Privacy Policy
Finsoul Ireland respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, disclose and protect personal data when you visit our website, contact us, request information, use our services, submit an enquiry, or otherwise interact with us.
This Privacy Policy has been prepared with regard to the General Data Protection Regulation (EU) 2016/679 (GDPR), the Data Protection Act 2018, the Irish electronic communications and ePrivacy requirements applicable to cookies and similar technologies, and other applicable data protection requirements.
This Privacy Policy is provided as a transparency notice. It explains how and why Finsoul Ireland processes personal data and the rights available to individuals. It is not intended to constitute a contract or to obtain consent merely by your use of the website. Where consent is legally required, we will request it separately.
About Finsoul Ireland
Finsoul Ireland provides professional business, financial, accounting, tax, advisory, technology, ISO, marketing, corporate and related professional services to businesses and individuals in Ireland and, where applicable, internationally.
Registered Office: Alexandra House, Ballsbridge Park 3, Dublin, D04 C7H2, Ireland
Email: info@finsoulireland.com
Website: https://finsoulireland.com/
For the purposes of applicable data protection legislation, Finsoul Ireland acts as a Data Controller where it determines the purposes and means of processing personal data.
In certain client engagements, Finsoul Ireland may act as a Data Processor where it processes personal data on behalf of another organisation and in accordance with that organisation’s instructions.
For general privacy and data protection enquiries, please contact us at info@finsoulireland.com.
Services Covered by This Privacy Policy
Finsoul Ireland provides a range of professional services, including ISO, accounting, tax, financial and business advisory, audit and assurance, digital marketing, IT and technology, immigration, company formation, HR, ESG, real estate, supply chain and procurement services.
The personal data processed depends on the service requested and may include contact, identification, business, financial, accounting, tax, employment, educational or corporate information where necessary to provide the service, manage the engagement, comply with legal obligations or follow client instructions. Where technology, accounting software, automation, AI or cybersecurity services are involved, personal data may also be processed to configure, support, integrate or manage the relevant service. The range of services may change over time, and this Privacy Policy applies to the services actually provided.
Who This Privacy Policy Applies To
This Privacy Policy applies to individuals whose personal data we process in connection with our business activities, including:
- Website visitors
- Individuals who contact us
- Individuals who submit enquiries
- Prospective and existing clients
- Client representatives and authorised contacts
- Business partners and professional contacts
- Suppliers and service providers
- Individuals who communicate with us by email or telephone
- Individuals who apply for employment or other opportunities
- Individuals whose information is provided to us in connection with a business or professional relationship
Different categories of individuals may be subject to different processing activities depending on how and why their personal data is collected.
Personal Data We Collect
The personal data we collect depends on your relationship with Finsoul Ireland and the services you request.
Contact Information
This may include:
- Name
- Email address
- Telephone number
- Postal or business address
- Job title
- Company or organisation name
- Other contact information you provide
Identification Information
Where necessary for a particular service, we may collect identification or verification information, including information contained in documents you provide to us.
Business and Client Information
This may include:
- Company information
- Business contact details
- Service requirements
- Engagement information
- Information contained in documents
- Financial or business information relevant to the service
- Correspondence and records relating to our business relationship
Technical and Website Information
When you use our website, technical information may be collected automatically, depending on the technologies used and your cookie choices. This may include:
- IP address
- Browser type and version
- Device type
- Operating system
- General location information derived from IP address
- Pages visited
- Date and time of visits
- Referring website or source
- Website interaction information
- Technical and security information
Communication Information
We may retain information contained in:
- Emails
- Contact forms
- Consultation requests
- Telephone communications
- Other correspondence
- Records of communications concerning our services
Recruitment Information
Where you apply for a role, we may process:
- Name and contact details
- CV
- Employment history
- Qualifications
- Professional experience
- References
- Interview information
- Other information voluntarily provided during recruitment
We will process recruitment information only as reasonably necessary for recruitment, selection, employment-related administration and applicable legal obligations.
How We Collect Personal Data
We may collect personal data:
- Directly from you
- Through contact forms
- Through consultation requests
- By email
- By telephone
- During meetings or consultations
- During client onboarding
- During recruitment
- Through our website and associated technologies
- From your organisation or authorised representatives
- From publicly available professional or business sources where lawful and appropriate
- From service providers acting on our behalf
- From other third parties where necessary and lawful
Where personal data is obtained from a third party rather than directly from you, we will process it in accordance with applicable GDPR requirements.
