Privacy Policy
1. Introduction and company information
This Privacy Policy explains how Hawthorn Business Services Limited (“we”, “us”, “our”) collects, uses, stores, shares, and protects personal data when you use our services, contact us, visit our premises, or otherwise interact with us.
Hawthorn Business Services Limited is the controller of the personal data described in this Privacy Policy.
Company details:
Hawthorn Business Services Limited
Hawthorn Office Solutions, 14 Fitzwilliam Square, Dublin 2, D02 X285, Ireland
Email: [email protected]
Phone: +353 1 524 8791
This Privacy Policy applies to our local business operations and the personal data we process in the ordinary course of providing office and business-related services, managing customer and supplier relationships, and operating our business.
2. Data collection and processing
We may collect and process personal data directly from you, automatically through your use of our website or digital communications, and from third parties where lawful and appropriate.
The personal data we may process includes, depending on your interaction with us:
- Identification details, such as your name, company name, job title, and preferred language;
- Contact details, such as email address, telephone number, postal address, and billing address;
- Business communication details, including correspondence, enquiries, feedback, and meeting notes;
- Service and account information, such as service requests, contract details, invoices, payment records, and preferences;
- Technical data, such as IP address, device information, browser type, logs, and usage data if you interact with our website or online tools;
- Financial and transaction data, where necessary for invoicing, payment processing, or compliance with accounting obligations;
- Any other information you voluntarily provide to us.
We do not intentionally collect special category data unless it is necessary and lawful for a specific purpose or you provide it to us voluntarily. Where relevant, we will apply additional safeguards required by law.
3. Purpose of data processing
We process personal data for the following purposes:
- To respond to enquiries and communicate with you;
- To provide and manage our services;
- To manage customer, supplier, and business relationships;
- To issue invoices, process payments, and maintain financial records;
- To administer contracts and fulfil our obligations;
- To maintain internal records and business administration;
- To improve our services, operations, and customer experience;
- To ensure the security of our systems, premises, and business operations;
- To comply with legal, regulatory, tax, accounting, and record-keeping obligations;
- To establish, exercise, or defend legal claims;
- To send administrative communications related to our services or contractual relationship.
4. Legal basis for processing
We only process personal data where we have a lawful basis to do so. Depending on the context, our legal bases may include:
- Performance of a contract: where processing is necessary to enter into or perform a contract with you or your organisation;
- Legal obligation: where we must process data to comply with legal, tax, accounting, or regulatory requirements;
- Legitimate interests: where processing is necessary for our legitimate business interests, provided that these are not overridden by your rights and freedoms. This may include business administration, service improvement, fraud prevention, security, and customer communications;
- Consent: where you have given clear consent for a specific purpose. You may withdraw consent at any time;
- Vital interests: where necessary to protect someone’s life or physical safety in exceptional circumstances.
Where we rely on legitimate interests, we assess the impact on your rights and apply appropriate safeguards.
5. Data sharing and third parties
We may share personal data with trusted third parties where necessary for the purposes described in this Privacy Policy and where permitted by law. Such third parties may include:
- IT, cloud hosting, software, and cybersecurity service providers;
- Professional advisers, including accountants, auditors, consultants, lawyers, and insurers;
- Payment processors, banks, and financial service providers;
- Delivery, postal, and communications service providers;
- Business partners and suppliers involved in providing our services;
- Public authorities, regulators, courts, or law enforcement where required or permitted by law.
We require third parties that process personal data on our behalf to protect the data and use it only in accordance with our instructions and applicable law.
We do not sell personal data.
6. Data transfer to third countries
Where personal data is transferred outside Ireland or the European Economic Area (EEA), we take steps to ensure an appropriate level of protection in accordance with applicable privacy laws.
Such safeguards may include:
- Transfers to countries deemed to provide an adequate level of protection;
- Standard contractual clauses or equivalent contractual protections;
- Additional technical and organisational measures where appropriate;
- Other lawful transfer mechanisms permitted under applicable law.
Where required, you may request further information about the safeguards applied to specific transfers.
7. Storage duration
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including for legal, accounting, tax, dispute resolution, and record-keeping purposes.
Retention periods are determined based on:
- The nature of the data and the purpose of processing;
- Contractual and business requirements;
- Legal and regulatory retention obligations;
- Applicable limitation periods for legal claims;
- The need to maintain security and business continuity.
When personal data is no longer required, we will delete, anonymise, or securely archive it in accordance with our retention practices and legal obligations.
8. User rights
Subject to applicable law, you may have the following rights in relation to your personal data:
- Right of access: to obtain confirmation of whether we process your personal data and to receive a copy of that data;
- Right to rectification: to request correction of inaccurate or incomplete personal data;
- Right to erasure: to request deletion of your personal data in certain circumstances;
- Right to restriction: to request that we restrict processing in certain circumstances;
- Right to data portability: to receive certain data in a structured, commonly used, machine-readable format and to request transmission to another controller where technically feasible;
- Right to object: to object to processing based on legitimate interests and to object to direct marketing where applicable.
To exercise any of these rights, please contact us using the details provided below. We may need to verify your identity before responding. We will respond within the time required by applicable law.
9. Withdrawal of consent
Where we process your personal data based on consent, you have the right to withdraw that consent at any time. Withdrawal of consent will not affect the lawfulness of processing carried out before the withdrawal.
If you withdraw consent, we may still be able to process your personal data where another lawful basis applies.
10. Right to complain
If you are dissatisfied with how we handle your personal data, please contact us first so we can try to resolve the issue.
You also have the right to lodge a complaint with the relevant data protection supervisory authority. In Ireland, this is generally the Data Protection Commission (DPC).
We encourage you to contact us before making a formal complaint so that we can address your concerns promptly and directly.
11. Data security
We take appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access.
These measures may include:
- Access controls and role-based permissions;
- Encryption and secure transmission methods where appropriate;
- Regular backups and recovery procedures;
- Staff confidentiality obligations and awareness training;
- Physical security measures for our premises and records;
- Monitoring, maintenance, and security updates for systems and devices.
While we take reasonable steps to protect personal data, no system can be guaranteed to be completely secure.
12. Contact information
If you have any questions about this Privacy Policy, our data practices, or wish to exercise your rights, please contact us at:
Hawthorn Business Services Limited
Hawthorn Office Solutions, 14 Fitzwilliam Square, Dublin 2, D02 X285, Ireland
Email: [email protected]
Phone: +353 1 524 8791
13. Changes to privacy policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or business operations. Any updated version will be effective when published, unless otherwise stated.
We encourage you to review this Privacy Policy periodically to stay informed about how Hawthorn Business Services Limited processes personal data.