GDPR & privacy · version 2026-09-05-location-buffer-v2

IFE Privacy Notice and permissions

This notice explains how Irish Fodder Exchange, operated by Kieran McKenna, handles personal data. The authenticated request form below is the current contact channel for privacy enquiries and GDPR rights.

Minimum necessary

IFE collects data needed to verify users, match transactions, test quality, arrange haulage, bill and resolve disputes.

Role restricted

Farm and counterparty identities, certificates and evidence photos are not exposed outside the authorised workflow.

Lawful processing

Contract, legal obligations and legitimate interests support required processing; optional updates require consent.

Sign in to record privacy choices or submit a GDPR request.

1. Controller and scope

Irish Fodder Exchange (IFE), operated by Kieran McKenna, is the controller for marketplace account, transaction, review, approval and integrity data described here. Laboratories, hauliers, payment providers and other partners may be separate controllers for their own regulated or professional services.

2. Data collected

Account identifiers and contact details; role and partner-verification records; listings and farm location data; laboratory results and certificates; quotations, orders, invoices and payments; transport routes and equipment; uploaded batch photographs, time-stamped lift photographs, time-stamped delivery photographs, time-stamped damage photographs and notes; file fingerprints, reviews, complaints, signatures, consent records, mystery-shopper findings, and proportionate security and audit logs.

3. Purposes and lawful bases

IFE processes data to authenticate users, perform marketplace contracts, provide matching and logistics, verify quality and partners, prevent circumvention and fraud, invoice and collect fees, maintain evidence, handle complaints and legal claims, comply with law and protect marketplace integrity. The bases are performance of a contract, compliance with legal obligations and IFE’s legitimate interests in operating a safe and sustainable exchange. Where those bases apply, processing is not optional consent. Consent is used only for optional service-update messages and can be withdrawn without affecting prior lawful processing.

4. Disclosure and anonymity

Data is disclosed only to personnel, advisers, processors and transaction participants who need it for an authorised purpose. Buyer, seller and farm locations shown publicly or to hauliers before award use an approximate address area and a pin deliberately offset by up to 3 km. Exact names, addresses and contact details remain segregated until the relevant workflow requires disclosure, including release to the awarded haulier after the transaction is secured. Redacted certificates are used where farm identity is unnecessary. Evidence may be disclosed for an investigation, insurance matter, legal claim or lawful authority request.

5. Retention and security

IFE retains records only for the service, statutory accounting and tax obligations, accreditation or safety checks, complaints, fraud prevention and establishment or defence of claims. Routine access and unsuccessful demo records should be reviewed annually; evidence under an active dispute or legal hold is preserved until release is authorised. Private files are held separately from searchable metadata, access is role checked, and material evidence receives a server timestamp and cryptographic fingerprint.

6. International processing

Where a service provider processes data outside the EEA, IFE will use an applicable adequacy decision or appropriate safeguards such as EU standard contractual clauses and will assess supplementary safeguards where required.

7. Your rights

Subject to GDPR conditions and lawful exceptions, individuals may request access, correction, erasure, restriction, portability, object to processing, and withdraw consent. Requests can be submitted above. Individuals may also complain to Ireland’s Data Protection Commission at dataprotection.ie. The GDPR legal text is available from EUR-Lex.

8. Changes and required review

Material changes produce a new notice version and renewed acknowledgement. Before unrestricted commercial launch, IFE must confirm its final legal entity, postal address, privacy email, processor contracts, retention schedule, records of processing, breach procedure, data-protection impact assessments where required, and whether a Data Protection Officer must be appointed.

This operational notice and permission record support compliance but do not by themselves establish complete GDPR compliance. IFE should obtain Irish data-protection legal review before opening the service beyond controlled demonstration access.

Follow Irish Fodder Exchange