Data Privacy Statement
1. Introduction
EMCC Coaching Ireland Limited ("we", "us", "our") is committed to protecting the privacy and personal data of all individuals with whom we interact, including our members, event attendees, training participants, conference delegates, newsletter subscribers, and visitors to our website and social media channels.
This Privacy Statement explains how we collect, use, store, share, and protect your personal data. It also sets out your rights in respect of your personal data and how to exercise them.
This statement applies to all personal data we process and is published on our website. It should be read alongside any additional privacy notices we may provide at the point of data collection (for example, at event registration or when applying for membership).
|
This Privacy Statement applies to all data subjects whose personal data we process, including members, event and conference attendees, training participants, speakers, newsletter subscribers, social media followers, vendors and website visitors. |
2. Who We Are
EMCC Coaching Ireland is a not for profit, voluntary organisation incorporated in Ireland. We are the Data Controller for the personal data described in this statement, meaning we determine the purposes and means of processing your personal data.
|
Detail |
Information |
|
Organisation Name |
EMCC Coaching Ireland Limited |
|
Registered Address |
51 Bracken Road, Sandyford Business Park, Dublin 18, D18 CV48, Ireland |
|
Contact Email |
|
|
Website |
If you have any questions or concerns about how we handle your personal data, please contact us using the details above.
3. Legal Framework
We process personal data in accordance with the following legislation:
- The General Data Protection Regulation (EU) 2016/679 ("GDPR")
- The Data Protection Act 2018 (Ireland) ("DPA 2018")
- The European Communities (Electronic Communications Networks and Services) (Privacy and Electronic Communications) Regulations 2011 (as amended) – the Irish ePrivacy Regulations
- Any other applicable Irish or EU data protection legislation
4. What Personal Data We Collect
We collect and process the following categories of personal data, depending on your relationship with us:
4.1 Membership Data
- Full name, email address, postal address, telephone number
- Organisation / employer details
- Professional skills
- Professional development & achievements
- Membership category and membership number
- Payment information (processed via our secure online payment provider)
- Communications preferences
4.2 Event and Conference Data
- Name, email address, job title and organisation
- Dietary or accessibility requirements (where provided)
- Attendance records and session preferences
- Payment details for paid events (processed via our secure payment provider)
4.3 Training Data
- Name, email address, job title and organisation
- Training enrolment, completion records and assessment results
- Payment details for paid training courses
4.4 Images and Video Recordings
- Photographs, video recordings and audio recordings taken at in-person and online events and conferences
- We seek consent before capturing images at in-person events and will display consent notices at event venues
- Online events may be recorded; participants are notified in advance
4.5 Marketing and Communications Data
- Email address and communication preferences for newsletter subscribers
- Engagement data (e.g., whether you open or click on our emails)
4.6 Website and Technical Data
- IP address, browser type, operating system, pages visited, time and duration of visits
- Cookie identifiers (see Section 12 on Cookies)
4.7 Social Media Data
- Public profile information, interactions (likes, shares, comments) when you engage with our LinkedIn, Instagram, Facebook or X pages
4.8 Speaker and Service Provider Data
- Contact details, professional biography and bank / payment details for conference speakers and service providers
5. Why We Use Your Data – Purposes and Legal Bases
Under the GDPR, we must have a lawful basis for processing your personal data. The table below sets out our processing purposes and the legal basis we rely on for each:
|
Purpose |
Details |
Legal Basis (GDPR Art. 6) |
|
Membership management |
Processing membership applications, renewals, payments and maintaining the membership register |
Article 6(1)(b) Performance of a contract |
|
Event and conference management |
Registering attendees, managing attendance, processing payments and communicating event information |
Article 6(1)(b) Performance of a contract |
|
Training facilitation and delivery |
Enrolling participants, tracking completion, issuing certificates and processing payments |
Article 6(1)(b) Performance of a contract |
|
Marketing to members |
Sending relevant updates, news and communications to existing members |
Article 6(1)(f) Legitimate interests (keeping members informed of organisational activities) |
|
Marketing to newsletter subscribers |
Sending newsletters and promotional communications to individuals who have opted in |
Article 6(1)(a) Consent |
|
Images and video at in-person events |
Capturing and publishing photographs and video for promotional, educational and archival purposes |
Article 6(1)(a) Consent |
|
Images and video from online events |
Recording and publishing online events and webinars |
Article 6(1)(f) Legitimate interests / Consent where applicable |
|
Sharing data with global affiliate |
Fulfilling membership obligations and coordinating activities with our international affiliate body |
Article 6(1)(b) Contract / Article 6(1)(f) Legitimate interests |
|
Sharing with training partners |
Facilitating and delivering training programmes |
Article 6(1)(b) Contract |
|
Sharing with conference and event speakers |
Providing delegate lists and coordinating logistics for conferences and events |
Article 6(1)(f) Legitimate interests |
|
Board governance |
Maintaining board records, minutes and governance documentation |
Article 6(1)(f) Legitimate interests |
|
Online payments |
Processing membership and event payments securely via our payment provider |
Article 6(1)(b) Contract |
|
Website analytics |
Understanding how visitors use our website to improve user experience |
Article 6(1)(a) Consent (via cookie preferences) |
|
Legal compliance |
Meeting our legal and regulatory obligations under applicable law |
Article 6(1)(c) Legal obligation and any statutory duties |
6. Legitimate Interests
Where we rely on legitimate interests as our legal basis, we have assessed that our interests are not overridden by your rights and interests. Our legitimate interests include:
- Communicating with our members about our activities, events and news
- Recording online events to make content available to members who could not attend
- Sharing relevant delegate and speaker information to facilitate conferences and events
- Maintaining appropriate governance and organisational records
- Coordinating with our global affiliate body to fulfil membership obligations
You have the right to object to processing based on legitimate interests at any time. See Section 11 for further information on your rights.
