Skip to content
Home › Privacy Policy

Privacy Policy

Cyclone Corporate Services Group Limited (trading as 2Flow). Our commitments and your rights under the General Data Protection Regulation and the Irish Data Protection Acts.

Last updated: 24 April 2026
Contents
  1. Introduction & Purpose
  2. Right of Rectification or Erasure
  3. Right of Access
  4. Right to Data Portability
  5. Automated Decision Making & Profiling
  6. Right to Object
  7. Right to Restriction of Processing
  8. Rectification Policy
  9. Right to Withdraw Consent
  10. Right to Lodge a Complaint
  11. Right of Access Policy
  12. Cookie Policy

1. Introduction & Purpose

What is the purpose of this Privacy Statement?

This Privacy Statement refers to our commitment to treat the information of job candidates, employees, clients, contractors, suppliers and other interested parties with the utmost care and confidentiality.

With this statement, we ensure that we gather, store and handle data fairly, transparently and with respect towards individual rights in accordance with the applicable data protection legislation including the Irish Data Protection Acts and the EU General Data Protection Regulation.

Who does this Privacy Statement refer to?

This statement refers to all parties (job candidates, employees, clients, contractors, suppliers and other interested parties) whose personal data is processed by us.

Who must follow this Privacy Statement?

Our employees must follow this policy. Contractors, consultants, partners and any other external entity are also required to comply. Generally, this Statement applies to anyone we collaborate with or who acts on our behalf and may need occasional access to data.

What data is included?

As part of our services, we need to obtain and process data. This data includes any offline physical data or online data that makes a person identifiable such as names, addresses, phone numbers, usernames and passwords, IP addresses, any online identifier, CCTV, biometrics, digital footprints, photographs, social security numbers, financial data and similar. It may also include one or more factors specific to the physical, physiological, genetic, mental, cultural or social identity of that person.

When ordering online or by phone, registering on our websites, using Live Chat, submitting forms or providing us with feedback on our products or services you may be asked for your name, email address, phone number, credit card information or other details to help you with your experience.

How do we use your information?

We may use the information we collect from you in the following ways:

  • To personalise your experience and to allow us to deliver the type of content and product offerings in which you are most interested.
  • To improve our website in order to enhance your experience.
  • To allow us to better service you in responding to your customer service requests.
  • To quickly process your transactions.
  • To ask for ratings and reviews of services or products.
  • To follow up after correspondence (live chat, email or phone enquiries).
  • To protect against any unauthorised or illegal processing by internal or external parties.

Technical data may be used for administrative and statistical purposes and may be shared with our internet service provider. We may use this information to help us improve our website. Technical data does not provide us with the personal data of visitors to our website.

Web browsing

By simply visiting our website you do not disclose, nor do we collect, personal data on you. All that we may know about your visit may be limited to technical data such as:

  • The logical address (or IP address) of the server you used to access this website
  • The top level domain name from which you access the internet (for example .ie, .com, .org, .net)
  • The previous website address from which you reached us
  • The type of web browser you used
  • Web traffic data

Data retention

We retain personal data for no longer than is allowed under data protection law and, in any case, no longer than such personal data is necessary for the purpose for which it was processed. To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure, the purposes for which we process personal data and whether we can achieve those purposes through other means, and the applicable legal requirements.

As a registered user of our websites we will retain your Identity, Contact, Profile, Technical, Usage, Marketing and Communications Data for as long as your user account is live. We retain the personal data you provide while your account is in existence or as needed to provide you access to our websites. Even if you only use the Website or any other Cyclone service occasionally, we will retain your Identity, Contact, Profile, Technical, Usage, Marketing and Communications Data until you decide to close your user account. We retain personal data for longer if required by applicable law or regulation or justified under applicable statutory limitation periods.

Security of data

Cyclone takes seriously its security obligations in respect of your personal data under the Data Protection Acts to prevent unauthorised access to, or alteration or destruction of, personal data in our possession. Your personal information is contained behind secured networks and is only accessible by a limited number of persons who have special access rights to such systems, and are required to keep the information confidential. In addition, all sensitive and credit information you supply is encrypted via Secure Socket Layer (SSL) technology.

We implement a variety of security measures when a user places an order to maintain the safety of your personal information. All transactions are processed through a gateway provider and are not stored or processed on our servers.

Disclosure of data

Your personal information may also be processed by other organisations on our behalf for the purposes outlined above. We may disclose your information to partners, associates, agents or subcontractors and to possible successors to our business. Some of these parties may reside outside the European Economic Area (which currently comprises the Member states of the European Union plus Norway, Iceland and Liechtenstein). If we do this, your information will be treated to the same standards adopted in Ireland. We may also disclose your information for the prevention and detection of crime and to protect the interests of Cyclone or others, or if required to do so by law or other binding request.

