GDPR Compliance Information
Last updated: July 2026
Our Commitment to Data Protection
basin-seal is committed to ensuring that our processing of personal data complies with the General Data Protection Regulation (EU) 2016/679 ("GDPR"). This page provides specific information about how we meet our obligations under GDPR and how we protect your rights as a data subject.
Data Controller Information
For the purposes of GDPR, the data controller is:
basin-seal
Suite 412, Pembroke House
28-32 Upper Pembroke Street
Dublin 2, D02 EK84
Ireland
Email: [email protected]
Categories of Personal Data We Process
In the course of providing our leadership development services, we may process the following categories of personal data:
- Identity data: Name, title, employer information
- Contact data: Email address, postal address
- Professional data: Job title, department, industry sector
- Assessment data: Responses to psychometric assessments, feedback from colleagues
- Session data: Notes and observations from coaching sessions (with your consent)
- Technical data: IP address, browser type, device information
Lawful Bases for Processing
We rely on the following lawful bases under Article 6 of GDPR:
Consent (Article 6(1)(a))
We obtain your explicit consent before processing assessment data, recording session observations, or using your information for any purposes beyond service delivery.
Contract (Article 6(1)(b))
Processing is necessary for the performance of our service agreements, including responding to enquiries, scheduling sessions, and delivering programmes.
Legitimate Interests (Article 6(1)(f))
We may process data where necessary for our legitimate business interests, provided these interests do not override your fundamental rights. This includes improving our services and maintaining business records.
Your Rights Under GDPR
You have the following rights under GDPR, which we are committed to upholding:
Right of Access (Article 15)
You have the right to obtain confirmation as to whether we are processing your personal data and, where that is the case, access to the personal data and information about how it is processed.
Right to Rectification (Article 16)
You have the right to have inaccurate personal data corrected and incomplete data completed.
Right to Erasure (Article 17)
You have the right to have your personal data erased in certain circumstances, including where the data is no longer necessary for the purpose for which it was collected or where you withdraw consent.
Right to Restriction of Processing (Article 18)
You have the right to restrict processing in certain circumstances, such as while we verify the accuracy of data you have contested.
Right to Data Portability (Article 20)
Where processing is based on consent or contract and carried out by automated means, you have the right to receive your personal data in a structured, commonly used, machine-readable format.
Right to Object (Article 21)
You have the right to object to processing based on legitimate interests. We will cease processing unless we demonstrate compelling legitimate grounds that override your interests.
Rights Related to Automated Decision-Making (Article 22)
We do not make decisions based solely on automated processing that produce legal effects or similarly significantly affect you.
Exercising Your Rights
To exercise any of your rights under GDPR, please contact us at [email protected]. We will respond to your request within one month. In complex cases, we may extend this period by a further two months, and we will inform you of any such extension.
We do not charge a fee for processing rights requests unless requests are manifestly unfounded or excessive. In such cases, we may charge a reasonable fee or refuse to act on the request.
Data Security Measures
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
- Encryption of personal data where appropriate
- Access controls limiting who can view personal data
- Regular security assessments and updates
- Staff training on data protection obligations
- Secure disposal of personal data when no longer needed
Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Data Protection Commission within 72 hours of becoming aware of the breach. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly.
International Data Transfers
Where we transfer personal data outside the European Economic Area, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission or adequacy decisions.
Supervisory Authority
You have the right to lodge a complaint with a supervisory authority. Our lead supervisory authority is:
Data Protection Commission
21 Fitzwilliam Square South
Dublin 2, D02 RD28
Ireland
Website: www.dataprotection.ie
Updates to This Information
We may update this GDPR compliance information from time to time. Significant changes will be communicated to individuals whose data we process.