7. Who We Share Your Personal Data With
We do not sell your personal data. We may share your personal data with the following categories of recipients only where necessary and in accordance with this Privacy Statement:
7.1 Global Affiliate Organisation
As a member organisation, EMCC share relevant member data with our global affiliate body EMCC Global for the purposes of maintaining international membership records and coordinating activities. Our affiliate body is required to handle your data in accordance with applicable data protection law.
7.2 Training Partners
Where training is co-delivered or facilitated in partnership with third-party training providers, we share the necessary participant data (name, email, enrolment details) with those partners solely for the purpose of delivering and administering the training.
7.3 Conference & Event Speakers
We may provide selected speakers with relevant delegate information (such as attendee names and organisations) to assist with session preparation and coordination. Speakers are required to use such information only for the purposes for which it was shared.
7.4 Service Providers
We engage third-party service providers to support our operations, including but not limited to:
- IT systems and website hosting providers
- Online payment processing providers
- Email marketing and communication platforms
- Event management platforms
- Training platform providers
- Social media platforms (LinkedIn, Facebook, Instagram, X)
- Marketing agency providers
All service providers are required to process personal data only on our instructions and in accordance with applicable data protection law. We have appropriate data processing agreements in place with our service providers.
7.5 Board of Directors
Members of our Board of Directors may have access to personal data where necessary for the governance and oversight of the organisation. Board members are bound by confidentiality obligations.
7.6 Legal and Regulatory Obligations
We may disclose personal data to competent authorities, regulators or law enforcement agencies where required to do so by law or to establish, exercise or defend legal claims.
8. International Data Transfers
Where we transfer your personal data outside the European Economic Area (EEA) for example, to service providers located in third countries we ensure that appropriate safeguards are in place in accordance with Chapter V of the GDPR. These safeguards may include:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions issued by the European Commission
- Other appropriate safeguards as required by the GDPR
You may request details of the specific safeguards in place for any international transfers by contacting us at the details provided in Section 2.
9. How Long We Keep Your Personal Data
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law. Our retention periods are guided by the following principles:
|
Data Category |
Retention Period |
|
Membership records |
Duration of membership plus 7 years (for financial and legal compliance) |
|
Event and conference records |
7 years from the date of the event (financial records); 2 years for general attendance records |
|
Training records |
7 years from completion (or as required by the relevant accrediting body) |
|
Images and videos |
Until consent is withdrawn, or until no longer required for the stated purpose |
|
Marketing / newsletter data |
Until consent is withdrawn or you unsubscribe |
|
Website and technical data |
As specified in our Cookie Policy |
|
Payment records |
7 years (in accordance with Irish tax and financial regulations) |
|
Board and governance records |
As required by our statutory duties |
When personal data is no longer required, it is securely deleted or anonymised in accordance with our data retention policy.
10. Online Payments
We use a third-party online payment service provider Stripe Privacy Policy to process payments for membership subscriptions, event registrations and training courses. We do not store your full payment card details on our systems. All payment transactions are encrypted and processed securely by our payment provider in accordance with Payment Card Industry Data Security Standards (PCI DSS).
You should review your payment provider's own privacy notice for information about how they handle your payment data.
11. Your Data Protection Rights
Under the GDPR and DPA 2018, you have the following rights in respect of your personal data:
|
Your Right |
What This Means |
|
Right of access |
You have the right to request a copy of the personal data we hold about you (a Subject Access Request). |
|
Right to rectification |
You have the right to request that we correct any inaccurate or incomplete personal data we hold about you. |
|
Right to erasure |
You have the right to request deletion of your personal data in certain circumstances (the "right to be forgotten"). |
|
Right to restriction |
You have the right to request that we restrict the processing of your personal data in certain circumstances. |
|
Right to data portability |
Where processing is based on consent or contract and carried out by automated means, you have the right to receive your personal data in a structured, commonly used, machine-readable format. |
|
Right to object |
You have the right to object to processing based on legitimate interests or for direct marketing purposes. |
|
Right to withdraw consent |
Where processing is based on your consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out prior to withdrawal. |
|
Rights related to automated decision-making |
You have the right not to be subject to a decision based solely on automated processing where it produces a significant effect on you. |
To exercise any of the above rights, please contact us at [privacy@organisationname.ie]. We will respond within one calendar month of receipt of your request. In complex cases, or where a large number of requests are received, we may extend this period by a further two months, in which case we will notify you.
|
We will not charge a fee for exercising your rights unless your request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse to act on the request. |
12. Marketing and Electronic Communications
We send marketing and informational communications in accordance with the ePrivacy Regulations (SI No. 336 of 2011, as amended) and the GDPR.
