top of page

Privacy Policy

PRIVACY NOTICE FOR THE PROCESSING OF PERSONAL DATA

PURSUANT TO ARTICLE 13 GDPR

WEBSITE

Sparkwood People Ltd, a company incorporated in Ireland under company number 806996, with registered office at The Black Church, St. Mary’s Place, Dublin 7, D07 P4AX, Ireland (hereinafter the “Controller”), in its capacity as data controller, hereby informs you pursuant to Regulation (EU) 2016/679 (“GDPR”) and to the personal data protection legislation in force that your data (hereinafter the “Data”), in the context of the website www.sparkwood.ai and any of its subdomains (hereinafter the “Site”), as well as in the context of the use of the services offered by the Controller, will be processed in the manner and for the purposes set out below.
Unless otherwise stated, the contents of this notice apply only to Personal Data processed in the context of the use of the Site and its subdomains. It is understood that processing of Personal Data carried out for purposes other than those indicated below will be governed by the privacy notices relating to the services concerned in each case.

 

1. CATEGORIES OF DATA PROCESSED
The Controller processes the following ordinary Personal Data communicated by you while browsing the Site, by way of example: identification data (first name and surname), contact data (e-mail address), browsing data and the organisation you belong to.


2. PURPOSES AND LEGAL BASES OF PROCESSING
1    Handling requests for information received through the contact form.    Processing is necessary for the performance of a contract to which the data subject is party, or in order to take steps at the request of the data subject prior to entering into a contract, pursuant to Article 6(1)(b) GDPR.
2    Operating the Site and its functions, monitoring its correct functioning, improving the quality of the services offered and optimising the functionality of the Site.    Processing is necessary for the purposes of the legitimate interests pursued by the Controller pursuant to Article 6(1)(f) GDPR.
3    Exercise of the Controller’s rights before the courts and management of litigation.    Processing is necessary for the purposes of the legitimate interests pursued by the Controller pursuant to Article 6(1)(f) GDPR.
4    Prevention and suppression of unlawful acts.    Processing is necessary for the purposes of the legitimate interests pursued by the Controller pursuant to Article 6(1)(f) GDPR.

 

3. METHOD OF PROCESSING
Your Data is processed by electronic means so as to minimise the risk of destruction, loss (including accidental loss), unauthorised access or use, or use incompatible with the original purpose of collection. This is achieved through the technical and organisational security measures implemented by the Controller.

 

4. DATA RETENTION
Personal Data will be retained for the period strictly necessary to achieve the purposes for which it was collected, in accordance with the storage limitation principle set out in Article 5(1)(e) GDPR, and erased at the end of the applicable retention period. The Controller shall nevertheless be entitled to retain Personal Data further, in whole or in part, where specific legal provisions so require or in order to establish or defend a legal claim.
Specifically, retention periods vary according to the purpose of processing — by way of example, [six] years from the termination of the contractual relationship in respect of Data processed for the performance of the contract, for legal and accounting compliance and for the management of litigation, having regard to the limitation periods for actions founded on contract under the Statute of Limitations Act 1957 and to the accounting record retention requirements of the Companies Act 2014.

 

5. PROVISION OF DATA
The provision of Data for the purposes described above is:
•    necessary and mandatory; any refusal to provide such Data will make it impossible to respond to the request submitted to the Controller.

 

6. DISCLOSURE OF DATA
Within the scope of the purposes indicated above, the Controller may disclose your Data to:
•    collaborators, duly instructed and authorised to process the Data under the authority of the Controller pursuant to Article 29 GDPR and the Data Protection Act 2018;
•    third parties (for example, IT service providers, hosting providers, etc.) engaged by the Controller to carry out activities instrumental to achieving the purposes set out above, and which will process the Data in their capacity as processors or as independent controllers.
You may request an up-to-date list of the data processors from the Controller at any time.

 

7. TRANSFER OF DATA
The Controller may transfer Data outside the European Economic Area for the purposes set out above. This will take place solely on the basis of an adequacy decision pursuant to Article 45 GDPR or, in any event, in compliance with the safeguards set out in Chapter V of the GDPR.

 

8. RIGHTS OF THE DATA SUBJECT
The Controller informs you that, as a data subject, and provided that no limitations laid down by law apply, you have the right to:
•    obtain confirmation as to whether or not Personal Data concerning you exists, even if not yet recorded, and to have such Data made available to you in intelligible form;
•    obtain information and, where applicable, a copy of: (a) the origin and category of the Personal Data; (b) the logic applied where processing is carried out by electronic means; (c) the purposes and methods of processing; (d) the identification details of the Controller and of the processors; (e) the persons or categories of person to whom the Personal Data may be disclosed or who may become aware of it, in particular recipients in third countries or international organisations; (f) where possible, the retention period of the Data or the criteria used to determine that period; (g) the existence of automated decision-making and, if so, the logic involved and the significance and envisaged consequences for the data subject; (h) the existence of appropriate safeguards where Data is transferred to a non-EU country or to an international organisation;
•    obtain, without undue delay, the updating and rectification of inaccurate Data or, where you have an interest therein, the completion of incomplete Data;
•    withdraw at any time, easily and without hindrance, any consent given, using where possible the same channels through which it was provided;
•    obtain the erasure, anonymisation or blocking of Data that: (a) has been processed unlawfully; (b) is no longer necessary in relation to the purposes for which it was collected or subsequently processed; (c) where consent on which the processing is based has been withdrawn and there is no other legal ground for the processing; (d) where you have objected to the processing and there is no overriding legitimate ground for continuing it; (e) where erasure is required for compliance with a legal obligation; (f) where the Data relates to minors. The Controller may refuse erasure only in the case of: (a) exercise of the right to freedom of expression and information; (b) compliance with a legal obligation, performance of a task carried out in the public interest or exercise of official authority; (c) reasons of public health interest; (d) archiving in the public interest, scientific or historical research or statistical purposes; (e) the establishment or defence of a legal claim;
•    obtain restriction of processing in the event of: (a) contestation of the accuracy of the Personal Data; (b) unlawful processing by the Controller, in order to prevent erasure; (c) the establishment or defence of a legal claim; (d) verification as to whether the legitimate grounds of the Controller override those of the data subject;
•    receive, where processing is carried out by automated means, without hindrance and in a structured, commonly used and machine-readable format, the Personal Data concerning you, in order to transmit it to another controller or — where technically feasible — to obtain its direct transmission by the Controller to another controller;
•    object, in whole or in part, on legitimate grounds relating to your particular situation, to the processing of Personal Data concerning you.
In the cases set out above, where necessary, the Controller will inform the third parties to whom your Personal Data has been disclosed of any exercise of your rights, save in specific cases (for example, where doing so proves impossible or would involve a manifestly disproportionate effort in relation to the right protected).
If you consider that your rights have been infringed, you have the right to lodge a complaint with the Irish supervisory authority, the Data Protection Commission, 6 Pembroke Row, Dublin 2, D02 X963, Ireland. For any further information, we invite you to consult the authority’s website — www.dataprotection.ie — where you will find a section dedicated to these rights.

+

9. HOW TO EXERCISE YOUR RIGHTS
You may exercise your rights at any time by:
•    sending a letter by registered post to the Controller at its registered office set out above;
•    sending an e-mail to hello@sparkwood.ai.
 

bottom of page