Constituency — Terms & Conditions (General)

Controller

For Citizen Case content: the selected Representative (Controller); Philoware acts as Processor.

For Representative account/admin data and website visitor data: Philoware Limited is Controller.

Data Protection Officer: dpo@constituency.ie

A. Privacy Notice

1. What we collect

Account data: name, email, phone, role, organisation.

Case data: issue title/description, location, attachments, status, messages.

Technical data: IP address, device/browser, logs, cookies (see below).

Verification data: ID document details (citizens), deleted after verification with a hash retained for audit for up to 12 months.

2. Why we collect it & lawful bases

Provide the Service (contract / public task for representatives’ work).

Security & fraud prevention (legitimate interests; legal obligation).

Analytics & improvement (legitimate interests; consent where cookies or tracking are non-essential).

Marketing (aggregated/anonymised operational analytics; consent for electronic marketing to individuals).

3. Sharing

With the selected Representative and their authorised staff to progress the Case.

With third-party processors (hosting, email/SMS, security, identity checks).

With authorities where required by law.

4. Retention

Account data: active account + 12 months.

Case data: per Controller instructions; Public Cases may be retained for civic record.

Logs: 12 months. Back-ups: 30 days.

5. Your rights

Access, rectification, erasure, restriction, portability, and objection (including to profiling/analytics where based on consent/legitimate interests).

Requests: dpo@constituency.ie — we respond within 30 days.

6. Security

Hosting on AWS Ireland; encryption in transit and at rest; 2FA; RBAC; regular testing; ISO 27001 programme ongoing.

7. Contact & Complaints

Data Protection Officer: dpo@constituency.ie.

You may complain to the Data Protection Commission (DPC) in Ireland.

B. Cookie & Tracking Policy

1. Purpose

Explains how we use cookies, tags and similar technologies on the website and Platform.

2. Categories

Strictly necessary (always on): session management, load balancing, CSRF, 2FA.

Preferences: language, accessibility.

Analytics (consent-based): Google Analytics 4 via Google Tag Manager (with IP anonymisation).

Marketing (consent-based): Meta Pixel, LinkedIn Insight Tag for campaign attribution and audiences.

3. Consent

We operate prior consent for Analytics and Marketing cookies. On first visit you will see a banner with Accept All / Reject Non-Essential / Customise. You can change preferences at any time via “Cookie Settings”.

4. Retention & Control

Cookie lifetimes vary (session to 24 months). You may block cookies in your browser; parts of the site may not function.