GDPR Compliance
Last Updated: July 21, 2026
Our Commitment to GDPR
amethyst-geyser.com is committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR). This page explains how we comply with GDPR requirements and your rights as a data subject.
Legal Basis for Processing
We process your personal data based on the following legal grounds:
- Consent: When you voluntarily provide information through forms or subscribe to communications
- Contract Performance: When processing is necessary to provide advisory services you have requested
- Legitimate Interests: For website functionality, security, and service improvement
- Legal Obligation: When required by law to retain or process certain information
Your Rights Under GDPR
You have the following rights regarding your personal data:
- Right of Access: You can request a copy of the personal data we hold about you
- Right to Rectification: You can request correction of inaccurate or incomplete data
- Right to Erasure: You can request deletion of your personal data under certain circumstances
- Right to Restrict Processing: You can request limitation of how we use your data
- Right to Data Portability: You can request your data in a structured, commonly used format
- Right to Object: You can object to processing based on legitimate interests
- Right to Withdraw Consent: You can withdraw consent at any time where processing is based on consent
How to Exercise Your Rights
To exercise any of your GDPR rights, please contact us at [email protected]. We will respond to your request within 30 days.
Data Protection Officer
For data protection inquiries, you can contact our designated representative at [email protected].
Data Processing Activities
We process the following categories of personal data:
- Identity data (name)
- Contact data (email address)
- Service preference data (consultation selections)
- Technical data (IP address, browser type, access times)
- Communication data (correspondence records)
Data Retention Periods
We retain your personal data only as long as necessary for the purposes outlined in our Privacy Policy. Typical retention periods are:
- Consultation requests: 3 years from last contact
- Client relationship data: 7 years after service completion for legal compliance
- Technical logs: 12 months
International Data Transfers
When we transfer your data outside the European Economic Area, we ensure appropriate safeguards are in place through:
- Standard Contractual Clauses approved by the European Commission
- Adequacy decisions for countries with appropriate data protection levels
Automated Decision-Making
We do not use automated decision-making or profiling that produces legal effects or similarly significant impacts on individuals.
Security Measures
We implement appropriate technical and organizational measures including:
- Encryption of data in transit and at rest
- Access controls and authentication requirements
- Regular security assessments and updates
- Staff training on data protection principles
Data Breach Notification
In the event of a data breach that poses a risk to your rights and freedoms, we will notify you and the relevant supervisory authority within 72 hours of becoming aware of the breach.
Supervisory Authority
You have the right to lodge a complaint with the Data Protection Commission (Ireland) if you believe we have not handled your data appropriately:
Data Protection Commission
21 Fitzwilliam Square South
Dublin 2, D02 RD28
Ireland
Updates to This Notice
We may update this GDPR compliance notice to reflect changes in our practices or legal requirements. The last updated date will be revised accordingly.