logo
← All policies Food Safe Ireland · Legal

Privacy Policy

Last updated: 1 August 2026


This Privacy Policy explains how Interic Ltd, trading as Food Safe Ireland ("Food Safe Ireland", "we", "us", "our") collects, uses, stores and protects your personal data when you use our website foodsafeireland.ie, our learning management platform and our online training services (together, "our Services"). We are committed to handling your personal data lawfully, fairly and transparently, in accordance with the General Data Protection Regulation (EU 2016/679) ("GDPR") and the Data Protection Act 2018.

Please read this Policy carefully so that you understand how we treat your personal data. Our detailed compliance obligations and your full statutory rights are set out in our separate Data Protection (GDPR) Statement, which should be read alongside this Policy. By using our Services, you acknowledge that you have read and understood this Policy.

1. Who We Are

Interic Ltd, trading as Food Safe Ireland, is a company registered in Ireland under company registration number 714473, with its registered office at 77 Camden Street Lower, St Kevin's, Dublin 2, Ireland. We are the data controller responsible for your personal data, which means we decide how and why your personal data is processed.

For any privacy matter, or to exercise your data protection rights, you can contact us at [email protected]. Please mark your message for the attention of our data protection contact.

2. What Is Personal Data?

Personal data is any information that relates to an identified or identifiable living individual. This includes obvious information such as your name and contact details, and less obvious information such as your IP address, device identifiers, and records of your activity on our platform. It does not include data where your identity has been permanently removed (anonymous data).

We do not routinely collect special categories of personal data (such as data about your health, ethnicity or beliefs), and we ask that you do not submit such data to us unless it is specifically required for a Course and we have a lawful basis to process it.

3. What This Policy Covers

This Policy applies to your use of our website, platform and Services, whether you are an individual learner, a learner enrolled by an employer, a person purchasing on behalf of an organisation, or simply a visitor to our website.

Our site may contain links to third-party websites, plug-ins and applications that we do not control. Clicking on those links may allow third parties to collect or share data about you. We are not responsible for the privacy practices of those third parties, and we encourage you to read their privacy notices before providing them with any personal data.

4. The Personal Data We Collect

Depending on how you interact with us, we may collect, use, store and transfer the following categories of personal data:

  • Identity and account data — your name, username, password, account preferences and similar information used to set up and manage your account.
  • Contact data — your email address, telephone number and, where relevant, postal address.
  • Profile and learner data — your job title or profession, your employer (where you are enrolled by an organisation), and course-related records such as enrolments, progress, assessment attempts, results, certificates and certificate expiry dates.
  • Payment and transaction data — billing details, purchase history and records of payments. Your full card details are processed directly by our payment providers and are not stored on our servers.
  • Communications data — the content of emails, support tickets, live chat and any other messages you send to us.
  • Technical and usage data — your IP address, login data, browser type and version, time-zone setting, operating system, device information, referring website, and details of how you use our site and platform.
  • Marketing and communications preferences — your choices about receiving marketing from us and your communication preferences.
  • User-submitted content — any files, assignments, responses or materials you upload or submit as part of a Course.

If you fail to provide personal data that we need in order to perform a contract with you (for example, to set up your account or issue a certificate), we may be unable to provide the Services you have requested.

5. How We Collect Your Data

We collect personal data in three main ways:

  • Directly from you — when you create an account, purchase or enrol in a Course, complete assessments, contact us, subscribe to marketing, or otherwise interact with us.
  • Automatically — as you navigate our site, we may automatically collect technical and usage data through cookies and similar technologies (see our Cookie Policy).
  • From third parties — for example, from an employer or organisation that enrols you in training, from our payment providers in relation to a transaction, or from analytics and advertising providers.

6. Why We Use Your Data and Our Lawful Bases

Under the GDPR we must have a lawful basis for using your personal data. We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for a related and compatible purpose. The table below summarises how and why we use your data.

