Privacy Policy
1. Who we are
Innostack Limited (“Innostack”, “we”, “us”) is a company registered in Ireland, company registration number 793621, with its registered office at 56 Bramble Avenue, Castleoaks, Carlow, Co. Carlow, R93 F9NF, Ireland.
We build and host websites, web applications and custom software, and provide an ongoing managed service covering hosting, maintenance, security and support.
Contact us about privacy: privacy@innostack.co
We have not appointed a Data Protection Officer. We are not required to under Article 37 of the GDPR, and we have not appointed one voluntarily. Privacy questions go to the address above and reach a director.
2. What this policy covers — and what it does not
Read this section first: it decides whether this policy applies to you at all.
Innostack handles personal data in two very different roles.
When we are the controller — this policy applies
We decide how and why personal data is used when it concerns:
- visitors to our own websites, innostack.co and innostack-hub.com;
- people who contact us, request a quote, or subscribe to updates;
- our clients’ staff and directors, for contracts, billing and support; and
- people who correspond with our functional mailboxes.
This policy tells you what we do with that data.
When we are a processor — our client’s policy applies, not ours
When you use a website or application we built and host for one of our clients — booking an appointment, submitting an enquiry form, making a payment — our client decides how your data is used. We only process it on their instructions.
In that situation:
- the client is the controller, and their own privacy policy governs;
- this policy does not apply to that data;
- you should contact the client, not us, to exercise your rights; and
- if you contact us anyway, we will pass your request to them promptly and tell you we have done so. We will not answer it ourselves, because doing so would mean using your data outside our client’s instructions.
If you are unsure which applies, ask us at privacy@innostack.co and we will tell you.
3. What we collect, why, and our lawful basis
| What we collect | Where it comes from | Why | Lawful basis |
|---|---|---|---|
| Business contact details — name, business email, phone, role, company | You, when you enquire, engage us, or correspond | Responding to enquiries, quoting, delivering services, support | Contract (Art 6(1)(b)), or legitimate interests in responding to business enquiries (Art 6(1)(f)) |
| Contract and billing records — order details, invoices, payments, VAT and tax identifiers | You, and our payment provider | Performing the contract; issuing invoices; meeting tax and company-law obligations | Contract (Art 6(1)(b)); legal obligation (Art 6(1)(c)) |
| Correspondence — emails, messages, support requests and our replies | You | Providing support, keeping a record of what was agreed, resolving disputes | Contract; legitimate interests in keeping accurate records (Art 6(1)(f)) |
| Technical data — IP address, browser and device information, request and error logs, session identifiers | Automatically, when you visit our sites | Delivering the site, keeping it secure, detecting and preventing abuse, diagnosing faults | Legitimate interests in operating and securing our services (Art 6(1)(f)) |
| Usage and analytics data — pages viewed, navigation, referral source | Cookies and similar technologies, only if you consent | Understanding how our site is used so we can improve it | Consent (Art 6(1)(a)) and Regulation 5(3) of the ePrivacy Regulations |
| Marketing preferences — subscription status, opt-in and opt-out records | You | Sending updates you asked for; proving we respected your choices | Consent (Art 6(1)(a)); legitimate interests for existing-customer updates about similar services, which you can stop at any time |
We do not collect special category data (health, biometrics, race, religion, political opinion, sexual life or orientation, trade union membership) about visitors to our own sites, and we ask you not to send it to us. If you send it anyway, we will delete it unless we need it and have a valid basis under Article 9.
We do not make decisions about you by solely automated means, and we do not profile you.
We do not sell your personal data, and we do not share it with third parties for their own marketing.
Do you have to give us this information?
Providing personal data to us is not a statutory requirement, and nothing in this policy obliges you to give us anything.
- Enquiries — voluntary. If you do not give us a name and a contact address, we cannot reply to you or prepare a quotation.
- Clients — contractually necessary. We need your name, contact details and billing details to enter into and perform a contract, to issue invoices, and to meet our tax and company-law obligations. Without them we cannot provide the service or bill for it.
