Last updated: September 3, 2026
ivory-ravine is fully committed to compliance with the General Data Protection Regulation (EU) 2016/679. As a data controller and processor, we have implemented comprehensive measures to ensure the protection of personal data and respect for individual privacy rights.
We adhere to the following GDPR data processing principles:
As a data subject, you have the following rights under GDPR:
You have the right to obtain confirmation as to whether your personal data is being processed and, if so, access to that data and information about how it is being processed.
You can request correction of inaccurate personal data and completion of incomplete data.
Under certain circumstances, you can request deletion of your personal data, including when the data is no longer necessary for its original purpose or you withdraw consent.
You can request that we limit processing of your personal data in specific situations, such as when you contest the accuracy of the data.
You can receive your personal data in a structured, commonly used, and machine-readable format and transmit it to another controller.
You can object to processing based on legitimate interests or for direct marketing purposes.
You have the right not to be subject to decisions based solely on automated processing that produces legal or similarly significant effects.
To exercise any of your GDPR rights, please submit a request to [email protected]. Include sufficient information to verify your identity and specify which right you wish to exercise. We will respond to your request within one month, though this period may be extended by two additional months for complex requests.
We maintain detailed records of processing activities, including:
For questions specifically related to data protection and GDPR compliance, you may contact our data protection team at [email protected].
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. If the breach is likely to result in a high risk to your rights, we will also communicate the breach to you without undue delay.
When we act as a data processor for our clients, we enter into data processing agreements that specify the subject matter, duration, nature, and purpose of processing, as well as the obligations and rights of both parties in accordance with Article 28 GDPR.
Any transfer of personal data to countries outside the European Economic Area is conducted in accordance with Chapter V of GDPR, using appropriate safeguards such as Standard Contractual Clauses, adequacy decisions, or other legally recognized transfer mechanisms.
We implement data protection principles into all our systems and processes from the design stage. By default, we process only the personal data necessary for each specific purpose and ensure appropriate security levels.
Our lead supervisory authority is the Data Protection Commission of Ireland. You have the right to lodge a complaint with this authority or with the supervisory authority in your EU member state if you believe we have not complied with GDPR requirements.
Data Protection Commission
21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland
Website: dataprotection.ie
We may update this GDPR compliance information to reflect changes in our practices or legal requirements. Material changes will be communicated through appropriate channels.