Data Protection and Cookies
Data Protection Policy (‘Privacy Notice’)
Introduction
Code in Motion Ltd (collectively, “I” or “we” or “us”) knows you care about how your personal data is used and shared. For Code in Motion to succeed, we need to ensure you can trust us with your personal data.
The following describes how we collect, store, use and disclose your personal data*.
*Personal data is data relating to a living individual who can be identified, or is identifiable, using this data or if this data is used in conjunction with other data that is in Code in Motion’s possession, or could come into its possession.
If you have any questions, comments or concerns about any of this, you can contact us at hello@codeinmotion.ie or at +353 (1) 554 6268.
Below, we describe the types of steps we take to secure your data while it is in our possession.
We then provide more specific detail on how your personal data is collected, stored, used, shared and retained, categorised by the different types of relationships an individual may have with Code in Motion. e.g. You may be just a site visitor, a newsletter subscriber, and/or a client.
Security Controls
Before we discuss the specific ways that we collect, store, use and store your personal data, we will describe the types of broad security controls in place within Code in Motion that provide some level of assurance about how your personal data is secured by Code in Motion.
Device Security
All of the personal data stored on Code in Motion’s computer devices is encrypted. The devices are updated with the latest software and security patches at regular intervals. They are protected with anti-virus, anti-malware and other security layers. Device screens are configured to automatically lock after a short period of inactivity to reduce the risk of unauthorised access. Important data stored on local devices is backed up on a frequent basis and the backups are encrypted.
Account Security
If you know Sam Glynn, you know he is obsessed with Multi-Factor Authentication (MFA). MFA means that one needs more than just a password to log in to an account. We use MFA on all of the IT systems that are used to store or process client data. We also regularly review any login alerts from key systems to reduce the risk of suspicious activity going unnoticed.
Organisational Security
We are fully aware of the things we can, and can’t, do with your data. Sam Glynn’s experience with data protection also means we are very aware of our responsibilities to protect your data.
When others are brought in to work on behalf of Code in Motion, they are brought through data protection and IT security training as part of their on-boarding.
3rd Party Security
As detailed further in the privacy policy below, we only engage 3rd parties who understand their data protection obligations and know how to keep data secure. All are under contractual obligations to comply with GDPR and to only use your data in ways that we have instructed.
Email Security
Most of our conversations with clients occur using email. Our emails are stored in Microsoft’s European data centres and the Code in Motion email environment is secured in line with security best practices.
Document Sharing Security
If we need to share information that includes data of a sensitive nature, we will always do so in a secure way. For example:
- The information will be stored in a file that is encrypted using AES encryption, or shared via a secure file sharing platform.
- Passwords will be communicated over a different channel to the information itself – e.g. We may send the password to you via a phone call or message.
Website visitors
The following describes the personal data we collect, store, use, share, and retain about site visits and site visitors.
What personal data is collected?
For security monitoring: Some or all of the following about site visitor: Originating Internet Protocol (IP) address, proxy IP address, url accessed on codeinmotion.ie, complete http header, http request body.
For site page views: Code in Motion collects data about page views but not about site visitors. No personal data is collected. All data collected is aggregate data that cannot be tied back to one individual. For the avoidance of doubt, Code in Motion does not not collect personal data such as your computer’s Internet Protocol address (e.g. IP address), browser version, unique device identifiers and other diagnostic data.
What is the purpose of this data collection?
For security monitoring – To try to protect the website from attackers and unauthorised / unusual activity.
For site page views – To understand how the site is used by collecting page view data. This data is only about the number of page views. It is not personal data.
What’s the lawful basis for this?
Legitimate interest (protecting the website; understanding site usage).
How do we use this data?
This data is collected and analysed by security components that are protecting the website.
Page view data is collected by, and analysed with, the Fathom Analytics platform.
Who could see this data?
This data could be accessible to specific data processors involved in running this website – e.g. the website hosting provider, website security providers, and analytics provider.
How do we protect this data?
Alongside the ‘Security Controls’ described earlier, there are other components / configurations in place to secure the data:
- Data Processing Agreements are in place with all 3rd parties with access to personal data.
- Multi-factor authentication is activated on all admin accounts , reducing the likelihood of a successful breach.
- Email alerts are sent to us when any sign-ins occur on the site.
- Security layers monitor and protect the site from hacking attempts.
- The software on the site is updated on a frequent basis.
How long do we keep this data?
The maximum length of time this IP address data is retained is 90 days after Code in Motion’s contract with its hosting provider ends.
Scorecard Users
The following describes the personal data we collect, store, use, share, and retain about anyone who uses the free score cards accessible from the Code in Motion site.
What personal data is collected?
For security monitoring: Some or all of the following about site visitor: Originating Internet Protocol (IP) address, proxy IP address, url accessed, complete http header, http request body.
For score card reporting: Your email address, your IP address, your answers, and how long you took to answer each question.
What is the purpose of this data collection / How is the data used?
