Data Privacy Statement
1. Who We are
We are Tipperary Credit Union Ltd (“we” or “us”). We are committed to protecting and respecting your privacy. When we ask you for personal information online it will only be in response to you requesting or using one of our online products or services.
This Privacy Statement explains how we collect, use, share, retain and protect personal data, and outlines your rights under the General Data Protection Regulation (GDPR) and applicable Irish data-protection law.
We are a data controller for the purpose of the General Data Protection Regulation (GDPR).
2. The personal data we collect
We may collect personal data directly from you, from your use of our services, or from third parties where it is permitted by law. This may include:
- Identity and contact data: name, address, date of birth, contact details, identification documents and membership details.
- Financial and transaction data: account details, payment information, savings, loans, transactions, income, expenditure and repayment information.
- Credit and lending data: information needed to assess applications, affordability, eligibility, creditworthiness, fraud risk and debt recovery.
- Communications data: correspondence, service requests, complaints and recordings of telephone calls.
- Online and technical data: IP address, device and browser information, operating system, website usage, connection speed, and visit dates and duration.
- Marketing preferences: your communication preferences and permissions relating to marketing.
- We may receive personal data from joint account holders, authorised representatives, credit-reference agencies, fraud-prevention bodies, service providers, regulators and other organisations where necessary and lawful
3. What we do with your information
We process information held about you in the following ways:
- to provide credit union and other related services, products and facilities to you;
- to assess eligibility and credibility for the services, products and facilities we offer;
- to implement any contracts, we have entered into with you; and
- to conduct credit searches with credit reference agencies in order to provide credit facilities and, where necessary, for fraud prevention and debt recovery.
- to comply with legal obligations.
We may also use information about you to notify you about changes to our services to which you have subscribed or to provide you with information about products or services that you request from us or, where you have agreed to us doing so, which we feel may interest you.
We may use anonymised or statistical information to analyse our website and services and to make improvements or other adjustments to them.
Where we rely on consent, you may withdraw it at any time. Withdrawal will not affect the lawfulness of processing carried out before consent was withdrawn.
4. Where we store your personal information
It is possible that some of the information about you that we hold may be transferred to, and stored at, a destination outside the European Economic Area (“EEA”). It may also be processed by one of our suppliers or someone else operating outside the EEA. For instance, if it is necessary to do so to complete a transaction, your
personal information (e.g. name and account details) may be sent to a third party or one of our contracted suppliers outside the EEA. The data processing companies
commissioned by Tipperary Credit Union to receive your data are contractually obligated to keep your data confidential and to process it only in the context of
service provision.
By submitting your personal data, you agree to this transfer, storing or processing.
We will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this privacy statement.
5. How long we keep personal data
We retain personal data only for as long as necessary for the purpose for which it was collected, including to meet legal, regulatory, accounting, tax, fraud-prevention and record-keeping requirements.
Retention periods depend on the type of data and service involved. When determining retention periods, we consider the nature of the information, the purpose of processing, legal and regulatory requirements, limitation periods and the need to resolve disputes. When information is no longer required, it will be securely deleted, anonymised or otherwise disposed of. Our retention policy clearly identifies the regulatory requirement retention periods.
6. Cookies and online services
Our website uses cookies and similar technologies to operate securely, remember preferences, understand website use and improve services.
- Essential cookies are necessary for the website or online services to function.
- Optional analytics or similar cookies are used only in accordance with applicable consent requirements.
You can manage cookie preferences through our cookie settings tool and, in some cases, through your browser settings. Blocking essential cookies may affect the availability or performance of certain parts of our website or CU Online services.
7. Security of CU Online and your information
We use appropriate technical and organisational measures to protect personal data, including secure servers, access controls and encryption for payment transactions through CU Online.
To help keep your account secure:
- keep your username, password, PIN and security devices confidential;
- do not share security credentials with anyone;
- log out of CU Online and your online account when you have finished; and
- use up-to-date devices, software and security protections.
While we take reasonable steps to protect personal data, transmission of information over the internet carries inherent risks.
8. Your data-protection rights
Subject to applicable legal conditions and exemptions, you have the right to:
- request access to your personal data;
- request correction of inaccurate or incomplete personal data;
- equest deletion of personal data in certain circumstances;
- request restriction of processing in certain circumstances;
- object to processing based on legitimate interests, including direct marketing;
- receive personal data you provided to us in a portable format, where applicable;
- withdraw consent where processing is based on consent; and
- make a complaint to the Data Protection Commission.
To stop direct marketing, use the unsubscribe option in a marketing message or contact us at dpo@tipperarycu.ie.
To exercise any of your rights, contact our Data Protection Officer at dpo@tipperarycu.ie.
We may need to verify your identity before responding to your request.
9. Changes to our Privacy Statement
Any changes we may make to our privacy statement in the future at our sole discretion will be posted on this page from time to time.
10. Contact Us
Questions, comments and requests regarding this privacy statement are welcomed and should be addressed to dpo@tipperarycu.ie.
