Privacy Policy

How Harrington Compliance Group collects, uses and protects personal data — written to be read, not to be survived.

Last updated 5 August 2026 GDPR & Data Protection Act 2018

1. Who we are

Harrington Compliance Group is a limited company registered in Ireland, based in Dublin 2. We provide compliance training courses and the Harrington Hub learning platform to regulated firms.

For personal data collected through this website and for our own business contacts, we are the data controller. You can reach us about anything in this policy at info@harringtoncompliance.ie or +353 1 908 1911.

2. When we are a controller, and when we are a processor

This distinction decides who you should contact about your data, so it is worth being clear about.

  • Website visitors and enquirers. If you fill in the demo form or email us, we decide what happens to that data. We are the controller and this policy governs it.
  • Learners enrolled by an employer. If your firm bought Harrington training and enrolled you, your firm is the controller and we act as their processor. We handle your training records on their written instructions under a data processing agreement. Requests about that data should go to your firm first — though you are welcome to contact us and we will point you the right way.

3. What data we collect

When you contact us

Your name, work email address, firm name, your role, approximate team size, and whatever you write in the message field. That is the entire demo form.

When you use the platform as a learner

Your name and work email address, the courses assigned to you, your progress through each one, your exam answers and score, completion timestamps, and the certificates issued to you.

When you browse the website

Standard server log data: IP address, browser and device type, pages requested, and the time of the request. This is generated automatically by the web server.

We do not collect special category data, we do not ask for financial details through the website, and we do not buy contact lists.

4. Our lawful basis

  • Contractual necessity — delivering the training platform, tracking completions and issuing certificates to firms that have bought our courses.
  • Legitimate interest — replying to enquiries, and occasional relevant updates to professional contacts at firms we work with. We have weighed this against your interests and you can object at any time.
  • Consent — optional marketing subscriptions and any non-essential cookies. Withdrawable at any point, without affecting anything processed before you withdrew.
  • Legal obligation — retaining training records for the periods anti-money-laundering law requires, and meeting our own tax and company law duties.

5. How we use your data

To answer your enquiry, provide and support the platform, track course completion, issue and re-issue certificates, produce the audit reports your firm's MLRO relies on, send service messages such as renewal and overdue-training reminders, and improve the courses themselves.

We do not sell personal data, we do not share it with advertisers, and we do not use it to train third-party machine learning models.

6. Cookies and analytics

The public website uses only what it needs to function. The platform uses a session cookie to keep you logged in, which is strictly necessary and cannot be switched off without breaking sign-in.

Where we use analytics to understand which pages are useful, it is configured to avoid identifying individuals, and any non-essential cookie is set only after you consent. You can clear or block cookies in your browser settings at any time; the strictly necessary ones will simply mean you have to sign in again.

7. Who we share data with

A short list of processors, each under a written contract that limits them to acting on our instructions:

  • Our hosting provider, for running the website and platform.
  • Our email delivery provider, for service messages and certificate delivery.
  • Our analytics provider, where used.

We will also disclose data where the law requires it, or to establish or defend a legal claim. If we are ever involved in a merger or acquisition, personal data may transfer to the acquiring entity, and you would be told before that happened.

8. Where your data is stored

Personal data is hosted within the European Economic Area, in the Ireland region where the provider offers it. We do not routinely transfer personal data outside the EEA. If that ever changes, the transfer will rest on an adequacy decision or Standard Contractual Clauses with the additional safeguards the case requires, and this policy will be updated to say so.

9. How long we keep it

  • Training and certification records — six years after the end of the relationship, which is the retention period anti-money-laundering legislation expects for training evidence.
  • Enquiries that do not become customers — 24 months, then deleted.
  • Marketing contact data — until you unsubscribe or object.
  • Server logs — 90 days.
  • Website analytics — 14 months.

Where we act as a processor for your employer, retention follows their instructions and their own retention schedule.

10. How we protect it

Encryption in transit across the whole site and platform, encryption at rest for the platform database, access limited to staff who need it for their role, multi-factor authentication on administrative accounts, logged and reviewed access, and regular backups. If a breach ever posed a risk to your rights, we would notify the Data Protection Commission within 72 hours and tell you directly where the risk was high.

11. Your rights

Under the GDPR you have the right to:

  • Ask what we hold about you, and get a copy.
  • Have inaccurate data corrected.
  • Have data erased, where no legal retention duty applies.
  • Restrict how we use it while a dispute is resolved.
  • Receive your data in a portable, machine-readable format.
  • Object to processing based on legitimate interest, including any direct marketing.
  • Withdraw consent at any time, where consent was the basis.

Email info@harringtoncompliance.ie to exercise any of these. We will respond within one month, and we do not charge for it. We may ask you to confirm your identity first, which is a protection for you rather than an obstacle.

12. Complaints

If you are unhappy with how we have handled your data, please tell us first — most things are quicker to fix directly. You also have the right to complain to the Irish supervisory authority at any time:

Data Protection Commission
6 Pembroke Row, Dublin 2, D02 X963
www.dataprotection.ie

13. Changes to this policy

When we change this policy we update the date at the top of the page. If a change materially affects how we use your data, we will tell affected users directly rather than relying on you to re-read the page.