It applies to Information collected by us, or provided by you through our Website or in any other way (such as by email, over the telephone, by post or in meeting discussions). It is also intended to assist you in making informed decisions when using our Website and our products and services. Please take a minute to read and understand the policy.
All your personal Information shall be held and used in accordance with the EU General Data Protection Regulation 2016/679 ("GDPR") and national laws implementing GDPR and any legislation that replaces it in whole or in part and any other legislation relating to the protection of personal data. If you want to know what information we collect and hold about you, or to exercise any of your rights as set out in Section 10 below, please write to us at the address on our contact page or via e-mail at [email protected]:
Ireland Website Design is a registered Irish business, with company number 494870 and VAT number IE 3312898AH.
Last Updated: 23rd May 2018
a) Necessary for compliance with a legal obligation – we are subject to certain legal requirements which may require us to process your Information. We may also be obliged by law to disclose your Information to a regulatory body or law enforcement agency;
b) Necessary for the purposes of legitimate interests - either we, or a third party, will need to process your Information for the purposes of our (or a third party's) legitimate interests, provided we have established that those interests are not overridden by your rights and freedoms, including your right to have your Information protected. Our legitimate interests include responding to requests and enquiries from you or a third party, the delivery/implementation of our products or services (including but not limited to web design, web development, content management, digital marketing and hosting of websites, databases, SSL’s, email, SMS and any other Ireland Website Design advertised product or services), optimising our website and customer experience, informing you about our products and services and ensuring that our operations are conducted in an appropriate, fair and efficient manner;
c) Consent – in some circumstances, we may ask for your consent to process your Information in a particular way.
2.2 We have a policy of limited usage or retention of paper-based materials. Most data worked with is stored in electronic format, with the exception of hardcopy customer contracts, invoicing and company admin records (e.g. staff contracts, CV’s etc.).
2.3 We classify the data we hold under the following categories:
a) Existing Paying Ireland Website Design Customers:
For paying customers of Ireland Website Design we may store any business/company or employee data submitted to us for use in the fulfilment or billing of our products, on web design projects, hosting services, or marketing services. Data would typically be limited to contact full names, company name, email address(es), phone number(s), mobile number(s), materials, including but not limited to any communication emails, design materials, website/server login details, strategic business information, website briefs, notes on phone calls or meetings, or contact details provided of other individuals involved in the quotation purposes.
Billing details captured would include billing company name, admin contact person, email address, phone number, direct debit / bank account or credit card details for recurring payments. These sensitive billing details are securely stored in out WHMCS customer portal/billing software which customers are supplied with a secure login to for update/admin purposes. Bank account details are encrypted and credit card details are securely passed to our third party PCI DSS compliant payments provider Stripe or PayPal for storage and processing. We do not store credit card details on our servers, only a unique customer ID which is passed to Stripe/PayPals systems which carries out the actual payment.
Ireland Website Design may provide a range of Shared Hosting services, which allow a customer to provision a website, store database information, and host their email accounts on shared servers (Servers that share resources with other customers). The responsibility for securing the data is therefore shared between Ireland Website Design and the customer as detailed in Section 9.
Some Ireland Website Design customers may store personal information from their customers or website users on our web, database or email server space. This customer data is processed by Ireland Website Design in a hosting only capacity or per the instructions of our customer. We accept no responsibility for our customers use of this data, how they request that we handle this data, nor do we monitor their usage of this data apart from a server resource capacity/performance point of view. The types of data customers collect varies greatly (including eCommerce data, custom customer/user databases, eZine databases, data capture forms, data backup databases, data lookups, or unique application integrations). We encourage customers who have specific questions or requests relating to GDPR compliance to contact us at [email protected]
b) Past Ireland Website Design Customers:
Following then end of a customer relationship, we may retain certain customer detail for a period of 6 years to ensure compliance with tax requirements. Customer website data will be fully deleted from our servers within 365 days of the customer leaving (or earlier if requested).
