Gabadoo Limited / My OT & Me
Last updated: October 2026
Gabadoo Limited is committed to protecting the privacy, confidentiality and security of the personal information entrusted to us by children, young people, adults, families, schools, professionals and partner organisations.
We process personal data in accordance with the General Data Protection Regulation (GDPR), the Data Protection Act 2018 and other applicable Irish data protection requirements.
This policy outlines how we collect, use, store, share and protect personal information across our clinical, school, online and education services.
For more detailed information about how personal information is collected and processed when using our website and services, please also refer to our separate Privacy Policy.
We aim to ensure that personal information is:
We take particular care when processing information relating to children and young people and information concerning health, disability or support needs.
Depending on the service being provided, we may process information including:
We seek to collect only information that is relevant and necessary for the particular service being provided.
As many of our services support children and young people, we recognise that their personal information requires particular care.
Information concerning a person's health is considered special category personal data under GDPR and is subject to additional protections.
We only collect and process this type of information where there is an appropriate lawful basis and where it is necessary and relevant to the service being provided.
Access to clinical and sensitive information is restricted to authorised personnel who require access for their role.
Personal information may be used to:
We do not use clinical information for unrelated marketing purposes.
We use a limited number of technology providers and systems to operate our services.
Cliniko is used for clinic and client management, appointments, scheduling and relevant clinical administration and records.
Gabadoo is our own secure digital platform used to provide Gaba Plans and other information to families and schools and to securely manage relevant client information. The platform uses cloud infrastructure, including Amazon Web Services/Amazon S3.
Webflow is used to operate our website. Information submitted through website forms may be collected and forwarded to authorised members of our team for the purpose of responding to the enquiry or providing the requested service.
Google Workspace/Gmail is used for company email and communication.
Brevo is used to manage appropriate email communications, including service and marketing communications where applicable.
Where external technology providers process personal information on our behalf, we take reasonable steps to ensure appropriate contractual, security and data protection safeguards are in place.
We use organisational and technical measures designed to protect personal information against unauthorised access, disclosure, alteration, loss or destruction.
These include:
All therapists, employees and contractors with access to personal information are expected to comply with our confidentiality, data protection and information-security procedures.
Families, schools and professionals may send us reports, assessments, referral information or other documents by email.
Email is a widely used method of communication; however, standard email may not provide the same level of security as a dedicated clinical or secure document-management system.
We encourage families, schools and professionals to send only information that is relevant and necessary to the service being provided.
Where information received by email is required as part of a client's clinical or service record, the relevant information may be transferred to the appropriate secure client-management system.
We aim to avoid retaining unnecessary copies of sensitive information across multiple systems.
Where a school, healthcare professional or other organisation provides information about a child or client, that organisation is responsible for ensuring that it has an appropriate basis for sharing that information with us.
We will use information received from third parties only for the purposes for which it has been provided and where it is relevant to the service being delivered.
Where appropriate, families will be informed about information received from other sources.
We do not sell personal or clinical information.
Information may be shared, where appropriate and necessary, with:
We seek to share only the minimum information reasonably necessary for the relevant purpose.
Where a report, recommendation or Gaba Plan is being shared with another professional or organisation, appropriate consent or another applicable lawful basis will be established where required.
Gabadoo may use artificial intelligence and AI-assisted tools to improve efficiency in administrative, operational, content-development and professional workflows.
We do not knowingly enter identifiable client information, children's personal information, clinical records, reports or other confidential personal data into general-purpose AI services.
Where AI-assisted functionality is incorporated into our own systems or an approved service in the future, appropriate data protection, privacy and security safeguards will be considered before personal information is processed.
AI may support our team in working more efficiently but does not replace professional judgement. Clinical recommendations, reports and decisions relating to an individual remain subject to appropriate professional oversight.
We do not use AI to make solely automated clinical decisions about children, families or clients.
Gabadoo may from time to time participate in research, evaluation or service-development projects with universities, colleges, healthcare organisations, public bodies or other recognised research partners.
We recognise that research involving children, families, clients or clinical information requires particular care.
Participation in research will not automatically form part of receiving a Gabadoo service. Where a research project requires the use of identifiable personal or clinical information, this information will not be provided to or used by a research partner without the appropriate lawful basis and, where we rely on consent, explicit permission from the individual, parent or legal guardian as appropriate.
