---
title: Privacy Policy | TimeBank Ireland
description: How we collect, use, and protect your personal data on our community platform.
canonical: https://hour-timebank.ie/privacy
generated: 2026-10-04T00:04:38.024Z
---# Privacy Policy

Effective: 30 September 2026 Version 2.0

Replaces the previous website privacy policy with the approved NOS DPN002 Data Privacy Notice, Version 2. Includes the named Data Protection Officer and privacy contact, and updated information on membership, referees, Facebook, Garda Vetting, data sharing, retention, cookies and individual rights.

## Contents

· Introduction 1 Who We Are 2 Who This Notice Applies To 3 Personal Data We Collect 4 Where We Get Personal Data From 5 Why We Use Personal Data and Our Lawful Bases 6 What You Have to Provide 7 What Other Members Can See 8 Who We Share Personal Data With 9 Partner Organisations 10 International Transfers 11 How Long We Keep Personal Data 12 Cookies and Similar Technologies 13 Automated Decision-Making and Profiling 14 Your Data Protection Rights 15 How We Protect Personal Data 16 Children 17 Personal Data Breaches 18 Complaints and the Data Protection Commission 19 Changes to This Privacy Notice 20 Contact Us

## ·Introduction

This Privacy Notice explains how hOUR Timebank CLG collects and uses personal data when you visit our website, apply to join or use the timebank, act as a referee, attend an event, volunteer or otherwise interact with us. It also explains your data protection rights and how to exercise them.

We aim to use personal data only where it is needed, to keep it secure, and to be clear about who can see it and why.

**Controller:** hOUR Timebank CLG **Registered address:** 21 Páirc Goodman, Skibbereen, Co. Cork, P81 AK26, Ireland **General privacy contact:** [privacy@hour-timebank.ie](mailto:privacy@hour-timebank.ie) **Data Protection Officer:** Nikita Serkevich, [privacy@hour-timebank.ie](mailto:privacy@hour-timebank.ie) **Website:** [https://hour-timebank.ie](https://hour-timebank.ie/) **Registered Charity Number:** 20162023 **CRO Number:** 608327

## 1Who We Are

hOUR Timebank CLG, also referred to as “hOUR Timebank”, “Timebank Ireland”, “hTB”, “we”, “us” or “our”, is a Company Limited by Guarantee and a registered Irish charity.

We operate a community timebanking platform through which members can offer and request services, communicate with each other, and record time-credit exchanges.

For personal data processing that we determine, hOUR Timebank CLG is the data controller under the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and the Data Protection Act 2018.

## 2Who This Notice Applies To

This notice applies to personal data relating to:

- current and prospective members;
- people named as character referees by prospective members;
- volunteers, trustees/directors and people carrying out roles on behalf of hOUR Timebank;
- people who attend our events or activities;
- people who contact us, make enquiries, complaints or rights requests;
- website visitors and platform users; and
- representatives of partner organisations, suppliers, funders and other organisations with which we work.

## 3Personal Data We Collect

### 3.1 Membership applications and accounts

When you apply to join or create an account, we may collect:

- your name and contact details, such as email address and telephone number;
- your address or general location where required for local membership administration or community matching;
- account identifiers and authentication information — we store a secure password hash rather than your plain-text password;
- your profile description, interests, skills, offers and requests;
- a profile photograph if you choose to provide one;
- membership application, verification and administration information; and
- the names and contact details of character referees where references form part of the membership process.

### 3.2 Use of the timebank platform

When you use the platform, we may process:

- offers, requests and exchange information;
- time-credit balances and transaction history;
- messages and communications sent through the platform;
- member feedback, complaints, dispute or support records where applicable;
- account status, login history and security events; and
- records needed to investigate misuse, protect members, resolve disputes or keep the platform secure.

### 3.3 Website and technical information

When you visit our website or use the platform, our systems may automatically record limited technical information such as your IP address, browser and device information, date and time of access, requested pages, authentication events and server/security logs.

We use this information to operate, secure and troubleshoot our services.

**3.4 Facebook Group information**

We operate a private Facebook Group as an optional channel for member communication, community updates and arranging timebank exchanges.

