Privacy Policy
Information Collection & Use
We collect minimal personal data necessary for service delivery: name, email, company, and role. Usage analytics (anonymised) are captured via self-hosted Matomo; no third-party tracking scripts are employed. Data is processed under Art. 6(1)(b) GDPR for contract fulfillment and Art. 6(1)(f) for legitimate interest (service improvement).
Data Retention & Deletion
Client data is retained for 24 months post-engagement, then anonymised. Prospect inquiry data is deleted after 12 months unless consent is renewed. Automated erasure occurs via cron jobs; manual requests can be made to [email protected].
- Retention period: 24 months (clients), 12 months (prospects)
- Deletion method: Secure overwrite + database purge
- Legal basis: GDPR Art. 17 ‘Right to erasure’
Data Sharing & International Transfers
We host data on EU-based servers (Hetzner) and US-based AWS (us-west-2) under Standard Contractual Clauses. No data is sold or rented. Subprocessors: Stripe (payment processing), SendGrid (transactional email) — both SCC-compliant.
Your Rights
Under GDPR and CCPA, you have rights to access, rectify, port, and object. File a request via [email protected]. We respond within 30 days. Supervisory authority: Irish Data Protection Commission.
Cookies & Tracking
Session cookies (necessary for login) expire on browser close. Functional cookies store preferences (e.g., timezone) for 1 year. No advertising cookies. Matomo respects DNT headers. Cookie consent is acquired via banner before any data collection.