Where consent is sought for participation in a research study:
Where possible and appropriate, research and service evaluation may use anonymised or aggregated information so that individual children, families, schools or clients cannot be identified.
Information that has been genuinely anonymised so that an individual is no longer identifiable is not treated as personal data under GDPR. Pseudonymised or coded information that could still be linked back to an individual will continue to be treated as personal data and protected accordingly.
Any research collaboration involving personal data will be subject to appropriate data protection, confidentiality and information-security arrangements. Where required, this may include research agreements, data-sharing arrangements, data protection impact assessments and/or appropriate research ethics processes.
Gabadoo will not disclose identifiable client or clinical information for publication, presentation or research purposes without an appropriate legal basis and the required permissions.
We may use contact information to communicate about relevant Gabadoo or My OT & Me services, resources, training or events where we have an appropriate lawful basis to do so.
Where marketing communications are based on consent, individuals may withdraw that consent or unsubscribe at any time.
Clinical or sensitive information is not used to determine or personalise marketing communications.
We retain personal information only for as long as it is necessary for the purpose for which it was collected and to meet applicable clinical, professional, contractual, insurance, regulatory and legal requirements.
Because we provide clinical and therapy services, some records must be retained for an extended period even after a person is no longer actively using our services.
As a general retention approach:
Where a legal, regulatory, safeguarding, insurance or professional requirement requires information to be retained for longer, we may retain the relevant information for the required additional period.
Information does not necessarily need to remain in the system in which it was originally received. For example, where a report is received by email and becomes part of a client's clinical record, the relevant record may be securely retained within the client's clinical record rather than keeping unnecessary duplicate copies across different systems.
Once personal information is no longer required, it will be securely deleted, destroyed or anonymised as appropriate.
We aim to collect and retain the minimum amount of personal information necessary to provide our services safely and effectively.
Staff and therapists should avoid recording unnecessary personal information and should not retain duplicate copies of reports, records or other sensitive documents where these are not required.
Any suspected loss, accidental disclosure, unauthorised access or other potential breach involving personal information must be reported internally as soon as it is identified.
Gabadoo will assess the incident and take appropriate steps to contain and investigate it.
Where required under GDPR, we will notify the Data Protection Commission and/or affected individuals within the applicable legal timeframes.
Depending on the circumstances, individuals have rights under data protection legislation including the right to:
These rights are not absolute. For example, a request for deletion does not necessarily require us to delete a clinical record that we are legally or professionally required to retain.
Requests relating to personal information should be made using the contact details provided on our website.
Individuals also have the right to raise a concern with the Irish Data Protection Commission.
Everyone working with Gabadoo who has access to personal information must:
Access may be removed immediately when a person's engagement with Gabadoo ends or where access is no longer required.
When providing services to schools, Family Resource Centres, public bodies or other organisations, the respective data protection responsibilities of Gabadoo and the organisation may vary depending on the service being provided.
In some circumstances, Gabadoo may act as an independent data controller. In others, Gabadoo may process information on behalf of an organisation.
Where required, appropriate data-processing or data-sharing arrangements will be established between Gabadoo and the relevant organisation.
Schools and organisations should only provide Gabadoo with personal information that is necessary for the agreed service.
Some technology providers used by Gabadoo may process or store information using infrastructure located outside Ireland or the European Economic Area.
Where this occurs, we seek to ensure that appropriate mechanisms and safeguards for international data transfers are in place as required under applicable data protection legislation.
Gabadoo is responsible for maintaining appropriate data protection practices and keeping this policy under review.
Our systems, suppliers and procedures may change as our services develop. We will periodically review our data protection arrangements and update this policy where appropriate.
Staff and contractors are expected to raise any data protection or information-security concerns promptly so they can be investigated and addressed.
Questions, requests or concerns regarding personal information or this policy can be submitted to Gabadoo using the contact details provided on our website or to support@gabadoo.com.
If an individual is dissatisfied with how their personal information has been handled, they may also contact the Data Protection Commission (Ireland).
Gabadoo Limited / My OT & Me
Hospital, Co. Limerick, Ireland
Last updated: October 2026