If you join or participate in the group, we may process information made available to us through Facebook, including your Facebook name/profile, group membership, posts, comments, offers and requests, and other information you choose to share in the group.

Where an exchange arranged through Facebook needs to be recorded in the official timebank system, we may record the relevant exchange information in our own platform.

Use of the Facebook Group is optional. Members can also arrange exchanges through the hOUR Timebank website or through the Exchange Broker.

### 3.5 Events, photographs and communications

If you attend an event, we may process your name, attendance or related communications where needed to organise the event.

We will use identifiable photographs for optional publicity or similar non-essential purposes only where an appropriate lawful basis applies. Where we ask for consent, participation is voluntary and you may withdraw that consent for future use.

### 3.6 Garda Vetting information

Where Garda Vetting is legally required or appropriate for a relevant role or activity, vetting is processed through the applicable National Vetting Bureau process.

Cork Volunteer Centre may act as the liaison or intermediary for the vetting process. hOUR Timebank may receive the vetting disclosure or outcome relevant to the role.

Depending on the disclosure, this may state that no criminal record or specified information exists, or may contain criminal record or specified information lawfully disclosed under the National Vetting Bureau (Children and Vulnerable Persons) Acts 2012 to 2016.

Garda Vetting information is highly restricted and is used only for the relevant safeguarding, suitability and legal purposes.

## 4Where We Get Personal Data From

Most personal data is provided directly by you, for example when you register, update your profile, send a message, record an exchange or contact us.

We may also obtain personal data from:

- another member, where information about you is necessarily included in an exchange, message, complaint or support request;
- Meta/Facebook, where you join or interact with our private Facebook Group and Facebook makes your profile information, group membership or group activity available to hOUR Timebank as group administrator;
- a prospective member who names you as a character referee;
- Cork Volunteer Centre, the National Vetting Bureau or another authorised vetting intermediary where Garda Vetting applies;
- a partner organisation where you join or participate through that organisation;
- our service providers, where they generate security, delivery or technical records on our behalf; and
- public authorities or other lawful sources where necessary for legal, safeguarding, fraud-prevention or governance purposes.

### 4.1 If someone names you as a character referee

If a prospective member gives us your name and contact details as a character referee, we did not obtain that information directly from you.

We use it only to contact you and, where appropriate, obtain a reference for the applicant. Our lawful basis is our legitimate interest in assessing applications and maintaining a safe and trusted community.

We do not use referee contact details for marketing or unrelated purposes.

We will provide or link you to this privacy information when we first contact you and will retain referee information only for as long as reasonably necessary for the membership decision, any related query or complaint, and applicable legal or safeguarding needs.

## 5Why We Use Personal Data and Our Lawful Bases

We do not rely on a single blanket consent given at registration. The lawful basis depends on the purpose for which the information is used.

**Creating and managing membership/accounts and providing requested platform functions:** account, contact, profile, exchange, time-credit and messaging information. We rely on Article 6(1)(b) GDPR where processing is necessary to provide the service you request or to take steps at your request before membership.

**Operating and administering the timebank community:** membership administration, offers and requests, support, communications and limited account information. We rely on Article 6(1)(f) GDPR and our legitimate interests in operating an effective community service, coordinating membership and supporting members.

**Operating the private Facebook Group:** Facebook profile information, group membership, posts, comments and exchange-related information that members choose to share in the group. We rely on Article 6(1)(f) GDPR and our legitimate interests in providing members with an optional community communication channel, facilitating exchanges, administering group membership and maintaining a safe and effective timebank community.

**Protecting members, preventing misuse and securing the platform:** security logs, account activity, complaints, disputes and incident information. We rely on our legitimate interests in safety, fraud and abuse prevention, network and information security, and protecting our legal rights.

**Checking character references:** referee contact details and reference information. We rely on our legitimate interests in assessing applications and supporting community trust and safety.

**Complying with company, charity, tax, safeguarding and other legal requirements:** governance, financial, statutory and safeguarding information. We rely on Article 6(1)(c) GDPR where processing is necessary to comply with a legal obligation.