For security monitoring – To try to protect the service from hackers and unauthorised / unusual activity.
For score card reporting – To produce your score card and to email the results to you, so you can access the results again later. To help us understand where you may need help (in case you follow up with us about the score). At an aggregate level, to help us identify the common gaps / issues, and to identify any questions that seem to confuse people.
What’s the lawful basis for this?
Legitimate interest (protecting the service; producing your score card; informing our future conversations).
Who could see the data?
This data is accessible to specific data processors involved in running this scorecard service – e.g. Hyper Targeted Marketing Limited (provider of the ScoreApp.com platform).
Does the data leave the EEA?
Yes.
- Hyper Targeted Marketing Limited (provider of the ScoreApp.com platform) may transfer your personal data outside of the EEA. During such transfers, ScoreApp commits to implementing an appropriate level of protection.
How long is the data kept?
Unless you contact us about your score card results or you ask for your results to be retained, your email address will be removed from the score card platform 90 days after you completed the score card.
From that point, any data remaining on the score card platform (e.g. your answers) will no longer be associated with your email address or any other piece of data that someone could link back to you.
In theory, this means the data is anonymised. Whether it truly is or not, let’s just say it will be very difficult for someone to figure out that these answers came from you.
Email Subscribers
The following describes the personal data I collect, store, use, share, and retain about people who have signed up for my emails (e.g. email courses; newsletters).
What personal data do I collect?
First name and email address. I may also be able to derive your employer from your email address.
Why do I collect this?
To send you emails and updates – e.g. whenever a new blog post is published on the site.
What’s my lawful basis for this?
Consent – Anyone on the list has given their consent to be on the list.
If you withdraw your consent, your personal data will remain on MailChimp (as an unsubscribed user) until the end of that calendar year, on the basis of legitimate interest – See the ‘Retention’ section for more information.
How do I use this data?
I use this to send my newsletter and blog updates to interested individuals.
Who could access this data?
This data is accessible to MailChimp. This is the service I use to manage my subscriber list.
When you subscribe, I receive an email to notify me. Your details are contained in this email and retained on Microsoft Office 365.
Does the data leave the EEA?
Yes. MailChimp is based in the USA. It is certified under the EU-approved “EU-US Privacy Shield” to ensure the data remains protected while it is outside of the EEA.
How do I protect this data?
Alongside the ‘Security Controls’ described earlier, there are other components / configurations in place to secure the data:
- Data Processing Agreements are in place with MailChimp to protect the data.
- Two-factor authentication is activated on all Code in Motion accounts on MailChimp.
- Email alerts are sent to me when any signins occur with these accounts.
How long do I keep this data?
The data is used on MailChimp to send you updates by email until you withdraw your consent.
At this point, the data remains on MailChimp until the end of that calendar year, at which point I delete all those who have unsubscribed from the mailing list. My lawful basis for keeping it until the end of that year is legitimate interest – To let me see at what point I lost subscribers so I can understand the content that is getting good or bad feedback.
The email sent to my email account when you sign up to the list is retained until the end of that calendar year (i.e. no later than the MailChimp retention period).
Do you have concerns about MailChimp?
If you would like to receive my email newsletters etc but do not want your personal data going to MailChimp, let me know and I’ll find another way to keep you updated.
People who contact me or who I contact
The following describes the personal data I collect, store, use, share, and retain about people (who are not and never were clients or employees / agents of clients) that contact me or who I contact in my day-to-day business.
What personal data do I collect?
One or more of: Name, email address, phone number, job title, employer. Possibly other information published online (e.g. LinkedIn profile)
What is the purpose of this processing?
To grow and support my business; to respond to potential clients; to build networks with others in the industry.
What is my lawful basis for this processing?
Legitimate interest – I have a legitimate interest to grow my business.
How do I use this data?
Mainly to understand how I can help you, or how we could possibly help each other.
How do I protect this data?
Alongside the ‘Security Controls’ described earlier, there are other components / configurations in place to secure the data. For example:
- Data Processing Agreements are in place with any online services that I use to process your data.
- Multi-Factor Authentication (MFA) is activated wherever possible to reduce the likelihood of a hack.
How long do I keep this data?
For a maximum of 5 years after our last interaction / conversation.
Clients
The following describes the personal data I collect, store, use, share, and retain about the employees and other individuals connected to a client of Code in Motion.
What personal data do I collect?
One or more of: Name, email address, phone number, job title, employer. Possibly other personal data that these individuals (or their colleagues or employers) have provided to me in the course of the contract.
What is the purpose of this processing?
To perform a contract between Code in Motion and one of its clients.
What’s my lawful basis for this?
Legitimate interest. It is in the legitimate interest of Code in Motion and its client to perform the contract.
It is also usually in the individual’s legitimate interest – e.g. to ensure I can communicate with them.
How do I use this data?
I use the data for the purposes of performing the contract of work that is in place between Code in Motion and the client.
Who are the main 3rd parties who could also access your personal data?
