Last Updated: January 2024
fogokiradio is committed to complying with the General Data Protection Regulation (GDPR) and protecting the personal data of individuals in the European Union. This page outlines our GDPR compliance measures and your rights under this regulation.
1. Data Controller
fogokiradio acts as the data controller for personal information collected through our website and services. As the data controller, we determine the purposes and means of processing personal data.
Contact Details:
fogokiradio
Unit 14, Sandyford Business Centre
Sandyford Industrial Estate
Dublin 18, D18 Y2C7
Ireland
Email: [email protected]
2. Lawful Basis for Processing
Under GDPR, we must have a valid legal basis for processing your personal data. We rely on the following lawful bases:
- Consent (Article 6(1)(a)): Where you have given clear consent for us to process your data for specific purposes, such as receiving marketing communications.
- Contract (Article 6(1)(b)): Where processing is necessary to perform a contract with you or to take steps at your request before entering into a contract.
- Legitimate Interests (Article 6(1)(f)): Where processing is necessary for our legitimate business interests, provided these do not override your fundamental rights and freedoms.
- Legal Obligation (Article 6(1)(c)): Where we need to process your data to comply with legal or regulatory obligations.
3. Your Rights Under GDPR
GDPR provides you with specific rights regarding your personal data:
3.1 Right of Access (Article 15)
You have the right to request access to the personal data we hold about you and receive a copy of this data along with supplementary information about how it is processed.
3.2 Right to Rectification (Article 16)
You have the right to request correction of inaccurate personal data and to have incomplete data completed.
3.3 Right to Erasure (Article 17)
Also known as the "right to be forgotten", you may request deletion of your personal data in certain circumstances, such as when the data is no longer necessary for its original purpose.
3.4 Right to Restriction of Processing (Article 18)
You may request that we limit how we use your data in certain circumstances, such as when you contest the accuracy of the data.
3.5 Right to Data Portability (Article 20)
You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit this data to another controller.
3.6 Right to Object (Article 21)
You have the right to object to processing based on legitimate interests or for direct marketing purposes.
3.7 Rights Related to Automated Decision Making (Article 22)
You have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects. We do not currently use automated decision-making processes.
4. Exercising Your Rights
To exercise any of these rights, please contact us at [email protected] with your request. We will respond within one month of receiving your request. In complex cases or where we receive numerous requests, this period may be extended by two additional months, in which case we will inform you.
We may need to verify your identity before processing your request. We will not charge a fee for handling your request unless it is manifestly unfounded or excessive.
5. Data Protection Measures
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
- Encryption of data in transit using SSL/TLS protocols
- Access controls limiting data access to authorised personnel
- Regular security assessments and updates
- Staff training on data protection practices
- Secure data storage with appropriate backup procedures
6. Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Data Protection Commission within 72 hours of becoming aware of the breach. Where the breach is likely to result in a high risk, we will also notify affected individuals without undue delay.
7. International Data Transfers
When we transfer personal data outside the European Economic Area, we ensure appropriate safeguards are in place, such as:
- Transfers to countries with an adequacy decision from the European Commission
- Standard Contractual Clauses approved by the European Commission
- Binding Corporate Rules where applicable
8. Data Protection Impact Assessments
Where processing operations are likely to result in high risk to individuals' rights and freedoms, we conduct Data Protection Impact Assessments to identify and mitigate risks.
9. Supervisory Authority
If you believe that your data protection rights have been violated, you have the right to lodge a complaint with the supervisory authority:
Data Protection Commission
21 Fitzwilliam Square South
Dublin 2, D02 RD28
Ireland
Website: www.dataprotection.ie
10. Updates to This Information
We may update this GDPR compliance information periodically to reflect changes in our practices or legal requirements. The date at the top indicates when this page was last revised.