**Garda Vetting:** vetting disclosures or outcomes and related suitability information. Processing is based on an applicable Article 6 lawful basis together with Article 10 GDPR and applicable Irish law, including the National Vetting Bureau legislation, as relevant to the role.

**Optional photographs and other genuinely optional uses for which we ask permission:** where we expressly rely on consent, the lawful basis is Article 6(1)(a) GDPR. You may withdraw consent at any time for future processing.

**Legal claims and regulatory matters:** relevant account, exchange, communication, incident or governance information may be processed where necessary to establish, exercise or defend legal claims or respond to regulators or competent authorities.

Where we rely on legitimate interests, we consider whether the processing is necessary and balance our interests against the rights and interests of the people affected.

## 6What You Have to Provide

Some information is necessary to create and administer a membership account or provide a requested feature.

Mandatory fields should be identified during the registration or application process. If you do not provide information that is necessary for membership, account security, eligibility or a requested service, we may be unable to approve the application, create the account or provide that service.

Other information, such as optional profile details, profile photographs or optional contact information, is voluntary.

Choosing not to provide optional data should not prevent you from using core features unless that information is genuinely needed for a particular exchange or activity.

## 7What Other Members Can See

Timebanking depends on members being able to identify suitable offers, requests and people with whom to exchange time.

Certain profile and activity information is therefore visible to other registered members as part of the service.

Depending on the feature, this may include your:

- name;
- profile description;
- general location or neighbourhood;
- profile photograph;
- skills;
- offers and requests; and
- information about timebank activity intended to be shared within the member community.

We do not make private contact details or exact home-address information broadly visible by default.

Where contact details or an address are needed to arrange a particular exchange, they are shared only to the extent necessary and, where possible, under the member’s control.

Please avoid putting sensitive information in public or broadly visible profile fields.

Messages sent through the platform are intended for the relevant participants. Authorised hOUR Timebank personnel may access messages where reasonably necessary to:

- provide support;
- investigate a complaint or suspected misuse;
- protect members;
- comply with law; or
- maintain the security and integrity of the service.

## 8Who We Share Personal Data With

We do not sell, rent or trade personal data and we do not share member data with advertisers or data brokers.

Where necessary and lawful, we may share personal data with:

- other registered members, as described above;
- Meta/Facebook, where you choose to use our private Facebook Group. Facebook is operated independently by Meta and processes information about your Facebook account and use of its platform for purposes determined by Meta;
- Cork Volunteer Centre and the National Vetting Bureau process where Garda Vetting applies;
- partner organisations involved in a particular community or membership arrangement;
- service providers that help us operate the website and platform, such as hosting, infrastructure, email delivery, data storage and backup, IT support and security providers;
- professional advisers such as accountants, auditors, insurers or solicitors where necessary;
- funders, researchers or public bodies using aggregated or genuinely anonymised information where individuals are not identifiable; and
- An Garda Síochána, Tusla, the HSE, the Charities Regulator, the Data Protection Commission, courts or other competent authorities where disclosure is required or permitted by law.

hOUR Timebank is the controller for the purposes for which we operate and administer our private Facebook Group, including managing membership, moderating group activity and using relevant information to facilitate timebank exchanges.

Meta independently determines how it operates the Facebook platform and processes Facebook account, usage, security, personalisation and other platform data. For the ordinary use of our private Facebook Group, we currently treat hOUR Timebank and Meta as separate controllers for their respective processing activities. Meta is not treated as a data processor acting solely on hOUR Timebank's instructions.

If we introduce Facebook or Meta functionality that involves jointly determining particular processing with Meta, we will reassess the controller relationship and comply with Article 26 GDPR where applicable.

Further information about hOUR Timebank's use of Facebook is provided in our **Facebook Group Privacy Information** , available within the private group.

Where a service provider processes personal data on our behalf, we require an appropriate data processing agreement and confidentiality and security obligations.

We only give service providers the data and access reasonably necessary for their role.

Administrative notifications contain only the personal data necessary for the recipient to act. Where authorised administrators can securely access the relevant information in the platform, we aim not to duplicate personal data into email notifications merely for convenience.

