Privacy Policy
Last Updated: January 17, 2026
1. Introduction
ERD Solutions ("we", "our", or "us") is committed to protecting your privacy and ensuring GDPR compliance. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website erdsolutions.ie and use our services.
2. Data Controller and Data Protection Officer
2.1 Data Controller
ERD Solutions is the data controller responsible for your personal data under GDPR.
Company Name: ERD Solutions
Email: info@erdsolutions.ie
Website: erdsolutions.ie
Address: Ireland
2.2 Data Protection Officer (DPO)
In accordance with GDPR Article 37-39, we have designated a Data Protection Officer to oversee our data protection strategy and ensure compliance with GDPR requirements.
Contact Our Data Protection Officer
For all data protection inquiries, GDPR compliance questions, or to exercise your data subject rights:
DPO Email: privacy@erdsolutions.ie
Alternative Contact: dpo@erdsolutions.ie
Subject Line Format: [DPO Request] - [Your Topic]
Response Time: Within 72 hours for acknowledgment, full response within 30 days
The DPO is responsible for:
- Monitoring GDPR compliance and data protection practices
- Advising on data protection impact assessments (DPIAs)
- Cooperating with the Irish Data Protection Commission
- Acting as point of contact for data subjects and supervisory authorities
- Conducting internal audits and staff training on data protection
3. Lawful Basis for Data Processing
We process your personal data under the following lawful bases as per GDPR Article 6:
- Contract Performance: To provide services you have requested
- Legitimate Interest: To improve our services and communicate with you
- Consent: For marketing communications and cookies (you can withdraw at any time)
- Legal Obligation: To comply with applicable laws and regulations
4. Information We Collect
4.1 Business Information
We collect the following business information from our clients:
- Company name and business registration details
- Business contact information (email, phone, address)
- Project and service information
- Billing and payment information
- Communication logs and project documentation
4.2 Website Usage Data
- IP address and browser type
- Pages visited and time spent on our website
- Referring website addresses
- Cookie data (with your consent)
Important: We do NOT collect or store personal consumer information. We only process business-to-business information necessary for service delivery.
5. How We Use Your Information
- Provide, operate, and maintain our services
- Process invoices and payments
- Communicate about projects and services
- Send important notices and updates
- Improve our website and services
- Respond to inquiries and provide support
6. Data Minimization
We adhere to the principle of data minimization (GDPR Article 5). We only collect and process data that is necessary for the specific purposes outlined in this policy. Data is kept only for as long as necessary to fulfill these purposes or as required by law.
7. Your Rights Under GDPR (Articles 15-22)
As a data subject, you have the following rights under GDPR. We are committed to facilitating the exercise of these rights in accordance with applicable law.
Right to Access (Article 15)
You have the right to request a copy of your personal data we hold.
How to exercise:
- Send an email to privacy@erdsolutions.ie with subject "Data Access Request"
- Include your full name, email, and company name (if applicable)
- Provide proof of identity (copy of ID or passport)
- We will provide your data within 30 days in a secure, readable format
Right to Rectification (Article 16)
You can request correction of inaccurate or incomplete data.
How to exercise:
- Email privacy@erdsolutions.ie with subject "Data Correction Request"
- Specify which information is incorrect and provide the correct information
- We will update your data within 30 days and notify you once complete
Right to Erasure (Article 17) - "Right to be Forgotten"
You can request deletion of your data in certain circumstances.
How to exercise:
- Email privacy@erdsolutions.ie with subject "Data Deletion Request"
- State the reason for deletion (e.g., data no longer necessary, withdrawal of consent)
- We will assess and process within 30 days
Note: We may retain certain data if required by law (e.g., tax records for 7 years) or to defend legal claims.
Right to Restriction (Article 18)
You can request limitation of data processing in specific situations.
How to exercise:
- Email privacy@erdsolutions.ie with subject "Processing Restriction Request"
- Explain the grounds for restriction (e.g., contesting accuracy, unlawful processing)
- We will mark your data as restricted and only process it in specific circumstances
Right to Data Portability (Article 20)
You can request your data in a structured, machine-readable format (JSON, CSV, XML).
How to exercise:
- Email privacy@erdsolutions.ie with subject "Data Portability Request"
- Specify your preferred format (JSON, CSV, or XML)
- We will provide your data in the requested format within 30 days
Right to Object (Article 21)
You can object to data processing based on legitimate interests or for direct marketing.