- Technical data — not provided by you at all. Your IP address, browser and device information and request logs are generated automatically when you visit our websites, and are necessary to deliver and secure them.
- Analytics — entirely optional. You can use our websites fully whether or not you accept analytics cookies, and nothing is withheld if you decline.
- Marketing — entirely optional, and you can withdraw at any time.
Once we hold financial and tax records, we are required by law to keep them for six years. That obligation is ours, not yours.
4. Cookies
Our websites use cookies and similar technologies. Only strictly necessary cookies are set before you choose. Everything else — analytics, preferences — is set only if you consent, and you can change or withdraw that consent at any time through the cookie settings link on our site.
Full detail is in our Cookie Policy at innostack.co/cookies.
5. Who we share it with
We use a small number of service providers. Each is bound by a written data processing agreement, and none of them may use your data for their own purposes except where stated.
| Provider | What they do for us | Where they process |
|---|---|---|
| Cloudflare, Inc. | Content delivery, reverse proxy, web application firewall and DDoS protection for our websites | Global edge network |
| Namecheap, Inc. | Hosts our functional mailboxes and their aliases | United States |
| Stripe | Processes payments made to us. Card details go directly to Stripe — we never see or store them. Stripe also acts as an independent controller for fraud prevention and its own regulatory obligations | Ireland / United States |
| Website analytics, where you have consented; our own business tooling | EU / United States |
An up-to-date list of the providers we use is published at innostack.co/subprocessors. That page also covers providers involved only in the services we deliver for our clients, so it is broader than the table above.
We may also disclose personal data to our professional advisers (accountants, solicitors, insurers) where necessary, and to a public authority or court where we are legally required to do so.
If our business is sold or merged, personal data may transfer to the buyer. We will tell affected clients before that happens.
6. Where your data is, and international transfers
Our own infrastructure is in Ireland. We own and operate our servers in Carlow. We do not use third-party cloud hosting to run client systems or to store the personal data they hold.
Some of the providers in section 5 process data outside the European Economic Area — principally in the United States. Where that happens we rely on the European Commission’s Standard Contractual Clauses (Implementing Decision (EU) 2021/914), together with technical and organisational measures appropriate to the transfer, and, where the provider is certified, the EU–US Data Privacy Framework.
A note on how we protect sensitive data in transit
Where a system we build handles special category data — for example health information submitted to a healthcare client’s booking form — that data is encrypted in your browser before it leaves your device. It passes across our content delivery provider’s network as a sealed block that provider cannot read and holds no key for, and it stays encrypted at rest on our own servers in Ireland. The decryption keys are held only on our own infrastructure. This is deliberate design, not a side effect.
You can ask us for details of the safeguards we rely on for any transfer, at privacy@innostack.co.
7. How long we keep it
| What | How long | Why |
|---|---|---|
| Business contact and enquiry records | While the relationship is active, then 2 years | So we can pick up a conversation, and stop holding data we no longer need |
| Contracts and related records | 6 years after the contract ends | Legal claims can be brought within six years under the Statute of Limitations Act 1957 |
| Financial, invoicing and tax records | 6 years | Required by section 886 of the Taxes Consolidation Act 1997 and section 285 of the Companies Act 2014 |
| Support and general correspondence | 2 years after the matter closes | |
| Server and security logs | 12 months | Security investigation and abuse prevention |
| IP addresses held for security analysis | 90 days | |
| Marketing opt-outs | Indefinitely | So we do not contact you again by mistake |
| Marketing consent records | 3 years | To show we had your consent |
| Analytics data | As set out in our Cookie Policy | |
| Backups | Overwritten on a rolling cycle and fully expunged within 90 days | Backups are held for disaster recovery only and are not used for anything else |
Where we are required to keep something longer by law, or need it for an ongoing legal claim or a Revenue query, we keep it for as long as that requires and no longer.
What happens in our backups when you ask us to delete something
We remove your data from our live systems straight away. A copy may remain in our encrypted disaster-recovery backups for up to 90 days, after which it is overwritten. While it is still there:
- it is not accessible to our staff for any operational purpose;
- it is not used to make any decision about you, and not used for anything other than checking that the backup itself works; and
- it is not restored into a live system except as part of a genuine recovery after an incident — and if that happens, we re-apply your deletion.
