1. Who we are
People 4 People ("we", "us") is an HR consultancy operating in Ireland. Data protection contact: hello@people4people.ie, 087 798 7884. Website: https://people4people.ie
We are the controller for the personal data described in sections 2, 5 and 6. Section 3 explains the different roles that apply to HR casework.
We have assessed the requirement under Article 37(1)(c) GDPR to appoint a Data Protection Officer. Our core activities do not consist of regular and systematic monitoring of individuals on a large scale, and our processing of special category data (Article 9) arises on a per-engagement basis within HR casework rather than as large-scale processing forming our core activity. On that basis, appointment of a statutory DPO is not currently required. This assessment is recorded in writing and is reviewed every six months, and sooner if the scale or nature of our investigation and casework activity changes.
2. Website visitors
| What we process | Purpose | Legal basis (GDPR) | ePrivacy consent? |
|---|---|---|---|
| Contact form / email / phone: name, email, phone, organisation, message | To respond to a service enquiry | Art. 6(1)(b) — steps at your request prior to entering a contract | No |
| Other correspondence not related to a possible engagement | To respond and keep a record | Art. 6(1)(f) — legitimate interest in handling correspondence | No |
| Server logs: IP address, browser, timestamp, requested page | Security, abuse prevention, availability | Art. 6(1)(f) — legitimate interest in system security | No — strictly necessary |
| Analytics: pages viewed, session duration, approximate region | To understand which pages are useful | Art. 6(1)(a) — consent | Yes |
| Marketing list membership and preferences | To send updates you asked for | Art. 6(1)(a) — consent (see section 5) | n/a |
Where we rely on legitimate interest we have carried out and documented a balancing test. You may request a summary of it at any time.
No advertising, no profiling
We do not use this website for advertising, retargeting, profiling of visitors, or real-time bidding, and we do not share personal data with advertising networks or data brokers.
Full detail on cookies is in our separate Cookie Policy.
3. HR casework: whose data, and who is responsible
When a client organisation engages us for employee relations support, mediation, workplace investigations, HR audits or operational support, we process personal data about that organisation's employees, managers, complainants, witnesses and others. Which of the two arrangements below applies is recorded in writing in the engagement letter for each assignment.
(a) We act as processor. The client organisation remains the controller. We act on their documented instructions under an Article 28 data processing agreement. If you are an employee of a client and wish to exercise your rights over data we hold in this capacity, your employer is the controller and the correct point of contact.
(b) We act as controller. Where we conduct an independent investigation, the independence of the process means we determine certain purposes and means ourselves. In those engagements we are a controller for the investigation file and you may contact us directly.
Don't know which applies? Contact us anyway.
Email hello@people4people.ie and we will tell you within five working days which arrangement covers your data, and — where we are the processor — forward your request to the controller and confirm to you that we have done so. Establishing our role is our job, not yours.
Where we act as controller, every individual affected by an investigation receives a separate, specific notice under Articles 13 and 14 GDPR at the start of the process, covering the scope of the investigation, what we process, who will see the report, and how long we keep it. This website notice does not replace that notice.
4. Special category and criminal offence data
Investigations, grievances and mediation can involve data revealing health, trade union membership, religious or philosophical beliefs and other Article 9 categories, and can touch on allegations of criminal conduct under Article 10.
| Situation | Condition we rely on |
|---|---|
| Article 9 data processed in connection with employment obligations and rights | Article 9(2)(b) GDPR, as given effect by section 46 of the Data Protection Act 2018 (processing for the purposes of employment and social welfare law) |
| Article 9 data processed to establish, exercise or defend legal claims, or in connection with legal advice | Article 9(2)(f) GDPR, as given effect by section 47 of the Data Protection Act 2018 |
| Article 10 data (allegations or records of criminal offences) arising in the course of an investigation | Section 55 of the Data Protection Act 2018, subject to compliance with Article 6(1) and to suitable and specific measures |
The suitable and specific measures we apply, as required by section 36 of the Data Protection Act 2018, include: access limited to the named individuals assigned to the engagement; a written policy on the processing of special category data, available to the Data Protection Commission on request; encryption of investigation files at rest and in transit; logging of access; defined retention and secure destruction; and confidentiality undertakings from everyone involved.
We do not seek out criminal offence data. Where allegations of criminal conduct arise during an engagement, we process them only so far as necessary to complete it, and escalate to the client and, where required, to An Garda Síochána.
