Last updated: September 22, 2024
Spire Craft is committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR). This statement outlines how we comply with GDPR requirements and respect your rights as a data subject.
We process your personal data only when we have a lawful basis to do so under GDPR Article 6. These bases include:
As a data subject, you have the following rights:
You have the right to request copies of your personal data. We may charge a reasonable fee if your request is clearly unfounded, repetitive, or excessive.
You have the right to request that we correct any information you believe is inaccurate or complete information you believe is incomplete.
You have the right to request that we erase your personal data under certain conditions, such as when the data is no longer necessary for the purposes for which it was collected.
You have the right to request that we restrict the processing of your personal data under certain conditions.
You have the right to object to our processing of your personal data under certain conditions, particularly for direct marketing purposes.
You have the right to request that we transfer the data we have collected to another organisation, or directly to you, under certain conditions.
Where we rely on your consent to process your personal data, you have the right to withdraw that consent at any time.
To exercise any of these rights, please contact us at [email protected]. We will respond to your request within one month of receipt. If your request is complex or if you have made multiple requests, we may extend this period by two further months, and we will inform you of any such extension.
For the purposes of GDPR, the data controller is:
Spire Craft
15 Camden Street Lower
Dublin 2, D02 X285
Ireland
Email: [email protected]
For questions specifically related to data protection and GDPR compliance, you may contact our team at [email protected] with "Data Protection" in the subject line.
We process your personal data for the following purposes:
Your personal data may be transferred to and processed in countries outside the European Economic Area (EEA). When we transfer your data outside the EEA, we ensure appropriate safeguards are in place, such as standard contractual clauses approved by the European Commission or adequacy decisions.
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy any legal, accounting, or reporting requirements. When determining retention periods, we consider:
We have implemented appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay. We will also notify the relevant supervisory authority within 72 hours of becoming aware of the breach, where feasible.
You have the right to lodge a complaint with a supervisory authority, in particular in the EU member state of your habitual residence, place of work, or place of the alleged infringement. In Ireland, the supervisory authority is:
Data Protection Commission
21 Fitzwilliam Square South
Dublin 2, D02 RD28
Ireland
Phone: +353 57 868 4800
Email: [email protected]
We may update this GDPR compliance statement from time to time to reflect changes in our practices or applicable law. We will post any updates on this page and indicate the date of the latest revision.
If you have any questions or concerns about our GDPR compliance or how we handle your personal data, please contact us at [email protected].