Privacy Statement
Yogashop is committed to keeping your data safe.
We will only store and process your personal data in accordance with the relevant Irish and EU data protection legislation (including the General Date Protection Regulation – GDPR).
You can opt-out of any communications you are getting from us at any time.
You can make a request about your data at any time using this form.
Our full data protection policy follows below (PDF here).
Yogashop – Data Protection Policy
Introduction
This document provides a concise policy regarding the data protection practices of Yogashop and is part of our commitment to data protection by design and default.
Yogashop is a data controller with reference to the personal data which it manages, processes and stores.
Our commitment to data protection
Yogashop is committed to keeping personal data safe, in particular are commited to privacy and data protection in respect of the rights of data subjects. We are committed to retaining transparency and accountability in data use and management.
Purpose of this Policy
As a data controller, Yogashop must comply with the data protection Principles set out in the relevant Irish and EU legislation.
This Policy applies to all personal data collected, processed and stored by Yogashop in the course of its activities. This Policy is designed to ensure Yogashop’s compliance with the following legislation:
The European General Data Protection Regulation (GDPR)
The EU Electronic Communications Regulations (2011)
The GDPR confers rights on individuals as well as additional responsibilities on those persons and organizations processing personal data and Yogashop will ensure that all policies and activities are done in compliance with this legislation.
Definitions
For the purpose of this Policy:
‘Personal data’ means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person
‘Processing’ means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;
‘Controller’ means the natural or legal person which, alone or jointly with others, determines the purposes and means of the processing of personal data;
‘Processor’ means a natural or legal person, which processes personal data on behalf of the controller;
‘Consent’ of the data subject means any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her;
‘Supervisory authority’ means the Irish Data Protection Commissioner, as an independent public authority established by Ireland pursuant to Article 51 of the GDPR.
Yogashop’s use of personal data
Yogashop, as a data controller, collects, processes and stores volumes of personal and sensitive personal data on an ongoing basis.
Yogashop collects data about its customers, partners and course participants who come into contact with the organisation through our activities. We process personal data for the following reasons:
- The organization and facilitation of retail and procurement activities.
The collection and management of payments
The operations, monitoring and evaluation of our work, including outreach, public relations, advocacy, and communications and sales work
The recruitment, management and payment of staff and contractors
Ensuring the security of staff and premises
Compliance with statutory obligations
Yogashop may also contract other companies to act as data processors for the personal data collected by Yogashop. In such cases we will satisfy ourselves they have GDPR-compliant data protection policies in place.
This Policy applies to all data collected, both manually and automated, held by Yogashop. This includes electronic and paper records.
Ownership
The Data Protection Policy is maintained by Yogashop and is appoved by the Management . Further comments or questions on the content of this Policy should be directed to the Head of Customer Relations. Any material changes to this Policy will require approval by the Yogashop management..
Employers
In its role as an employer, Yogashop may keep information relating to staff members to ensure its compliance with employment law.
Yogashop will ensure that all staff members receive awareness raising and training on data protection.
Failure of staff to process personal data in compliance with this Policy may result in disciplinary proceedings.
The Data Protection Principles
The following key Principles are enshrined in EU legislation and are fundamental to Yogashop’s Data Protection Policy.
In its capacity as data controller, Yogashop ensures that all data shall:
Be obtained and processed fairly and lawfully
Yogashop will only process personal data in line with one of the lawful bases enshrined in Article 7 of the GDPR. Yogashop fulfills its obligation in this regard by ensuring that:
- Where possible, the informed consent of the data subject will be sought before their data is processed. Yogashop will ensure that the request for consent is presented in a manner which is clearly distinguishable from the other matters, in an intelligible and easily accessible form, using clear and plain language. Yogashop will also ensure that the data subject is made aware of his or her right to withdraw his or her consent at any time
- Where it is not possible to seek consent, Yogashop will ensure that collection of the data is justified under one of the other lawful processing conditions listed in Article 7 of the GDPR (compliance with legal obligation, contractual necessity, vital interests of data subject, public interest, or the legitimate interests of the data controller);
- Where the data processed by Yogashop can be considered sensitive personal data, as defined in Article 9 of the GDPR, Yogashop will not collect, process and store such data, unless permissible under the exemptions listed in Article 2 (a-j) of the GDPR;
Where Yogashop intends to record activity on CCTV or video, a Fair Processing Notice will be posted in full view, prior to the recording and purpose, storage and the conditions for viewing the data will be laid out clearly and communicated to staff; - Processing of the personal data will be carried out only as part of Yogashop’s lawful activities, and it will safeguard the rights and freedoms of the data subject;
- The data subject’s personal data will not be disclosed to a third party other than to a party contracted by Yogashop and operating on its behalf, or where Yogashop is required to do so by law.
Be obtained only for one or more specified, legitimate purposes
Yogashop will obtain data for purposes which are specific, lawful and clearly stated. A data subject will have the right to question the purpose(s) for which Yogashop holds their data, and it will be able to clearly state that purpose or purposes. - Not be further processed in a manner incompatible with the specified purpose(s). Any use of the data by Yogashop will be compatible with the purposes for which the data was acquired and Yogashop takes steps to ensure that no personal data will be further processed in a manner that is incompatible with those purposes in line with the principles laid down in Article 5 of the GDPR.
