Privacy Policy

Privacy Policy – Double Helix Ltd.

This is the Privacy Policy of Double Helix Ltd. of 6-9 Trinity Street, Dublin 2.

The purpose of this Privacy Policy is to ensure individuals and data subjects understand how we process their information.

Double Helix Ltd. endeavours to comply with the General Data Protection Regulation, Data Protection Act 2018 and data protection best practices.

We process personal information provided to us by individuals, whether it be provided through our website www.doublehelix.ie by any form, correspondence, telephone, email or by any other means, or otherwise processed by us concerning you, in the manner set out in this policy.

By submitting your information to us, and or engaging with our services and or by using the Website you consent to the use of your personal information as set out by this Privacy Policy. If you do not agree with the terms of this Privacy Policy please do not use the Website or volunteer or provide us with any personal information.

Information collected by us

The information about you that we may collect, use and store (process) includes:

  • Information necessary for the provision of services by Double Helix Ltd. (of which such data may include name, address, contact details, etc.)
  • Information necessary to facilitate, process, invoice or collect monies related to any agreed business transaction with Double Helix Ltd. (of which such data may include name, address, contact details, billing details, etc.).
  • Information you provide to us by filling out any forms on the website or by way of emailing us or by any other form of written communication.
  • Records of correspondences whether by email, telephone, through any form on our website or by any other means,
  • Information you provide to us in person,
  • Details of any business, commercial or trade transactions you carry out with us, whether through email, the website, telephone, or by any other means.
  • Information provided by an employer, and or their agent and or servant, who engages with Double Helix Ltd. for the provision of employment services and or employment support services provided by Double Helix Ltd. in furtherance of any contract in place.
  • For Double Helix Ltd. complying with any legal obligation.
  • Information provided by an employer and or potential employer who engages with Double Helix Ltd. to comply with any legal obligation.
  • Details of your visits to our website including traffic data, location data, weblogs and other communication data by our Cookie Policy that may identify personal information (e.g. cookies) and non-personal information (e.g. information of an anonymised or technical nature).

How we use your personal information

We may use your personal information for:

  1. Processing any enquiry requested by you;
  2. Entering into and or completing any sales commercial or business-related requests or transactions requested by you;
  • Complying with any contractual obligations relating to any accountancy and or payroll agreement that you may enter into;
  1. Setting up, operating and managing an account or line of credit, if applicable;
  2. Setting up, operating and managing any marketing and or advertising services subject to your explicit consent (please see Marketing & Advertising below);
  3. Complying with our legal duties and responsibilities;
  • Debt collection and the collection of outstanding monies;
  • Providing, monitoring, reviewing and supporting our online presence via our website and social media (please see our Cookie Policy)
  1. Monitoring any billing or credit transactions to prevent fraud;
  2. Provision of security to, and ensuring the health and safety of employees, customers and visitors to our premises.
  3. The provision of employment services and or employment support services to an employer where the data originated from the employer and Double Helix Ltd. acts as a data processor on behalf of the employer data controller.
  • The provision of employment auditing and or compliance services to third party firms in cases where the personal data originated from the third party and Double Helix Ltd. acts as a data processor on behalf of this third party.

We normally obtain consent to process personal data by way of notification on our website that requires explicit acceptance of this Privacy Policy and associated Cookie Policy to use the website. Consent for data processing purposes can also be obtained by way of a physical application form, credit form or other paperwork of Double Helix Ltd. that refers to our privacy policy on this website and acceptance of same.

All data processed will be held as confidential, secure, will be used only for the purposes for which it was collected and will be destroyed or deleted once is it no longer necessary by our data retention policy. Our standard data retention period is seven years.

Double Helix Ltd. does not engage in any automated decision-making processes nor do we use any personal data as a basis for any such automated decisions.

Double Helix Ltd. does not transfer personal data outside the jurisdiction of, or application of, the General Data Protection Regulation. However, Double Helix Ltd. may outsource some commercial activities and or and or engage with some third-party service providers based within the EU that may share data within other EU member states (e.g. back up, storage facilities, etc.) and such third-party suppliers are subject to the One-Stop-Shop Mechanism as identified by the Irish Data Protection Commission.