PurposeLawful basis
Creating and managing your account and providing access to CoursesPerformance of a contract
Processing payments, managing billing and preventing fraudPerformance of a contract; legal obligation; legitimate interests
Delivering assessments, issuing and verifying certificates, and keeping training recordsPerformance of a contract; legal obligation; legitimate interests
Providing customer support and responding to your queriesPerformance of a contract; legitimate interests
Improving our site, platform and Services and ensuring their securityLegitimate interests
Sending you service messages and certificate-expiry notificationsPerformance of a contract; legitimate interests
Sending marketing communications and personalising advertisingConsent (you may withdraw it at any time)
Meeting our legal, accounting, tax and regulatory obligationsLegal obligation

Where we rely on legitimate interests, we have weighed those interests against your rights and freedoms and concluded that our processing does not unfairly override them. You can ask us for more information about this balancing exercise at any time.

7. Marketing, Service Messages and Reviews

Where you have given consent, we may send you information about our Courses, offers and news by email. You can opt out of marketing at any time by using the unsubscribe link in our emails, by adjusting your account preferences, or by contacting us.

If you are an existing customer, we may also email you about our own similar training courses — for example, new courses or important updates to our course range — on the basis of our legitimate interest, as permitted by the Privacy and Electronic Communications Regulations (the "soft opt-in"). We only ever tell you about our own courses, never third-party products, and every such email includes an easy way to unsubscribe. This applies to customers who have purchased from us; it does not apply to people who have only registered for a free trial, or to learners enrolled through a youth group.

Separately from marketing, we send essential service messages that are necessary to provide the Services — such as purchase confirmations, billing notices, and notifications about changes to a Course you hold or a certificate that is due to expire. These relate to training you already have, so you will receive them regardless of your marketing preferences.

After you complete a Course, we may send you a follow-up email inviting you to give feedback or leave a review. We do this on the basis of our legitimate interest in understanding your experience and improving our Courses. We use Google and Trustpilot to collect reviews; if you choose to leave a review, the information you provide will also be handled in accordance with that provider's own privacy policy.

Where a learner is having technical difficulty with the platform, we may use WhatsApp as an optional, alternative channel to provide support, including to receive an exam or assignment that cannot be uploaded in the usual way. Any such material is promptly downloaded, added to your record on the platform, and then deleted from the chat, so that your assessment record is held securely within the platform. We do not use WhatsApp or other direct messaging channels with supervised minors enrolled through youth groups; their uploads and communications go through the responsible Group Leader and the platform.

8. Who We Share Your Data With

We do not sell your personal data. We share it only with the categories of recipient necessary to operate our Services, and only to the extent required. These include:

  • Payment providers — Stripe and PayPal, to process payments securely and to help prevent fraud.
  • Our learning management and platform provider, which hosts and operates the e-learning environment on our behalf.
  • Cloud hosting and infrastructure providers — including Google Cloud and Amazon Web Services, and our domain and web hosting provider GoDaddy — all located within Ireland and the European Union.
  • Our communications and customer-relationship providers — Microsoft 365, which supports our email and business communications, and Heffl, which provides our customer-relationship management system.
  • Our telephony provider — Goldfish.ie, which provides our VoIP telephone service for calls to and from us.
  • WhatsApp (Meta) — used as an optional support channel where a learner is having technical difficulty, as described below. WhatsApp is operated by Meta and processes data outside the EEA under appropriate safeguards.
  • Analytics and marketing providers — including Google Analytics, Google Tag Manager, Google Ads, Meta (Facebook and Instagram) and LinkedIn — used to understand how our site is used and to deliver relevant advertising. See our Cookie Policy for detail.
  • Review providers — Google and Trustpilot, where we invite you to review a Course you have completed and you choose to leave a review.
  • Professional advisers and authorities — such as our accountants, auditors and legal advisers, and competent authorities where we are required to disclose data by law.

