Compliance & policy

Privacy Policy

Last updated: 1 June 2026

1. Who we are

Munster Heart Foundation Charity ("we", "us") is a registered charity in Ireland, Registered Charity Number 20081706, with its registered office at 18 Abbey St, Clonroad Beg, Ennis, Co. Clare, V95 AX83, Ireland. We are the data controller for the personal data described in this notice. Our data protection contact can be reached at aundrea-randallb7zt@gmx.com or +353 65 682 2871.

We process personal data in accordance with Regulation (EU) 2016/679 (the General Data Protection Regulation) and the Data Protection Act 2018.

2. The information we collect

  • Supporters and donors: name, postal address, email address, phone number, donation history, Gift Aid style tax-relief declarations (CHY3/CHY4 forms), and bank or card payment references supplied by our payment processor. We never see or store full card numbers.
  • Workshop participants: name, email or phone number, the venue and date attended, and any accessibility requirement you choose to tell us about.
  • Volunteers: contact details, references, Garda vetting outcome (not the vetting content itself), training records, and next-of-kin details for emergencies.
  • Support group members: your name and contact details, and only the health information you voluntarily share for the purpose of receiving appropriate support.
  • Website visitors: IP address, browser type, pages visited and referring page, collected in aggregate server logs for security and performance.

3. Special category (health) data

Some of our work involves health information — for example, a blood pressure reading taken at a seminar, or what you tell a facilitator in a support group. We treat this as special category data under Article 9 GDPR and process it only with your explicit consent, only for the purpose you gave it, and only for as long as needed. Blood pressure readings taken at public events are given to you and are not retained by us unless you ask us to follow up with you.

4. Why we process your data, and our lawful basis

  • To process a donation and claim tax relief — performance of a contract and compliance with a legal obligation (Revenue requirements, Charities Act 2009).
  • To run workshops, seminars and support groups — legitimate interests in delivering our charitable purpose, and consent for health data.
  • To manage volunteers and safeguard participants — legal obligation (National Vetting Bureau Acts, Children First Act 2015) and legitimate interests.
  • To send newsletters and appeals — consent, which you may withdraw at any time using the unsubscribe link in every email.
  • To keep accounts and meet audit obligations — legal obligation.

5. Marketing and your choices

We only email you appeals or newsletters if you have opted in. We do not make unsolicited telephone appeals, we do not sell, rent or swap our supporter list with any other organisation, and we do not carry out wealth screening or data profiling of donors. You can change your contact preferences or ask us to stop entirely by emailing us — we will action it within five working days.

6. Who we share data with

We share the minimum necessary with service providers acting as our processors under written contract: our payment processor, our email delivery provider, our cloud hosting and backup provider, our accountants and our auditors. Where a provider is outside the European Economic Area, transfers are covered by the European Commission's Standard Contractual Clauses. We disclose data to An Garda Síochána, Tusla, the HSE, Revenue or the Charities Regulator only where we are legally obliged or where there is a safeguarding duty.

7. How long we keep it

  • Donation and financial records: 7 years (Revenue and company law).
  • Tax-relief declarations: 6 years after the year of the last donation covered.
  • Workshop attendance records: 3 years, then anonymised into statistics only.
  • Volunteer records: 7 years after the volunteer relationship ends.
  • Safeguarding records and concerns: retained in accordance with our Safeguarding Policy and Tusla guidance.
  • Newsletter subscriptions: until you unsubscribe, then a suppression record only.

8. Security

Personal data is held in access-controlled cloud systems with encryption in transit and at rest, multi-factor authentication for staff accounts, role-based access limited to those who need it, and annual review of permissions by the board's finance and audit subcommittee. Paper records at our Ennis office are held in a locked cabinet. We have an internal breach procedure and will notify the Data Protection Commission within 72 hours where a breach presents a risk to your rights.

9. Your rights

You have the right to access your data, to have inaccurate data corrected, to erasure where no legal obligation requires us to keep it, to restrict or object to processing, to data portability, and to withdraw consent at any time. To exercise any right, contact us at aundrea-randallb7zt@gmx.com. We respond within one month and will never charge you for a request.

If you are unhappy with how we have handled your data you may complain to the Data Protection Commission, 21 Fitzwilliam Square South, Dublin 2, D02 RD28, or at dataprotection.ie.

10. Cookies

This website uses only strictly necessary cookies required to remember your language preference and to keep the site secure. We do not use advertising cookies, cross-site trackers or third-party analytics profiling. Because we set no non-essential cookies, no consent banner is required.

11. Children

We deliver education programmes in secondary schools. Where a participant is under 18, personal data is handled through the school as joint arrangement, with parental consent obtained by the school for photography or media use. We do not knowingly collect data directly from children under 16 through this website.

12. Changes to this notice

We review this notice annually and on any material change to our processing. The version date appears at the top of this page. Material changes are notified to newsletter subscribers by email.