Privacy Policy

Last updated: 14 February, 2026
Effective date: 14 February, 2026

AIM Ireland is the national trade body representing Ireland’s independent music industry.

This Privacy Policy explains how we collect, use, share, and protect personal data when you visit our website, contact us, join as a member, register for events, or engage with our services.

1. Who we are

For the purposes of the General Data Protection Regulation (GDPR), AIM Ireland is the Data Controller for personal data processed through this website and related online services.

Controller contact details

  • Organisation name: Association of Independent Music Ireland (AIM Ireland)
  • Registered address: The Glasshouses GH2, 92 George’s St Lower, Dun Laoghaire, Co. Dublin, A96 VR66

2. What personal data we collect

We may collect the following categories of personal data:

A. Data you provide to us

  • Contact details: name, email address, phone number, organisation, role
  • Membership and account details: membership type, billing/contact information, organisation details, communications preferences
  • Event and training registrations: booking details, attendance information, access requirements you choose to share
  • Communications: messages submitted via forms, email, or feedback surveys
  • Payment details: we do not store full card details ourselves; payments are handled by our payment providers (see Section 6)

B. Data we collect automatically (website usage)

  • Device and technical data: IP address, browser type, device identifiers, operating system, referral URLs
  • Usage data: pages visited, actions taken, approximate location (inferred from IP), session duration
  • Cookie and tracking data: subject to your preferences (see Section 9)

C. Data from third parties

  • Where relevant, we may receive limited data from:
    • Event partners/co-hosts (e.g., attendee lists where you register via a partner system)
    • Payment providers (confirmation of payment status)
    • Email/newsletter platforms (delivery and engagement metrics)

3. Why we use your data (purposes)

We use personal data to:

  • Provide and administer membership services
  • Process event registrations, attendance management, and related communications
  • Respond to enquiries and provide support
  • Send service communications (e.g., essential notices about membership or event changes)
  • Send newsletters and marketing communications where permitted
  • Manage payments, invoicing, and financial records
  • Improve our website, services, and user experience (including analytics, where enabled)
  • Maintain security, prevent fraud, and protect our rights and the rights of others

4. Lawful bases for processing

Under GDPR, we rely on one or more of the following lawful bases:

  • Contract: where processing is necessary to provide membership, event registration, or requested services.
  • Consent: where you opt in to marketing communications or non-essential cookies/tracking.
  • Legitimate interests: where we have a genuine reason to process data (e.g., website security, service improvement, limited direct outreach to organisations relevant to AIM Ireland’s remit), balanced against your rights.
  • Legal obligation: where we must keep records for tax, accounting, or regulatory compliance.

Where we rely on consent, you can withdraw it at any time (see Section 10).

5. Marketing communications

If you subscribe to our newsletter or opt in to marketing, we may send updates about AIM Ireland news, events, training, advocacy work, and member opportunities.

  • We do not sell mailing lists.

6. Who we share your data with

We may share personal data with trusted service providers who help us run the website and deliver services. These providers act as processors (processing data on our instructions) or, in some cases, independent controllers (processing under their own terms).

Typical categories include:

  • Website hosting, content management, and technical support providers
  • Membership/CRM systems
  • Email newsletter and communications platforms
  • Event registration and ticketing platforms
  • Payment processing and accounting providers
  • Analytics and performance tools (where enabled via cookie preferences)
  • Professional advisers (legal, accounting) where necessary

We may also share data:

  • With event partners where necessary to deliver a co-hosted event (e.g., attendee lists for access control), with appropriate safeguards
  • If required by law, court order, or to protect rights, safety, and security

7. International transfers

Where personal data is transferred outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, such as:

  • Transfers to countries recognised as providing an adequate level of protection; and/or
  • Standard Contractual Clauses (and supplementary measures where needed).

8. How long we keep your data (retention)

We keep personal data only for as long as necessary for the purposes described in this policy.

Typical retention periods (adjust to your operations):

  • Membership records: for the duration of membership, plus 24 months for admin and continuity
  • Financial and invoicing records: 7 years to meet legal/accounting obligations
  • Event registrations: 24 months after the event (unless longer retention is needed for reporting obligations you clearly communicate)
  • Newsletter mailing list: until you unsubscribe or we clean inactive contacts in line with our retention practices

We may retain certain information for longer where required by law, to resolve disputes, or to enforce agreements.

9. Cookies and tracking technologies

We use cookies and similar technologies to operate the website, understand usage, and improve performance.

Under Irish ePrivacy rules, consent is generally required for cookies that are not strictly necessary.

  • Strictly necessary cookies (essential for the site to function) do not require consent.
  • Analytics, preference, and marketing cookies are optional and are used only if you choose to enable them.

Cookie controls

  • You can manage cookies via our cookie banner/preferences tool and through your browser settings.
  • You can withdraw consent at any time by updating your cookie preferences.

10. Your data protection rights

Depending on the circumstances, you may have the right to:

  • Access your personal data
  • Correct inaccurate data
  • Request deletion of your data
  • Restrict processing
  • Object to processing (including certain uses based on legitimate interests)
  • Data portability
  • Withdraw consent at any time (where we rely on consent)

11. Complaints

If you have concerns, we encourage you to contact us first so we can try to resolve the issue.

12. Security

We implement appropriate technical and organisational measures to protect personal data, including access controls and security monitoring. No method of transmission or storage is completely secure, but we work to protect data against unauthorised access, alteration, disclosure, or destruction.

13. Children’s privacy

Our website and services are not intended for children under 16 without parental/guardian involvement. If you believe a child has provided personal data to us without appropriate consent, please contact us and we will take steps to remove it where required.

14. Third-party links and embedded content

Our website may contain links to third-party websites or embedded content (e.g., videos, social media). If you follow a third-party link, their privacy policy applies. We are not responsible for third-party privacy practices.

15. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our services, legal requirements, or processing activities. The “Last updated” date at the top indicates when changes were made. If changes are material, we will take reasonable steps to notify users where appropriate.

16. Contact us