Privacy Statement
Last updated: 14th Sept 2026
1. Who we are
Clonmel BID (Clonmel Business Improvement District Company Limited by Guarantee) is a not-for-profit company established by the businesses of Clonmel, Co. Tipperary, under the Local Government (Business Improvement Districts) Act 2006. We run initiatives to make the town centre safer, busier and more attractive: marketing and promotion, events such as our Christmas programme, business support, street improvements and visitor experience.
For the purposes of data protection law, Clonmel BID is the data controller of the personal data described in this statement.
Registered office: Unit 102 Regus, The Ormonde Centre, Gladstone St, Burgagery-Lands West, Clonmel, Co. Tipperary, E91 T3Y7
Company number: 819972
Data protection contact: May Stokes, CEO – ceo@clonmelbid.com – 083 370 6112
This statement covers everything Clonmel BID does, not just this website. Where we collect data in a specific way – on a form, at an event, on a sign-up sheet – we may also give you a shorter notice at that point.
2. Who this applies to
We deal with several groups of people, and we hold different information about each:
Levy payers and their staff – the owners, occupiers and representatives of rateable businesses within the BID area
Businesses and organisations we work with – suppliers, contractors, partners, sponsors, event vendors and stallholders
The public – people who visit the website, sign up for our newsletter, contact us, attend our events or take part in our campaigns
Directors, committee members and volunteers
Job applicants and staff
3. What we collect, why, and on what legal basis
Under the GDPR, we need a lawful basis for each use of your data. The main ones we rely on are: performing a contract with you; a legal obligation; our legitimate interests as the town’s BID (where these are not outweighed by your rights); and your consent, which you can withdraw at any time.
We do not carry out automated decision-making or profiling that produces legal or similarly significant effects on you.
4. Where the data comes from
Most of the data we hold comes from you directly. Levy payer information also comes from Tipperary County Council’s rates records and from publicly available sources such as the Valuation Office. Event booking data may come from the operators we partner with (see section 5).
5. Who we share data with
We do not sell personal data. We share it only where necessary, with:
Tipperary County Council – as rating authority, the Council issues and collects the BID levy. We exchange levy payer and property data with the Council under a data sharing agreement.
Event operators and partners – for example, the operator of Clonmel On Ice handles rink bookings and ticketing under its own privacy policy. Where we run an event with a partner, we agree in advance who is responsible for what data.
Service providers who process data on our behalf – listed below. Each is bound by a data processing agreement and may only use the data on our instructions.
Professional advisers – accountants, auditors, solicitors and our data protection adviser.
Public bodies – where the law requires it, for example the Companies Registration Office, Revenue, An Garda Síochána or the Data Protection Commission.
6. Transfers outside the EEA
Some of the providers above store or access data outside the European Economic Area (EEA), mainly in the United States and, in some cases, the United Kingdom. The GDPR only allows this where an approved safeguard is in place. Depending on the provider, we rely on one of the following:
An EU adequacy decision. The European Commission has formally decided that certain countries protect personal data to a standard equivalent to the EU, so data can flow to them without further safeguards. The United Kingdom is covered by an adequacy decision, as are countries such as Switzerland, Canada, Japan and New Zealand. Where a provider is based in one of these countries, this is the basis we use.
The EU–US Data Privacy Framework. This is the Commission’s adequacy decision for the United States, and it applies only to US companies that have certified under the Framework. We check that a provider is certified before relying on it.
Standard Contractual Clauses. Where neither of the above applies, we use the European Commission’s Standard Contractual Clauses, built into our data processing agreement with the provider, together with any extra measures the transfer needs.
The table in section 5 shows which safeguard applies to each provider. In particular, our newsletter data is held by Mailchimp in the United States. If you would rather we did not transfer your data in this way, don’t sign up for the newsletter – you can still keep up with us on the website and social media.
You can ask us for more detail on any transfer, or a copy of the relevant safeguard, at ceo@clonmelbid.com.
7. Email newsletter and tracking
We only send our newsletter to people who have opted in. Every email has an unsubscribe link, and you can also email ceo@clonmelbid.com to be removed.
We do not track whether you open our emails or which links you click. Open and click tracking is switched off in our email system.
8. How long we keep data
9. Your rights
You have the right to:
Access the personal data we hold about you
Have inaccurate data corrected
Have your data erased, where there is no good reason for us to keep it
Restrict how we use it in certain circumstances
Object to processing based on our legitimate interests, including direct marketing
Receive a copy of the data you gave us in a portable format
Withdraw consent at any time, where we rely on it
To exercise any of these, email ceo@clonmelbid.com. We will respond within one month. We may ask you to confirm your identity first.
If you are not happy with how we handle your data, you can complain to the Data Protection Commission, 6 Pembroke Row, Dublin 2, D02 X963 – www.dataprotection.ie. We would appreciate the chance to resolve it with you first.
10. Security
We keep personal data on password-protected, access-controlled systems with multi-factor authentication. Access is limited to people who need it for their role. Paper records are kept securely at our office. If a data breach is likely to put you at risk, we will tell you and the Data Protection Commission as the law requires.
11. Children
Our services are aimed at adults and businesses. Where children take part in events, for example school sessions at Clonmel On Ice, we collect only what is needed to run the session safely and deal with the responsible adult, school or club.
12. Changes to this statement
We will update this statement as our activities change. The date at the top tells you when it was last revised. Significant changes will be flagged on the website and, where appropriate, by email.

