Data protection

GDPR information for Ireland

1. Who we are (data controller)

For the purposes of data protection law, the data controller is:

We are responsible for deciding how and why your personal data is processed when you use our website, book appointments, create a client account, or contact the barber shop.

2. Irish and EU data protection framework

In Ireland, GDPR applies alongside the Data Protection Act 2018. Together they set out how organisations must handle personal data fairly, lawfully, and transparently.

The Irish supervisory authority is the Data Protection Commission (DPC). You have the right to lodge a complaint with the DPC if you believe your data protection rights have been infringed.

3. Personal data we process

Depending on how you interact with us, we may process:

We do not intentionally collect data from children under 16 without appropriate parental consent. Our online account and booking services are intended for adults and older teenagers booking their own appointments.

4. Why we use your data (lawful bases)

Under GDPR Article 6, we rely on the following lawful bases:

Where you provide health-related booking notes, we process that information only to deliver your appointment safely and with your knowledge.

5. How long we keep your data

We keep personal data only for as long as necessary:

When data is no longer required, we delete or anonymise it where possible.

6. Your rights under GDPR

As a data subject in Ireland, you have the following rights (subject to certain exceptions in law):

We will respond to valid requests within one month of receipt, as required by GDPR Article 12. This may be extended by a further two months for complex requests; we will inform you if an extension is needed.

7. How to make a GDPR request

You can exercise your rights in any of the following ways:

  1. Client dashboard — if you have an account, sign in and submit a data export or account deletion request from your privacy controls.
  2. Email — write to privacy@turkishbarbers.com with the subject line “GDPR Request” and tell us which right you wish to exercise.
  3. Post — send a written request to Turkish Barbers, 44 Talbot Street, Dublin, Ireland, Dublin 1.

We may need to verify your identity before processing a request to protect your data from unauthorised access. There is no fee for most requests unless a request is manifestly unfounded or excessive.

8. Data sharing and processors

We do not sell your personal data. We may share data only where necessary:

Where data is transferred outside the European Economic Area (EEA), we ensure appropriate safeguards are in place as required by GDPR Chapter V.

9. Security

We implement appropriate technical and organisational measures to protect personal data, including encrypted storage of sensitive booking notes where applicable, password hashing, CSRF protection, access controls on admin areas, and audit logging of admin sign-ins.

10. Cookies and similar technologies

Essential cookies are used for secure sessions and booking functionality. For more detail, see our privacy policy. Non-essential analytics cookies, if used in future, will only be activated with your consent.

11. Complaints to the Data Protection Commission

If you are unhappy with how we handle your personal data or a GDPR request, please contact us first so we can try to resolve the matter. You also have the right to complain to the Irish Data Protection Commission:

12. Changes to this notice

We may update this GDPR information page when our practices or legal obligations change. The “Last updated” date at the top of this page will be revised accordingly.