Legal
GDPR & Data Protection Policy
This GDPR & Data Protection Policy explains how Abbey Blue Legal Ltd, trading as Abbey Blue Formations, processes personal data in compliance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and Irish data protection law.
Abbey Blue Formations
GDPR & Data Protection Policy
This policy applies to all personal data processed through our websites, services, communications, and internal systems.
Data Controller
Data Controller: Abbey Blue Legal Ltd
Trading as: Abbey Blue Formations
Address:
49 North Main StreetWexford TownCo. WexfordY35 YT44IrelandWebsites:
- www.abbeybluelegal.ie
- www.abbeyblueformations.ie
Abbey Blue Legal Ltd determines the purposes and means of processing personal data.
Regulatory Status
Abbey Blue Legal Ltd is registered in Ireland as a Trust or Company Service Provider (TCSP) and is subject to anti-money laundering, counter-terrorist financing, and data protection obligations under Irish and EU law.
Personal Data We Process
We may process the following categories of personal data:
- Identity data (name, date of birth, nationality)
- Contact details (address, email, telephone number)
- Business and company information
- Identification and verification documents (for AML/KYC purposes)
- Financial and billing information
- Correspondence and communications
- Website usage and technical data (IP address, cookies, logs)
We only collect data that is relevant, necessary, and proportionate to the services provided.
Purposes of Processing
Personal data is processed for the following purposes:
- Providing company formation and related services
- Meeting legal, regulatory, and compliance obligations
- Conducting AML and KYC checks
- Communicating with clients and responding to enquiries
- Billing, payments, and record-keeping
- Improving our services and website functionality
Legal Basis for Processing
We process personal data under one or more of the following legal bases:
- Contractual necessity – to perform a contract or take steps at your request
- Legal obligation – to comply with Irish and EU law
- Legitimate interests – for business administration, security, and service improvement
- Consent – where explicitly required, such as marketing communications
Data Minimisation & Accuracy
We take reasonable steps to ensure that:
- Personal data is accurate and kept up to date
- Data is limited to what is necessary for its purpose
- Inaccurate or outdated data is corrected or deleted where appropriate
Data Retention
Personal data is retained only for as long as necessary to:
- Provide services
- Meet legal and regulatory obligations
- Resolve disputes and enforce agreements
Retention periods vary depending on the type of data and applicable legal requirements.
Data Sharing & Processors
We may share personal data with:
- Professional advisers and service providers
- IT and cloud service providers
- Payment processors
- Regulatory or law-enforcement authorities where required by law
All third parties are required to process data securely and in accordance with GDPR.
International Data Transfers
Where personal data is transferred outside the European Economic Area (EEA), appropriate safeguards are implemented in accordance with GDPR requirements.
Data Security
We implement appropriate technical and organisational measures to protect personal data against:
- Unauthorised access
- Loss or destruction
- Alteration or disclosure
While no system is completely secure, we take reasonable steps to safeguard all personal data.
Data Subject Rights
Under GDPR, individuals have the right to:
- Access their personal data
- Rectify inaccurate or incomplete data
- Request erasure of personal data where applicable
- Restrict or object to processing
- Data portability where applicable
- Withdraw consent at any time
Requests can be made using the contact details below.
Complaints
If you believe your data protection rights have been breached, you have the right to lodge a complaint with the Data Protection Commission (Ireland).
Data Breaches
In the event of a personal data breach, we will:
- Assess the risk to individuals
- Notify the Data Protection Commission where required
- Inform affected individuals where legally necessary
Policy Review & Updates
This GDPR Policy may be updated from time to time to reflect legal or operational changes. The latest version will always be available on our websites.
Contact Details
For GDPR-related enquiries or to exercise your data protection rights, please contact: