Guardian Safety — Food Safety Training
  • Home
  • HACCP training
    • HACCP Level 1 Course
    • HACCP Level 2 Course
    • HACCP Level 1 & 2 Course
    • HACCP Level 3 Course
    Specialist courses
    • Allergen Awareness Course
    • Knife Safety Training Course
    • Health & Safety in Commercial Kitchens
    Browse
    • All courses
    • Online courses
    • Classroom courses
    Training a team?Trainer-led courses at your premises or ours, for groups of up to 12. One invoice, certificates on the day.Get a group quote
  • For Business
  • About
  • Blog
  • Contact
01 424 3013Call usBook training
  • Home
  • Courses
    HACCP training
    • HACCP Level 1 Course
    • HACCP Level 2 Course
    • HACCP Level 1 & 2 Course
    • HACCP Level 3 Course
    Specialist courses
    • Allergen Awareness Course
    • Knife Safety Training Course
    • Health & Safety in Commercial Kitchens
    Browse
    • All courses
    • Online courses
    • Classroom courses
  • For Business
  • About
  • Blog
  • Contact
Book trainingCall 01 424 3013
Privacy policy · Updated 18 September 2026

Privacy policy.

How Guardian Safety collects, uses and protects personal data across our websites, our online academy and the training we deliver in person.

On this page
  1. Who we are
  2. What we collect
  3. Why we use it and our legal basis
  4. Trainees booked by an employer
  5. Who we share data with
  6. How long we keep it
  7. Your rights
  8. Cookies
  9. How we protect your data
  10. Children
  11. Changes to this policy

Questions about this page? Email [email protected] or call 01 424 3013.

Who we are

Kearns Environmental Health and Safety Limited, trading as Guardian Safety, is the data controller for the personal data described in this policy. We are a training company based at Unit C1, Centrepoint Business Park, Oak Road, Dublin 12, Ireland. You can reach us at [email protected] or on 01 424 3013.

This policy covers all of our websites and services:

  • food-safety.ie, food safety and HACCP training
  • manual-handling.ie, manual handling training
  • guardiansafetytraining.ie, our main training website
  • online.guardiansafetytraining.ie, our online academy, where online courses are bought and taken

It also covers enquiries and bookings made by phone or email, courses delivered at our training centre or at your premises, and the certificates we issue. Wherever you deal with Guardian Safety, this is the policy that applies.

What we collect

We only collect what we need to answer you, deliver training and issue valid certificates.

  • Enquiries. When you fill in a form, email or call us: your name, company, phone number, email address, the course you are interested in, how many people need training, and anything you tell us in your message. Our forms also record which website and page the enquiry came from.
  • Bookings and invoicing. Company name, billing address, purchase order numbers, the names of the people attending, and the invoices and payments that follow.
  • Trainee details. For every person we train: name, employer, email address, the course taken, the date, the result, and the certificate number. Employers often give us these details on behalf of their staff.
  • Online academy accounts. Name, email address, password (stored in encrypted form), the courses you are enrolled on, your progress, test attempts and scores, and the certificates you have earned.
  • Payments. Card payments are processed by our payment provider. We receive confirmation of the payment and the last four digits of the card. We never see or store your full card number.
  • Website use. Standard server logs (IP address, browser, pages visited, time of visit) and, only if you accept them, analytics cookies. See the cookies section below.
  • Correspondence. Emails, letters and notes of phone calls about your enquiry, booking or certificate.

We do not collect special categories of data. If a trainee needs an adjustment for a course, such as extra time or a different format, we only keep the note we need to arrange it.

Why we use it and our legal basis

Under the General Data Protection Regulation we need a legal basis for everything we do with personal data. Ours are:

  • To perform a contract with you: answering your enquiry, quoting, taking a booking, delivering the course, marking assessments, issuing your certificate and taking payment.
  • To meet a legal obligation: keeping training and certification records so that a certificate can be verified, keeping invoices and accounts for Revenue, and responding to lawful requests from regulators such as environmental health officers or the Health and Safety Authority.
  • Our legitimate interests: keeping our websites secure, preventing spam and fraud, understanding how our sites are used so we can improve them, telling existing customers about renewals and refresher dates for courses they have already done, and managing our business. We balance these interests against your rights, and you can object at any time.
  • Your consent: analytics cookies, and any marketing email you sign up for. You can withdraw consent whenever you like and it will not affect anything that happened before.

Trainees booked by an employer

Most of the people we train are booked by their employer. If that is you, your employer has given us your name and contact details so that we can enrol you, record your attendance and issue your certificate. We hold those records as the data controller because a certificate must be traceable to the person who earned it and to the training provider who issued it.

We share your result and certificate with the employer who booked and paid for the course. We do not share it with anyone else unless the law requires it or you ask us to, for example to confirm a certificate to a new employer.

