Last updated: September 2026
Onyx Crag is committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR). This document outlines how we comply with GDPR requirements and safeguard your information.
We process your personal data on the following legal bases:
As a data subject, you have the following rights:
You may request confirmation of whether we process your personal data and obtain a copy of that data.
You can request correction of inaccurate or incomplete personal information we hold about you.
You may request deletion of your personal data under certain circumstances, such as when the data is no longer necessary for the purposes for which it was collected.
You can request that we limit how we use your personal data in specific situations.
You have the right to receive your personal data in a structured, commonly used format and transmit it to another controller.
You may object to processing of your personal data based on legitimate interests or for direct marketing purposes.
We do not use automated decision making or profiling that produces legal or similarly significant effects.
To exercise any of these rights, contact us at [email protected]. We will respond to your request within one month, though this period may be extended by two additional months if your request is particularly complex.
Onyx Crag acts as the data controller for personal information collected through this website. Our contact details are:
15 Merchant's Quay
Dublin, D02 H657
Ireland
[email protected]
We implement appropriate technical and organizational security measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include encryption, access controls, and regular security assessments.
In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and inform affected individuals without undue delay.
We process and store data within the European Economic Area. Any transfers outside the EEA are conducted in accordance with GDPR requirements, including appropriate safeguards such as Standard Contractual Clauses.
If you believe we have not handled your personal data in accordance with GDPR, you have the right to lodge a complaint with the Data Protection Commission in Ireland or the supervisory authority in your EU member state.
Our services are not directed at individuals under 16 years of age. We do not knowingly collect personal data from children. If you believe we have inadvertently collected such information, please contact us immediately.