Clients

Where you, as a Data Controller, engage the services of Cyclone, we will act as Data Processors on your behalf. In doing so, we will:

  • Only process personal data under the Contract in accordance with your reasonable written instructions and in accordance with applicable Data Protection Legislation.
  • Adopt appropriate technical and organisational measures against accidental disclosure, loss or destruction of personal data.
  • Inform you promptly in the event of unauthorised disclosure, loss or destruction of any personal data processed on your behalf.
  • Refer to you any requests, notices or other communication from data subjects, the Office of the Data Protection Commissioner or any other law enforcement agency relating to personal data processed on your behalf.
  • Ensure that all Cyclone personnel processing personal data are under an obligation of confidentiality.
  • Make available reasonable information necessary to demonstrate compliance with our Data Protection Obligations.
  • Make available such information and assistance as is reasonably necessary for you to comply with your obligations to respond to requests for exercising the data subject's rights, to report personal data breaches and to conduct Data Protection Impact Assessments and Prior Consultation with Data Protection Authorities.
  • Comply with our obligations to you in respect of sub-processing and Third Country Transfers.
  • Delete or return all personal data processed on your behalf, upon the termination of any services provided by us to you.

How we protect your data

  • Restrict and monitor access to sensitive data.
  • Develop transparent data collection procedures.
  • Train employees in data protection and security measures.
  • Build secure networks to protect online data from cyber attacks.
  • Establish clear procedures for reporting privacy breaches or data misuse.
  • Include contract clauses or communicate statements on how we handle data.
  • Establish data protection practices (document shredding, secure locks, data encryption, frequent backups, access authorisation).

Third-party disclosure

We do not sell, trade, or otherwise transfer to outside parties your personal information. This does not include trusted partners who assist us in operating our website, conducting our business, or servicing you, so long as those parties agree to keep this information confidential.

We use the following third-party services that may process personal data on our behalf:

  • HubSpot (EU1 region) — our CRM platform. When you submit a quote request or contact form, your details (name, email, phone, company and business information) are stored in HubSpot. HubSpot also sets tracking cookies to identify returning visitors. Data is hosted on HubSpot's EU servers. See HubSpot's Privacy Policy.
  • Google Analytics (GA4) — website traffic and performance analysis. Runs in Google Consent Mode; sends only cookieless, aggregated pings until you accept analytics cookies. See Google's Privacy Policy.
  • Google Ads — conversion tracking and remarketing for our advertising campaigns. Advertising cookies are set only after you accept advertising cookies. See Google's Privacy Policy.
  • LinkedIn Insight Tag — conversion tracking, retargeting and campaign analytics for our LinkedIn advertising. Loads only after you accept advertising cookies. See LinkedIn's Privacy Policy.
  • Lemlist — visitor identification for B2B sales signals. Recognises organisations visiting our website so our sales team can follow up. Loads only after you accept advertising and marketing cookies. See Lemlist's Privacy Policy.

Non-personally identifiable visitor information may be provided to other parties for analytical or operational purposes.

Third-party links

Occasionally, at our discretion, we may include or offer third-party products or services on our website. These third-party sites have separate and independent privacy policies. We therefore have no responsibility or liability for the content and activities of these linked sites. Nonetheless, we seek to protect the integrity of our site and welcome any feedback about these sites.

Our data principles

Once personal data is available to us, the following rules apply. Our data will be:

  • Accurate and kept up to date
  • Collected fairly and for lawful purposes only
  • Processed by us on the basis of either a valid contract, consent, legal compliance or legitimate interest
  • Protected against any unauthorised or illegal processing by internal or external parties

Our data will not be:

  • Communicated to any unauthorised internal or external parties.
  • Stored for more than a specified amount of time required for the purpose it was obtained.
  • Transferred to organisations, states or countries outside the European Economic Area without adequate safeguards being put in place as required under Data Protection law.

Where consent is relied upon as a basis for processing of any personal data, you will be presented with an option to agree or disagree with the collection, use or disclosure of personal data. Explicit consent will be required for the processing of any special category of personal data.

2. Right of Rectification or Erasure

If we hold incorrect information about you which was originally submitted by you through our websites, you have the right to have the data amended. Further, you have the right to have any information you have sent to us via this website erased. To request your right to rectification and/or erasure please send your request to us in writing to the Data Protection Officer (address below), together with:

  • Your name and address.
  • A description of the specific personal data you wish rectified.
  • If you request an erasure of your personal data all your data will be erased, subject to the following notice.

We are not required to rectify or erase your data where to do so would prevent you from meeting your contractual obligations to us or where we are required to process (including retaining) your personal data for a lawful purpose in accordance with the Data Protection Acts.

3. Right of Access

You have a right to be given a copy of any of your personal data held by us, in accordance with section 4 of the Data Protection Acts subject to certain exceptions. To request a copy of your personal data, please send a written request to the Data Protection Officer at the address below.

Please note: we do not accept access requests via telephone, email or text message.

4. Right to Data Portability

You will receive your personal data concerning you in a structured, commonly used and machine-readable format if:

  • Processing is based on consent
  • Processing is carried out by automated means

Will Cyclone transfer the personal data to another service provider if I requested this?

We can transfer this data to another company selected by you on your written instruction where it is technically feasible taking account of the available technology and the feasible cost of transfer proportionate to the service we provide to you.

