Irish privacy notice
Data Protection Commission (DPC) registration IE-14872 · Irish Data Protection Act 2018 · GDPR
· I ·Who is the controller
The data controller is GuestlinePortal Ltd, a company incorporated in the Republic of Ireland under Companies Registration Office number 728 419, with registered office at 21 Grafton Street, Dublin D02 XH54, Ireland. VAT number IE 3841972K. Tax reference 3841972K. The company is registered with the Irish Data Protection Commission (DPC) under registration number IE-14872. The Data Protection Officer is contactable at dpo@guestlineportal.com or by post to the Data Protection Officer at the registered office. This notice supplements the general privacy policy with the Irish-specific bases and rights that apply to personal data processed in Ireland or affecting Irish data subjects.
· II ·Legal framework — Irish Data Protection Act 2018
Personal data is processed in accordance with (a) the General Data Protection Regulation (Regulation (EU) 2016/679), (b) the Data Protection Act 2018 (No. 7 of 2018) which gives effect to the GDPR in Ireland and provides for the derogations and specifications permitted under Article 23 GDPR, (c) the ePrivacy Regulations (SI 336/2011) as amended by SI 336 of 2011 and SI 526 of 2018, and (d) sector-specific rules including the Consumer Protection Act 2007 and the European Communities (Consumer Information, Cancellation and Other Rights) Regulations 2013 (SI 484/2013).
· III ·Personal data categories and Irish legal bases
- Client Portal user data (Irish hotel operator contact and property details) — Article 6(1)(b) GDPR (contract) and section 42 of the Data Protection Act 2018 (processing necessary for the performance of a contract).
- Prospect enquiry data (contact form) — Article 6(1)(a) GDPR (consent) and section 40 of the Data Protection Act 2018.
- Support ticket transcripts — Article 6(1)(b) and Article 6(1)(f) GDPR (contract + legitimate interest in service quality) and section 43 of the Data Protection Act 2018.
- Financial records — Article 6(1)(c) GDPR (legal obligation) and section 41(a) of the Data Protection Act 2018 (compliance with legal obligation under Revenue Commissioners record-keeping rules — seven-year retention).
- Fraud and abuse investigation — Article 6(1)(f) GDPR (legitimate interest) and section 47 of the Data Protection Act 2018.
· IV ·Cross-border processing
GuestlinePortal is established in Ireland only. All processing takes place in the EU. No personal data is transferred to any third country. Where a data subject is resident in another EU Member State, the Data Protection Commission remains the lead supervisory authority under Article 56 GDPR because the main establishment of the controller is in Dublin.
· V ·Northern Ireland customers
For Northern Ireland-based Customers billed in GBP, the UK GDPR applies in parallel. The Information Commissioner's Office (ICO) is the relevant supervisory authority in that jurisdiction. GuestlinePortal has appointed an Article 27 UK GDPR representative in Belfast for Northern Ireland Customers — contactable at ni-rep@guestlineportal.com. Data still resides in the Republic of Ireland and is transferred to and from Northern Ireland on the basis of the UK adequacy decision maintained by the EU Commission.
· VI ·Rights in Ireland
Data subjects in Ireland have the full suite of rights under Articles 15 to 22 GDPR. The Irish Data Protection Act 2018 provides supplementary rights and procedures — including access requests under section 91, rectification under section 92 and erasure under section 93. Requests should be addressed in writing to the Data Protection Officer at dpo@guestlineportal.com. The response time is one calendar month, extensible by up to two further months for complex requests, notified within the first month.
· VII ·Complaints to the DPC
Complaints may be lodged with the Data Protection Commission. Contact details: Data Protection Commission, 21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland. Telephone +353 578 684 800. Web www.dataprotection.ie. The DPC investigates complaints without charge and may issue enforcement notices or administrative fines under Part 6 of the Data Protection Act 2018.
· VIII ·Security and breach notification
Personal data breaches are notified to the DPC within 72 hours as required by Article 33 GDPR and section 86 of the Data Protection Act 2018, where the breach is likely to result in a risk to the rights and freedoms of natural persons. Notifications include the nature of the breach, the categories and approximate number of data subjects affected, the likely consequences and the measures taken or proposed. Where a high risk is likely, affected data subjects are notified directly without undue delay under Article 34 GDPR.
· IX ·Retention specific to Ireland
Financial records are retained for seven years to comply with sections 851 and 886 of the Taxes Consolidation Act 1997 and Revenue Commissioners record-keeping rules. Employment records where applicable are retained per the Employment Equality Acts. Personal data unrelated to a legal retention requirement is deleted within the timelines set out in /privacy.
· X ·Changes
Material changes to this notice are published to /changelog and notified to Client Portal users 30 days in advance. The current version is dated 27 August 2026.