Privacy Policy
Draft for review and tailoring by The Hibernian Orchestra. This document is intended as a general website privacy policy for an Irish arts organisation and should be reviewed against the orchestra’s actual data processing practices, suppliers, and retention periods before publication.
Who we are – Introduction
The Hibernian Orchestra is committed to protecting and respecting personal data. This Privacy Policy explains how personal data may be collected, used, stored, shared, and otherwise processed through the orchestra’s website and related activities. Under the GDPR, privacy notices should accurately reflect an organisation’s real processing activities and should be reviewed and updated as those activities change.dataprotection+1
Personal data must be processed lawfully, fairly, and transparently, and information about that processing should be clear, accessible, and easy to understand.
Who This Policy Applies To
This policy is intended for website visitors, concert attendees, mailing list subscribers, supporters, Friends of the Orchestra, prospective players, competition applicants, volunteers, contractors, suppliers, donors, and anyone else whose personal data may be processed in connection with the orchestra’s website or activities.
Data Controller
The data controller for the purposes of this website and related activities is:
The Hibernian Orchestra
Dublin, Ireland
Email: manager@thehibernianorchestra.ie
If the orchestra appoints a dedicated data protection contact or Data Protection Officer in future, that person’s details should be added here. Under Articles 13 and 14 GDPR, a privacy notice should identify the controller and, where applicable, the Data Protection Officer or relevant contact for data protection matters.
Personal Data the Orchestra May Collect
Depending on how an individual interacts with the website or the orchestra, the following categories of personal data may be collected:
- Identity data, such as name or title.
- Contact data, such as email address, postal address, and telephone number.
- Membership, supporter, donor, or Friends scheme information.
- Player, volunteer, or audition/trial-related information.
- Event, booking, enquiry, and correspondence records.
- Payment-related information required to administer memberships, donations, subscriptions, or ticket-related transactions, although card or online payment details may be processed directly by third-party payment providers rather than by the orchestra itself.
- Technical data, such as IP address, browser type, device information, pages visited, and usage data collected through server logs, cookies, or analytics tools.
- Any other personal data that an individual chooses to provide through forms, email, or other communication channels.
Under GDPR transparency requirements, individuals should be told what categories of data are processed, the purposes of processing, recipients, retention periods, lawful bases, and their rights.
How Personal Data May Be Collected
Personal data may be collected in a number of ways, including:
- When an individual completes a contact form or other website form.
- When an individual signs up to a mailing list or newsletter.
- When someone purchases tickets, makes a donation, joins a Friends or membership scheme, or completes a payment-related form.
- When a person applies to join the orchestra, enters a competition, or submits documents or recordings.
- When the orchestra communicates by email, telephone, post, or in person.
- Automatically through cookies, analytics tools, and standard website server logs.
Where personal data is collected directly from an individual, the required transparency information should be provided at the time of collection
Purposes of Processing
Personal data may be processed for the following purposes:
- To respond to enquiries and communicate with website users.
- To administer concerts, events, rehearsals, competitions, and related activities.
- To manage orchestra membership, prospective players, volunteers, and supporters.
- To process donations, subscriptions, Friends memberships, ticketing, and related payments.
- To send newsletters, concert announcements, and other updates where the orchestra is permitted to do so.
- To maintain internal records and administer the orchestra’s operations.
- To improve the website, monitor its performance, maintain security, and prevent misuse.
- To comply with legal, regulatory, accounting, tax, governance, and safeguarding obligations.
- To establish, exercise, or defend legal claims where necessary.
Under the GDPR, the purposes of processing should be explicit and legitimate, and data should not be further processed in a way that is incompatible with those purposes.
Lawful Bases for Processing
The orchestra may rely on one or more of the following lawful bases under Article 6 GDPR, depending on the circumstances:
- Consent — for example, where an individual opts in to receive marketing emails or agrees to a specific use of their data.
- Contract — where processing is necessary to perform a contract or to take steps at the individual’s request before entering into a contract, such as processing a Friends subscription or administering participation in an event.
- Legal obligation — where processing is necessary to comply with legal or regulatory obligations.
- Legitimate interests — where processing is reasonably necessary for the orchestra’s legitimate interests, such as administering the organisation, responding to enquiries, maintaining security, operating the website, or communicating with supporters, provided those interests are not overridden by the individual’s rights and freedoms.
The DPC notes that personal data must have a lawful basis for processing and identifies consent, contract, legal obligation, vital interests, public task, and legitimate interests as the six lawful reasons available under Article 6 GDPR.
Marketing Communications
Where the orchestra sends newsletters, concert announcements, fundraising messages, or other direct electronic communications, it will do so in accordance with applicable Irish and EU data protection and ePrivacy rules. Where consent is required, marketing communications will only be sent where valid consent has been obtained, and individuals will be able to withdraw that consent or unsubscribe at any time.dataprotection+1
An unsubscribe link should be included in relevant emails where appropriate, and withdrawal of consent should be as easy as giving it. Where the orchestra relies on legitimate interests rather than consent for certain communications, individuals should be informed of that and of their right to object.