How We Use Personal Data
We may use personal data for the following purposes:
- Responding to enquiries
- Providing information about our services
- Providing and administering services
- Managing client relationships
- Preparing proposals and quotations
- Preparing engagement documentation
- Managing consultations and appointments
- Performing contracts
- Processing payments
- Maintaining business records
- Managing suppliers and professional relationships
- Providing accounting, tax, advisory, ISO, technology, marketing or other professional services
- Managing recruitment
- Maintaining website functionality
- Monitoring website performance
- Maintaining information security
- Preventing fraud and misuse
- Protecting our systems and users
- Complying with legal and regulatory obligations
- Establishing, exercising or defending legal claims
- Managing data protection requests
- Sending marketing communications where permitted by law
- Other purposes that are compatible with the purpose for which the information was collected and permitted by applicable law
We will not process personal data for incompatible purposes unless permitted or required by applicable law.
Legal Bases for Processing
We process personal data only where a lawful basis under the GDPR applies.
Contract
We may process personal data where necessary to enter into or perform a contract with you or to take steps at your request before entering into a contract.
This may include:
- Preparing proposals
- Providing requested services
- Managing an engagement
- Communicating about services
- Administering contractual arrangements
Legal Obligation
We may process personal data where necessary to comply with a legal or regulatory obligation.
This may include obligations relating to:
- Accounting
- Tax
- Financial records
- Corporate requirements
- Regulatory requirements
- Record keeping
- Legal reporting
- Lawful requests from authorities
- Prevention or detection of unlawful activity
Legitimate Interests
We may rely on legitimate interests where processing is necessary for our legitimate business interests and those interests are not overridden by your rights and freedoms.
Our legitimate interests may include:
- Managing and developing our business
- Managing professional relationships
- Responding to business enquiries
- Maintaining website security
- Protecting our systems
- Preventing fraud and misuse
- Improving our services
- Managing suppliers
- Maintaining appropriate business records
- Establishing, exercising or defending legal claims
Where we rely on legitimate interests, we consider whether the processing is necessary and whether your interests, rights or freedoms require greater protection.
Consent
Where consent is required by law, we will request consent before carrying out the relevant processing.
This may include certain non-essential cookies, tracking technologies or electronic marketing activities.
Where processing is based on consent, you may withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.
Marketing Communications
We may communicate with existing or prospective clients about our services, business updates or related information where permitted by applicable law.
Where consent is required, we will obtain consent before sending the relevant marketing communications.
Where another lawful basis is available under applicable electronic marketing and data protection requirements, we may rely on that basis where appropriate.
You can unsubscribe from marketing communications at any time by using the unsubscribe option provided in the communication or by contacting info@finsoulireland.com.
Unsubscribing from marketing communications will not necessarily stop service-related or transactional communications that are necessary for an existing business relationship.
Cookies and Similar Technologies
Our website may use cookies and similar tracking technologies.
Cookies are small files or similar technologies that may be stored on or accessed from your device when you visit a website. They may be used for essential functionality, security, preferences, analytics and, where applicable, marketing or advertising.
Under Irish ePrivacy requirements, consent is normally required before non-essential cookies or similar tracking technologies are placed on or accessed from a user’s device. Strictly necessary technologies may fall within a limited exemption where they are required to provide a service explicitly requested by the user.
Strictly Necessary Cookies
These cookies are necessary for essential website functionality, security or a service explicitly requested by the visitor.
Where the applicable exemption applies, these cookies may be used without consent.
Functional Cookies
Functional cookies may remember preferences or settings selected by visitors.
Where consent is required, these cookies will only be activated after the relevant consent has been obtained.
Analytics Cookies
Analytics technologies may help us understand how visitors use our website, including which pages are visited, how visitors navigate the website and whether technical problems occur.
Where consent is required, analytics technologies will not be activated until the required consent has been obtained.
Marketing and Advertising Cookies
Where used, marketing or advertising technologies may help measure advertising performance, understand conversions, build audiences or provide relevant advertising.
