WHO WE ARE
[A Ghrá Care Service Ltd] (“we”, “us”) is the operator of the website www.aghra.ie We collect, use and are responsible for certain information about you. When we do so, we are regulated under the General Data Protection Regulation which applies across the European Union and we are responsible as ‘controller’ of that personal information for the purposes of those laws. The person responsible for how we handle personal information is Colm Muldowney
THE PERSONAL INFORMATION WE COLLECT AND USE
Personal information provided by you
In the course of operating our business, we collect personal information when you provide it to us, such as your name, postal address, email address, phone numbers, date of birth, medical condition, illnesses, medications, disabilities and personal requirements in terms of preferences and individual care needs necessary to construct an individualised care plan.
We also collect personal information from you if you apply for a job with us or work for us for any period. In this context, personal information we gather may include: contact details, financial and payment details, details of education, qualifications and skills, details required to secure garda vetting, nationality, PPN number, job title, and CV.
Personal information provided by third parties
If you apply for a job with us, we may receive information from the people who provide references.
Personal information about other individuals
If you give us information on behalf of someone else as an alternate contact, referee or next of kin, you confirm that the other person has agreed that you can:
- give consent on his/her behalf to the processing of his/her personal data;
- receive on his/her behalf any data protection notices; and
- if relevant, give consent to the transfer of his/her personal data abroad.
Sensitive personal information
If we request such information, we will explain why we are requesting it and how we intend to use it.
Sensitive personal information includes information relating to, your physical or mental health or condition, and whether you have committed a criminal offense. We will only collect your sensitive personal information with your explicit consent.
We do not knowingly collect personal data relating to children under the age of 16. If you are a parent or guardian of a child under the age of 16 and think that we may have information relating to that child, please contact us. We will ask you to prove your relationship to the child but if you do so you may (subject to applicable law) request access to and deletion of that child’s personal data.
HOW AND WHEN DO WE COLLECT INFORMATION FROM YOU?
We may monitor and record communications with you (such as telephone conversations and emails). We may do this for several reasons, such as to check the quality of our service, for training purposes, to prevent fraud or to make sure we are complying with legal requirements.
If you visit our offices in Tuam, some personal data may be collected from monitoring devices and systems such as closed circuit TV (CCTV) and door entry systems at the site.
You can set your browser not to accept cookies and the websites below tell you how to remove cookies from your browser. However, some of our website features may not function as a result.
REASONS WE CAN COLLECT AND USE YOUR PERSONAL INFORMATION
We rely on a different lawful basis for collecting and using personal data in different situations.
Where you make enquiries about us before you become a client, we need to collect personal information about you so that we can take steps to enter a contract with you. Once you have become a client, we need to collect and use personal information to provide services to you and to claim our right to be paid in return for our services under our standard terms of business with you. This includes collecting and using your personal information to:
- enable us to follow up on enquiries made by you in relation to A Ghrá becoming your service provider.
- prepare a Care plan with you as and when required;
- manage any accounts you hold with us;
- contact you for reasons related to the service you have signed up for or to provide information you have requested;
- deal with payment for our services;
- notify you of any changes to our website or to our services that may affect you; and
- resolve disputes or collect overdue payments.
If you apply for a job with us, we will collect and use personal information to process your application and check references. If you take a job with us, we will collect and use your personal information to enter into an employment contract with you and to administer the employment relationship, including making payments to you, accounting for tax, ensuring safe working practices, monitoring and managing staff access to systems and facilities, monitoring absences and performance and conducting assessments.
We collect and use personal information from our clients and staff to comply with our legal obligations. For example, we will take copies of documents that identify you so that we can comply with anti-money laundering and counter-terrorist financing requirements.
Legitimate business interests
Our priority is to make sure we give a high quality and secure service to clients and to follow up effectively on enquiries even though we accept that not all enquiries will lead to a business relationship or contract. We collect personal information to:
- follow up on enquiries in accordance with industry guidelines and to assess our ability to meet your requirements;
- conduct research and analyse website visitor behaviour patterns;
- customise our website and its content to your particular preferences;
- improve our services;
- detect and prevent fraud;
- prevent offensive, inappropriate or objectionable content being sent to or posted on our websites or to stop any other form of disruptive behaviour.
We operate CCTV within our Head Office facility in Tuam. We collect and process CCTV images
- so we can fulfill our contractual obligation to deliver a secure office environment;
- to establish whether you are doing something that breaches your contract with us; and
- to assist in the establishment or defence of any crime or other investigation.
We will also communicate with you information about other services we can offer you and update you about our activities and promotions which may be of interest to you from time to time. See ‘What rights do you have?’ below for further information. If you ask us to stop contacting you in this way, you can also ask us to start again at any time.
If we propose to use your information for any other uses we will ensure that we notify you first. If we need your consent to use your information for these other purposes, we will give you the opportunity to opt in or to refuse. If you opt in, you will be able to opt out at any time.
