vine-jay
Information on this site is advertising in nature
  • Home
  • Services
  • About
  • Contact

GDPR Compliance

Our commitment to protecting your data rights under European law

Last updated: September 3, 2026

Our GDPR Commitment

vine-jay is committed to full compliance with the General Data Protection Regulation (GDPR). As a company operating in Ireland and serving clients across the European Economic Area, we take our data protection responsibilities seriously. This page outlines how we meet our GDPR obligations and how you can exercise your rights under this regulation.

Data Controller Information

Data Controller: vine-jay Automation Solutions
Registered Address: 47 Harcourt Street, Dublin 2, D02 XY47, Ireland
Data Protection Contact: [email protected]

Lawful Basis for Processing

We process personal data only when we have a lawful basis to do so. Our processing activities are based on:

Consent (Article 6(1)(a))

When you provide your information through contact forms or subscribe to communications, you give us explicit consent to process that data. You may withdraw consent at any time by contacting us.

Contract Performance (Article 6(1)(b))

When you engage our services, we process your data to fulfill our contractual obligations, including implementation, support, and billing.

Legitimate Interests (Article 6(1)(f))

We may process data based on legitimate interests, such as improving our services, preventing fraud, and ensuring network security. We always balance these interests against your rights and freedoms.

Legal Obligation (Article 6(1)(c))

We process certain data to comply with legal requirements, such as tax regulations and financial record-keeping obligations.

Your Rights Under GDPR

The GDPR grants you comprehensive rights regarding your personal data:

Right to Access (Article 15)

You have the right to obtain confirmation of whether we process your personal data and, if so, to receive a copy of that data along with information about how it is processed.

Right to Rectification (Article 16)

You may request correction of inaccurate personal data and completion of incomplete personal data.

Right to Erasure (Article 17)

Also known as the "right to be forgotten," you may request deletion of your personal data in certain circumstances, such as when it is no longer necessary for the purposes for which it was collected.

Right to Restriction of Processing (Article 18)

You may request that we restrict processing of your personal data in specific situations, such as when you contest the accuracy of the data or object to processing.

Right to Data Portability (Article 20)

You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller.

Right to Object (Article 21)

You may object to processing of your personal data based on legitimate interests or for direct marketing purposes.

Rights Related to Automated Decision-Making (Article 22)

You have the right not to be subject to decisions based solely on automated processing that produce legal effects or similarly significantly affect you.

How to Exercise Your Rights

To exercise any of your GDPR rights, please submit a request to [email protected]. We will respond to your request within one month, though this may be extended by two additional months in complex cases. We will always inform you of any such extension.

We may request additional information to verify your identity before processing requests, particularly for access or deletion requests.

Data Protection Measures

We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:

  • Encryption of personal data in transit and at rest
  • Regular security assessments and penetration testing
  • Access controls and authentication requirements
  • Staff training on data protection principles and practices
  • Regular backups and disaster recovery procedures
  • Incident response and breach notification procedures

Data Breach Procedures

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Irish Data Protection Commission within 72 hours of becoming aware of the breach. If the breach is likely to result in a high risk to your rights and freedoms, we will also communicate the breach to you without undue delay.

Data Processing Activities

We maintain records of our processing activities as required by Article 30 of the GDPR. These records include:

  • Categories of personal data processed
  • Purposes of processing
  • Categories of data subjects
  • Recipients of personal data
  • International data transfers and safeguards
  • Retention periods
  • Security measures

Third-Party Processors

When we engage third-party service providers who process personal data on our behalf, we ensure they:

  • Provide sufficient guarantees regarding technical and organizational security measures
  • Process data only on our documented instructions
  • Maintain confidentiality of personal data
  • Assist us in meeting our GDPR obligations
  • Delete or return personal data after the service relationship ends

All processor relationships are governed by written contracts that meet GDPR requirements.

International Data Transfers

When we transfer personal data outside the European Economic Area, we ensure appropriate safeguards are in place, such as:

  • Standard Contractual Clauses approved by the European Commission
  • Adequacy decisions by the European Commission
  • Binding Corporate Rules where applicable

Children's Data

Our services are not directed to children under 16 years of age. We do not knowingly collect or process personal data from children without appropriate parental consent as required by GDPR.

Retention Periods

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, taking into account:

  • Legal and regulatory requirements
  • Contractual obligations
  • Legitimate business interests
  • Your preferences and rights

Specific retention periods are outlined in our Privacy Policy and may vary depending on the type of data and purpose of processing.

Supervisory Authority

Our lead supervisory authority is the Irish Data Protection Commission:

Data Protection Commission
21 Fitzwilliam Square South
Dublin 2, D02 RD28
Ireland
Phone: +353 (0)761 104 800
Email: [email protected]

You have the right to lodge a complaint with the Data Protection Commission or your local supervisory authority if you believe we have not complied with applicable data protection laws.

Updates to GDPR Compliance

We regularly review our data protection practices to ensure ongoing compliance with GDPR requirements. Any material changes to our compliance approach will be communicated through updates to this page and our Privacy Policy.

Contact for Data Protection Matters

For any questions about our GDPR compliance or to exercise your rights, please contact us at:

Email: [email protected]
Subject line: GDPR Request

We will acknowledge receipt of your request within 48 hours and provide a substantive response within one month.

vine-jay

Automating application processing for modern organizations across Ireland and beyond.

Services

  • All Services
  • Document Processing
  • Form Recognition

Company

  • About Us
  • Contact

Legal

  • Privacy Policy
  • GDPR
  • Cookies Policy
  • Terms of Use

Disclaimer: Results from automation implementation may vary depending on your existing systems, data quality, and workflow complexity. Our services are designed to support and enhance your operations but should not replace professional business process consulting where needed. We recommend consulting with your IT department before implementing major automation changes.

© 2026 vine-jay. All rights reserved.