Legal

Privacy Policy

Last updated: August 2026

EFH (Business Consultants) Ltd is committed to protecting your personal data and respecting your privacy. This policy explains how we collect, use, and safeguard your information in accordance with the General Data Protection Regulation (GDPR) and the Data Protection Act 2018.

1. Who We Are

Data Controller: EFH (Business Consultants) Ltd

Managing Director: Eugene F. Healy MA, MIEI

Address: Trim, Co. Meath, Ireland

Email: [email protected]

Phone: +353 86 814 4525

2. What Personal Data We Collect

We may collect and process the following categories of personal data:

  • ▸Identity data — name, job title, company name
  • ▸Contact data — email address, telephone number, postal address
  • ▸Correspondence data — emails, letters, and records of communications
  • ▸Engagement data — information you provide when booking a consultation or submitting an enquiry
  • ▸Case-related data — employment, HR, or legal information provided in the course of a consultancy engagement

We do not collect special category data (e.g. health, racial or ethnic origin, political opinions) unless strictly necessary for a specific engagement, and only with your explicit consent.

3. How We Collect Your Data

We collect data through:

  • ▸Direct interactions — contact forms, email, telephone, or in-person meetings
  • ▸Consultancy engagements — information provided during the course of our advisory work
  • ▸Referrals — data passed to us by third parties who have referred you to EFH

4. Legal Basis for Processing

We process your personal data on the following legal bases under Article 6 GDPR:

  • ▸Contract — processing is necessary to perform or prepare a consultancy contract with you
  • ▸Legitimate interests — to respond to enquiries, manage our business relationship, and improve our services
  • ▸Legal obligation — where processing is required to comply with Irish or EU law
  • ▸Consent — where you have given explicit consent, which you may withdraw at any time

5. How We Use Your Data

We use your personal data to:

  • ▸Respond to your enquiries and provide consultancy services
  • ▸Manage our ongoing business relationship with you
  • ▸Prepare and deliver reports, correspondence, and advice
  • ▸Meet our legal and regulatory obligations
  • ▸Send relevant information about our services where you have consented

We will never sell, rent, or share your personal data with third parties for their own marketing purposes.

6. Data Sharing

We do not share your personal data with third parties except where necessary to deliver our services or comply with legal obligations. Where sharing is required, it may include:

  • ▸Professional advisors (legal counsel, barristers) engaged on your behalf
  • ▸Regulatory bodies (WRC, Labour Court, Data Protection Commission) where required by law
  • ▸IT service providers who process data on our behalf under binding data processing agreements

All third parties are required to respect the security of your data and to treat it in accordance with the law.

7. Data Retention

We retain personal data only for as long as necessary for the purposes for which it was collected, or as required by law. Retention periods are as follows:

  • ▸Consultancy engagement records — 7 years from the end of the engagement
  • ▸General correspondence and enquiries — 2 years from last contact
  • ▸Legal or regulatory case records — for the duration of any proceedings plus 7 years

After applicable retention periods, data is securely deleted or anonymised.

8. Your Rights Under GDPR

Under GDPR and the Data Protection Act 2018, you have the following rights:

  • ▸Right of access — to obtain a copy of the personal data we hold about you
  • ▸Right to rectification — to correct inaccurate or incomplete data
  • ▸Right to erasure — to request deletion of your data where there is no lawful basis for retention
  • ▸Right to restriction — to limit how we process your data in certain circumstances
  • ▸Right to data portability — to receive your data in a structured, machine-readable format
  • ▸Right to object — to processing based on legitimate interests or for direct marketing
  • ▸Right to withdraw consent — at any time, without affecting the lawfulness of prior processing

To exercise any of these rights, contact us at [email protected]. We will respond within one month.

9. Data Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, or disclosure. These include:

  • ▸Secure email and document storage systems
  • ▸Access controls limiting data to authorised personnel only
  • ▸Regular review of data handling practices

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Data Protection Commission within 72 hours and you directly where required.

10. Complaints

If you are unhappy with how we have handled your personal data, please contact us in the first instance at [email protected].

You also have the right to lodge a complaint with the Data Protection Commission (DPC), the Irish supervisory authority for data protection:

Data Protection Commission

21 Fitzwilliam Square South, Dublin 2, D02 RD28

www.dataprotection.ie

LoCall: 1800 437 737

11. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal obligations. The current version will always be available on this page. We encourage you to review it periodically.

Questions About Your Data?

Contact us directly and we will respond within one business day.

[email protected]