c) Non Ireland Website Design Customers Seeking Quotations:
Where owners or employees of businesses seek quotes for our services, we request and securely store the person’s full name, company name, email address(es), phone number(s), mobile number(s), and details of the service request. For quotation purposes, we may also securely store materials, including but not limited to any subsequent communication emails, design materials, website/server login details, strategic business information, website briefs, notes on phone calls or meetings, or contact details provided of other individuals involved in the quotation purposes.
d) Subscribers to Ireland Website Design’s Email Newsletter:
Our email newsletter subscription asks for your first name, last name, phone and email address. Typically our newsletters will only use your email address, but may be personalised with your name.
e) Paid Email Databases:
Ireland Website Design may purchase a third party database of businesses email addresses for direct email marketing purposes. The databases would always be purchased from reputable data sources (e.g. Data Ireland which is part of An Post) and would never contain personal identifiable data, only general business email addresses.
d) Admin/Staff Related:
Ireland Website Design office administrative data for accounts, staffing and other administrative purposes.
a) by visiting Ireland Website Design.ie's contact form you may provide us with personal information such as name, company name, email address, phone/ mobile phone number and possible additional information if you choose to do so in the comments box.
b) by corresponding with us by email, in which case we may retain the content of your email messages together with your email address and our responses;
c) in phone calls or meetings with Ireland Website Design staff where related notes may be securely stored;
d) through our mailing list opt-in where we request your name and email address.
3.2 We may collect Information about your computer, including where available your IP address, operating system, browser type and the geographical location of your computer, for system administration, prevention of fraud or business lead identification purposes. We also use statistical and user behaviour analysis software (Google Analytics, Stat Counter, Crazy Egg, Facebook Pixel, LinkedIn Pixel, HotJar and IP Fingerprint) to get a better idea of how to improve user experience on our website. We may also report aggregate information. This is statistical data about browsing actions and patterns and does not identify you as an individual. In all cases, the suppliers of these products have stated their GDPR complieance.
4.1 We will hold, use and disclose your Information for our legitimate business purposes including:
a) answering or dealing with the purpose of the query, or implementation / quotation for the product or service(s) requested and any follow-on service or product dealings in the event of a customer.
b) emails and postal communication related to billing of our services;
c) direct marketing to keep you up to date about important changes to our business; product or service interruptions/outages/updates, product upgrades, or useful product, service, case study, or digital marketing information, research, tips or advice which may help our customers businesses. These communications may also include details of our products and services (including where we may be resellers of third-party products or services), advise you of news and industry, product or company updates, events, promotions or competitions. Before we do so, you will be given an option to opt-out of such communications and an option to unsubscribe will also be provided with each communication;
d) to apply profiling technology which analyses our customers’ engagement with our direct marketing communications, activity and interests so that we can send you content that is relevant to you;
e) to provide further services to you by sharing your Information trusted GDPR compliant third parties who we use in provision of our products or services. Further details about this are set out in the section 7 below on Sharing your Personal Information;
f) to release Information to regulatory or law enforcement agencies, if we are required or permitted to do so.
4.2 We do not process or hold certain sensitive personal data (known as special category data in GDPR) where you include it in information you send to us e.g. if you include information about your health in enquiries. We have processes in place to limit our use and disclosure of such sensitive data other than where permitted by law.
a) Employees: We may disclose your personal data to our employees on a need to know basis. Our employees sign confidentiality agreements on commencement of employment.
b) Trusted third party partners: In order to provide certain services, we may share your information with reputable and trusted third party business partners, suppliers and sub-contractors such as IT, hosting, backup, CRM, business productivity, security, billing, phone, network, email logistics providers or data centre infrastructure companies (e.g. Sungard Availability Services, Gmail). For security reasons we will not publish a full list here to minimise targeting of data within these businesses. We can supply a list of such partners upon request. We will not share your data with any third party if it is not a necessity in providing services to you or where the third party does not clearly state their own GDPR compliance policies either publically or within a direct contract with Ireland Website Design.
c) Regulatory and law enforcement agencies: As noted above, if we receive a request from a regulatory body or law enforcement agency, and if permitted under GDPR and other laws, we may disclose certain personal information to such bodies or agencies.
d) New business owners: If we or our business merges with or is acquired by another business or company, we will share your personal information with the new owners of the business or company and their advisors. If this happens, you will be sent notice of such event and you will be afforded an opportunity to opt-out.
e) Aggregated and De-Identified Information: We may share information that has been aggregated or reasonably de-identified, so that the information could not reasonably be used to identify you. For instance, we may publish aggregate statistics about the use of our services.