How to exercise:
- Email privacy@erdsolutions.ie with subject "Processing Objection"
- State your grounds for objection
- For marketing: We will immediately stop processing; for other objections, we will assess within 30 days
📧 Data Subject Request Contact Information
Primary Contact: privacy@erdsolutions.ie
Alternative Contact: info@erdsolutions.ie
Response Time: Within 30 days (may extend to 60 days for complex requests with notification)
Cost: First request is free; excessive or repeat requests may incur reasonable administrative fees
Identity Verification: We may request proof of identity to protect your data security
Important: When submitting a data subject request, please include:
- Full name and email address
- Company name (if applicable)
- Specific details of your request
- Proof of identity (for security purposes)
8. Automated Decision-Making and Profiling (Article 22)
✓ Our Commitment: No Automated Legal Decisions
We do NOT use automated decision-making or profiling that would produce legal effects or similarly significantly affect you (as per GDPR Article 22).
What This Means:
- No Automated Decisions: All significant decisions about your services, pricing, or contract terms are made by humans
- No Profiling: We do not create automated profiles that would affect your access to services or pricing
- No Discriminatory Processing: We do not use algorithms that could discriminate or unfairly disadvantage you
AI Tools We Use (With Human Oversight):
- Content Generation: AI assists with proposal writing, contract drafting, and email templates - always reviewed and approved by our team
- Chatbot Assistance (Eddy AI): Our chatbot provides information and support but cannot make binding decisions - only humans can approve proposals, contracts, or changes
- Analytics: We use automated tools to analyze website traffic and user behavior patterns to improve our services - this does not affect individual decisions
Your Right to Human Review (Article 22):
If you believe any automated decision has been made that affects you, you have the right to:
- Request human intervention and review of the decision
- Express your point of view regarding the decision
- Contest the decision and request a manual review
To request human review: Email privacy@erdsolutions.ie with subject "Automated Decision Review Request"
Transparency Commitment:
If we ever introduce automated decision-making that would significantly affect you, we will:
- Notify you in advance and update this Privacy Policy
- Explain the logic involved and the significance of such processing
- Provide information on how to contest automated decisions
- Obtain your explicit consent where required by law
9. Third-Party Data Processors and Data Sharing
✓ We do NOT sell or rent your personal information to third parties.
We only share data with carefully selected third-party processors who assist in delivering our services. All processors are bound by Data Processing Agreements (DPAs) compliant with GDPR Article 28.
9.1 Third-Party Processors We Use
Stripe, Inc.
Payment Processing
Data Processed: Payment information, billing details, transaction history
Location: EU/EEA servers
Purpose: Processing online payments and managing subscriptions
Safeguards: GDPR-compliant, PCI DSS Level 1 certified
DPA: Available here
Base44 Platform
Hosting & Database Services
Data Processed: All application data (client information, projects, invoices, communications)
Location: EU/EEA data centers (AWS Frankfurt, Ireland)
Purpose: Application hosting, database management, file storage
Safeguards: GDPR-compliant, ISO 27001 certified, encryption at rest and in transit
DPA: Available here
Google Analytics
Website Analytics (Optional - Requires Consent)
Data Processed: Website usage data, IP addresses (anonymized), browser information
Location: USA (with Standard Contractual Clauses)
Purpose: Analyzing website traffic and user behavior to improve services
Safeguards: IP anonymization enabled, Standard Contractual Clauses (SCCs)
DPA: Available here
Email Service Provider
Transactional Emails (Invoices, Notifications)
Data Processed: Email addresses, names, email content
Location: EU/EEA servers
Purpose: Sending transactional emails (invoices, proposals, notifications)
Safeguards: GDPR-compliant, TLS encryption, DPA in place
9.2 Data Processing Agreements (DPAs)
Access to Our Data Processing Agreements
As required by GDPR Article 28, we maintain Data Processing Agreements with all third-party processors. These agreements ensure that processors:
- Only process data according to our documented instructions
- Maintain appropriate technical and organizational security measures
- Maintain confidentiality of personal data
- Assist with data subject rights requests
- Delete or return data upon termination of services
- Allow audits and inspections when necessary
📄 Request DPA Copies:
You can request copies of our Data Processing Agreements by emailing:privacy@erdsolutions.ie with subject "DPA Request"
We will provide summaries or full copies within 30 days, subject to confidentiality provisions.
9.3 Other Data Sharing Scenarios
Legal Requirements & Law Enforcement
We may disclose your data when required by law, court order, or to comply with legal process. We will notify you unless legally prohibited.
Business Transfers (Mergers/Acquisitions)
If we are involved in a merger, acquisition, or sale of assets, your data may be transferred. You will be notified via email and/or prominent notice on our website, with options provided.
With Your Consent
We may share data with third parties when you have provided explicit consent for specific purposes.
