- Introduction:
- This GDPR Policy outlines how Legacy of Sport complies with the General Data Protection Regulation (GDPR) and ensures the protection of individuals’ rights regarding the processing of their personal data.
- Data Controller:
- Legacy of Sport Limited, located at Lough Cutra Castle, Gort, County Galway, Ireland, is the data controller responsible for the processing of personal data.
- Lawful Basis for Processing:
- We process personal data based on the lawful bases defined in Article 6 of the GDPR, such as the necessity of processing for the performance of a contract, compliance with a legal obligation, protection of vital interests, consent, the performance of a task carried out in the public interest or the exercise of official authority, and legitimate interests pursued by the data controller.
- Types of Personal Data Collected:
- We collect personal data necessary for the fulfillment of orders, remembrance activities, and communication. This may include names, addresses, contact details, and payment information.
- Purpose of Processing:
- Personal data is processed for the following purposes:
- Order processing and delivery
- Confirmation of remembrance activities
- Communication regarding orders and services
- Compliance with legal obligations
- Consent:
- Where required by law, we obtain explicit consent before processing personal data. Consent is freely given, specific, informed, and revocable.
- Data Subject Rights:
- Individuals have the right to request access to, rectification, erasure, or restriction of processing of their personal data. Requests can be made in writing to colm@legacyofsport.com.
- Data Security:
- We implement appropriate technical and organizational measures to ensure the security of personal data, including protection against unauthorized or unlawful processing, accidental loss, destruction, or damage.
- Data Breach Notification:
- In the event of a data breach leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data, we will report the breach to the Information Commissioner’s Office (ICO) within 72 hours and, when applicable, inform affected individuals.
- Data Transfer: – Personal data is not transferred to countries outside the European Economic Area (EEA) without ensuring an adequate level of protection or appropriate safeguards.
- Data Protection Officer (DPO): – Legacy of Sport Ltd appoints a Data Protection Officer who is responsible for overseeing compliance with this GDPR Policy. The DPO can be contacted at colm@legacyofsport.com.
- Review and Update: – This GDPR Policy is reviewed regularly and updated as needed. The latest version is available on our website.
For any GDPR-related inquiries or requests, please contact our Data Protection Officer at colm@legacyofsport.com.