GDPR Privacy Policy – FirstAid101

Effective Date: [20/04/2025]
Last Updated: [24/04/2025]

1. Introduction

At FirstAid101, your privacy is important to us. This Privacy Policy outlines how we handle your personal data in compliance with the General Data Protection Regulation (EU) 2016/679 (GDPR) and the Data Protection Act 2018 in Ireland.

This policy applies to all learners, clients, partners, and website visitors.


2. Who We Are

FirstAid101
3 Glebe Newcastle, Co. Dublin
Company Registration Number: 760538
Email: info@firstaid101.ie

3. What Personal Data We Collect

Depending on how you engage with us, we may collect:

Name, address, email address, phone number

Health information relevant to course participation (e.g., physical limitations or allergies)

Payment details (processed securely by third-party payment providers)

Certification history (e.g., course type, completion status, expiry dates)

IP address and usage data if visiting our website(see point 10 for cookies)

We do not collect more data than necessary for the delivery of our services.


4. Why We Collect Your Data

We process your data to:

Register you for training courses

Issue certification and maintain training records

Manage payments and invoicing

Comply with regulatory and accrediting body requirements 

Respond to your queries or requests

Send course updates, renewal reminders, and training promotions (Implied consent by booking a course with FirstAid101)


5. Legal Basis for Processing

We process your personal data under the following GDPR bases:

Contractual necessity – to deliver training and issue certification

Legal obligation – to retain training records for compliance

Consent – for marketing

Legitimate interest – to ensure the safety and quality of training


6. Sharing Your Information

We do not sell your personal data. We may share your data with:

Affiliated body approved training institute(ATI) U.F.A.S for certification purposes

Service providers (e.g., online booking platforms, payment processors)

Government or regulatory authorities, if legally required

All third parties are contractually bound to protect your data.


7. Data Retention

We keep your personal data only for as long as necessary:

Course and certification records are kept for 7 years (in line with regulatory requirements)

Financial records are retained for 6 years (Revenue requirements)

Marketing preferences are reviewed every 2 years or upon request


8. Your Rights

You have rights under GDPR, including:

Access to your personal data

Rectification of inaccurate data

Erasure (where not restricted by legal obligation)

Restriction or objection to processing

Data portability

Withdrawal of consent (for marketing or health-related data)


9. Data Security

We take all reasonable steps to protect your data:

Secure booking and payment

Restricted access to personal data

Staff training on data protection and confidentiality


10. Cookies & Website Tracking

This website uses cookies to improve your experience and personalize your online activity. We use essential cookies for the site to function, analytical cookies to track user behavior, and advertising cookies to deliver relevant ads. You can manage your cookie preferences through your browser settings. For more information about Google's cookies, see their privacy policy and cookie policy.

11. Updates to This Policy

This Privacy Policy may be updated occasionally to reflect changes in legislation or our practices. We recommend checking this page regularly.