Who we share data with

We do not sell personal data. We share it only with the companies that help us run the business, each of which is bound by a contract that limits what they can do with it:

  • Our CRM, where enquiries and bookings are stored so the right person can reply to you.
  • Our website and online academy platforms, which host these sites, your academy account and your course progress.
  • Our payment provider, which processes card payments securely on our behalf.
  • Google, for the reCAPTCHA check that protects our forms from spam and, if you accept analytics cookies, for anonymised website statistics.
  • Our accountants, IT support and professional advisers, where they need access to do their job.
  • Accreditation bodies, where a course is accredited and the body requires a record of who completed it.
  • Regulators, courts and law enforcement, where the law requires us to.

Some of these providers process data outside the European Economic Area, mainly in the United States. Where that happens we rely on the European Commission's adequacy decisions or on Standard Contractual Clauses, and we check that the provider offers an appropriate level of protection.

How long we keep it

We keep personal data only for as long as we need it, then delete or anonymise it.

  • Enquiries that do not lead to a booking: 24 months from your last contact with us. If you go on to book, or the enquiry becomes part of a customer account or support history, it is kept with that account for as long as the account is active.
  • Training records and certificates: 7 years after the certificate expires. Employers, insurers and inspectors ask us to verify certificates long after a course, and some workplace training must be evidenced for the period the person is employed.
  • Online academy accounts: for as long as the account is active, and for 5 years after the last login. Certificates are renewed on the cycle shown on each certificate, so this keeps your history and renewal reminders available for a full cycle plus a margin. After that the account is closed and only the certificate record above is kept.
  • Support tickets and correspondence: kept with the related account or enquiry and deleted on the same timetable.
  • Invoices, payments and accounts: 7 years, as Irish tax and company law requires.
  • Website logs: 12 months. Analytics data is held in anonymised form only.

Your rights

You have the right to:

  • Access the personal data we hold about you and get a copy of it.
  • Correct anything that is inaccurate or incomplete, including the name on a certificate.
  • Erase your data where we no longer need it. We cannot erase a certificate record during its retention period, because that would stop the certificate from being verifiable, but we will explain that if it applies.
  • Restrict or object to how we use your data, including for our legitimate interests or any marketing.
  • Receive your data in a portable format where we process it on the basis of a contract or consent.
  • Withdraw consent at any time where consent is the basis we rely on.

To use any of these rights, email [email protected] or write to us at Unit C1, Centrepoint Business Park, Oak Road, Dublin 12, Ireland. We will reply within one month. We may ask you to confirm your identity first so that we do not release your data to the wrong person.

If you are unhappy with how we have handled your data, you can complain to the Data Protection Commission, 6 Pembroke Row, Dublin 2, D02 X963, or at dataprotection.ie. We would ask that you contact us first so we can try to put things right.

Cookies

Our websites use a small number of cookies and similar technologies.

  • Essential cookies keep you logged in to the online academy, remember your basket during checkout and protect our forms against spam. The sites do not work without them, so they do not need your consent.
  • Analytics cookies tell us which pages are read and where visitors come from, in aggregate and with IP addresses anonymised. We only set these if you accept them, and you can change your mind through the cookie settings on the site.
  • Third-party embeds. Our enquiry forms are provided by our CRM, the spam check by Google reCAPTCHA, and some pages embed videos. These providers may set their own cookies when the embed loads. Their policies apply to those cookies.

You can also block or delete cookies in your browser settings. If you block essential cookies some parts of the sites, in particular the online academy, will not work.

How we protect your data

All of our websites are served over encrypted connections. Access to our CRM, academy and accounting systems is limited to the staff who need it and protected by individual logins and two-factor authentication where available. Payment card details are handled entirely by our payment provider under the PCI DSS standard. Paper records are kept at our training centre and shredded when no longer needed.

No system is perfectly secure. If we ever discover a breach that puts your rights at risk we will tell you and the Data Protection Commission without undue delay, as the law requires.

Children

Our courses are for people in work or preparing for work. We do not knowingly collect data from anyone under 16 except where a school, college or employer enrols them on a course, in which case that organisation is responsible for obtaining any consent needed.

Changes to this policy

We update this policy when our services or the law change. The date at the top tells you when it was last revised. Significant changes will be announced on the site or, for academy account holders, by email.

This policy was last updated on 18 September 2026.

Guardian Safety — Food Safety Training

Food safety and HACCP training from Guardian Safety, Dublin. See all our health and safety courses at guardiansafetytraining.ie.

Courses

  • HACCP Level 1
  • HACCP Level 2
  • HACCP Level 1 & 2
  • HACCP Level 3
  • Allergen Awareness
  • Knife Safety Training
  • Health & Safety in Commercial Kitchens

Company

  • Home
  • For Business
  • About
  • Blog
  • Contact
  • Online Academy
  • Guardian Safety Training

Contact

  • 01 424 3013
  • [email protected]
  • Dublin, Ireland
© 2026 Kearns Environmental Health and Safety Limited, trading as Guardian Safety.
  • Privacy
  • Terms