- Be adequate, relevant and not excessive in relation to the purpose(s) for which the data were collected and processed. Yogashop will ensure that the data it processes in relation to data subjects is adequate, relevant and limited to what is necessary in relation to the purposes for which the data is collected, in line with the principles laid down in Article 5 of the GDPR. Data which is not relevant to such processing will not be acquired or maintained, in line with the principle of data minimization.
- Be kept accurate, complete and up-to-date where necessary. Yogashop shall endeavor to keep the personal data it controls as accurate and up-to-date as possible, in line with the principles laid down in Article 5 of the GDPR, and to correct any inaccuracies as soon as they are discovered.
- Not be kept for longer than is necessary to satisfy the specified purpose(s). Yogashop will ensure that personal data is not kept for longer than is necessary for the purpose for which the data is processed, in line with the principles laid down in Article 5 of the GDPR. To fulfil this commitment, Yogashop has developed a schedule and ageing process with retention periods for the categories of personal data processed by the organization.Once the respective retention period has elapsed, Yogashop undertakes to destroy, erase or otherwise put this data beyond use, save for limited personal data which may be stored for longer periods solely for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes, in line with Article 5 of the GDPR.
- Be kept safe and secure. Yogashop will ensure that the personal data it collects will be protected against unauthorized or unlawful processing and against accidental loss, destruction or damage. In the event of a data breach likely to result in a risk to the rights and freedoms of the data subject or other persons, Yogashop will notify the Irish Data Protection Commissioner without undue delay and, where feasible, within 72 hours after having become aware of the breach, in line with Article 33 of the GDPR. In the event of a data security breach affecting the personal data being processed on behalf of the data controller, the relevant third party processor will notify the data controller without undue delay.
Data subject rights.
A ‘data subject’ is any person whose data we process and store.
Clear and easily accessible communication
Yogashop will take appropriate measures to ensure any and all communication with a data subject is conducted in a concise, transparent, intelligible and easily accessible from, using clear and plain language that is easy for the data subject to understand.
Information provided to data subject.
Yogashop will ensure that all data subjects will be made aware, at the time their data is being collected, of:
- The identity of the data controller (Yogashop);
The purpose(s) for which the data is being processed;
The legitimate interests pursued by the controller (if processing is based on Article 6 (1)(f) of the GDPR)
The person(s) to whom the data may be disclosed by the data controller;
Any other information that is necessary so that the processing may be considered fair.
Right of access by data subjects
Upon receipt of a valid, formal request by a data subject in relation to the personal data held by Yogashop which relates to them, Yogashop will provide the data subject with the following information, free of charge, in line with Article 15 of the GDPR:
- The basis on which the data was obtained.
The purposes for processing the data.
The categories of personal data concerned.
To whom the data has been or will be disclosed.
Whether the data has been or will be transferred outside of the EU.
The period for which the data will be stored, or the criteria to be used to determine retention periods.
Information about the right to make a complaint to the Irish Data Protection Commissioner.
Information about the right to request rectification or deletion of the data.
Whether the individual has been subject to automated decision making.
Yogashop will ensure that all subject access requests receive a response within 30 days. Further details can be found in the Yogashop Subject Access Request Policy.
Right to rectification and the right to be forgotten
Yogashop has put in place processes to ensure the accurate nature of the personal data it collects. However, in the event that a data subject submits a valid request for correction or completion of incorrect or incomplete data, Yogashop will ensure that any such data will be rectified or completed without undue delay, in line with Article 16 of the GDPR, and that the data subject is informed of the correct or completion of data.
Yogashop will ensure that, upon request of the data subject, and where one of the specific grounds listed in Article 17 of the GDPR applies, all personal data related to the data subject in question is erased without undue delay, and that the data subject is informed of the erasure.
The right to restriction of processing and the right to object.
Yogashop will put in place processes that ensure respect for a data subject’s right to object or have restriction put in place against processing of their data. Yogashop will ensure these processes comply fully with Articles 19 and 21 of the GDPR.
Review
This Policy will be reviewed at least annually by Yogashop Management to ensure alignment to appropriate risk management requirements and its continued relevance to current and planned operations, or legal developments and legislative obligations.
Supervisory authority
Yogashop is in Ireland. Should you wish to contact the relevant supervisory authority in relation to a data protection issue involving Friends of the Earth Ireland, you should contact:
The Irish Data Protection Commissioner
Telephone
+353 57 8684800
+353 (0)761 104 800
Fax
+353 57 868 4757
Postal Address
Data Protection Commissioner Canal House Station Road Portarlington
Dublin Office
21 Fitzwilliam Square Dublin 2 D02 RD28 Ireland.
Portarlington Office
Canal House Station Road Portarlington R32 AP23 Co. Laois
Yogashop Data Protection manager contact details:
The Data Protection Policy is maintained by Yogashop management.
Email: dataprotection@yogashop.ie
Phone: 021-4373994
Download Subject Access Request Policy Here
Download Subject Access Request Form Here