Where consent is required, these technologies will not be activated unless the required consent has been obtained.
Cookie Consent and Withdrawal
Where non-essential cookies or tracking technologies require consent, our website will use an appropriate cookie-consent mechanism.
The consent mechanism should allow visitors to:
- Accept non-essential cookies
- Reject non-essential cookies
- Manage cookie categories
- Change cookie preferences
- Withdraw consent
Withdrawal or variation of consent will be made available through the cookie-preference mechanism and will be as easy as giving consent.
The actual cookies and tracking technologies used by the website may change. Cookie information should therefore be reviewed together with the cookie-consent mechanism displayed on the website.
Third-Party Services and Data Processors
Finsoul Ireland may use third-party providers to support our website, services and business operations.
Depending on the systems and services actually used, these providers may include:
- Website hosting providers
- Website security providers
- Email and communication providers
- Analytics providers
- Cookie-consent management providers
- Appointment and scheduling providers
- CRM providers
- Cloud storage providers
- IT support providers
- Cybersecurity providers
- Payment service providers
- Document management providers
- Website maintenance providers
- Professional advisers
Where a third party processes personal data on our behalf, we will take appropriate steps to ensure that the processing is governed by suitable contractual and data protection requirements.
Third-party providers will only receive personal data to the extent reasonably necessary for the relevant service or lawful purpose.
The specific providers used by Finsoul Ireland may change over time. Where appropriate and required by law, relevant recipients or categories of recipients will be disclosed.
Third-Party Platforms Used in Client Services
Certain Finsoul Ireland services may involve third-party platforms, software or systems.
These may include accounting, ERP, CRM, marketing, cloud, analytics, communication, cybersecurity, automation or other business platforms.
Where Finsoul Ireland processes personal data on behalf of a client through such platforms, the processing may be carried out according to the client’s instructions and applicable data-processing arrangements.
The responsibilities of Finsoul Ireland, the client and the third-party provider will depend on the specific service and processing arrangement.
Sharing Personal Data
We do not sell personal data.
We may disclose personal data where necessary and lawful to:
- Service providers and processors
- IT and hosting providers
- Professional advisers
- Accountants and auditors
- Legal advisers
- Payment providers
- Business partners where necessary for the relevant service
- Government departments and regulatory authorities
- Courts and law enforcement authorities where legally required
- Insurers and professional organisations where appropriate
- Other parties where necessary to establish, exercise or defend legal claims
We will seek to limit disclosures to information that is reasonably necessary for the relevant purpose.
International Data Transfers
Some third-party providers or business partners may process personal data outside Ireland or the European Economic Area.
Where personal data is transferred outside the EEA, we will ensure that an appropriate transfer mechanism is used where required under the GDPR.
Depending on the circumstances, this may include:
- A European Commission adequacy decision
- European Commission Standard Contractual Clauses
- Appropriate supplementary safeguards
- Another lawful transfer mechanism recognised under applicable data protection law
The actual location and transfer mechanism will depend on the third-party providers and technologies used by Finsoul Ireland.
Data Security
Finsoul Ireland takes appropriate technical and organisational measures to protect personal data against unauthorised access, accidental loss, destruction, alteration, disclosure or other unlawful processing.
Depending on the circumstances, our security measures may include:
- Access controls
- Authentication measures
- Encryption where appropriate
- Secure storage
- Confidentiality obligations
- Staff awareness and data protection procedures
- Security monitoring
- Backup and recovery measures
- Technical safeguards against unauthorised access
No website, electronic transmission or storage system can be guaranteed to be completely secure. We therefore cannot guarantee absolute security of personal data.
Data Retention
We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, unless a longer period is required or permitted by law.
Retention depends on:
- The purpose of processing
- The type and sensitivity of the information
- Whether an ongoing business relationship exists
- Contractual requirements
- Legal and regulatory obligations
- Accounting and tax requirements
- Potential disputes or legal claims
- Record-keeping requirements
- Our legitimate business needs
Enquiry and Contact Information
General enquiry information may be retained for as long as reasonably necessary to respond to the enquiry, manage the relationship and maintain appropriate business records.
Client and Service Records
Client and engagement information may be retained for the duration of the relationship and for an appropriate period afterwards where required for legal, regulatory, accounting, tax, audit, dispute-resolution or record-keeping purposes.
