Privacy Policy
Effective Date: 14/07/2025
At AndySullsHair Barbershop & Academy, we are committed to protecting your personal data and respecting your privacy in accordance with the General Data Protection Regulation (GDPR) and the Data Protection Act 2018 (Ireland). This Privacy Policy explains how we collect, use, share, and protect your information when you interact with our website, booking services, or educational programmes.
We collect personal data when you visit our website, submit a contact form, book an appointment, join our mailing list, or use our live chat feature. This may include your name, email address, phone number, appointment details, and any other information you choose to share. We also collect technical data such as your IP address, browser type, device ID, and website interaction behaviour. This information may be collected directly or through tools such as analytics or cookies, which are managed via Cookiebot. Upon visiting our site, you are presented with a cookie banner that lets you provide or withhold consent for non-essential cookies, and you may update your preferences at any time.
Our website is hosted on Squarespace, which also manages our newsletter sign-ups. When you subscribe, your data is securely stored and used only to send you updates or offers you’ve opted into. Our appointment bookings are handled via Squire, and personal details you enter when scheduling a haircut are processed to manage your booking, send reminders, and provide customer service. For Academy-related queries and follow-ups, we use GoHighLevel (GHL) as our customer relationship management (CRM) system. This platform handles form submissions, live chat, course enquiries, and automated follow-ups related to your interest in the Academy.
We also use third-party platforms such as Google Analytics, Meta (Facebook and Instagram), LinkedIn, and TikTok to understand how users interact with our website and to run targeted marketing campaigns. These platforms may use cookies and tracking pixels to collect browsing data and deliver personalised ads. All non-essential tracking is disabled unless you give explicit consent through our cookie settings.
We rely on the following legal bases to process your data: Consent is used when you opt in to receive marketing communications, agree to cookie use, or allow analytics tracking. Contract performance applies when you book a service or submit an enquiry — we need this data to fulfil your request. Legitimate interest applies to essential website security, analysing usage trends, and improving service delivery, provided this does not override your rights. Legal obligation covers our requirements to maintain business records for tax, accounting, or regulatory reasons.
We do not sell or rent your personal data. We only share it with trusted service providers when necessary to deliver our services or support our marketing efforts, and these third parties are contractually obligated to handle your data securely and lawfully. We implement appropriate technical and organisational measures to protect your personal data, including access restrictions, secure storage, and staff confidentiality protocols.
We retain your personal data only for as long as necessary. Appointment and client records, including booking and payment history where applicable, are retained for 6 years to comply with Irish financial and record keeping laws. Marketing data is retained until you unsubscribe. Analytics data (e.g. Google Analytics) is retained for 26 months, unless otherwise configured. Financial or legal records are kept for 6 years in compliance with statutory obligations.
Some of the platforms we use — including Google, Meta, LinkedIn, TikTok, Squarespace, Squire, and GoHighLevel — may store or process personal data outside the European Economic Area (EEA), such as in the United States. In these cases, we rely on our service providers to implement appropriate safeguards under GDPR, including the use of Standard Contractual Clauses (SCCs) approved by the European Commission, to ensure your data remains protected and your rights are upheld.
AndySullsHair Barbershop & Academy is the data controller responsible for the personal information collected through this website and our services. Our business address is Unit 1 Lancaster Quay, Mardyke, Cork, T12 P218, Ireland, and you can contact us by phone at 085 836 5644 or by email at andysullshair@gmail.com with any data-related concerns.
You have the right to access any personal data we hold about you, to request corrections, deletion, or to restrict how it’s used. You may also object to processing, request a copy of your data in a portable format, or withdraw consent at any time (such as for marketing emails or cookies). To make such a request, please contact us at andysullshair@gmail.com with proof of identity. If you are unsatisfied with our response, you have the right to lodge a complaint with the Data Protection Commission at www.dataprotection.ie.
We do not knowingly collect personal data from children under the age of 16. If you believe a child has provided us with their information, please contact us and we will take steps to delete it promptly.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Data Protection Commission within 72 hours and inform affected users without undue delay, as required by law.
We do not use any automated decision-making or profiling technologies that have legal or similarly significant effects on individuals.
We may occasionally update this Privacy Policy to reflect changes in our systems, partners, or legal obligations. The most recent version will always be published on our website. This policy was last updated on 14 July 2025.