## 9Partner Organisations

Some members may join or participate through a partner organisation or a specific community supported by another organisation.

The data protection role of that organisation depends on what it actually does with the data.

A partner organisation may be:

- a separate controller for information it collects and uses for its own purposes;
- a joint controller with hOUR Timebank where both organisations jointly determine particular purposes and essential means of processing; or
- a processor acting only on documented instructions.

Where a partner organisation has access to or receives your personal data, we will provide additional information where needed so that you understand:

- which organisation is involved;
- what information it receives;
- why it receives it; and
- the applicable controller arrangement.

## 10International Transfers

Some organisations involved in providing services or platforms used by hOUR Timebank, or their service providers and sub-processors, may store, access or otherwise process personal data outside the European Economic Area (“EEA”). This may include international processing associated with third-party platforms such as Facebook.

Where hOUR Timebank is responsible for a restricted international transfer, we will ensure that an appropriate GDPR transfer mechanism is available, such as:

- an adequacy decision;
- the European Commission’s Standard Contractual Clauses; or
- another lawful transfer mechanism.

Where Meta independently transfers personal data processed through Facebook, those transfers are governed by Meta's own data protection arrangements and transfer mechanisms. Information about Meta's international transfers is available in Meta's privacy information.

Where appropriate, we also assess supplementary safeguards.

You may contact us for further information about safeguards relevant to your personal data.

## 11How Long We Keep Personal Data

We keep personal data only for as long as it is needed for the purpose for which it was collected.

We take account of legal requirements, disputes or complaints, safeguarding, security and the establishment or defence of legal claims.

**Active member accounts and profiles:** retained while your membership/account is active and the information is needed to provide the service.

**After membership ends:** we hide or deactivate your profile promptly. Personal data that is no longer needed is deleted or irreversibly anonymised after the applicable closure period. Limited information may be kept longer where needed for disputes, safeguarding, fraud or abuse prevention, legal claims or another documented purpose.

**Exchange and time-credit records:** retained while needed to maintain accurate balances and transaction history, resolve disputes and protect the integrity of the timebank. After membership ends, identifiable records are retained only where a continuing purpose justifies them.

**Messages, support and complaint records:** retained for as long as needed to provide support, resolve the issue and meet any legitimate safeguarding, security or legal-claim need.

**Character referee data:** retained only for as long as reasonably necessary for the membership decision, any related query or complaint, and applicable legal or safeguarding needs, after which it is deleted or minimised.

**Garda Vetting information:** restricted and retained only for the relevant vetting and safeguarding purpose. Where hOUR Timebank follows a three-year vetting cycle, records are reviewed at the end of that cycle and are not retained longer without a documented need or legal requirement.

**Financial and accounting records:** retained for at least six years after the end of the relevant financial year where required by applicable company or accounting law, and longer where another legal requirement applies.

**Board and statutory governance records:** retained for periods required by company and charity law. Certain formal minutes, registers and governance records may be retained permanently.

**Security logs:** retained for a proportionate period based on their security purpose and risk. Relevant logs may be retained longer where an incident or investigation requires it.

A general seven-year retention period does not automatically apply to all former-member information.

## 12Cookies and Similar Technologies

At the date of this notice, our website is intended to use only cookies or similar technologies that are strictly necessary to provide the website or platform, or to carry out communications requested by the user, such as session, authentication or security functions.

Strictly necessary cookies do not require consent under the applicable Irish ePrivacy rules, although we still provide information about their use.

We do not currently use advertising, behavioural-tracking or analytics cookies.

If we introduce analytics, marketing or other non-essential cookies or similar technologies, we will:

- update our information;
- obtain valid consent before setting or accessing them where consent is required; and
- allow users to withdraw or change their consent.

We provide or maintain appropriate cookie information on our website so visitors can understand the cookies in use, their purposes and their duration.

This section concerns cookies and similar technologies used on hOUR Timebank's own website and platform. Facebook may use cookies and similar technologies when you use Facebook or interact with our private Facebook Group. Those technologies are controlled by Meta and are described in Meta's own privacy and cookie information.

