Last Updated: September 3, 2026
spring-starling.com is committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR). This page outlines how we comply with GDPR requirements and explains your rights as a data subject.
For the purposes of GDPR, the data controller is:
spring-starling.com
42 Grafton Street
Dublin 2, D02 VF65
Ireland
Email: [email protected]
We process personal data only when we have a lawful basis to do so. Our lawful bases include:
Under GDPR, you have the following rights regarding your personal data:
You have the right to request copies of your personal data. We may charge a reasonable fee for additional copies if your request is clearly unfounded or excessive.
You have the right to request that we correct any information you believe is inaccurate or complete information you believe is incomplete.
You have the right to request that we erase your personal data under certain conditions, such as when the data is no longer necessary for the purposes for which it was collected.
You have the right to request that we restrict the processing of your personal data under certain conditions.
You have the right to object to our processing of your personal data under certain conditions, particularly for direct marketing purposes.
You have the right to request that we transfer the data we have collected to another organization, or directly to you, under certain conditions.
Where we rely on consent to process your personal data, you have the right to withdraw that consent at any time.
To exercise any of your GDPR rights, please contact us at [email protected]. We will respond to your request within one month of receipt. In complex cases, we may extend this period by two additional months, and we will inform you of any such extension.
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including for the purposes of satisfying legal, accounting, or reporting requirements. Retention periods vary depending on the type of data and the purpose for processing.
When we transfer personal data outside the European Economic Area (EEA), we ensure that appropriate safeguards are in place, such as:
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you without undue delay. We will also notify the relevant supervisory authority within 72 hours of becoming aware of the breach.
We do not use automated decision-making or profiling that produces legal effects or similarly significantly affects you.
Our services are not directed at children under the age of 16. We do not knowingly collect personal data from children. If you are a parent or guardian and believe your child has provided us with personal data, please contact us.
If you believe we have not handled your personal data in accordance with GDPR, you have the right to lodge a complaint with the relevant supervisory authority. In Ireland, this is the Data Protection Commission:
Data Protection Commission
21 Fitzwilliam Square South
Dublin 2, D02 RD28
Ireland
Website: dataprotection.ie
We may update this GDPR compliance statement from time to time to reflect changes in our practices or legal requirements. We encourage you to review this page periodically for the latest information.
If you have any questions about our GDPR compliance or how we process your personal data, please contact us at [email protected].