10. Data Security
We implement appropriate technical and organizational measures to protect your data, including:
- Encrypted data transmission (SSL/TLS)
- Secure data storage with access controls
- Regular security assessments
- Staff training on data protection
11. Data Retention
We retain your data only for as long as necessary:
- Client business data: Duration of service + 7 years (tax/legal requirements)
- Communication logs: 3 years
- Website analytics: 26 months
- Marketing consent: Until withdrawn
12. Cookies and Tracking Technologies
We use cookies and similar tracking technologies to enhance your browsing experience, analyze site traffic, and deliver personalized content. You can manage your cookie preferences through our Cookie Consent Banner.
12.1 Cookie Categories and Specific Cookies Used
Always ActiveEssential Cookies (No Consent Required)
These cookies are strictly necessary for the website to function and cannot be switched off.
cookie_consent
Stores your cookie preferences
Duration: 1 year | Type: First-party
cookie_consent_date
Records when you provided consent
Duration: 1 year | Type: First-party
session_token
Maintains your login session
Duration: Session | Type: First-party | Secure & HttpOnly
client_portal_auth
Client portal authentication
Duration: 7 days | Type: First-party | Secure & HttpOnly
Requires ConsentAnalytics Cookies
These cookies help us understand how visitors interact with our website.
_ga
Google Analytics - Distinguishes unique users
Duration: 2 years | Type: Third-party (Google)
_ga_[container_id]
Google Analytics - Persists session state
Duration: 2 years | Type: Third-party (Google)
_gid
Google Analytics - Distinguishes users
Duration: 24 hours | Type: Third-party (Google)
site_analytics
Base44 Analytics - Page views and interactions
Duration: 1 year | Type: First-party
Requires ConsentMarketing Cookies
These cookies track your online activity to help deliver more relevant advertising.
_fbp
Facebook Pixel - Delivers relevant ads and measures performance
Duration: 3 months | Type: Third-party (Meta)
_gcl_au
Google Ads - Stores conversion data
Duration: 3 months | Type: Third-party (Google)
li_sugr
LinkedIn Insight - Browser identifier for analytics
Duration: 3 months | Type: Third-party (LinkedIn)
12.2 Tracking Scripts and Third-Party Technologies
The following third-party tracking scripts may be loaded on our website when you consent to analytics or marketing cookies:
Google Analytics (gtag.js)
Script URL: https://www.googletagmanager.com/gtag/js
Purpose: Website traffic analysis, user behavior tracking, conversion measurement
Data Collected: IP address (anonymized), browser info, pages visited, referrer, device type, session duration
Privacy Controls: IP anonymization enabled, data retention set to 26 months
Google Privacy Policy →Facebook Pixel
Script URL: https://connect.facebook.net/en_US/fbevents.js
Purpose: Ad targeting, conversion tracking, audience building
Data Collected: Page views, button clicks, form submissions, device info, cookie data
Privacy Controls: Limited Data Use mode available for EU users
Meta Privacy Policy →LinkedIn Insight Tag
Script URL: https://snap.licdn.com/li.lms-analytics/insight.min.js
Purpose: Conversion tracking, retargeting, website demographics
Data Collected: LinkedIn member data, URL, referrer, IP address, device info
LinkedIn Privacy Policy →Base44 Analytics
First-party analytics (self-hosted)
Purpose: Track page views, user interactions, form submissions
Data Collected: Page URL, referrer, user actions, timestamps (no personal identifiers)
Privacy: Data stored in EU, no third-party sharing
12.3 Managing Your Cookie Preferences
You can manage your cookie preferences at any time:
- Our Cookie Banner: Click the cookie icon in the bottom left corner of any page
- Browser Settings: Most browsers allow you to refuse or delete cookies via settings
- Opt-Out Tools: Use Google Analytics Opt-out Browser Add-on, Facebook Ad Preferences, LinkedIn Ad Settings
- Do Not Track: We respect Do Not Track (DNT) browser signals for analytics cookies
Note: Blocking essential cookies may affect website functionality. Blocking analytics/marketing cookies won't affect core features.
13. International Data Transfers (GDPR Chapter V)
Primary Data Storage: Your data is primarily stored within the EU/EEA (Ireland and Germany).
In certain cases, we may transfer data outside the EU/EEA. When we do, we ensure appropriate safeguards are in place as required by GDPR Articles 44-49.
