Privacy Policy

This Privacy Policy explains how personal data is processed, protected, and managed across the Platform in accordance with GDPR and the Irish Data Protection Act 2018.

1. Data Controller Identification and Regulatory Basis

Processing of personal data in connection with the Platform is carried out in accordance with Regulation (EU) 2016/679 ("GDPR") and the Irish Data Protection Act 2018.

1.1. Citizen Case Content

For personal data submitted in relation to individual citizen cases, the selected Representative acts as the Data Controller. The Representative determines why the case information is processed, how it is used, and how long it is retained in the exercise of official public functions. Philoware Limited (T/A Constituency) acts solely as Data Processor in respect of such Case Content and processes such data only on documented instructions.

1.2. Representative Account Data and Website Visitor Data

For Representative account registration data, platform administration data, analytics data, contact form submissions, IP logs, and system security logs, Philoware Limited (T/A Constituency) acts as Data Controller such that it independently determines the purposes and means of processing such data for account administration, cybersecurity, fraud prevention, regulatory compliance, and platform performance monitoring.

2. Categories of Personal Data

Collection of the following data is limited to what is technically necessary to operate, secure, and improve the Platform and is not used for behavioural advertising, viz:

2.1. Citizen Case Content

The following categories of personal data may be collected when a Citizen submits a Case: full name; email address; residential address or constituency location; telephone number (if voluntarily provided); case narrative content; attachments such as correspondence, photographs or supporting documents; information relating to public services; and any personal data voluntarily disclosed by the Citizen within the Case. Philoware Limited (T/A Constituency) does not independently determine the content of such data and does not repurpose it.

2.2. Representative Account Data

The following information may be collected by Constituency: Full name; official email address; official title; constituency affiliation; login credentials (hashed password and authentication tokens); IP address at registration; two-factor authentication data; and system access logs.

2.3. Website Visitor Data

The following information may be collected by Constituency: IP address; browser type and version; device type; operating system; pages visited; timestamps; referring URLs; cookie identifiers; and analytics event data collected through privacy-compliant analytics tools.

3. Purpose Limitation, Data Minimisation and Retention

Each Controller identified in Section 1 shall ensure that personal data is collected for specified, explicit and legitimate purposes and not further processed in a manner incompatible with those purposes, in accordance with applicable laws.

3.1. Citizen Case Content

For Citizen Case Contents, case data is processed for the purpose of reviewing, responding to, escalating, forwarding, or otherwise addressing the matter raised by the Citizen in the exercise of official public functions.

3.2. Representative Account and Administrative Data

For Representative Account and Administrative Data, account data is processed to create and manage user accounts, authenticate access, prevent unauthorised access, maintain audit trails, ensure cybersecurity, comply with statutory obligations, and respond to regulatory requests.

3.3. Website Visitor Data

For Website Visitor Data, it is processed to monitor website functionality, detect security threats, maintain system stability, and generate aggregated analytics reports.

4. Export and External Processing of Case Data

Where functionality is made available, Case data may be accessed, exported, or downloaded in PDF or similar format. Any such access, export, or download may result in the processing of personal data outside the Platform environment. The Company does not control or monitor the processing of Case data outside the Platform and shall not be responsible for any use of such data beyond the Platform environment. All processing of Case data, whether within or outside the Platform, must be carried out in accordance with applicable laws, and must be limited to lawful and compatible purposes for which the data was originally collected.

5. Data Retention Periods

In accordance with Storage Limitation Principle under existing laws, the following are the data retention periods:

5.1. Citizen Case Content

Retention is determined by the Representative acting as Controller. In the absence of a specific statutory retention obligation, Case data will not be retained longer than seven (7) years from closure of the Case, unless required for legal proceedings or statutory compliance.

5.2. Representative Account Data

Representative account data shall be retained for the duration of the account and for seven (7) years thereafter for audit, regulatory, and limitation period.

5.3. Security Logs and Technical Logs

System logs, access logs, and IP logs are retained for twelve (12) months for cybersecurity and incident investigation purposes, unless required for longer retention in connection with an identified security incident.