Marketing Information
Marketing information will generally be retained while there is a valid lawful basis for the relevant marketing activity or until you unsubscribe, subject to any legal or record-keeping requirements.
Recruitment Information
Recruitment information will generally be retained for as long as reasonably necessary for the recruitment process and any applicable legal or employment-related requirements.
Website and Technical Information
Website, analytics and technical information may be retained for periods appropriate to the relevant purpose, including security, performance monitoring, troubleshooting and legal requirements.
When information is no longer required, we will take reasonable steps to securely delete, anonymise or otherwise dispose of it.
Your Data Protection Rights
Depending on the circumstances, you may have the following rights under the GDPR:
Right of Access
You may request access to personal data we hold about you and information about how it is processed.
Right to Rectification
You may request correction of inaccurate or incomplete personal data.
Right to Erasure
You may request deletion of your personal data in certain circumstances.
This right is subject to legal and other applicable exemptions.
Right to Restriction
You may request restriction of processing in certain circumstances.
Right to Object
You may object to certain processing, including processing based on legitimate interests.
You have an absolute right to object to the processing of your personal data for direct marketing purposes.
Right to Data Portability
Where applicable, you may request certain personal data in a structured, commonly used and machine-readable format and request its transmission to another controller.
Right to Withdraw Consent
Where processing is based on consent, you may withdraw consent at any time.
Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
Rights Concerning Automated Decision-Making
Where applicable, you may have rights concerning decisions based solely on automated processing, including profiling, where such decisions produce legal or similarly significant effects.
Finsoul Ireland does not intend to make solely automated decisions producing legal or similarly significant effects unless permitted or required by applicable law and appropriate safeguards are in place.
How to Exercise Your Rights
To exercise your data protection rights or raise a question about how your personal data is processed, contact us:
Email: info@finsoulireland.com
Registered Office: Alexandra House, Ballsbridge Park 3, Dublin, D04 C7H2, Ireland
We may need to verify your identity before responding to certain requests to ensure that personal data is not disclosed to an unauthorised person.
We will respond to valid requests within the period required by applicable data protection law.
Data Protection Officer
Finsoul Ireland has not identified a Data Protection Officer in this Privacy Policy unless a DPO is required under the GDPR or has been formally appointed.
Where a DPO is legally required, Finsoul Ireland will publish the relevant DPO contact details and provide them to the Data Protection Commission as required.
For general privacy and data protection enquiries, please contact info@finsoulireland.com.
Complaints to the Data Protection Commission
If you have concerns about how Finsoul Ireland processes your personal data, we encourage you to contact us first so that we can investigate and address your concern.
You also have the right to lodge a complaint with the Data Protection Commission (DPC), Ireland’s supervisory authority for data protection.
Data Protection Commission
6 Pembroke Row
Dublin 2
D02 X963
Ireland
Website: https://www.dataprotection.ie/
Third-Party Websites
Our website may contain links to third-party websites, platforms or services.
Finsoul Ireland does not control the privacy practices, security or content of third-party websites.
When you follow a third-party link, that third party’s privacy policy, cookie policy and terms may apply.
We recommend reviewing the privacy information of any third-party website before providing personal data.
Children's Privacy
Our website and professional services are not specifically directed at children.
We do not knowingly collect personal data from children where such collection is not appropriate or permitted by law.
If we become aware that personal data has been collected from a child in circumstances where it should not have been collected, we will take appropriate steps to address the situation and, where appropriate, delete the information.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect:
- Changes to our services
- Changes to our website or technology
- Changes to our processing activities
- Changes to third-party service providers
- Changes in legal or regulatory requirements
- Changes to our data protection practices
When material changes are made, we may update the effective date and provide additional notice where appropriate.
We recommend reviewing this page periodically to remain informed about how Finsoul Ireland processes personal data.
Contact Us
If you have questions about this Privacy Policy, wish to exercise your data protection rights, or have concerns about how your personal data is processed, please contact:
- Alexandra House, Ballsbridge Park 3, Dublin, D04 C7H2, Ireland
- info@finsoulireland.com
- Finsoul Ireland
We will consider and respond to privacy-related enquiries in accordance with applicable data protection law.