Privacy Notice
Last updated: 31 July 2026
This notice explains how the Irish Association of Humanistic & Integrative Psychotherapy, CLG
(“IAHIP”, “we”) handles personal data on this page, where accredited members
request a copy of their 2B requirements document.
Who is the data controller
The Irish Association of Humanistic & Integrative Psychotherapy, CLG,
26 Fitzwilliam Street Upper, Dublin 2, D02 CT89, Ireland.
For anything in this notice, contact
[email protected].
What we collect
- The email address you type into the form.
- Technical data about the request: your IP address, your browser's user-agent
string, and the date and time. We record this to stop abuse of the form.
- Your requirements document and the details inside it: your name and the
practice, supervision and personal therapy hours recorded by IAHIP for your accreditation.
This comes from IAHIP's own membership records — you do not enter it here.
We do not use tracking or advertising cookies. The only cookie set is a session cookie needed to
protect the form against cross-site request forgery.
Why we use it, and on what basis
- To send you your document — necessary for the membership and accreditation
relationship between you and IAHIP.
- To keep the form secure (rate limiting, blocking automated abuse, security
logs) — our legitimate interest in protecting members' data from unauthorised access.
The form never confirms whether an address is on file: every submission returns the same message.
That is deliberate, so the page cannot be used to find out who is an IAHIP member.
Who else processes it
- Hostinger — hosting of this site and its database (EU).
- Cloudflare — content delivery and protection against attacks; sees the
connection metadata of every request.
- Microsoft 365 — delivers the email carrying your document.
- Google reCAPTCHA — distinguishes people from bots on this form. Google
receives your IP address and interaction data, subject to
Google's
privacy policy.
How long we keep it
- Your document and the PDF itself: 400 days after it
was last sent to you, then deleted from the database and from disk.
- Records of document requests: 90 days.
- Security logs: 180 days.
- Send queue entries: 30 days.
- Rate-limit records: 24 hours. Abuse blocks: 7 days.
Deletion runs automatically every night.
Your rights
You have the right to ask for a copy of your personal data, to have it corrected or erased, to
restrict or object to how we use it, and to receive it in a portable format. Write to
[email protected].
If you are not satisfied with how we handle your request, you can complain to the Irish Data
Protection Commission —
dataprotection.ie.
← Back to the request form