Legal

Privacy Policy

Website publication copy · Version 1.0 · Issued 25 August 2026 · Next review August 2027

How Rockstone handles personal data outside the recruitment-candidate context

SCOPEThis policy covers the public website, business enquiries, client and supplier contacts, event or marketing interactions and general administration. Recruitment candidates should also read the Candidate Privacy Notice.

Who we are and who controls your data

Rockstone Engineering is a cross-border engineering and specialist recruitment group operating through separate Swiss and Irish companies. The controller is the entity that decides why and how the relevant personal data is used.

Rockstone entities

ENTITY REGISTERED DETAILS
Switzerland Rockstone Engineering Switzerland Sàrl. Route de l’Ancienne-Papeterie 106, 1723 Marly, Switzerland.
Ireland Office 5, M:TEK II Building, Knockaconny, Armagh Road, Monaghan, H18 YH59, Ireland.

For general website administration, the Swiss entity normally acts as controller unless the interaction is expressly directed to the Irish entity. The Irish entity normally controls Irish contracts, Irish employment and Irish recruitment activity; the Swiss entity normally controls the corresponding Swiss activity. The entities may act as independent controllers and, for a jointly managed activity, may be joint controllers. You can contact either entity through the group address below.

Data we collect and where it comes from

  • identity and contact details, including name, employer, role, address, telephone number and email address;
  • communications, meeting records, enquiries, proposals, contracts, purchase orders and account-administration records;
  • website and device information, such as IP address, browser, device identifiers, consent choices and security logs;
  • professional information from you, your organisation, referrals, public professional sources or legitimate business databases;
  • financial and transaction information where needed for invoicing, payment, fraud prevention or statutory records; and
  • special-category or criminal-offence information only where necessary, proportionate and permitted by law.

Why we use personal data

PURPOSE TYPICAL LAWFUL BASIS
Respond to enquiries; arrange meetings; prepare proposals Steps requested before a contract; legitimate interests in business communications
Deliver engineering, consulting or recruitment-related contracts Contract; legitimate interests; legal obligations
Manage client, supplier and professional relationships Contract; legitimate interests in operating and improving the business
Operate, secure and improve the website Legitimate interests for security and essential operation; consent for optional cookies
Send relevant business updates Consent where required; otherwise legitimate interests, with an easy opt-out
Invoices, accounting, tax, disputes, compliance and fraud prevention Contract; legal obligations; establishment, exercise or defence of legal claims

Where Rockstone relies on legitimate interests, it considers necessity, proportionality and your reasonable expectations. You may object as explained below.

Sharing and service providers

Rockstone shares personal data only where necessary and subject to appropriate safeguards. Recipients may include the other Rockstone entity, professional advisers, IT and cloud providers, website and communications providers, banks, insurers, auditors, public authorities and counterparties to a corporate transaction. Service providers are required to protect data and act only on permitted instructions where they process data for Rockstone.

International transfers

Information may be accessed from Switzerland, Ireland or another country used by an approved service provider. Transfers from the EEA to Switzerland may rely on the European Commission’s adequacy decision while it remains applicable. Other transfers use an adequacy decision, approved standard contractual clauses or another lawful safeguard. Information about the relevant safeguard is available on request, subject to necessary redactions.

Retention

RECORD TYPICAL PERIOD OR CRITERION
Enquiry that does not lead to a contract Up to 24 months after the last meaningful contact
Client, supplier, finance and contract records Contract term plus applicable accounting, tax, limitation and regulatory periods; commonly up to 10 years where required
Business contact and marketing records While relevant to the relationship; suppression records retained as needed to honour opt-outs
Website security logs Normally no longer than 12 months unless needed to investigate an incident
Cookie-consent evidence For the period needed to demonstrate the choice and manage renewal; optional consent is requested again at least every six months
Rights requests and complaints For an appropriate period after closure to demonstrate compliance and manage claims

Rockstone may retain information longer where required by law, a regulator, litigation hold or a live dispute, and may delete or anonymise it earlier where no longer needed.

Your choices and rights

  • ask for access to, correction of or deletion of your personal data;
  • ask Rockstone to restrict processing or provide portable data where the legal conditions apply;
  • object to processing based on legitimate interests and object at any time to direct marketing;
  • withdraw consent at any time without affecting earlier lawful processing; and
  • complain to a competent data-protection authority.

Rockstone may need to verify identity and may refuse or limit a request where the law permits. Rockstone does not use solely automated decision-making that produces legal or similarly significant effects in the activities covered by this policy.

Security and incidents

Rockstone uses organisational and technical measures designed for the sensitivity and risk of the information, including access controls, approved systems, confidentiality duties, secure configuration, backup and incident response. No internet service can be guaranteed completely secure. Rockstone assesses suspected personal-data breaches and notifies authorities and affected people where legally required.

Changes

Rockstone may update this policy to reflect legal, operational or technology changes. The website will show the current version and issue date. Material changes may be highlighted through the website or direct communication where appropriate.

Contact

Privacy questions, rights requests or complaints may be sent to info@rockstoneengineering.com. Please state which Rockstone entity, role, application, project or website interaction your request concerns. Rockstone will route it to the responsible team and entity.

You may also complain to the Irish Data Protection Commission (www.dataprotection.ie) or the Swiss Federal Data Protection and Information Commissioner (www.edoeb.admin.ch). You may contact the authority in the country connected with your matter; other competent authorities may also be available under applicable law.

Approval

APPROVED BY ROLE EFFECTIVE / REVIEW
Christopher Greenan Director, for and on behalf of both Rockstone entities 25 August 2026 / August 2027