1. Who we are (data controller)
For the purposes of data protection law, the data controller is:
- Turkish Barbers
- 82 Grafton Street, Dublin
- Email: privacy@turkishbarbers.com
- Phone: +353 208 7242
We are responsible for deciding how and why your personal data is processed when you use our website, book appointments, create a client account, or contact the barber shop.
2. Irish and EU data protection framework
In Ireland, GDPR applies alongside the Data Protection Act 2018. Together they set out how organisations must handle personal data fairly, lawfully, and transparently.
The Irish supervisory authority is the Data Protection Commission (DPC). You have the right to lodge a complaint with the DPC if you believe your data protection rights have been infringed.
- Website: www.dataprotection.ie
- Address: 21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland
3. Personal data we process
Depending on how you interact with us, we may process:
- Identity & contact data — name, email address, phone number
- Account data — login credentials (stored as a secure password hash), loyalty points, no-show records
- Booking data — service selected, staff member, date and time, add-ons, booking status
- Special-category notes — only where you voluntarily provide health-related information (for example allergies or skin sensitivities) in booking notes; we treat this carefully and limit access
- Communication data — messages sent through our contact form, email correspondence, and appointment reminders
- Technical data — IP address and session identifiers for security, fraud prevention, and admin audit logging
We do not intentionally collect data from children under 16 without appropriate parental consent. Our online account and booking services are intended for adults and older teenagers booking their own appointments.
4. Why we use your data (lawful bases)
Under GDPR Article 6, we rely on the following lawful bases:
- Contract — to take and manage bookings, provide barber services, and operate your client account
- Legitimate interests — to run the barber shop securely, prevent abuse, improve our services, and send service-related communications (balanced against your rights)
- Consent — where required, for example optional marketing or non-essential cookies if enabled
- Legal obligation — where we must retain certain records for tax, accounting, or regulatory purposes
Where you provide health-related booking notes, we process that information only to deliver your appointment safely and with your knowledge.
5. How long we keep your data
We keep personal data only for as long as necessary:
- Active accounts & bookings — for the period you remain a client and as needed to deliver services
- Financial and booking records — typically up to 7 years where required for Irish tax and accounting obligations
- Security logs — for a limited period appropriate to security monitoring
- GDPR requests — request records are retained to demonstrate compliance
When data is no longer required, we delete or anonymise it where possible.
6. Your rights under GDPR
As a data subject in Ireland, you have the following rights (subject to certain exceptions in law):
- Right of access (Article 15) — request a copy of the personal data we hold about you
- Right to rectification (Article 16) — ask us to correct inaccurate or incomplete data
- Right to erasure (Article 17) — ask us to delete your data in certain circumstances (“right to be forgotten”)
- Right to restriction (Article 18) — ask us to limit how we use your data in specific situations
- Right to data portability (Article 20) — receive certain data in a structured, machine-readable format where processing is based on contract or consent
- Right to object (Article 21) — object to processing based on legitimate interests or direct marketing
- Rights related to automated decision-making (Article 22) — we do not use solely automated decisions that produce legal or similarly significant effects
We will respond to valid requests within one month of receipt, as required by GDPR Article 12. This may be extended by a further two months for complex requests; we will inform you if an extension is needed.
7. How to make a GDPR request
You can exercise your rights in any of the following ways:
- Client dashboard — if you have an account, sign in and submit a data export or account deletion request from your privacy controls.
- Email — write to privacy@turkishbarbers.com with the subject line “GDPR Request” and tell us which right you wish to exercise.
- Post — send a written request to Turkish Barbers, 44 Talbot Street, Dublin, Ireland, Dublin 1.
We may need to verify your identity before processing a request to protect your data from unauthorised access. There is no fee for most requests unless a request is manifestly unfounded or excessive.
Submit a request (client login) Read privacy policy
8. Data sharing and processors
We do not sell your personal data. We may share data only where necessary:
- With service providers who help us operate the website, email delivery, or hosting (under data processing agreements where required)
- With professional advisers (for example accountants) where legally required
- With public authorities when required by Irish or EU law
Where data is transferred outside the European Economic Area (EEA), we ensure appropriate safeguards are in place as required by GDPR Chapter V.
9. Security
We implement appropriate technical and organisational measures to protect personal data, including encrypted storage of sensitive booking notes where applicable, password hashing, CSRF protection, access controls on admin areas, and audit logging of admin sign-ins.
10. Cookies and similar technologies
Essential cookies are used for secure sessions and booking functionality. For more detail, see our privacy policy. Non-essential analytics cookies, if used in future, will only be activated with your consent.
11. Complaints to the Data Protection Commission
If you are unhappy with how we handle your personal data or a GDPR request, please contact us first so we can try to resolve the matter. You also have the right to complain to the Irish Data Protection Commission:
- How to contact the DPC
- Online complaints: forms.dataprotection.ie
12. Changes to this notice
We may update this GDPR information page when our practices or legal obligations change. The “Last updated” date at the top of this page will be revised accordingly.