- Microsoft: Most client work is communicated over email and my email provider is Microsoft.
- Accounting firms: I use accountants to help with company financials. They seldom need the personal data of clients but it may happen – e.g. if a client is a sole trader, their ‘business name’ is their own name and so counts as personal data.
- Legal firms or debt collection agencies: If a client is not complying with payment terms, the client contract allows Code in Motion to engage with these 3rd parties to pursue payment. Personal data about one or more employees working for the client (e.g. contact details of an employee working in the client’s finance department) may be share in such a scenario.
How do I protect this data?
Alongside the ‘Security Controls’ described earlier, there are other components / configurations in place to secure the data. For example:
- Data Protection Agreements are in place with relevant 3rd parties.
- Multi-Factor Authentication is activated wherever possible to reduce the likelihood of a breach.
How long do I keep this data?
Personal data needed for the performance of the contract is retained for a period of 7 years after the contract ends, in line with contract law and the statute of limitations.
Other Notes
Business Transfers: I may choose to buy or sell assets, and may share and/or transfer personal data as part of such transactions. Also, if I (or our assets) are acquired, or if I go out of business, enter bankruptcy, or go through some other change of control, your personal data could be one of the assets transferred to or acquired by a third party.
Protection of Code in Motion and Others: I reserve the right to access, read, preserve, and disclose any information as necessary to comply with law or court order; enforce or apply my agreements with you and other agreements; or protect the rights, property, or safety of Code in Motion, my employees, my customers, or others.
Disclosures for National Security or Law Enforcement: Under certain circumstances, I may be required to disclose your personal data in response to valid requests by public authorities, including to meet national security or law enforcement requirements.
Cookie Policy
The website does not use cookies, because the site does not use Google website analytics tools, ad networks, or other trackers.
As mentioned earlier, Code in Motion collects basic site usage information (e.g. number of page views) at an aggregate level through Fathom Analytics, a privacy-centric web analytics service. This service does not use cookies or other tracking technologies that retain your personal data. More information about Fathom Analytics is accessible from https://usefathom.com/.
Third-party links
Occasionally, I may include links to third-party products or services on my website. While I will only mention trustworthy sites, these third-party sites have separate and independent privacy policies. I have no responsibility or liability for the content and activities of these linked sites. Having said that, I seek to protect the integrity of my site and welcome any feedback about these sites.
Your rights
While I have personal data about you, you have certain rights. These include:
Right to access
You may request a copy of all personal data held by Code In Motion about you.
Right to rectify
You have the right to ask Code in Motion to correct any inaccuracies in the personal data held about you.
Right to erasure
In certain circumstances, you have the right to ask that I erase any personal data I am processing about you.
For example, if I have your data because you gave me your consent, you are now withdrawing consent and I have no other lawful basis for keeping the data.
Please note that I may still be allowed to retain and use your information. For example, if it is necessary to comply with a legal obligations, resolve disputes, enforce our agreements, or defend / establish a legal claim.
Right to restrict
In certain circumstances, you have the right to request that I restrict the processing of your personal data.
Right to object
In certain circumstances, you have the right to object to my processing of your personal data. This is especially true if I am processing your data on the basis of Code in Motion’s legitimate interest.
Right not to be subjected to automated decision making
You have the right not to be subjected to automated decision making where the decision has legal or significant effects. However, I don’t think I have such automated decision making processes in Code in Motion.
Right to withdraw consent
Where I am processing your personal data on the basis of your consent, you have the right to withdraw your consent at any time.
For example, if I am sending you marketing emails, you can withdraw your consent immediately by clicking the UNSUBSCRIBE link in the footer of the email.
How to exercise your rights
Please contact me at hello@codeinmotion.ie and provide me with as much information as possible to enable me to respond to your request.
Right to complain
If you believe Code in Motion is breaching your data protection rights, you have the right to complain to the data protection regulator.
Code in Motion is established in Ireland and is regulated by Ireland’s Data Protection Commission (Click here to visit the regulator’s website).
Contact me
If you have any questions about this privacy or cookie notice, please contact me by emailing hello@codeinmotion.ie
Changes to this notice
Any changes to this Privacy Notice will be posted on this website so you are always aware of the personal data I collect, use, store, disclose and retain.
If at any time I decide to use your personal data in a manner significantly* different from that stated in this Privacy Notice or otherwise stated to you at the time it was collected, I will note this significant* change below. I will also notify you if you have asked to be notified of such changes.
(* I don’t regard changes that just clarify meaning or improve explanations as significant).
History of Significant Changes (over the last 3 years)
June 2023: Reviewed and updated content. Removed third parties that are no longer in use.
January 2023: Added reference to the score cards that are now available on my website.
1st February 2021: Added reference to UseFathom.com, a privacy-centric website analytics platform that is now being used on the site. Removed reference to EverNote.
6th June 2020: Changed page title and heading. Adjusted some sub-headings. No significant content changes.