We may also outsource some commercial actives to third parties that are based outside the EU but GDPR still applies to any data processed as a result, by GDPR, the Data Protection Act 2018 and practice directives issued by the Irish Data Protection Commission.

For example, if you give us your explicit consent, we may use Mailchimp to send you marketing emails but Mailchimp uses Standard Contractual clauses and has an EU-US Privacy Shield Framework in place to ensure GDPR compliance. For Mailchimp’s data protection practices please see their privacy policy available at www.mailchimp.com/legal/privacy.

For more information about the One Stop Shop Mechanism, Privacy Shield Framework or Standard Contractual Clauses applicable to data being processed outside of Ireland and or the EU, please visit the Data Protection Commission website at www.dataprotection.ie.

Data Processing Agreements

 A Data processing agreement, which ensures compliance with the Data Protection Act 2018 and GDPR, between a data controller and data processer, is incorporated into our standard terms of business for all clients.

For the avoidance of doubt, we have an applicable data processing agreement/terms of service for when we act as a data controller and, separately, for when we act as a data processor on behalf of a data controller in the provision of services (e.g. where we provide payroll services to a business).

Where we act as a data processor for a data controller

At times we may act as a data processor for a data controller, mainly in the provision of payroll services and, as such, we may process personal data that originated from the data controller. As such we are relying on the veracity and lawful processing identified by the data controller.

This policy and our data protection practices also applies to when we act as a data processor. Notwithstanding our obligations under GDPR and the Data Protection Act 2018, nor any data protection agreement or terms of service, it is up to the data controller to ensure ongoing compliance and inform us of any updates or changes to personal data.

Marketing & Advertising

Double Helix Ltd. provides accountancy services, payroll services and services to assist firms in compliance and regulatory matters, including auditing, review and assessment of a firm’s financial data and financial sustainability.

As part of our marketing and advertising practices, we may use promotional emails, text messages and or phone calls to people who have consented to be contacted for marketing and advertising purposes.

In terms of data processing, subject to your explicit consent, we may use your personal information for:

  1. Marketing and Sales promotions;
  2. Providing you with information about promotional offers on our products and services;
  • Carrying out any service user, membership or customer research, survey and analysis;
  1. Commercial activities, including brand or event awareness, participation and product or service launches;

At some interactions with Double Helix Ltd., you may be asked to consent to your data being used for marketing purposes. In such cases, consent will require positive action on your part. For example, on an enquiry form, you would have to tick a box stating that you consent to your data being processed for marketing purposes in accord with this privacy policy to receive personalised targeted marketing emails, text messages and or phone calls.

At times, Double Helix Ltd. may host or organise events in which data subjects may interact with us face-to-face, e.g. at trade shows, talks, presentations, etc. In such cases, we may verbally ask if you consent to your data being processed for marking and advertising purposes subject to this policy. We may also announce that photographs may be taken for social medical purposes but please refer to the social media section below.

Double Helix Ltd. may use Mailchimp for our email marketing who are GDPR compliant by way of an EU-US Privacy Shield. Please note that if you do not consent to your email being used for marketing purposes then we do not contact you by email for marketing or advertising purposes and the privacy shield stated here is not applicable.  For more information on Privacy Shield please see the Data Protection Commission’s website www.dataprotection.ie  and Mailchimp at https://mailchimp.com/help/about-mailchimp-the-eu-swiss-privacy-shield-and-the-gdpr/

Double Helix Ltd. is committed to privacy by design and privacy by default. As such, you will never have to ‘opt-out’ of our marketing processes; you will only ever have the option of ‘opting in’ if you’d like to be included. We do not engage in ‘pre-ticked’ boxes on consent forms nor do we ever assume you would consent to your data being processed. You are free to withdraw consent for any marketing matters at any time you want.