All of our processors are required by contract to protect your personal data, to use it only on our instructions, and to apply appropriate security measures. Where you are enrolled by an employer or organisation, we will share your enrolment and completion records with that organisation, which acts as a separate data controller in respect of its own staff.

9. International Transfers

Your account, learner and payment data is stored on secure cloud infrastructure located within Ireland and the European Union. We do not routinely transfer this data outside the European Economic Area (EEA).

Certain analytics and advertising providers used on our site (such as Meta, Google and LinkedIn) may process limited data outside the EEA in connection with marketing cookies. Where this occurs, those transfers are protected by appropriate safeguards, such as the EU–US Data Privacy Framework or the European Commission's Standard Contractual Clauses. You can prevent these transfers by declining marketing cookies — see our Cookie Policy.

10. How Long We Keep Your Data

We keep your personal data only for as long as necessary for the purposes for which it was collected, including to satisfy any legal, accounting, tax or certification requirements. To decide the appropriate retention period, we consider the amount, nature and sensitivity of the data, the potential risk of harm from unauthorised use or disclosure, the purposes for which we process it, and applicable legal requirements.

Type of dataRetention period
Account, login and profile dataWhile your account is active and up to 2 years after your last activity. Your training and certification records are kept for longer (see below), even if your account is closed
Training records, assessment results and certificatesFor the validity period of the certificate and for at least 7 years after it expires. Certificates issued without an expiry date are kept for at least 10 years from issue. We may keep them longer where necessary to verify the certificate or to establish, exercise or defend a legal claim
Payment and transaction recordsAs required by law, generally up to 6 years
Marketing dataUntil you unsubscribe or withdraw consent, with a suppression record kept to honour your opt-out
Support and communications dataUp to 2 years after the matter is resolved

We deliberately keep training and certification records well beyond the life of the certificate, for two main reasons. First, as the body that issues the certificate, we need to be able to verify that it is genuine and to stand behind it — for example, when a learner, employer, auditor, insurer or accreditation body asks us to confirm that a certificate is valid. This is central to the integrity of our certification, and is especially important for certificates issued without an expiry date. Second, training certificates can form part of the evidence in workplace health and safety matters — for instance, supporting an employer's position that it took reasonably practicable steps under the Safety, Health and Welfare at Work Act 2005 — and a related personal injury claim can arise and conclude several years after the training was completed (an injured person generally has 2 years from the date of the accident, or date of knowledge, to bring a claim, with litigation and any appeal taking longer still). Retaining the records for these purposes is permitted under data protection law, including as being necessary for the establishment, exercise or defence of legal claims. Where a learner is a minor, the limitation period generally does not begin until they reach 18, so the relevant records may be retained for longer.

In some circumstances we may anonymise your personal data so that it can no longer be associated with you, in which case we may use that anonymised information indefinitely without further notice to you.

11. Keeping Your Data Accurate

It is important that the personal data we hold about you is accurate and current, particularly your name, which appears on your certificates. Please keep your account details up to date and let us know if your personal data changes.

12. How We Keep Your Data Secure

We have put in place appropriate technical and organisational measures to protect your personal data against accidental loss and unauthorised access, alteration or disclosure. These measures include secured cloud hosting within the EU, access controls and authentication, and the encryption of payment transactions by our payment providers. We limit access to your personal data to those who have a genuine business need to access it.

While we work hard to protect your data, no method of transmission over the internet is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your account credentials confidential and for not sharing your password.

13. Data Breaches

We have procedures in place to detect, report and investigate personal data breaches. Where a breach is likely to result in a risk to your rights and freedoms, we will notify the Data Protection Commission, and you, where we are required to do so by law.

14. Profiling and Automated Decision-Making

We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing. We may use limited analytics to understand how our Services are used and to tailor marketing, but this does not involve automated decisions of that kind.