8. How we protect it
We hold no third-party security certification, and we do not claim one. What we actually do:
- Encryption — AES-256 for data at rest; TLS 1.3 in transit; additional end-to-end encryption for special category data, as described in section 6.
- Access control — role-based access on the principle of least privilege, reviewed periodically. Multi-factor authentication on administrative accounts. Passwords stored salted and hashed.
- Our own infrastructure — owned and operated by us, in Ireland, with physical access restricted to authorised personnel.
- Network protection — Cloudflare as reverse proxy and firewall; our origin servers are not directly exposed to the internet.
- Monitoring and logging — automated monitoring with alerting to our team, audit logging of access to and changes in personal data, and a documented process for handling incidents.
- Separation of environments — live personal data is never copied into development or test environments. Development uses synthetic data.
- Backups — taken weekly, held off-server, encrypted, and restore-tested automatically so we know they work. Backup copies are kept for a limited period and then overwritten — see section 7.
- Maintenance — software, framework and dependency updates applied as part of our managed service, with automated dependency scanning.
- Confidentiality — everyone with access is bound by confidentiality obligations.
No system is completely secure, and we cannot guarantee the security of data transmitted over the internet. If a personal data breach is likely to result in a high risk to your rights, we will tell you without undue delay, and we will notify the Data Protection Commission within 72 hours where Article 33 requires it.
9. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you and receive a copy;
- rectify it if it is inaccurate or incomplete;
- erase it, where there is no good reason for us to keep it. We remove it from our live systems straight away; a copy may remain in our encrypted backups until they are overwritten — see section 7 for how long that takes and what we do and do not do with it in the meantime;
- restrict how we use it, in certain circumstances;
- object to processing based on our legitimate interests, and to object at any time to direct marketing — which we will always honour;
- data portability — receive data you gave us in a structured, commonly used, machine-readable format; and
- withdraw consent at any time, where we rely on consent. This does not affect anything we did before you withdrew it.
To exercise any of these, email privacy@innostack.co.
How we will handle it
We will acknowledge your request within 3 business days and respond in full within one month. If your request is complex, or you have made several, we may extend that by up to two further months — and if we do, we will tell you within the first month and explain why.
We may need to confirm your identity before we act, so that we do not disclose your data to someone else. We will ask for the minimum necessary to do that.
There is no charge. We may charge a reasonable fee, or decline, only if a request is manifestly unfounded or excessive — and we will explain our reasoning if that ever happens.
If your request relates to a website we built for a client, see section 2 — the client is the controller and we will forward your request to them.
10. Children
Our services are intended for people aged 18 or over. We do not knowingly collect personal data from anyone under 18 through our own websites.
The age of digital consent in Ireland is 16, under section 31 of the Data Protection Act 2018. We have set a higher threshold because our services involve contracts and payments.
If you believe a child under 18 has given us personal data, contact privacy@innostack.co and we will delete it.
11. Changes to this policy
We update this policy when our practices or the law change. The version number and date at the top always tell you which version you are reading.
If we make a change that materially affects how we use your personal data, we will tell affected clients and subscribers directly, at least 30 days before it takes effect where we reasonably can.
12. Contact and complaints
Privacy questions, or to exercise your rights: privacy@innostack.co
Post: Innostack Limited, 56 Bramble Avenue, Castleoaks, Carlow, Co. Carlow, R93 F9NF, Ireland
We would like the chance to resolve any concern first. But you always have the right to complain to the Irish supervisory authority:
6 Pembroke Row, Dublin 2, D02 X963, Ireland
www.dataprotection.ie · Telephone (01) 765 0100
The DPC does not have a public counter and does not accept complaints by telephone — complaints are made through the contact form on its website.
You may also complain to the supervisory authority where you live or work, if that is different, and you have the right to an effective judicial remedy under Articles 78 and 79 of the GDPR.
This policy is governed by Irish law.