St. Margaret’s Golf & Country Club 

Last updated: June 2026 

1. Introduction 

St. Margaret’s Golf & Country Club is committed to protecting the privacy and personal data of our Members and Visitors. This Privacy Policy explains what personal data we collect, why we collect it, the legal basis for doing so, how long we retain it, and your rights under applicable data protection law. 

This policy applies to all personal data collected through our website, by telephone, by email, and in person at our facility. 

2. Who We Are (Data Controller) 

The data controller responsible for your personal data is: 

St. Margaret’s Golf & Country Club 

  • Address: St. Margaret’s, Co. Dublin, K67 K339, Ireland 

3. Personal Data We Collect 

We may collect the following categories of personal data: 

  • Identity data: name 
  • Contact data: email address, postal address, phone number 
  • Transaction data: booking history, competition entries, golf lesson records 
  • Communications data: enquiry form submissions, survey responses 
  • Marketing preferences: newsletter subscription status, email engagement 
  • Security data: CCTV footage captured at our facility 

We collect personal data only when voluntarily provided by you, whether on our website, over the phone, by email, or in person at our facility. Members and Visitors may decline to provide certain information, but this may limit their ability to use some of our services. 

We do not collect special category data (e.g. health, ethnicity, religion) unless specifically required and with explicit consent. 

4. How We Collect Personal Data 

We collect personal data through the following means: 

  • Our website (contact forms, enquiry forms, online booking engine) 
  • Telephone calls with our staff 
  • In-person visits to our facility 
  • Email correspondence 
  • Competition entries and event registrations 
  • CCTV cameras installed at the facility 

5. Legal Basis for Processing 

Under the GDPR (EU) 2016/679, we rely on the following legal bases for processing your personal data: 

Processing Activity Legal Basis (GDPR Article 6) 
Responding to enquiries and contact form submissions Legitimate interests (Art. 6(1)(f)) — responding to communications 
Golf bookings, restaurant reservations, golf lesson bookings Performance of a contract (Art. 6(1)(b)) 
Membership administration and communications Performance of a contract (Art. 6(1)(b)) 
Sending marketing newsletters and promotional emails Consent (Art. 6(1)(a)) 
SMS safety/course status updates to Members Legitimate interests (Art. 6(1)(f)) — health and safety 
Running competitions and promotions Consent (Art. 6(1)(a)) 
CCTV surveillance at the facility Legitimate interests (Art. 6(1)(f)) — security and safety of staff and visitors 
Processing data for legal obligations Legal obligation (Art. 6(1)(c)) 

Where we rely on consent as the legal basis, you have the right to withdraw your consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal. 

6. Children’s Data 

We recognise the importance of protecting the privacy of children. In line with the Irish Data Protection Act 2018, the age of digital consent in Ireland is 16 years. Where we need to collect personal data from a person under the age of 16 — for example in relation to golf camps, junior lessons, or competitions — we will obtain verifiable consent from a parent or legal guardian prior to collecting or processing that data. 

We do not knowingly collect personal data from children under 16 without parental or guardian consent. 

7. Retention Periods 

We retain personal data only for as long as necessary to fulfil the purpose for which it was collected, or as required by law. Specific retention periods are as follows: 

Data Category Retention Period Reason 
Booking and transaction records 3 years from the date of the booking Legitimate interests; possible disputes or claims 
Membership records Duration of membership + 3 years after termination Contractual obligation and legal claims 
Marketing / newsletter consent & data Until you unsubscribe or withdraw consent Consent-based; inactive contacts deleted after 1 year of no engagement 
Enquiry and contact form data 1 year from date of submission Legitimate interests 
CCTV footage 60 days, then deleted unless required for an investigation Security; proportionality principle 
Competition and event data 1 year from the date of the event Legitimate interests 

 We periodically review all data held and delete data that is no longer necessary for its original purpose. 

8. Sharing Your Personal Data 

We do not sell, rent, or trade your personal data to third parties for their own marketing purposes. 

We may share your personal data with the following categories of third-party processors who act on our behalf: 

  • Booking management system providers (e.g. BRS Golf) — for golf and restaurant bookings. 
  • Till Software for members accounts (eg: Xpos) 
  • Membership software for membership management and processing (eg: golfclubsubs) 
  • Handicap administration services (e.g. Handicap Master, Golf Ireland portal) — for competition and handicap management. 
  • Email marketing platforms — for sending newsletters and surveys 
  • Payment processors — for processing online transactions 

All third-party processors are required to process your data only in accordance with our instructions and in compliance with applicable data protection law. We have, or will enter into, Data Processing Agreements (DPAs) with all processors as required by Article 28 of the GDPR. 