15. Business Transfers

If we sell, transfer or reorganise part of our business, your personal data may be transferred as part of that transaction, provided the recipient agrees to handle it in accordance with this Policy. Where this affects how your data is used, we will notify you and, where appropriate, give you a choice about the continued use of your data.

16. Your Rights

You have rights over your personal data, including the right to be informed, to access, to rectification, to erasure, to restrict processing, to object, and to data portability. These rights, and how to exercise them, are explained in full in our Data Protection (GDPR) Statement. To make a request, contact us at [email protected]. We will respond within the timeframes required by law.

Erasure, Account Closure and Certification Records

You may ask us to delete your personal data, and you may ask us to close your account. The right to erasure is not absolute, however. Because we issue training certificates and must be able to verify and stand behind them, and because those records may be needed for the establishment, exercise or defence of legal claims, we may retain your training and certification record (typically your name, the Course, the result and the relevant dates) for the retention period set out above, even if you ask us to delete your data or close your account. This is permitted under Articles 17(3)(b) and 17(3)(e) of the GDPR.

Where this applies, we will: erase or anonymise any of your other personal data that is not needed for that purpose (such as marketing data, analytics and optional profile information); restrict the retained certification record so that it is held only for verification and legal-claims purposes and is not otherwise actively used; close your access to the account if you ask us to; and delete the retained record once the retention period ends. If we cannot fully action an erasure request, we will tell you why and let you know that you can complain to the Data Protection Commission.

17. Cookies

Our site uses cookies and similar technologies. Please see our Cookie Policy for full details of the cookies we use and how to manage your preferences.

18. Children and Learners Enrolled Through Youth Groups

Our Services are generally intended for users aged 16 and over. We do not knowingly collect personal data from children below this age without appropriate consent. Persons under 18 should use our site only with the involvement of a parent, guardian or employer.

We sometimes deliver training to supervised minors through youth groups, schools and similar organisations. We have designed this so that we collect as little personal data about those learners as possible, in line with the principle of data minimisation:

  • Minimal data — for these learners we typically collect only the learner's name, which is needed to issue a certificate. We do not require or collect their email address, billing details or other contact information.
  • Credentials via the Group Leader — we set up the accounts and provide the login details to the responsible youth group leader or organisation (the "Group Leader"), who distributes them to the learners. The learners do not register directly with us.
  • Responsible adult and consent — the Group Leader or organisation arranges the enrolment, provides any consent required for the minors to take part, and acts as the responsible adult and as a separate data controller for those learners.
  • Limited use — we use this minimal data only to deliver the training and to issue and verify certificates, and we retain it in line with the retention periods in this Policy.

Community and messaging features may be restricted or disabled for supervised minor accounts. If you believe a child has provided us with personal data without appropriate consent, please contact us and we will take steps to delete it.

19. Changes to This Policy

We may update this Policy from time to time to reflect changes in our practices or the law. Any changes will be posted on this page with an updated date, and significant changes will be brought to your attention where appropriate. Your continued use of our Services after an update constitutes acceptance of the revised Policy.

20. Contact and Complaints

If you have any questions about this Policy or how we handle your personal data, please contact us at [email protected]. We will always try to resolve any concern you have.

If you are not satisfied with our response, you have the right to lodge a complaint with the Data Protection Commission, 21 Fitzwilliam Square South, Dublin 2, D02 RD28 (dataprotection.ie).

FoodSafe Ireland

Trusted food safety and compliance training. Learn online at your own pace and earn QR-verified certificates employers can check in seconds.

[email protected]
Training All Courses All-Access Plans For Business
Popular Courses HACCP Level 1 & 2 HACCP Level 3 Manual Handling Fire Safety Allergen Awareness
Support Help Centre Verify a Certificate Contact Us Blog
Legal Privacy Policy Terms & Conditions Refund Policy Cookie Policy All Policies
© 2026 Food Safe Ireland. All rights reserved. Train · Verify · Stay Compliant