supplementary information. We will respond to access requests within one month.

Right to Rectification (Article 16)

You have the right to have inaccurate personal data rectified without undue delay. You may also have incomplete personal data completed.

Right to Erasure (Article 17)

Also known as the "right to be forgotten", you may request deletion of your personal data in certain circumstances, such as when the data is no longer necessary for its original purpose.

Right to Restrict Processing (Article 18)

You have the right to request restriction of processing in certain circumstances, such as when you contest the accuracy of the data.

Right to Data Portability (Article 20)

You have the right to receive your personal data in a structured, commonly used and machine-readable format, and to transmit that data to another controller.

Right to Object (Article 21)

You have the right to object to processing based on legitimate interests or for direct marketing purposes.

Rights Related to Automated Decision-Making (Article 22)

You have the right not to be subject to decisions based solely on automated processing, including profiling, which produce legal or similarly significant effects.

Exercising Your Rights

To exercise any of your rights under GDPR, please contact us at [email protected]. We may need to verify your identity before processing your request. We will respond to your request within one month, though this period may be extended by a further two months for complex requests.

There is no charge for exercising your rights, except where requests are manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse to act on the request.

Data Protection Impact Assessments

Where our processing activities are likely to result in a high risk to the rights and freedoms of individuals, we conduct Data Protection Impact Assessments (DPIAs) to identify and minimise data protection risks.

Data Breach Procedures

We have procedures in place to detect, report and investigate personal data breaches. Where a breach is likely to result in a risk to the rights and freedoms of individuals, we will notify the Data Protection Commission within 72 hours. Where the breach is likely to result in a high risk, we will also notify affected individuals without undue delay.

International Data Transfers

When we transfer personal data outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission or adequacy decisions.

Data Processing Agreements

Where we engage third-party processors to handle personal data on our behalf, we ensure appropriate Data Processing Agreements are in place that comply with Article 28 of the GDPR.

Supervisory Authority

If you are not satisfied with how we handle your personal data or respond to your requests, you have the right to lodge a complaint with the supervisory authority in your country of residence or where you believe an infringement has occurred.

In Ireland, the supervisory authority is:

Data Protection Commission
21 Fitzwilliam Square South
Dublin 2, D02 RD28
Ireland
Website: www.dataprotection.ie

Updates to This Information

We may update this GDPR compliance information from time to time to reflect changes in our practices or legal requirements. We encourage you to review this page periodically.

Contact Us

If you have any questions about our GDPR compliance or wish to exercise your data protection rights, please contact us:

Email: [email protected]

Post: fishgnomen, Unit 12, Digital Hub, Thomas Street, Dublin 8, D08 TCV4, Ireland