We do not currently transfer personal data outside the European Economic Area (EEA). If this changes, we will update this policy and ensure appropriate safeguards are in place (such as Standard Contractual Clauses approved by the European Commission). 

9. Marketing Communications 

We will only send you marketing communications (newsletters, promotions, event updates) where you have given us your express consent to do so. 

You can withdraw your consent and unsubscribe from marketing communications at any time by: 

  • Clicking the unsubscribe link at the bottom of any marketing email 

We will process your unsubscribe request promptly. Please note that operational communications (e.g. booking confirmations, safety SMS updates) are not marketing communications and are not subject to marketing opt-out. 

10. CCTV 

CCTV cameras operate at our facility for the purposes of security, health, and safety of Members, Visitors, and staff. This processing is carried out on the basis of our legitimate interests. 

CCTV footage is retained for a maximum of 60 days, after which it is permanently deleted unless it is required in connection with a criminal, health, or safety investigation. Where footage is shared with law enforcement or relevant authorities for such purposes, only the relevant footage will be shared, and footage of individuals not related to the matter will be protected to the greatest extent possible. 

Signage is displayed at our facility to inform you that CCTV is in operation. 

11. How We Protect Your Data 

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, alteration, or disclosure. These measures include: 

  • SSL encryption for all data transmitted via our website 
  • Access controls restricting staff access to personal data on a need-to-know basis 
  • Secure storage practices for physical and digital data 
  • Regular review of our data protection practices 

While we take all reasonable steps to protect your data, no method of transmission over the internet is completely secure. We cannot guarantee absolute security but will notify you and the DPC in the event of a data breach as required by law. 

12. Automated Decision-Making and Profiling 

We do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects. We may use basic email engagement tracking (e.g. open rates) to understand the effectiveness of our communications, but this does not result in any automated decisions being made about you. 

13. Your Data Protection Rights 

Under the GDPR, you have the following rights in relation to your personal data: 

Right What It Means 
Right to be Informed You have the right to receive clear, transparent information about how your data is used — which this policy provides. 
Right of Access You may request a copy of the personal data we hold about you (a Subject Access Request). 
Right to Rectification You may request that we correct inaccurate or incomplete personal data. 
Right to Erasure You may request that we delete your personal data in certain circumstances (e.g. withdrawal of consent, data no longer necessary). 
Right to Restrict Processing You may request that we limit how we use your data in certain circumstances. 
Right to Object You may object to processing based on legitimate interests or for direct marketing purposes. 
Right to Data Portability You may request your personal data in a structured, machine-readable format. 
Right not to be subject to Automated Decision-Making You have the right not to be subject to a decision based solely on automated processing that has a significant effect on you. 

 To exercise any of these rights, please contact us at info@stmargaretsgolf.com or by phone on 01-8640400. We will respond to your request within one calendar month. In complex or high-volume cases, we may extend this period by a further two months, in which case we will notify you within the first month. 

Requests that are manifestly unfounded or excessive may be subject to an administrative fee or may be refused, in accordance with Article 12(5) of the GDPR. 

If you are not satisfied with how we have handled your data or a rights request, you have the right to lodge a complaint with the Data Protection Commission (DPC) at www.dataprotection.ie. 

14. Cookies 

Our website may use cookies to improve your browsing experience. For full details of the cookies we use and how to manage your preferences, please refer to our separate Cookie Policy available on our website. 

15. Changes to This Privacy Policy 

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or for other operational reasons. When we make material changes, we will post a notice on our website and update the ‘Last updated’ date at the top of this policy. 

We encourage you to review this policy periodically. Continued use of our services after an update constitutes acceptance of the revised policy. 

16. Contact Us 

If you have any questions, concerns, or requests regarding this Privacy Policy or our data protection practices, please contact us: 

St. Margaret’s Golf & Country Club 

  • St. Margaret’s, Co. Dublin, K67 K339, Ireland 

This policy is governed by the General Data Protection Regulation (EU) 2016/679, the Irish Data Protection Act 2018, and all applicable Irish and EU data protection legislation