Privacy Policy
We are committed to protecting your personal data and respecting your privacy. This policy explains what information we collect, why we collect it, how we use it, and your rights under the General Data Protection Regulation (GDPR) and the Data Protection Acts 1988–2018.
Who We Are
Best Practice is a healthcare consultancy and training company based in Galway, Ireland. We work with GP practices and healthcare organisations across Ireland, providing practice management consultancy, training and development, and people support services.
For the purposes of GDPR, Best Practice is the data controller responsible for your personal data collected through this website.
Contact:
Best Practice, Platform94, Mervue Business Park, Galway, Ireland
Email: info@bestpractice.ie
Website: www.bestpractice.ie
What Personal Data We Collect
We collect personal data in the following ways:
| Source | Data collected |
|---|---|
| Contact / enquiry form | Name, email address, phone number (if provided), and the content of your message |
| Email marketing (Kajabi) | Name and email address when you subscribe to receive communications from us |
| Calendly booking | Name, email address, and any information you provide when booking a session or discovery call |
| Kajabi Payments / Stripe | Name, email address, and billing information when you purchase a product or service. Card details are processed directly by Stripe and are not stored by us |
| Cookies & website analytics | Technical data including your IP address, browser type, pages visited, and time spent on the site. See Section 7 for full cookie details |
We do not collect sensitive personal data (such as health information) through this website. Any sensitive information shared in the context of a consultancy or mediation engagement is governed by a separate confidentiality agreement.
Why We Collect Your Data and Our Legal Basis
| Purpose | Legal basis (GDPR Article 6) |
|---|---|
| Responding to an enquiry or contact form submission | Legitimate interests — to respond to your request |
| Sending you marketing emails and updates | Consent — you opted in to receive communications from us |
| Processing a booking via Calendly | Legitimate interests — to fulfil your booking request |
| Processing a payment for a product or service | Contract — necessary to deliver the service you have purchased |
| Improving our website through analytics | Legitimate interests — to understand how our site is used and improve user experience |
Where we rely on consent as our legal basis, you have the right to withdraw that consent at any time. This will not affect the lawfulness of any processing carried out prior to your withdrawal.
How We Use Your Data
We use your personal data only for the purposes for which it was collected. Specifically, we use it to:
- Respond to your enquiries and provide the information or support you have requested
- Send you email communications you have opted in to receive, including updates, newsletters, and information about our services and programmes
- Confirm and manage bookings made through Calendly
- Process payments for products and services purchased through our website
- Improve the performance and content of our website
We will never sell your personal data to third parties. We do not use your data for automated decision-making or profiling.
Who We Share Your Data With
We share your personal data only with trusted third-party service providers who assist us in operating our website and delivering our services. All third parties are required to handle your data securely and in accordance with GDPR.
| Third party | Purpose | Location |
|---|---|---|
| Kajabi | Website hosting, course delivery, email marketing, and payment processing infrastructure | USA (Standard Contractual Clauses apply) |
| Stripe | Secure payment processing | USA (Standard Contractual Clauses apply) |
| Calendly | Appointment and discovery call booking | USA (Standard Contractual Clauses apply) |
Where data is transferred outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, including Standard Contractual Clauses approved by the European Commission.
We do not share your personal data with any other third parties unless required to do so by law.
How Long We Keep Your Data
| Data type | Retention period |
|---|---|
| Enquiry / contact form data | 12 months from the date of your last contact with us, unless an ongoing client relationship is established |
| Email marketing subscribers | Until you unsubscribe or withdraw consent |
| Booking records (Calendly) | 12 months from the date of the appointment |
| Payment and transaction records | 7 years, in line with Irish Revenue requirements |
| Cookie and analytics data | As set out in the individual cookie settings — typically up to 24 months |
When your data is no longer needed, we will delete or anonymise it securely.
Cookies
Our website uses cookies — small text files placed on your device — to help the site function correctly and to understand how visitors use it.
| Cookie type | Purpose |
|---|---|
| Essential cookies | Required for the website to function. These cannot be disabled as they enable core features such as page navigation and secure access to purchased content |
| Functional cookies | Remember your preferences and settings to improve your experience on return visits |
| Analytics cookies | Help us understand how visitors interact with our website so we can improve its content and performance. Data is aggregated and anonymised where possible |
| Third-party cookies | Set by Kajabi, Stripe, and Calendly in connection with their services. These are governed by each provider's own privacy and cookie policies |
You can manage or disable non-essential cookies through your browser settings at any time. Please note that disabling certain cookies may affect the functionality of this website.
Your Rights Under GDPR
Under the General Data Protection Regulation, you have the following rights in relation to your personal data:
- Right of access — You have the right to request a copy of the personal data we hold about you.
- Right to rectification — You have the right to ask us to correct any inaccurate or incomplete data we hold about you.
- Right to erasure — You have the right to request that we delete your personal data, subject to certain legal exceptions.
- Right to restrict processing — You have the right to ask us to limit how we use your data in certain circumstances.
- Right to data portability — You have the right to receive your data in a structured, commonly used format and to transfer it to another organisation.
- Right to object — You have the right to object to our processing of your data where we rely on legitimate interests as our legal basis.
- Right to withdraw consent — Where we process your data on the basis of consent, you may withdraw that consent at any time without affecting prior processing.
To exercise any of these rights, please contact us at info@bestpractice.ie. We will respond within one month of receiving your request, as required under GDPR.
How We Protect Your Data
We take the security of your personal data seriously. We implement appropriate technical and organisational measures to protect your data against unauthorised access, accidental loss, alteration, or disclosure.
These measures include secure hosting through Kajabi, encrypted payment processing through Stripe, and restricted access to personal data within our organisation. Where data is shared with third-party processors, we ensure they meet equivalent security standards.
While we take every reasonable precaution, no method of transmission over the internet is completely secure. In the event of a data breach that poses a risk to your rights and freedoms, we will notify the Data Protection Commission and, where required, you directly, in line with our legal obligations.
Links to Other Websites
Our website may contain links to third-party websites, including Calendly and external resources. Once you leave our website, we are not responsible for the privacy practices of those sites. We encourage you to read the privacy policy of any website you visit.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal obligations. When we make significant changes, we will update the "Last reviewed" date at the top of this page. We encourage you to review this policy periodically.
Continued use of our website following any changes constitutes your acceptance of the updated policy.
How to Make a Complaint
If you have concerns about how we handle your personal data, we ask that you contact us in the first instance so we can address the matter directly. We take all complaints seriously and will respond promptly.
If you remain dissatisfied after contacting us, you have the right to lodge a complaint with the Data Protection Commission (DPC), which is the supervisory authority for data protection in Ireland.
Data Protection Commission
21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland
Website: www.dataprotection.ie
Phone: +353 (0)76 110 4800
Questions about this policy?
If you have any questions about how we handle your personal data, or wish to exercise any of your rights, please get in touch.
Email: info@bestpractice.ie
Post: Best Practice, Platform94, Mervue Business Park, Galway, Ireland
Website: www.bestpractice.ie