GDPR Compliance

Last updated: September 3, 2026

Our Commitment to GDPR

ivory-ravine is fully committed to compliance with the General Data Protection Regulation (EU) 2016/679. As a data controller and processor, we have implemented comprehensive measures to ensure the protection of personal data and respect for individual privacy rights.

Data Processing Principles

We adhere to the following GDPR data processing principles:

Your Rights Under GDPR

As a data subject, you have the following rights under GDPR:

Right of Access (Article 15)

You have the right to obtain confirmation as to whether your personal data is being processed and, if so, access to that data and information about how it is being processed.

Right to Rectification (Article 16)

You can request correction of inaccurate personal data and completion of incomplete data.

Right to Erasure (Article 17)

Under certain circumstances, you can request deletion of your personal data, including when the data is no longer necessary for its original purpose or you withdraw consent.

Right to Restriction of Processing (Article 18)

You can request that we limit processing of your personal data in specific situations, such as when you contest the accuracy of the data.

Right to Data Portability (Article 20)

You can receive your personal data in a structured, commonly used, and machine-readable format and transmit it to another controller.

Right to Object (Article 21)

You can object to processing based on legitimate interests or for direct marketing purposes.

Rights Related to Automated Decision-Making (Article 22)

You have the right not to be subject to decisions based solely on automated processing that produces legal or similarly significant effects.

How to Exercise Your Rights

To exercise any of your GDPR rights, please submit a request to [email protected]. Include sufficient information to verify your identity and specify which right you wish to exercise. We will respond to your request within one month, though this period may be extended by two additional months for complex requests.

Data Processing Activities

We maintain detailed records of processing activities, including:

Data Protection Officer

For questions specifically related to data protection and GDPR compliance, you may contact our data protection team at [email protected].

Security Measures

We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:

Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. If the breach is likely to result in a high risk to your rights, we will also communicate the breach to you without undue delay.

Data Processing Agreements

When we act as a data processor for our clients, we enter into data processing agreements that specify the subject matter, duration, nature, and purpose of processing, as well as the obligations and rights of both parties in accordance with Article 28 GDPR.

International Data Transfers

Any transfer of personal data to countries outside the European Economic Area is conducted in accordance with Chapter V of GDPR, using appropriate safeguards such as Standard Contractual Clauses, adequacy decisions, or other legally recognized transfer mechanisms.

Privacy by Design and Default

We implement data protection principles into all our systems and processes from the design stage. By default, we process only the personal data necessary for each specific purpose and ensure appropriate security levels.

Supervisory Authority

Our lead supervisory authority is the Data Protection Commission of Ireland. You have the right to lodge a complaint with this authority or with the supervisory authority in your EU member state if you believe we have not complied with GDPR requirements.

Data Protection Commission
21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland
Website: dataprotection.ie

Updates to This Information

We may update this GDPR compliance information to reflect changes in our practices or legal requirements. Material changes will be communicated through appropriate channels.