Where personal data is transferred outside of the EEA, your rights as a data subject are protected by data transfer mechanisms such as Standard Contractual Clauses and EU/US Privacy Shield and we have only chosen suppliers who have stated their GDPR compliance.
Data submitted through the IrelandWebsiteDesign.com contact form or mailing list form is https encrypted and automatically fed into our website database and into our cloud based CRM system. This CRM is hosted on EU servers and are contractually committed GDPR compliance.
Where data is stored electronically on our servers, we have implemented appropriate IT security measures to secure your personal data. These measures include server patching/maintenance routines, anti-virus protection, firewalls and data encryption technologies and access protocols. Periodic third party security penetration test are also carried out on servers to ensure security hardness and any recommendations deployed. Physical server and data centre policies are in place with our ISO accredited data centre partner Hosting Ireland. Unfortunately, no data transmission over the Internet or electronic storage system can be guaranteed as secure, however, we will ensure that the technical and organisational measures in place are regularly reviewed to ensure that they are up-to-date and functioning effectively. Where data is stored in hard copy format, we have management and destruction procedures in place and staff training to ensure that paper records are stored securely.
Customer requests sent to Ireland Website Design will only be acted upon if the request is from an authorised customer contact listed in our CRM. For security reasons, customer requests must be submitted to [email protected] from an authorised email address. Requests will not be acted upon over the phone.
9.2 Shared Hosting: Ireland Website Design provide a range of Shared Hosting services, which allow for server setup of a website, store database information, and host their email accounts on shared servers (Servers that share resources with other customers). The responsibility for securing the data is therefore shared between Ireland Website Design and the customer. Ireland Website Design are responsible for securing the shared hosting infrastructure (the underlying hardware and operating systems), providing server backups, disaster recovery and supporting the platform whilst the content, passwords, access to the data etc. is the responsibility of the customer. Where upgrades or data backups is not opted for in the services provided by Ireland Website Design, then the customer is responsible for their own backups and for securing the CMS applications by keeping them up to date. Ireland Website Design do not provide backups or virus/spam protection for our entry level POP3 email account offering. Customers are responsible for downloading all mail from our servers and providing their own backup and virus/spam protection. The customer is responsible for email setup on their mail client and securely accessing their email using the encrypted protocols we provide over both POP3 and Webmail. Email account changes can be requested by the customer or their approved agents and it is the customer responsibility to ensure the detail of these requests are approved and fully correct before submitting them to Ireland Website Design.
9.3 Website Content Management Security & Passwords: Ireland Website Design is responsible for providing reasonable security updates to a customer Website content management system only if contracted to do so, otherwise it is the responsibility of the customer to ensure such security updates.
The customer is fully responsible for ensuring that passwords to their websites and content management system are not easily guessed or hackable (e.g. minimum 10 characters with mix of alphanumeric characters) and are securely stored. Ireland Website Design recommends that any website or content management system admin areas are encrypted across https.
The nature of the Internet is such that no business can guarantee or warrant the security of any server or web application, especially as the underlying technology will be provided by third parties or upon open source software. We will however take all reasonable steps and organisational measures to protect servers and data through appropriate schedule server patching routines and server / network access controls.
9.4 SSL Certificates: Ireland Website Design are authorised resellers of SSL certificates and we collect personally identifiable information (name email address, CRO number etc.) pertaining to the certificate to provide the SSL provider with the information necessary to validate the registrant.
9.5 Network control: This includes the configuration, management, and securing of network elements such as virtual networking, DNS, and gateways. The controls provide a means for services to communicate and interoperate. This is Webtrade’s responsibility as it is outside the control of the customer. DNS changes may be requested by the customer or their agents and it is the customer responsibility to ensure the detail of these requests is correct before submitting them to Ireland Website Design.