Under what circumstances can Cyclone refuse?

You will not be able to obtain, or have transferred in machine-readable format, your personal data if we are processing this data in the public interest or in the exercise of official authority vested in us.

Will Cyclone provide me with my personal data if the file contains the personal data of others?

We will only provide you with your personal data, ensuring we protect the rights and freedoms of others. Where personal data of another person may be on the same files as yours, we will redact the full details of the other person.

5. Automated Decision Making & Profiling

Cyclone does not have any automated decision-making processes. Where any such processes are introduced, we will provide you with the relevant information required under the General Data Protection Regulation.

6. Right to Object

We have informed you of your right to object prior to us collecting any of your personal data as stated in our privacy notice.

When can I object to Cyclone processing my personal data?

You can object on grounds relating to your particular situation. Cyclone will stop processing your personal data unless:

  • We can demonstrate compelling legitimate grounds for the processing, which override your interests, rights and freedoms; or
  • The processing is for the establishment, exercise or defence of legal claims.

What are my rights to object for direct marketing purposes?

Where your personal data is processed for direct marketing purposes, you have the right to object at any time to processing of personal data concerning you for such marketing, which includes profiling to the extent that it is related to such direct marketing. Where you object to processing for direct marketing purposes, we will no longer process this data for such purposes.

7. Right to Restriction of Processing

You may have processing of your personal data restricted:

  • While we are verifying the accuracy of your personal data which you have contested.
  • If you choose restricted processing over erasure where processing is unlawful.
  • If we no longer need the personal data for its original purpose but are required to hold the personal data for defence of legal claims.
  • Where you have objected to the processing (where it was necessary for the performance of a public interest task or purpose of legitimate interests), and we are considering whether our legitimate grounds override.

Where we have disclosed your personal data in question to third parties, we will inform them about the restriction on the processing, unless it is impossible or involves disproportionate effort to do so. We will inform you on an individual basis when a restriction on processing has been lifted.

8. Rectification Policy

Where you suspect that data we hold about you is inaccurate, we will on demand rectify any inaccuracies without undue delay and provide confirmation of same.

Where we have disclosed inaccurate personal data to third parties, we will inform them and request confirmation that rectification has occurred. We will also provide you with details of the third parties to whom your personal data has been disclosed.

9. Right to Withdraw Consent

You can withdraw consent if we are processing your personal data based on your consent. You can withdraw consent at any time.

If I withdraw consent what happens to my current data? Any processing based on your consent will cease upon the withdrawal of that consent. Your withdrawal will not affect any processing of personal data prior to your withdrawal of consent, or any processing which is not based on your consent.

10. Right to Lodge a Complaint

You can lodge a complaint with the Data Protection Commission in respect of any processing by or on behalf of Cyclone of personal data relating to you.

Making a complaint is simple and free. All you need to do is write to the Data Protection Commission giving details about the matter. You should clearly identify the organisation or individual you are complaining about, and outline the steps you have taken to have your concerns dealt with by the organisation, and what sort of response you received from them. Please also provide copies of any letters between you and the organisation, as well as supporting evidence and material.

The Data Protection Commission will then take the matter up with Cyclone for you. Contact: info@dataprotection.ie.

11. Right of Access Policy

When do I have the right to access my personal data from Cyclone?

Where Cyclone process any personal data relating to you, you have the right to obtain confirmation of same from us, and to have access to your data.

What information will Cyclone provide to me?

If we are processing your personal data you are entitled to access a copy of all such personal data processed by us. We will also provide the following information including your full rights under Data Protection:

  • Why we are processing your personal data.
  • The types of personal data concerned.
  • The third parties or categories of third parties to whom the personal data have been or will be disclosed, including any outside the EEA or international organisations.
  • How your personal data is safeguarded where provided outside the European Economic Area or to an international organisation.
  • The length of time we will hold your data or, if not possible, the criteria used to determine that period.
  • Your rights to request rectification, erasure, restriction, objection, portability, and complaint with the Data Protection Commission.
  • Where we have collected your personal data from a third party, details of our source.
  • Any automated decision making or profiling, including meaningful information about the logic involved, and the significance and envisaged consequences of such processing for you.

How long will it take to receive my personal data from Cyclone?

We will provide you with a copy of the personal data we are currently processing within 30 days of request. In rare situations, if we are unable to provide you with the data within 30 days, we will notify you within 10 days of your request explaining the reason for the delay and will commit to delivery within 60 days.

How much will it cost me to receive my personal data?

We will not charge for providing your personal data unless we believe the request is excessive and the cost of providing your data is disproportionate to your services provided. If you require additional copies we will charge €20 to cover our administrative costs. You can request your personal data by electronic means and we will provide it in a commonly used electronic form if technically feasible.

12. Cookie Policy

For a full explanation of the cookies we use, their purpose, and how to manage or disable them, please read our dedicated Cookie Policy.

Data Protection Officer Cyclone
Pleasant's House
Pleasant's Street
Dublin 8, D08F54N
Ireland

Email: Eve.Martin@2flow.ie
Phone: 1800 532 532