When will we contact any other person about you?
If you provide us with details of any other person we can contact to discuss your needs, we may contact that person and discuss and share the details of your requirements with that person and deal with that person in relation to your needs as if that person was you. We may particularly want to do this if we are unable to get in touch with you for any reason. If you change your mind, you can email or write to us and have this person taken off your file as an alternate contact person (see ‘How can you contact us?’ below).
If you provide us the details of a person who we can contact for a job reference, we may contact that person in connection with your job application.
Who your information might be shared with
We may disclose your personal data to:
- service providers under contract with us to support our business operations, such as our software scheduling system providers, payroll, and other technology services
- HSE case managers (were appropriate) assigned as Case managers and medical personnel responsible for managing to your case, your health and wellbeing.
- our insurers and insurance brokers.
- HSE, law enforcement or government agencies in connection with any investigation to help prevent or detect unlawful activity.
- any person or agency if we need to share that information to comply with the law or to enforce any agreement, we may have with you or to protect the health and safety of any person.
- any person who you have named as a person we can contact to discuss your needs.
- any person who is your agent or representative, such as the holder of a power of attorney, a legal guardian or person administering a will.
- any person who we are negotiating with as a potential buyer of our business or property or if we are proposing to merge our business with another business;
If we pass data on to insurers, they may enter your data onto a register of claims which is shared with other insurers to prevent fraudulent claims. If we use an outside party to process your information, we will require them to comply with our instructions in connection with the services they provide for us and not for their own business purposes.
KEEPING YOUR PERSONAL INFORMATION SECURE
We have appropriate security measure in place to prevent personal information from being accidentally lost or used or accessed in an unauthorised way. We limit access to your personal information to those who have a genuine business need to know it. Those people processing your information will do so only in an authorised manner and are subject to a duty of confidentiality.
We will use technical measures to safeguard your personal data, for example:
- we store your personal data on secure servers; and
- payment details are encrypted on the secure server
- In the event that we use a third-party processor for your data we will seek, through annual checks, assurances from them that they too are fully GDPR compliant
We have procedures in place to deal with any suspected data security breach. We will notify you and any applicable supervisory body of a suspected data breach where we are legally required to do so.
While we will use all reasonable efforts to keep your personal data safe, you acknowledge that the use of the internet is not entirely secure and for this reason we cannot guarantee the security or integrity of any personal data that is transferred from you or to you via the internet. If you have any concerns about your information, please contact us (see ‘How to contact us’ below).
Our website contains links to websites and applications owned and operated by other people and businesses. These third-party sites have their own privacy policies and use their own cookies and we recommend that you review them before you provide them with personal information. They will tell you how your personal information is collected and used whilst you are visiting these other websites. We do not accept any responsibility or liability for the content of these sites or the use of your information collected by any of these other sites and you use these other sites at your own risk.
HOW LONG DO WE KEEP YOUR PERSONAL INFORMATION?
We will usually hold your personal information as a client or employee on our system for the period we are required to retain this information by applicable Irish law, currently 7 years from the end of our contract or 6 months after any unsuccessful job application, unless you have told us you want us to delete the information earlier (see section “What rights do you have” below).
WHAT RIGHTS DO YOU HAVE?
Under the General Data Protection Regulation, you have a number of important rights. These include the following rights:
- request a copy of your information which we hold (subject access request).
- require us to correct any mistakes in your information which we hold.
- require the erasure of personal information concerning you in certain situations
- require us to stop contacting you for direct marketing purposes.
- object in certain other situations to our continued processing of your personal information.
- restrict our processing of your personal information in certain circumstances.
- object to decisions being taken by automated means which produce legal effects concerning you or which affect you significantly; and
- receive the personal information concerning you which you have provided to us, in a structured, commonly used and machine-readable format and have the right to transmit those data to a third party in certain situations.
Further information on each of these rights is available from the Information Commissioner’s Office.
If you would like to exercise any of these rights, please:
- email, call or write to us (see ‘How to contact us’ below)
- let us have proof of your identity and address (a copy of your driving licence or passport and a recent utility or credit card bill), and
- let us know the information to which your request relates, including any account or reference numbers, if you have them
HOW TO CONTACT US
The General data Protection Regulation also gives you the right to lodge a complaint with a supervisory authority. The supervisory authority In Ireland is the Data Protection Commissioner who may be contacted at https://www.dataprotection.ie/docs/complaints/1592.htm or telephone +353 57 8684800
This Privacy Notice was published on 25th April 2018 and last updated on 25th April 2018. We may change this Privacy Notice from time to time. You should check this policy occasionally to ensure you are aware of the most recent version.
DO YOU NEED EXTRA HELP?
If you would like this policy in another format (for example: large print,) please contact us (see ‘How can you contact us?’ above).