1. Who we are
The Wild Atlantic Inn is a bed & breakfast at The Square, Rathbaun, Lisdoonvarna, Co. Clare, V95 DK50, Ireland, operated by Noel Malone ("we", "us"). For the purposes of the EU General Data Protection Regulation (GDPR) and the Irish Data Protection Act 2018, we are the data controller for the personal information described in this policy.
Contact: [email protected] · +353 83 070 4931.
2. What we collect and why
| Information | When | Why (legal basis) |
|---|---|---|
| Name, email, phone | You send an enquiry or make a booking | To respond and manage your booking (contract / steps prior to contract) |
| Stay details — dates, guests, room preference, message | Enquiry or booking | To check availability and prepare for your stay (contract) |
| Special requirements you choose to tell us (e.g. dietary needs, accessibility) | Enquiry, booking or during your stay | To look after you properly (consent) |
| Payment details | Booking or check-in | To take payment (contract). Card payments are processed by our payment provider — we do not store full card numbers. |
| Marketing preferences | If you tick the consent box on our enquiry form | To send occasional offers (consent — withdraw any time) |
| CCTV images | Common areas and the exterior of the property | Safety and security of guests and the property (legitimate interest). Cameras do not cover bedrooms or bathrooms. |
| Photo identification | We may ask at check-in | To verify the booking and for the security of guests and the property (legitimate interest; legal obligation where applicable) |
3. Where your data is processed
Our website, enquiry form and guest communications run on a customer-relationship platform provided by Lead Machine Inc., built on infrastructure operated by HighLevel Inc. ("LeadConnector"). Data submitted through our forms is stored on these systems, which may be located outside the European Economic Area, including in the United States. Such transfers are safeguarded by the platform's data processing agreement incorporating Standard Contractual Clauses.
We do not sell your personal information, and we do not share it with third parties except: service providers who help us run the business (booking platform, payment processing, website/CRM as above), and authorities where the law requires it.
4. How long we keep it
- Enquiries that don't become bookings — up to 24 months, then deleted.
- Booking and stay records — up to 7 years, as required for tax and accounting.
- Marketing consents — until you withdraw consent or 3 years of inactivity.
- CCTV footage — kept for a short period, typically no more than 30 days, before being overwritten, unless needed in connection with an incident.
5. Your rights
Under the GDPR you can ask us at any time to:
- see a copy of the information we hold about you (access);
- correct it (rectification) or delete it (erasure);
- limit how we use it (restriction) or object to our use of it;
- receive it in a portable format (portability);
- withdraw any consent you've given — this doesn't affect processing before withdrawal.
Email [email protected] and we'll respond within one month. If you're not happy with our answer, you can complain to the Irish supervisory authority: the Data Protection Commission, 21 Fitzwilliam Square South, Dublin 2, D02 RD28 — www.dataprotection.ie.
6. Cookies
This website uses a small number of cookies set by our website platform to make the site work and to measure visits in aggregate. If we add analytics or advertising tools in future, we will update this policy and, where required, ask for your consent first. You can control cookies through your browser settings.
7. Marketing
We only send marketing emails if you've ticked the consent box, and every message includes an unsubscribe link. We never pass your details to anyone else for their marketing.
8. Changes to this policy
If we change how we handle personal information, we'll update this page and the date at the top. Significant changes affecting existing guests will be notified by email where we can.