Last updated: 1 August 2026
This Data Protection Statement sets out, in detail, how Interic Ltd, trading as Food Safe Ireland ("Food Safe Ireland", "we", "us", "our") complies with the General Data Protection Regulation (EU 2016/679) ("GDPR") and the Data Protection Act 2018, and explains your rights over your personal data. It complements our Privacy Policy, which gives a plain-language overview of how we handle your data.
Interic Ltd, trading as Food Safe Ireland, is the data controller for the personal data described in this Statement. We are registered in Ireland under company registration number 714473, with our registered office at 77 Camden Street Lower, St Kevin's, Dublin 2, Ireland.
For any data protection query, or to exercise your rights, contact us at [email protected]. Please mark your message for the attention of our data protection contact. We are not currently required to appoint a statutory Data Protection Officer, but we have designated a point of contact responsible for data protection matters.
We are committed to processing personal data in accordance with the principles of the GDPR. We process personal data lawfully, fairly and transparently; collect it only for specified, explicit and legitimate purposes; limit it to what is necessary; keep it accurate and up to date; retain it no longer than necessary; and keep it secure.
We process the following categories of personal data: identity and contact data; account and login data; learner, enrolment, assessment and certification data; payment and transaction data; communications data; technical and usage data; and marketing preferences. We do not routinely process special categories of personal data, and ask that you do not submit such data to us unless specifically required and lawful.
We rely on the following lawful bases under Article 6 of the GDPR:
| Processing activity | Lawful basis |
|---|---|
| Providing your account, courses, assessments and certificates | Article 6(1)(b) — performance of a contract |
| Taking payment and managing billing | Article 6(1)(b) — performance of a contract |
| Keeping training and certification records | Article 6(1)(c) — legal obligation; and Article 6(1)(f) — legitimate interests |
| Improving and securing our platform | Article 6(1)(f) — legitimate interests |
| Providing support and service communications | Article 6(1)(b) and (f) |
| Sending marketing communications and setting marketing cookies | Article 6(1)(a) — consent; or Article 6(1)(f) — legitimate interests for soft opt-in emails to existing customers about our own similar courses |
| Inviting feedback or a review after course completion | Article 6(1)(f) — legitimate interests |
| Sending essential service messages (confirmations, billing, course and certificate notices) | Article 6(1)(b) — performance of a contract; and Article 6(1)(f) — legitimate interests |
| Meeting legal, accounting and tax obligations | Article 6(1)(c) — legal obligation |
Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms. Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of earlier processing.
We take particular care with the personal data of children. Our Services are generally intended for users aged 16 and over, which reflects the digital age of consent in Ireland under the Data Protection Act 2018.
Where we deliver training to supervised minors through youth groups, schools or similar organisations, we apply data minimisation rigorously: we typically collect only the learner's name, which is required to issue a certificate, and we do not collect the child's email address, billing details or other contact data. Accounts are set up by us and the credentials are provided to the responsible leader or organisation (the "Group Leader"), who distributes them and supervises the learners. The Group Leader or organisation is the data controller for those learners and is responsible for providing any consent required and for informing the learners and their parents or guardians as appropriate. We process this minimal data only to deliver the training and to issue and verify certificates.
We share personal data with the categories of recipient set out in our Privacy Policy, namely our payment providers (Stripe and PayPal); our learning management and platform provider; our cloud hosting and infrastructure providers (including Google Cloud, Amazon Web Services and GoDaddy, located within Ireland and the EU); our communications and customer-relationship providers (Microsoft 365 for email and business communications, and Heffl for customer-relationship management); our telephony provider (Goldfish.ie); WhatsApp (Meta), used as an optional support channel; our analytics and advertising providers (including Google, Meta and LinkedIn); our review providers (Google and Trustpilot); and our professional advisers and competent authorities where required by law. Each processor is bound by a contract requiring it to protect personal data and to process it only on our instructions. Where you are enrolled by an organisation, that organisation is a separate controller of its own staff or members' data.
Your account, learner and payment data is stored within Ireland and the European Union and is not routinely transferred outside the European Economic Area (EEA). Limited processing by certain advertising providers may involve transfers outside the EEA in connection with marketing cookies; where this occurs, it is protected by appropriate safeguards such as the EU–US Data Privacy Framework or the European Commission's Standard Contractual Clauses. You can avoid such transfers by declining marketing cookies.
We retain personal data only for as long as necessary for the purposes for which it was collected, including legal, accounting and certification obligations, and the establishment, exercise or defence of legal claims. Retention periods are set out in our Privacy Policy. In summary, account data is kept while your account is active and for up to 2 years afterwards; payment records are kept for up to 6 years; and training and certification records are kept for the validity period of the certificate and for at least 7 years after it expires (at least 10 years from issue for certificates with no expiry date).
We retain training and certification records on this longer timescale for two main reasons: first, so that we can verify our own certificates and stand behind their integrity when asked to do so by a learner, employer, auditor, insurer or accreditation body; and second, because they may be required for the establishment, exercise or defence of legal claims — for example, to support an employer's position that it took reasonably practicable steps under the Safety, Health and Welfare at Work Act 2005 — in proceedings that can arise and conclude several years after the training was completed. This is a recognised basis for retention under Article 17(3) of the GDPR. Where the learner is a minor, the limitation period generally runs from their 18th birthday, so records may be retained for longer.
We apply appropriate technical and organisational measures to protect personal data, including secured EU-based hosting, access controls and encryption of payment transactions. We have procedures to detect, report and investigate personal data breaches, and where a breach is likely to result in a risk to your rights and freedoms we will notify the Data Protection Commission within 72 hours where feasible, and notify affected individuals where required by law.
You have the following rights in relation to your personal data:
The right to erasure is not absolute. Where you ask us to delete your data or close your account, we may retain your training and certification record (typically your name, the Course, the result and the relevant dates) for the retention period described in section 9, because we need to be able to verify and stand behind the certificates we issue and because the record may be needed for the establishment, exercise or defence of legal claims. We rely on Articles 17(3)(b) and 17(3)(e) of the GDPR for this. In these cases we will erase or anonymise any other personal data that is not needed for that purpose, restrict the retained record so that it is held only for verification and legal-claims purposes, close your account access on request, and delete the retained record once the retention period ends. If we are unable to fully comply with an erasure request, we will explain why and inform you of your right to complain to the Data Protection Commission.
To exercise any of these rights, contact us at [email protected]. We may ask you to verify your identity before we act on a request, to protect your data. We will respond without undue delay and within one month of receiving your request. For complex or numerous requests, we may extend this by up to two further months and will tell you if we do. There is normally no charge, but we may charge a reasonable fee, or decline to act, where a request is manifestly unfounded or excessive.
You may request a copy of the personal data we hold about you (a "subject access request") by emailing [email protected]. Please provide enough detail for us to locate your data and to confirm your identity.
If you have concerns about how we handle your personal data, please contact us first so we can try to resolve them. You also have the right to lodge a complaint with the supervisory authority in Ireland: the Data Protection Commission, 21 Fitzwilliam Square South, Dublin 2, D02 RD28 (dataprotection.ie).
We may update this Statement from time to time to reflect changes in law or our practices. Any changes will be posted on this page.