Ireland Regional Privacy Policy
Privacy information for individuals in Ireland and the European Economic Area (EEA), aligned with the GDPR and applicable Irish data protection laws.
Ireland & EEA Privacy Overview
This Ireland Regional Privacy Policy (“Ireland Notice”) supplements Xaysi Marketplace’s main Privacy Policy and applies to individuals located in Ireland and, where relevant, the European Economic Area (EEA). It explains how we collect, use, share, and protect personal data when you use our Services, and describes your rights under the General Data Protection Regulation (GDPR) and applicable Irish data protection laws.
If there is any conflict between this Ireland Notice and our main Privacy Policy, this Ireland Notice applies for users in Ireland/EEA for the topics it covers (for example, legal bases, GDPR rights, and international transfers).
Your GDPR Rights
You may have rights to access, correct, delete, restrict, or port your data, object to certain processing, and lodge a complaint with a supervisory authority (including Ireland’s Data Protection Commission).
1Scope & Controller Information
This Ireland Notice applies when we process personal data subject to the GDPR (for example, because you are located in Ireland/EEA). Unless otherwise stated in our main Privacy Policy, Xaysi Inc. (or the relevant Xaysi entity identified in the main Privacy Policy) acts as the data controller for this processing.
Note: “Personal data” has the meaning given in the GDPR and generally includes information that identifies or can identify you directly or indirectly.
2Personal Data We Collect
We collect personal data to provide and improve our Services. Depending on how you interact with Xaysi Marketplace, this may include:
- Account & profile data: name, email address, login credentials, preferences.
- Seller/business data: business name, business contact details, tax/registration info (where required), storefront content.
- Transaction data: order details, purchase history, refunds/returns, delivery details.
- Payment data: payment method tokens and limited payment details (typically processed by payment providers; we may receive confirmations and partial identifiers).
- Customer support communications: messages, emails, chat logs, and related metadata.
- Device & usage data: IP address, device identifiers, browser type, pages viewed, approximate location derived from IP, cookies and similar technologies.
3How We Use Personal Data
We use personal data for purposes such as:
- Providing, operating, and maintaining the Services (including account creation and order fulfilment)
- Processing payments, preventing fraud, and securing accounts
- Customer support, dispute handling, and service communications
- Improving our Services, analytics, and product development
- Marketing and advertising (where permitted), including measuring campaign performance
- Complying with legal obligations and enforcing our terms
4Legal Bases for Processing (GDPR)
Under the GDPR, we rely on one or more legal bases depending on the context:
- Contract: to provide the Services you request (e.g., fulfil orders, manage accounts).
- Legal obligation: to meet legal requirements (e.g., accounting, compliance, responding to lawful requests).
- Legitimate interests: to secure and improve our Services, prevent fraud, and understand usage—balanced against your rights.
- Consent: for certain marketing communications and some cookie/technology uses where required. You can withdraw consent at any time.
- Vital interests: in rare cases, to protect someone’s life.
Where we rely on legitimate interests, you may have the right to object (see Section 8).
5Cookies, Analytics & ePrivacy
We use cookies and similar technologies to operate the Services, remember preferences, understand performance, and (where permitted) personalize advertising. Some technologies may require your consent depending on local law and configuration.
- Strictly necessary: required for core site functionality and security.
- Performance/analytics: help us measure and improve how the site works.
- Functional: remember choices (e.g., language, region).
- Marketing: help deliver and measure relevant ads where enabled.
Where a consent banner or preference tool is available, you can manage your choices there and change them later.
6Sharing & Disclosure
We may share personal data with:
- Service providers/processors: hosting, analytics, payment processing, customer support, security, and communications providers.
- Business partners: where needed to provide marketplace features you use (e.g., shipping integrations).
- Legal and compliance: when required by law, court order, or to protect rights, safety, and security.
- Corporate transactions: in connection with a merger, acquisition, reorganization, or sale of assets (subject to applicable safeguards).
When we share data with processors, we require appropriate contractual protections and instructions consistent with GDPR requirements.
7International Transfers
Your personal data may be processed in countries outside Ireland/EEA (for example, where our service providers operate). When we transfer personal data internationally, we use recognized safeguards as required by the GDPR, such as:
- Adequacy decisions (where applicable)
- Standard Contractual Clauses (SCCs) and, where needed, supplementary measures
- Other lawful transfer mechanisms permitted under GDPR
You may request more information about the safeguards we use by contacting us (see Section 10).
8Your Rights (GDPR)
Subject to conditions and exceptions under the GDPR, you may have the right to:
- Access: obtain confirmation and a copy of your personal data.
- Rectification: correct inaccurate or incomplete data.
- Erasure: request deletion of personal data in certain cases.
- Restriction: limit processing in certain cases.
- Portability: receive data in a structured, commonly used format and transmit it to another controller.
- Object: object to processing based on legitimate interests or for direct marketing.
- Withdraw consent: where we rely on consent, at any time (does not affect prior processing).
Direct marketing: You can object at any time, and we will stop using your data for direct marketing purposes.
9Data Retention & Security
We retain personal data only as long as necessary for the purposes described in this Ireland Notice and our main Privacy Policy, including to meet legal, accounting, or reporting obligations. We implement technical and organizational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access.
10Contact Us & Complaints
To exercise your rights, ask questions about this Ireland Notice, or request information about international transfer safeguards, please contact us using the contact details in our main Privacy Policy.
You also have the right to lodge a complaint with a supervisory authority. In Ireland, this is the Data Protection Commission (DPC).
Tip: If you’re submitting a request, include your account email, your location (Ireland/EEA), and the request type (access, rectification, erasure, restriction, portability, objection, or consent withdrawal) to help us process it faster.
Need Help With Your Privacy Rights?
Our support team can help you understand GDPR rights, manage preferences, and submit privacy requests.