5. Marketing
Electronic direct marketing in Ireland is governed by Regulation 13 of S.I. 336/2011 as well as by the GDPR. Our rules:
- We send marketing email only to people who have opted in, or to existing clients about services similar to those we have already provided, where they were given the chance to opt out when we collected the address and in every message since
- We never use a pre-ticked box. Marketing consent is always separate from any other consent or from accepting our terms
- Every marketing message carries an unsubscribe mechanism and a valid postal address at which we can be contacted
- We do not make unsolicited marketing calls to any number, and we check the National Directory Database before any telephone marketing
- We keep a record of when and how each consent or opt-out was given
To opt out: use the link in any message, or email hello@people4people.ie. Opting out of marketing does not affect data we hold for an existing engagement.
6. Where data comes from
Directly from you; from client organisations who engage us; from individuals participating in an investigation or grievance; from public professional sources such as LinkedIn where we research a prospective client organisation; and automatically from your device when you use this website.
7. Who we share data with
| Recipient | Purpose | Location | Leaves EEA? |
|---|---|---|---|
| Netlify, Inc. | Website hosting and content delivery | Global CDN, company based in the USA | Yes — EU-U.S. Data Privacy Framework |
| Google Ireland Limited (Google Workspace) | Business email and document storage | EU/global infrastructure, contracting entity based in Dublin, Ireland | Yes — Standard Contractual Clauses |
| — | Website analytics | Not currently used | n/a |
| Accountant, insurer, solicitors | Professional services | Ireland | No |
| Client organisation | Delivery of the engagement | Ireland | No |
| WRC, Labour Court, courts, An Garda Síochána, DPC | Legal obligation or legal claims | Ireland | No |
Every processor operates under a written contract meeting Article 28 GDPR and may not use the data for its own purposes.
8. International transfers
Our website is hosted by Netlify, Inc., which participates in the EU-U.S. Data Privacy Framework and also relies on Standard Contractual Clauses for cross-border transfers. Our business email and document storage runs on Google Workspace, provided by Google Ireland Limited; transfers outside the EEA within Google's global infrastructure are supported by Standard Contractual Clauses.
9. Retention and security
| Data | Retention |
|---|---|
| Website enquiries that do not become engagements | 12 months |
| Client contract and engagement records | 6 years from end of engagement |
| Financial and tax records | 6 years (Irish tax and company law) |
| Investigation files — we are controller | 12 months after the report issues, then returned or securely destroyed |
| Investigation files — we are processor | Per the client's documented instruction; returned or deleted on termination |
| Marketing list | Until you unsubscribe; then a suppression record only |
| Server logs | 90 days |
| Cookie consent records | Duration of the consent plus 12 months, to evidence Article 7(1) |
Access is limited to those who need it for the engagement they are working on. We use encryption in transit and at rest, multi-factor authentication on all business accounts, and device encryption. We maintain a documented breach response procedure: notification to the Data Protection Commission within 72 hours where Article 33 applies, and direct notification to affected individuals without undue delay where Article 34 applies.
10. Your rights
You have the right to request access, rectification, erasure, restriction and portability, and to object to processing based on legitimate interest. Where we rely on consent you may withdraw it at any time, without affecting the lawfulness of processing before withdrawal. We respond within one month. There is no charge. Contact: hello@people4people.ie
Your right to object to direct marketing
You have the right to object at any time to the use of your personal data for direct marketing, including any profiling connected to it. This right is absolute: if you object, we must stop, immediately and without exception. You do not need to give a reason. Email hello@people4people.ie or use the unsubscribe link in any message.
We do not carry out automated decision-making or profiling producing legal or similarly significant effects.
11. Complaints
Please contact us first at hello@people4people.ie — we would like the chance to put things right. You may also complain to the supervisory authority at any time:
Data Protection Commission
6 Pembroke Row, Dublin 2, D02 X963, Ireland
www.dataprotection.ie
You have a separate right to an effective judicial remedy under Article 79 GDPR, and may bring a data protection action before the Irish courts under section 117 of the Data Protection Act 2018.
12. Children
Our services are directed at organisations, not at children. We do not knowingly collect personal data from anyone under 16, which is the digital age of consent in Ireland under the Data Protection Act 2018. If you believe a child has provided us with personal data, contact us and we will delete it. Where an investigation concerns a person under 18, we process that data only on the client's documented instruction and with additional safeguards agreed in advance.
13. Artificial intelligence
We do not use artificial intelligence tools to transcribe, summarise, analyse or assess any material gathered in the course of an investigation or an engagement.
14. Third-party links and changes
Our site links to LinkedIn. We are not responsible for how third-party sites handle your data. We review this notice at least every six months and whenever we add a new tool or service. Material changes are flagged at the top of this page for 30 days. Previous versions are available on request.