Legal
Privacy Policy & GDPR Compliance
Last reviewed: 12 January 2026. This policy explains how we handle personal data under EU Regulation 2016/679 (the General Data Protection Regulation) and the Data Protection Act 2018.
1. Who we are (Data Controller)
Grand Gardens Restoration Group, a registered charity in Ireland (RCN: 20141004), of Ardamullivan, Shanaglish, Co. Galway, H91 CA30, Ireland, is the data controller for personal data processed through this website and in the course of our charitable activities.
2. Contacting our Data Protection Officer
Data protection matters are handled by our appointed Data Protection Officer, who may be reached by email at randolph-bevx@gmx.com (please mark your message "For the attention of the Data Protection Officer"), by telephone on +353 85 175 3192, or by post to the Data Protection Officer at our registered address above.
3. What personal data we collect
- Enquiry data: your name, email address, and the content of any message you send through our contact form or by email.
- Volunteer data: name, email, telephone number, town or townland, stated skills, availability, emergency contact details supplied on the day, and, where required by the role, Garda vetting outcome (retained as a pass/fail record only).
- Donor data: name, contact details, donation amount and date, and, where you choose to participate in the Charitable Donation Scheme, your PPS number as supplied on a Revenue CHY3 certificate.
- Partnership data: organisation name, contact name, work email and the content of any CSR proposal.
- Technical data: anonymised server log information such as request time and page requested, retained for security and stability purposes.
We do not knowingly collect personal data from children under 16 through this website. Personal data relating to children participating in school programmes is collected from and consented to by the school and the parent or guardian, never directly from the child.
4. Lawful bases for processing
- Consent (Article 6(1)(a)): newsletter subscriptions, photography of identifiable individuals at events, and volunteer contact lists.
- Contract (Article 6(1)(b)): administering a corporate partnership or a paid supplier relationship.
- Legal obligation (Article 6(1)(c)): retention of financial records under Irish taxation and charity law, and reporting obligations to the Charities Regulatory Authority and the Revenue Commissioners.
- Legitimate interests (Article 6(1)(f)): responding to enquiries, coordinating volunteer field days, acknowledging donations, and protecting the security of our systems. We have assessed that these interests are not overridden by your rights and freedoms.
- Vital interests (Article 6(1)(d)): use of emergency contact details in the event of an accident on a work site.
5. How we use your data
We use personal data only to reply to enquiries, organise and risk-assess volunteer activity, acknowledge and account for donations, administer tax reclaim where you have opted in, meet our statutory reporting duties, and — where you have consented — to send occasional updates about our work. We never sell, rent or trade personal data, and we do not use it for automated decision-making or profiling.
6. Retention periods
- General enquiries: 24 months from last contact.
- Volunteer records: for the duration of involvement plus 24 months.
- Accident and incident reports: 10 years, or until a participating minor reaches the age of 25, whichever is later.
- Financial and donation records: 7 years, as required by Irish taxation and charity law.
- Newsletter subscriptions: until you unsubscribe, plus a suppression record.
7. Sharing and international transfers
We share personal data only with: our email and website service providers acting as processors under written Article 28 agreements; our independent examiner and accountants; An Garda Síochána where vetting is legally required; and the Revenue Commissioners or the Charities Regulatory Authority where we are legally obliged to do so. Our data is stored within the European Economic Area. Where a processor transfers data outside the EEA, that transfer is made under European Commission Standard Contractual Clauses or an adequacy decision.
8. Your rights under EU Regulation 2016/679
- Right of access to the personal data we hold about you (Article 15).
- Right to rectification of inaccurate or incomplete data (Article 16).
- Right to erasure, subject to our legal retention duties (Article 17).
- Right to restriction of processing (Article 18).
- Right to data portability (Article 20).
- Right to object to processing based on legitimate interests (Article 21).
- Right to withdraw consent at any time, without affecting prior processing.
To exercise any right, contact our Data Protection Officer using the details in section 2. We respond within one month, free of charge. You also have the right to lodge a complaint with the Data Protection Commission, 6 Pembroke Row, Dublin 2, D02 X963 (www.dataprotection.ie).
9. Cookies
This website uses strictly necessary cookies only, to maintain your session and remember your language preference. We do not run advertising, tracking or third-party analytics cookies, so no consent banner is required for these under the ePrivacy Regulations 2011. The embedded map on our contact page is served by Google and may set cookies once it loads; you may block third-party cookies in your browser without affecting the rest of the site.
10. Security
Personal data is held on access-controlled systems protected by strong authentication and transport encryption (HTTPS). Paper records are held in a locked cabinet at the registered address. Access is restricted to the trustees and coordinators who need it. Any personal data breach presenting a risk to individuals will be notified to the Data Protection Commission within 72 hours and, where required, to affected individuals without undue delay.
11. Changes to this policy
We review this policy annually and on any material change to our processing. The review date is shown at the top of this page.