9.6 Backup Services (R1Soft /CDP): Where the customer has engaged Ireland Website Design backup offering, Ireland Website Design is responsible for provision of backups, disaster recovery and implementing operational controls to restrict authorised access to the backup servers and data. No customer access is given to this facility and any requests for data restores must be submitted to Ireland Website Design.
a) Right of Access. You have the right at any time to ask us for a copy of the Information about you that we hold, and to confirm the nature of the Information and how it is used. Where we have good reason, and if the GDPR permits, we can refuse your request for a copy of your Information, or certain elements of the request. If we refuse your request or any element of it, we will provide you with our reasons for doing so.
b) Right of Correction or Completion. If Information we hold about you is not accurate, or is out of date or incomplete, and requires amendment or correction you have a right to have the data rectified, updated or completed. You can let us know by contacting us at the address or email address set out above.
c) Right of Erasure. In certain circumstances, you have the right to request that Information we hold about you is erased e.g. if the Information is no longer necessary for the purposes for which it was collected or processed or our processing of the Information is based on your consent and there are no other legal grounds on which we may process the Information.
d) Right to Object to or Restrict Processing. In certain circumstances, you have the right to object to our processing of your Information by contacting us at the address or email address set out above. For example, if we are processing your Information on the basis of our legitimate interests and there are no compelling legitimate grounds for our processing which override your rights and interests. You also have the right to object to use of your Information for direct marketing purposes.
You may also have the right to restrict our use of your Information, such as in circumstances where you have challenged the accuracy of the Information and during the period where we are verifying its accuracy.
e) Right of Data Portability. In certain instances, you have a right to receive any Information that we hold about you in a structured, commonly used and machine-readable format. You can ask us to transmit that Information to you or directly to a third party organisation.
This right exists in respect of Information that:
• you have provided to us previously; and
• is processed by us using automated means.
While we are happy for such requests to be made, we are not able to guarantee technical compatibility with a third party organisation's systems. We are also unable to comply with requests that relate to Information of others without their consent.
10.2 You can exercise any of the above rights by contacting us at the address or e-mail address set out above. You can exercise your rights free of charge. In making any request in this regard, please provide us with sufficient information to enable us to identify you. We reserve the right to request you to provide additional information in order to enable us to identify your personal data and/or to verify your identity.
10.3 If you wish to receive a copy of the data which we hold about you, when contacting us please provide us with €26.35 and we will respond to your query as quickly as possible but in any event within 40 days of receipt of your request.
10.4 Most of the above rights are subject to limitations and exceptions. We will provide reasons if we are unable to comply with any request for the exercise of your rights.
12.2 Information gathered through cookies and web server logs may include the date and time of visits, the pages viewed, time spent at our Website, and the websites visited just before and just after our Website.
12.3 Cookies, in conjunction with our web server's log files, allow us to calculate the aggregate number of people visiting our Website and which parts of the website are most popular. This helps us gather feedback so that we can improve our Website and better serve our customers. Cookies do not allow us to gather any personal Information about you and we do not generally store any personal Information that you provided to us in your cookies.
12.4 We use ‘session’ cookies which enable you to carry information across pages of the Website and avoid having to re-enter information. Session cookies enable us to compile statistics that help us to understand how the Website is being used and to improve its structure.
12.5 We also use ‘persistent’ cookies which remain in the cookies file of your browser for longer and help us to recognise you as a unique visitor to the Website, tailoring the content of certain areas of the Website to offer you content that match your preferred interests.
12.6 Cookies set by visiting this website
This cookie is set when the button is clicked to confirm you agree to receiving cookies.
Google Analytics cookie, used to distinguish users and throttle request rate Read more
Decided by Google
Google Analytics non-personally identifiable information used for website analytics. Read more
Decided by Google
You can request a copy of what data we have on record for you or request any changes to that data by emailing [email protected] and separately providing us with a processing fee of €26.35 and we will respond to your query as quickly as possible but in any event within 40 days of receipt of your request.
Customers can update stored recorded billing contact or payment details by visiting our customer portal. Contact [email protected] for your login details.