5.4. Analytics Data

Analytics data is retained in aggregated or pseudonymised form for up to twenty-four (24) months.

6. Transparency and Information at Collection

Where personal data is collected directly from Citizens through the Platform interface, this Privacy Policy is made available at the point of submission. When a Representative receives personal data indirectly, such as in the case of walk-in submissions in relation with the specific terms under the Terms of Service, the Representative is responsible for compliance, including informing the individual about the processing of their data. This includes providing information for: (i) the identity and contact details of the Controller; (ii) the purposes and legal basis of processing; (iii) the categories of personal data concerned; (iv) any recipients or categories of recipients; (v) the applicable retention period; (vi) the individual's data protection rights; (vii) the right to lodge a complaint with a supervisory authority; and (viii) the source of the personal data. Philoware Limited (T/A Constituency) acts solely as a Data Processor and, where required under its contract with the Representative, will assist the Representative in meeting such transparency obligations.

7. Data Subject Rights

Citizens have the following rights: ● Right of access to obtain confirmation and a copy of personal data. ● Right to rectification of inaccurate data. ● Right to erasure. ● Right to restriction of processing. ● Right to data portability where processing is based on contract or consent. ● Right to object to processing based on legitimate interests or public task. ● Right not to be subject to solely automated decisions producing legal or similarly significant effects. Requests concerning Citizen Case Content must be addressed to the relevant Representative as Data Controller. All requests will be responded to within one (1) month.

8. Data Protection Officer and Contact Details

Philoware Limited may be contacted at: Philoware Limited trading as Constituency PhilHQ, Foxford, Co. Mayo, Ireland F26PP40 Email: info@constituency.ie Data Protection Contact: dpo@constituency.ie Where the Representative acts as Controller, the Citizen should contact the Representative directly using the official contact details provided in the Case interface.

9. International Data Transfers

Where personal data is transferred outside the European Economic Area (EEA), such transfers will take place only where appropriate safeguards are in place to ensure that the data continues to receive a level of protection equivalent to that required under EU data protection law. This includes transfers to countries formally recognised as providing an adequate level of protection, or transfers made subject to approved contractual safeguards. Any third-party service providers engaged by Philoware Limited (T/A Constituency) are contractually required to implement appropriate technical and organisational measures to protect personal data in accordance with applicable data protection laws.

10. Automated Decision-Making and Profiling

The Platform does not conduct automated decision-making that produces legal or similarly significant effects in respect of Citizen Case Content. Technical filtering tools are used solely for spam detection, abuse prevention, and cybersecurity monitoring.

11. Security Breach, Notification, and Supervisory Authority

Philoware Limited (T/A Constituency) implements encryption in transit (TLS), role-based access controls, multi-factor authentication, encrypted storage, access logging, and periodic security reviews. In the event of a personal data breach affecting Citizen Case Content, Philoware Limited (T/A Constituency) shall notify the relevant Representative without undue delay. The Representative, as Controller, is responsible for notifying the Irish Data Protection Commission where required under existing laws. Data subjects have the right to lodge a complaint with: Data Protection Commission 21 Fitzwilliam Square South Dublin 2, D02 RD28, Ireland Website: https://www.dataprotection.ie

12. Post-Resolution Confidentiality of Data

Upon resolution of a Case, its treatment shall depend on its classification at the time of submission. Personal data contained in Private Cases shall remain confidential and shall not be disclosed, published, or made publicly accessible by the Platform, except where the data subject has provided explicit consent or where disclosure is required by applicable law, legal process, or statutory obligation. Personal data contained in Public Cases may remain accessible following resolution and may continue to be indexed, archived, or disseminated by third parties beyond the control of the Platform, and may be retained or displayed for transparency, civic engagement, or informational purposes, subject to applicable law and the exercise of data subject rights. The Platform may use anonymised or aggregated information derived from Cases for statistical, operational, or service improvement purposes, provided that no individual is identifiable. Nothing in this Section shall restrict disclosure required for compliance with legal obligations or for the establishment, exercise, or defence of legal claims.