alpine-heath
Home About Services Contact This site contains advertising information

GDPR Information

Last Updated: July 21, 2026

1. Our Commitment to GDPR Compliance

alpine-heath is committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR). This page provides specific information about how we comply with GDPR requirements and how you can exercise your rights.

2. Data Controller Information

Data Controller: alpine-heath
Address: 28 Merrion Square, Dublin 2, D02 X576, Ireland
Contact: [email protected]

3. Your GDPR Rights

3.1 Right to Access

You have the right to request confirmation of whether we process your personal data and to obtain a copy of that data. You can also request information about the purposes of processing, categories of data, and recipients of your data.

3.2 Right to Rectification

If your personal data is inaccurate or incomplete, you have the right to request that we correct or complete it without undue delay.

3.3 Right to Erasure (Right to be Forgotten)

Under certain circumstances, you can request deletion of your personal data, including when:

  • The data is no longer necessary for the purposes for which it was collected
  • You withdraw consent and there is no other legal ground for processing
  • You object to processing and there are no overriding legitimate grounds
  • The data has been unlawfully processed

3.4 Right to Restriction of Processing

You may request that we restrict processing of your personal data in certain situations, such as when you contest the accuracy of the data or object to processing.

3.5 Right to Data Portability

You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller.

3.6 Right to Object

You have the right to object to processing of your personal data based on legitimate interests or for direct marketing purposes.

3.7 Right to Withdraw Consent

Where processing is based on your consent, you have the right to withdraw that consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.

3.8 Right to Lodge a Complaint

You have the right to lodge a complaint with a supervisory authority, particularly in the EU member state of your residence, place of work, or place of alleged infringement.

In Ireland, the supervisory authority is the Data Protection Commission: www.dataprotection.ie

4. How to Exercise Your Rights

To exercise any of your GDPR rights, please contact us at [email protected] with the subject line "GDPR Request" and specify which right you wish to exercise.

We will respond to your request within one month of receipt. In complex cases, this period may be extended by two additional months, and we will inform you of such extension.

5. Legal Basis for Processing

We process personal data based on the following legal grounds under GDPR:

  • Consent (Article 6(1)(a)): When you provide explicit consent for specific processing activities
  • Contract performance (Article 6(1)(b)): When processing is necessary to fulfill our contractual obligations with you
  • Legal obligation (Article 6(1)(c)): When we must process data to comply with legal requirements
  • Legitimate interests (Article 6(1)(f)): When processing is necessary for our legitimate business interests, balanced against your rights and freedoms

6. Data Transfers Outside the EEA

If we transfer your personal data outside the European Economic Area, we ensure appropriate safeguards are in place, such as:

  • Standard Contractual Clauses approved by the European Commission
  • Adequacy decisions recognizing that the destination country provides adequate protection
  • Other legally approved transfer mechanisms

7. Data Retention

We retain personal data only as long as necessary for the purposes stated in our Privacy Policy or as required by law. Specific retention periods include:

  • Enrollment and service data: Duration of relationship plus 7 years for business records
  • Marketing consent data: Until consent is withdrawn
  • Website usage data: 24 months unless deleted earlier

8. Automated Decision-Making

We do not use automated decision-making or profiling that produces legal effects or similarly significantly affects you.

9. Data Security Measures

We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:

  • Encryption of personal data in transit and at rest
  • Regular security assessments and updates
  • Access controls and authentication requirements
  • Staff training on data protection obligations

10. Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you without undue delay and, where required, report the breach to the relevant supervisory authority within 72 hours of becoming aware of it.

11. Updates to This Information

We may update this GDPR information to reflect changes in our practices or legal requirements. Significant changes will be communicated through our website.

12. Contact Us

For questions about GDPR compliance or to exercise your rights, contact us at [email protected]

alpine-heath

Professional development for the digital executive era.

Legal

  • Privacy Policy
  • GDPR Information
  • Cookie Policy
  • Terms of Use

Contact

Email: [email protected]

Dublin, Ireland

© 2026 alpine-heath. All rights reserved.