Social media

Double Helix Ltd. engages in several social media services and we strive to uphold privacy rights online. However, sometimes members of the public may post something objectionable and beyond our control to our social media pages/forums. In such cases, we will act to rectify any difficulties as soon as we are notified or become aware of the problem. We do not provide continuous monitoring of social media sites/forums so there may be a slight delay from the initial post to when becoming aware of a problem.

Double Helix Ltd. may hold marketing events in which customers, visitors or employees may be present. Sometimes we may wish to take a photograph at such events to promote our brand or event on social media. In such cases, it is our policy for our photographer/social media handler to announce their presence and provide additional instructions and assistance. However, we do not have any control over private individuals or their social media accounts, as such we cannot stop or prevent private individuals from posting materials to their social media accounts that others may find objectionable.

For information relating to social media usages, cookies or widgets, please see our Cookie Policy

We welcome enquires and communications from clients and prospective clients through social media however users are bound by the privacy policy of the respective social media organisation (e.g. Facebook, LinkedIn, etc.). We cannot be held liable for any act or omission of the social media organisation nor can we ensure that any communication through social media is encrypted or secure in any way.

Information Storage

We will take reasonable steps to ensure that your information is kept secure and protected, including but not limited to electronic data is protected using appropriate software, relevant networks safety and security checks to include two-step authentication, and, where applicable, any physical data records will be kept in an appropriately secure environment.

We comply with the Guidance for Controllers on Data Security by the Data Protection Commission issued in June 2019.

We have a general data retention policy that relates to the retention of relevant data for seven years. Personal data that is no longer required will be destroyed and or deleted insecure manner.

We do not record or process personal data that is not required or not necessary for any of our stated purposes.

Disclosure of data

We may outsource certain commercial functions to external third parties, e.g. debt collection, accounting auditors, etc. and in such cases where personal data is required to complete those functions than an appropriate data processing agreement, with relevant safeguards, will be in place to ensure our ongoing obligations under the Data Protection Act 2018 are upheld.

We may also have to disclose certain personal data by any legal obligation imposed on us. Any such disclosure would be by the law, e.g. disclosed on foot of a court order, Child First Act, etc.

Requesting your data

Any person has the right to find out whether an organisation has any personal data about them, what they use the personal data for and ask for copies of personal information held by that organisation.

If you wish to make a data access request to get a copy of any personal data we may process, please write a letter stating that you wish to make a data access request and address it to:

Data Protection

Double Helix Ltd.

6-9 Trinity Street,

Dublin 2.

Or by email to pjmurphy@doublehelix.ie.

To process your request, we may request that you send us a copy of your identification (passport, driver’s licence, etc.). The reason we ask for personal identification is to ensure that you are the correct person requesting your data.

Unfortunately, verbal access requests cannot be entertained.

In response to any data access request, you have the right to refer the matter to the Data Protection Commission if you are unhappy with the outcome, however, we ask that you notify us first of any issue so that we may help resolve it as quickly as possible.

Rectifying mistakes

You have the right to rectify any incorrect or inaccurate personal data at no cost to you.

If you believe that we are incorrectly processing any of your data, please inform us by writing to the above address or email pjmurphy@doublehelix.ie.

Queries or complaints

If you have any queries or complaints regarding our Privacy Policy or any data protection matter, please let us know by writing to the above address or email pjmurphy@doublehelix.ie

Individuals have the right to refer any matter to the Data Protection Commission by contacting them at www.dataprotection.ie or by writing to:

Data Protection Commission

Office of the Data Protection Commission

21 Fitzwilliam Square South

Dublin 2

D02 RD28

Ireland

If you are, for whatever reason, considering contacting the Data Protection Commission about us we would ask that you inform us of your difficulty first so that we can try to resolve it to your satisfaction.

Changes to our Privacy Policy

 Any changes we may make to our Privacy Policy in the future will be posted on our website.

Any changes will become effective upon posting the revised Privacy Policy on our website. If we make any material or substantial changes to this Privacy Policy we will use reasonable endeavours to inform you by email, notice on the Website or any other agreed communications channels.

Privacy Policy last reviewed: August 2019

 

Copyright retained by Argent Business Consultants and used with licence by Double Helix Ltd.

www.argentbusinessconsultants.ie