Privacy Policy

Last updated: January 2026

CREW (Comhoibriú CLG) places the highest priority on the protection of personal data and is committed to respecting your privacy. We take our responsibilities under data protection and privacy legislation seriously, including the General Data Protection Regulation (“GDPR”) and Irish data protection law.

This Privacy Policy explains how we collect, use, store, and protect your personal data when you engage with CREW, use our website, participate in our programmes, or interact with us in any other way. It also outlines your rights and how you can exercise them.

  1. Data Controller

Comhoibriú CLG (t/a CREW) is the data controller responsible for your personal data for the purposes of applicable data protection law.

Contact details:
Comhoibriú CLG (t/a CREW)
Cluain Mhuire
Wellpark Road
Galway
H91 8K85,
Ireland

Email: hello@crewdigital.ie

If you have any questions about this Privacy Policy or how we handle your personal data, please contact us using the details above.

  1. Personal Data We Collect

We collect and process personal data that is necessary to deliver our services, manage our community, and meet our legal obligations. This may include:

  • Identity data: name, job title, organisation name
  • Contact data: email address, phone number, postal address
  • Professional data: sector, role, business information
  • Account and membership data: programme participation, attendance, communications preferences
  • Technical data: IP address, browser type and version, device identifiers, pages visited, date and time of visits
  • Marketing and communications data: newsletter subscriptions, event registrations, engagement with communications

We do not knowingly collect special category data unless it is strictly necessary and lawfully permitted.

  1. How We Collect Personal Data

We collect personal data in the following ways:

  • When you subscribe to newsletters, mailing lists, or updates
  • When you apply for or participate in CREW programmes, events, or initiatives
  • When you contact us directly (by email, phone, or online forms)
  • When you visit or browse our website
  • From trusted third parties or partners where appropriate and lawful

Some data is provided directly by you, and some is collected automatically through your use of our website.

  1. Legal Basis for Processing

Under GDPR, we must have a lawful basis for processing your personal data. We rely on one or more of the following:

  • Consent – for example, where you opt in to receive newsletters or marketing communications
  • Contractual necessity – where processing is required to deliver membership services, programmes, or events
  • Legal obligation – where we are required to retain or process data for legal, regulatory, or financial reasons
  • Legitimate interests – where processing is necessary to operate and improve our services, manage relationships, and support the creative enterprise ecosystem, provided your rights do not override these interests
  1. How We Use Your Personal Data

We use personal data to:

  • Deliver and manage CREW services, programmes, and events
  • Communicate with members, participants, partners, and stakeholders
  • Send newsletters, updates, and information relevant to our community
  • Improve our website, services, and user experience
  • Maintain accurate records and meet our legal and governance obligations

You may opt out of marketing communications at any time by using the unsubscribe link in our emails or by contacting us directly.

  1. Cookies and Website Tracking

Our website uses cookies and similar technologies to ensure it functions correctly and to improve user experience.

  • Essential cookies are required for the operation of the website
  • Non-essential cookies (such as analytics or marketing cookies) are only placed on your device with your consent

You can manage or withdraw your cookie preferences at any time via our cookie settings. Further information is available in our separate Cookie Policy.

  1. Third-Party Service Providers

We may engage trusted third-party service providers to support our operations, such as:

  • Email and marketing platforms (e.g. Mailchimp by Intuit)
  • Website hosting and analytics providers
  • Event management or CRM systems

These third parties process personal data only on our instructions and are subject to contractual obligations to protect your data and use it solely for the agreed purposes.

  1. International Data Transfers

Some of our service providers may process personal data outside the European Economic Area (EEA). Where this occurs, we ensure appropriate safeguards are in place, including the use of Standard Contractual Clauses approved by the European Commission or other lawful transfer mechanisms.

  1. Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including legal, accounting, or reporting requirements.

  • Membership and programme data is retained for the duration of engagement and a reasonable period thereafter
  • Marketing data is retained until consent is withdrawn
  • Financial records are retained in line with statutory obligations

When data is no longer required, it is securely deleted or anonymised.

  1. Data Security

We take appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse, or alteration. These measures include access controls, secure systems, and staff confidentiality obligations.

While we strive to protect your personal data, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.

  1. Sharing Your Personal Data

We do not sell personal data. We may share personal data:

  • With service providers acting on our behalf
  • Where required by law or regulatory authorities
  • Where necessary to protect our rights or the rights of others

All sharing is carried out in accordance with data protection law.

  1. Your Data Protection Rights

You have the following rights under GDPR:

  1. The right to access your personal data
  2. The right to rectification of inaccurate or incomplete data
  3. The right to erasure (“right to be forgotten”)
  4. The right to restrict processing
  5. The right to data portability
  6. The right to object to processing
  7. The right to withdraw consent at any time
  8. The right to lodge a complaint with the Irish Data Protection Commission (www.dataprotection.ie)

To exercise any of these rights, please contact us using the details above.

  1. Children’s Data

Our services are not directed at individuals under the age of 16, and we do not knowingly collect personal data from children.

  1. Links to Third-Party Websites

Our website may contain links to third-party sites. We are not responsible for the privacy practices or content of those sites, and we encourage you to review their privacy policies before providing personal data.

  1. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect legal, regulatory, or operational changes. Any updates will be posted on this page, and the “Last updated” date will be revised accordingly. We encourage you to review this policy periodically.

  1. Contact Us

If you have any questions about this Privacy Policy or how we handle your personal data, please contact:

Email: hello@crewdigital.ie

Supporting creative enterprise and driving innovation, entrepreneurship and collaboration for sustainable growth’