Cookies and Similar Technologies
The website may use cookies and similar technologies to support core site functions, improve performance, analyse traffic, remember preferences, and help protect the website from misuse. The Irish Data Protection Commission provides specific guidance on cookies and other tracking technologies, and cookie use should be assessed separately from the general privacy policy.dataprotection
A separate Cookie Policy or Cookie Notice should explain:
- what cookies are used;
- whether they are strictly necessary, analytics, functionality, or marketing cookies;
- which third parties set cookies, if any; and
- how users can manage their preferences.
Where cookies are not strictly necessary, appropriate consent should be obtained before they are placed on a user’s device.Cookies and Similar Technologies
Sharing Personal Data
Personal data may be shared, where necessary and appropriate, with the following categories of recipients:
- Website hosting providers, developers, IT support providers, and security providers.
- Email and mailing list platforms.
- Payment processors and financial service providers.
- Ticketing or event administration providers.
- Cloud storage, office software, and collaboration platforms.
- Professional advisers such as accountants, auditors, insurers, or legal advisers.
- Public authorities, regulators, law enforcement, or other bodies where disclosure is required by law or necessary to protect rights or comply with legal obligations.
The privacy notice should state the recipients or categories of recipients of the personal data.dataprotection+1
Where third-party service providers process personal data on behalf of the orchestra, the orchestra should ensure appropriate controller-processor arrangements are in place, including contracts that satisfy GDPR requirements.
International Transfers
Some service providers used by the orchestra may store or process personal data outside the European Economic Area. Where personal data is transferred to a third country or international organisation, the orchestra will take steps to ensure that appropriate safeguards are in place, as required by the GDPR, such as adequacy decisions or approved transfer mechanisms.dataprotection+1
If the orchestra does not transfer personal data outside the EEA, this section should be amended to say so.
Data Retention
Personal data will be retained only for as long as necessary for the purposes for which it was collected, including to satisfy legal, accounting, reporting, governance, safeguarding, and dispute-resolution requirements. GDPR transparency rules require the retention period, or the criteria used to determine it, to be provided to individuals.dataprotection
In practice, retention periods may vary depending on the type of data, for example:
- routine enquiries may be retained for a short administrative period;
- supporter, donor, and membership records may be retained for the duration of the relationship and an appropriate follow-up period;
- financial records may be retained for longer where required by tax, accounting, or audit obligations;
- competition, safeguarding, or legal records may be retained in line with the relevant legal or operational need.
The orchestra should insert its actual retention schedule or a more specific summary once internal review is complete.
Data Security
The GDPR requires personal data to be processed in a manner that ensures appropriate security, including protection against unauthorised or unlawful processing and against accidental loss, destruction, or damage.dataprotection
The orchestra will use reasonable technical and organisational measures to protect personal data, which may include:
- access controls and password protection;
- role-based access to records;
- secure hosting and software updates;
- backup, monitoring, and malware protection measures;
- secure handling of forms, emails, and documents; and
- procedures for identifying and responding to personal data breaches.
No internet-based transmission or storage system can be guaranteed to be completely secure, but appropriate steps should be taken to reduce risk and protect personal data proportionately.
Individual Rights
Subject to applicable law and exemptions, individuals may have the following rights under data protection law:
- the right to be informed;
- the right of access;
- the right to rectification;
- the right to erasure;
- the right to restrict processing;
- the right to data portability;
- the right to object; and
- rights relating to automated decision-making and profiling.
The DPC states that these rights, together with information on how to exercise them, should be included in a privacy notice where relevant.dataprotection
Requests relating to personal data should be sent to the orchestra using the contact details above. The orchestra may ask for proof of identity before responding to a request where this is necessary to protect personal data.
Withdrawal of Consent
Where the orchestra relies on consent as the lawful basis for processing, that consent may be withdrawn at any time. Withdrawal will not affect the lawfulness of processing carried out before the consent was withdrawn
Complaints
Any individual who is unhappy with how their personal data has been handled should contact the orchestra first so that the matter can be considered and, where possible, resolved.
Individuals also have the right to lodge a complaint with the Irish Data Protection Commission:
Data Protection Commission
21 Fitzwilliam Square South
Dublin 2
D02 RD28
Ireland
Website: www.dataprotection.ie
Third-Party Websites
The website may contain links to third-party websites, platforms, ticketing providers, social media services, or embedded content. Those third parties operate under their own privacy policies and terms, and the orchestra is not responsible for their privacy practices. Users should review the relevant third-party policies before providing personal data to them.
Children’s Data
The website is not intended to collect personal data from children without appropriate safeguards. If the orchestra knowingly processes children’s data in connection with competitions, education projects, outreach, or safeguarding-related activity, it should take particular care to provide information in clear language and to ensure that the processing is lawful and appropriate.
Automated Decision-Making
Unless specifically stated otherwise, the orchestra does not expect to make decisions based solely on automated processing, including profiling, that produce legal or similarly significant effects for individuals. If that changes, this policy should be updated accordingly. The GDPR requires privacy notices to include information about automated decision-making where it takes place.
Changes to This Policy
This Privacy Policy should be reviewed regularly and may be updated from time to time to reflect changes in the law, guidance, suppliers, website features, or the orchestra’s activities. The DPC notes that privacy policies should be dynamic documents and regularly reviewed and updated to reflect changes in processing.