## 13Automated Decision-Making and Profiling

We do not currently use solely automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you within the meaning of Article 22 GDPR.

We do not use member profiles for advertising profiling or sell them to data brokers.

If this changes, we will update this notice and provide the information required by law before the relevant processing begins.

## 14Your Data Protection Rights

Depending on the circumstances and the lawful basis used, you may have the right to:

- access your personal data and receive a copy of it;
- have inaccurate or incomplete personal data corrected;
- ask us to erase personal data where the legal conditions for erasure apply;
- ask us to restrict processing in certain circumstances;
- receive certain personal data in a structured, commonly used and machine-readable format and have it transmitted to another controller where the right to portability applies;
- object to processing based on legitimate interests;
- object at any time to direct marketing if we ever use your personal data for that purpose;
- withdraw consent at any time where we rely on consent, without affecting processing that was lawful before withdrawal; and
- raise a concern with the Data Protection Commission.

To exercise a right, contact us at [privacy@hour-timebank.ie](mailto:privacy@hour-timebank.ie)

You do not need to use a particular form or legal wording.

We normally respond within one month. GDPR permits an extension in certain complex cases. If an extension applies, we will inform you within the initial one-month period.

We may ask for proportionate information to verify your identity where we have reasonable doubts about who is making the request.

Some rights are not absolute. If we cannot comply fully with a request, we will explain the reason where the law allows us to do so.

## 15How We Protect Personal Data

We use technical and organisational measures appropriate to the nature of the information and the risks involved.

These include, as appropriate:

- access restrictions;
- account authentication;
- secure password hashing;
- encryption in transit;
- secure storage and backups;
- confidentiality requirements;
- access reviews;
- incident response arrangements; and
- secure disposal of records.

No system can be guaranteed to be completely secure. We therefore review and improve our controls as the platform, risks and technology change.

## 16Children

The timebank platform is intended for users aged 18 and over.

We do not knowingly create ordinary member accounts for children.

If we become aware that a child’s personal data has been collected outside an approved safeguarding arrangement, we will assess the situation and take appropriate steps, including deletion where required.

Any future service or activity specifically involving children would require separate safeguarding and data-protection assessment and appropriate privacy information before it is introduced.

## 17Personal Data Breaches

If a personal data breach occurs, we assess the likely impact on the people affected and take steps to contain and address it.

Where GDPR requires notification, we will notify the Data Protection Commission without undue delay and, where feasible, within 72 hours of becoming aware of the breach.

Where a breach is likely to result in a high risk to individuals, we will also notify affected individuals without undue delay unless a legal exception applies.

## 18Complaints and the Data Protection Commission

If you have a concern about how we use your personal data, we encourage you to contact us or our Data Protection Officer first so that we can try to resolve it.

You also have the right to raise a concern or lodge a complaint with the Irish Data Protection Commission:

**Data Protection Commission** 6 Pembroke Row Dublin 2 D02 X963 Ireland

Website: [https://www.dataprotection.ie](https://www.dataprotection.ie/)

The DPC provides an online contact and complaint form on its website.

## 19Changes to This Privacy Notice

We may update this Privacy Notice to reflect changes in our services, technology, legal requirements or how we use personal data.

The current version will be published on our website with its revision date.

Where a change materially affects how we use existing personal data or your choices, we will take appropriate steps to bring the change to your attention before or when it takes effect, as required by law.

## 20Contact Us

For privacy questions, rights requests or concerns about this notice:

**hOUR Timebank CLG** 21 Páirc Goodman Skibbereen, Co. Cork P81 AK26 Ireland

**Email:** [privacy@hour-timebank.ie](mailto:privacy@hour-timebank.ie) **Website:** [https://hour-timebank.ie](https://hour-timebank.ie/)

For the Data Protection Officer, contact Nikita Serkevich at [privacy@hour-timebank.ie](mailto:privacy@hour-timebank.ie) .

[View previous versions of this document](/privacy/versions)

## Have Questions?

If you have any questions about this document, please contact us.

[Contact Us](/contact)