- Members: We may send you communications about our activities, events and news on the basis of our legitimate interests as a membership organisation. You may opt out at any time by contacting us or clicking the unsubscribe link in any communication.
- News subscribers: We send ther promotional communications only to individuals who have given their explicit consent to receive them. You may withdraw your consent and unsubscribe at any time by clicking the unsubscribe link in any email or by contacting us directly.
We will honour all opt-out and unsubscribe requests promptly and in any event within 10 working days.
13. Images, Video and Event Recordings
13.1 In-Person Events and Conferences
We may take photographs and video recordings at our in-person events and conferences for use in our publications, website, social media channels and promotional materials. We will:
- Display prominent notices at event venues advising that photography and filming may take place
- Seek your consent prior to capturing identifiable images where practicable
- Provide a clear mechanism for you to withhold or withdraw consent
If you do not wish to be photographed or filmed, please make yourself known to a member of our team at the event.
13.2 Online Events and Webinars
Online events and webinars may be recorded for subsequent publication or distribution to members. Participants will be notified at the start of any recorded session. Where recording is a condition of participation, this will be made clear at the point of registration.
14. Cookies and Online Technologies
Our website uses cookies and similar tracking technologies in accordance with the ePrivacy Regulations. Cookies are small text files placed on your device when you visit our website.
We use the following types of cookies:
- Strictly necessary cookies: Essential for the operation of the website; no consent is required for these.
- Analytical/performance cookies: Help us understand how visitors use our website. These are only placed with your consent.
- Functional cookies: Remember your preferences and settings. These are placed with your consent.
- Marketing/targeting cookies: Used to deliver relevant advertising and track campaign effectiveness. These are placed only with your explicit consent.
15. Social Media
We maintain official pages on LinkedIn, Instagram, X and Facebook. When you interact with us on these platforms (for example, by following our pages, commenting on posts or sending us messages), the relevant social media platform also processes your personal data in accordance with its own privacy policy. We encourage you to review the privacy policies of any social media platform you use.
We may use social media platforms' analytics tools to understand the performance of our content. This may involve the use of cookies or similar technologies operated by those platforms. Please refer to their privacy policies for further information:
- LinkedIn: https://www.linkedin.com/legal/privacy-policy
- Facebook (Meta): https://www.facebook.com/privacy/policy/
- Instagram (Meta): https://privacycenter.instagram.com/policy
- X:https://x.com/en/privacy
We do not use your social media data to build advertising profiles or to make automated decisions about you.
16. How We Protect Your Personal Data
We have implemented appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, destruction or alteration. These measures include:
- Encryption of data in transit and at rest where appropriate
- Access controls limiting personal data access to authorised personnel only
- Regular review of our information security practices
- Staff awareness and data protection training
- Documented data breach response procedures
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Data Protection Commission (DPC) within 72 hours of becoming aware of the breach and will communicate the breach to you without undue delay where required to do so.
17. Children's Data
Our services are not directed at children under the age of 18, and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data without appropriate consent, please contact us and we will take steps to delete that information.
18. Links to Third-Party Websites
Our website and communications may contain links to third-party websites, including social media platforms, payment providers and partner organisations. We are not responsible for the privacy practices of those websites, and we encourage you to review their privacy policies before providing them with any personal data.
19. Changes to This Privacy Statement
We may update this Privacy Statement from time to time to reflect changes in our practices, legal requirements or operational needs. The "Last Updated" date at the top of this document indicates when the most recent revision was made.
We will notify members and newsletter subscribers of any material changes to this statement by email and will publish the updated statement on our website. We encourage you to review this statement periodically.
20. Right to Lodge a Complaint
If you are unhappy with how we have handled your personal data, we encourage you to contact us in the first instance so that we can try to resolve the matter.
You also have the right to lodge a complaint with the Data Protection Commission (DPC), the supervisory authority for data protection in Ireland:
|
Authority |
Data Protection Commission (DPC) |
|
Website |
|
|
Address |
21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland |
|
Phone |
+353 (0)1 765 0100 / 1800 437 737 |
|
|
21. Contact Us
If you have any questions about this Privacy Statement, wish to exercise your data protection rights, or have a concern about how we process your personal data, please contact us:
|
Contact |
Details |
|
|
|
|
Post |
EMCC Coaching Ireland Limited 51 Bracken Road, Sandyford Business Park, Dublin 18, D18 CV48, Ireland |
|
Subject line |
Data Privacy Enquiry |
|
This Privacy Statement was prepared to comply with the General Data Protection Regulation (EU) 2016/679, the Data Protection Act 2018 (Ireland), and the ePrivacy Regulations (SI No. 336 of 2011, as amended). It is reviewed annually or whenever there is a material change in our processing activities.
Last Updated: 16th September 2026 Version: 2.0 |