1. Our Commitment
Buzybytes Solutions is fully committed to compliance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and the Irish Data Protection Acts 1988–2018. This policy sets out our approach to data protection governance.
2. Data Controller Details
Data Controller: Buzybytes Solutions
CRO Number: 759889
Registered Address: Dublin, Ireland
Data Protection Contact: connect@cohabi.eu
We have assessed that, at our current scale, appointment of a Data Protection Officer (DPO) under Article 37 GDPR is not mandatory. However, all data protection queries are handled directly by our data protection lead and responded to within 30 days.
3. Data Protection Principles
We process personal data in accordance with the six principles in GDPR Article 5:
- Lawfulness, fairness, and transparency: We process data only on a valid legal basis and inform users clearly via our Privacy Policy.
- Purpose limitation: Data is collected for specified, explicit, and legitimate purposes and not processed in ways incompatible with those purposes.
- Data minimisation: We collect only the data that is necessary for the stated purpose.
- Accuracy: We take reasonable steps to ensure data is accurate and kept up to date.
- Storage limitation: We retain data only for as long as necessary (see retention schedule in Privacy Policy).
- Integrity and confidentiality: We implement appropriate technical and organisational security measures.
4. Lawful Bases Used
- Article 6(1)(a) — Consent: Phone number collection, contact number reveal, Meta Pixel, advertising cookies.
- Article 6(1)(b) — Contract: Account creation, listing management, payment processing.
- Article 6(1)(c) — Legal obligation: Tax record retention, responding to DPC or court orders.
- Article 6(1)(f) — Legitimate interests: Fraud prevention, platform security, product improvement.
5. Data Subject Rights Procedure
Users may exercise their rights (access, rectification, erasure, portability, restriction, objection) by emailing connect@cohabi.eu. We will:
- Acknowledge the request within 5 business days
- Verify the identity of the requestor
- Respond fully within 30 calendar days (extendable to 90 days for complex requests with notice)
- Provide responses free of charge, except for manifestly unfounded or excessive requests
6. Data Breach Procedure
In the event of a personal data breach, we will:
- Assess the breach within 24 hours of becoming aware of it
- Notify the Irish Data Protection Commission within 72 hours if the breach is likely to result in a risk to individuals' rights and freedoms (GDPR Art. 33)
- Notify affected individuals without undue delay if the breach is likely to result in a high risk to their rights and freedoms (GDPR Art. 34)
- Document all breaches regardless of whether notification is required
7. Data Processing Agreements
We have binding Data Processing Agreements (DPAs) in place with all third-party processors in accordance with GDPR Article 28.
8. Privacy by Design
We embed data protection into our platform design and development processes, including:
- Collecting only the minimum data necessary for each function
- Pseudonymising data where feasible
- Conducting assessments of new features that involve high-risk processing
- Building consent mechanisms into user flows before data collection begins