Last Updated: January 2024
coral-glacier is fully committed to complying with the General Data Protection Regulation (GDPR) and the Irish Data Protection Acts. This page provides information about how we protect your personal data and your rights under data protection law.
We adhere to the following data protection principles:
We process personal data lawfully, fairly, and in a transparent manner. We clearly communicate how and why we use your data through our Privacy Policy and other notices.
We collect personal data only for specified, explicit, and legitimate purposes. We do not process data in ways that are incompatible with those original purposes without obtaining further consent.
We limit the personal data we collect to what is necessary for the purposes for which it is processed. We do not collect excessive or irrelevant data.
We take reasonable steps to ensure personal data is accurate and kept up to date. We have procedures in place for rectifying or erasing inaccurate data promptly.
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, subject to any legal requirements for longer retention.
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, destruction, or damage.
As a data subject, you have the following rights:
You have the right to be informed about how we collect and use your personal data. This information is provided in our Privacy Policy.
You can request a copy of the personal data we hold about you. We will respond to valid requests within one month.
If you believe any personal data we hold about you is inaccurate or incomplete, you can request that we correct it.
In certain circumstances, you can request that we delete your personal data. This right is not absolute and may be subject to legal obligations to retain certain data.
You can request that we limit how we use your personal data in certain circumstances, such as while we verify the accuracy of data you have challenged.
Where technically feasible, you can request that we provide your personal data in a structured, commonly used, machine-readable format for transfer to another controller.
You can object to processing of your personal data in certain circumstances, including processing based on legitimate interests or for direct marketing purposes.
You have rights regarding automated decision-making and profiling. We do not currently engage in automated decision-making that has legal or similarly significant effects on individuals.
To exercise any of your rights under GDPR, please contact us:
We will respond to your request within one month. If your request is complex or we receive a large number of requests, we may extend this period by up to two months, but we will inform you of any extension and the reasons for it.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Data Protection Commission within 72 hours of becoming aware of the breach. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly.
Where we transfer personal data outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, such as:
While we are not required to appoint a Data Protection Officer under GDPR, we have designated a privacy contact who can be reached at [email protected] for any data protection queries or concerns.
If you are unsatisfied with our response to a data protection concern, you have the right to lodge a complaint with the Data Protection Commission:
We may update this GDPR compliance information from time to time. Any changes will be posted on this page with an updated revision date.