13.1 Transfer Mechanisms & Safeguards
1Adequacy Decisions (Article 45)
We may transfer data to countries recognized by the European Commission as providing adequate data protection:
- Countries: UK, Switzerland, Canada, Japan, New Zealand, and others with adequacy decisions
- Safeguard: No additional measures needed - protection equivalent to GDPR
2Standard Contractual Clauses (SCCs) (Article 46)
For transfers to countries without adequacy decisions (e.g., USA), we use Standard Contractual Clauses approved by the European Commission:
- Legal Basis: Commission Implementing Decision (EU) 2021/914
- Purpose: Provide contractual guarantees for data protection
- Applicability: Google Analytics, certain cloud services
- Transfer Impact Assessment: We conduct TIAs to ensure effective protection
Access SCCs:
View EU Standard Contractual Clauses:Official EU Document
3Data Localization Preference
We prioritize using EU/EEA-based service providers whenever possible to minimize international transfers:
- Primary servers: AWS Frankfurt (Germany) and Ireland
- Payment processing: Stripe EU entities
- Email services: EU-based providers
- Database: EU/EEA regions only
13.2 Current International Transfers
| Service Provider | Destination | Transfer Mechanism | Additional Safeguards |
|---|---|---|---|
| Google Analytics | USA | SCCs | IP anonymization, data minimization, TIA completed |
| Base44 Platform | EU/EEA Only | No Transfer | All data stays in EU (Frankfurt, Ireland) |
| Stripe Payments | EU/EEA | No Transfer | EU entity, EU servers |
13.3 Your Rights Regarding International Transfers
You have the right to:
- Be Informed: Receive information about international transfers affecting your data
- Object: Object to transfers if you believe they don't provide adequate protection
- Request Copies: Obtain copies of the safeguards in place (SCCs, BCRs, etc.)
- Access Transfer Documentation: Request details about transfer impact assessments
To exercise these rights or request transfer documentation:
Email: privacy@erdsolutions.ie with subject "International Transfer Inquiry"
Transparency Commitment:
We continuously monitor legal developments (including adequacy decisions, Schrems II rulings, and new transfer mechanisms) and will update our practices accordingly. Any material changes to international transfers will be communicated to affected clients.
14. Children's Privacy
Our services are not directed to individuals under 18. We do not knowingly collect data from children.
15. Changes to This Policy
We may update this policy periodically. We will notify you of significant changes via email or website notice. Continued use of our services after changes constitutes acceptance.
16. Right to Lodge a Complaint
If you believe we have not handled your data properly, you have the right to lodge a complaint with the Irish Data Protection Commission:
Data Protection Commission
21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland
Phone: +353 (0)761 104 800
Email: info@dataprotection.ie
17. Record of Processing Activities (GDPR Article 30)
In compliance with GDPR Article 30, we maintain a Record of Processing Activities (RoPA) that documents all data processing operations. This record is available to the supervisory authority upon request.
Summary of Processing Activities
1. Client Relationship Management
Purpose: Managing client accounts, projects, and communications
Legal Basis: Contract performance (GDPR Art. 6(1)(b))
Data Categories: Business contact info, project details, communication logs
Data Subjects: Business clients and their representatives
Recipients: Internal staff, Base44 hosting (DPA in place)
Retention: Duration of relationship + 7 years (legal obligation)
Security Measures: Encryption, access controls, audit logs
2. Invoicing and Payment Processing
Purpose: Processing payments and maintaining financial records
Legal Basis: Contract performance + Legal obligation (tax law)
Data Categories: Billing information, payment details, invoices
Data Subjects: Business clients
Recipients: Stripe (payment processor with DPA), accounting staff
Retention: 7 years (tax and accounting regulations)
Security Measures: PCI DSS compliance, encrypted transmission
3. Website Analytics
Purpose: Analyzing website traffic and improving user experience
Legal Basis: Consent (GDPR Art. 6(1)(a))
Data Categories: IP address (anonymized), browser info, page views
Data Subjects: Website visitors
Recipients: Google Analytics (SCCs), internal analytics team
Retention: 26 months
Security Measures: IP anonymization, data minimization
4. Marketing Communications
Purpose: Sending promotional emails and service updates
Legal Basis: Legitimate interest (existing clients) + Consent (prospects)
Data Categories: Email, name, company, communication preferences
Data Subjects: Clients and business prospects
Recipients: Email service provider (DPA), marketing team
Retention: Until consent withdrawn or 3 years inactivity
Security Measures: Secure transmission, list segmentation
5. Contact Form Inquiries
Purpose: Responding to service inquiries and quote requests
Legal Basis: Legitimate interest (pre-contractual)
Data Categories: Name, email, phone, company, inquiry details
Data Subjects: Prospective clients
Recipients: Sales team, Base44 storage (DPA)
Retention: 3 years from last contact
Security Measures: Encrypted storage, access restrictions
Request Full RoPA Documentation
The complete Record of Processing Activities (RoPA) is available to supervisory authorities and can be provided to data subjects upon legitimate request. To request a copy:
Email: privacy@erdsolutions.ie with subject "RoPA Request"
18. Contact Us
For any privacy-related questions or to exercise your rights:
Primary: privacy@erdsolutions.ie
General Inquiries: info@erdsolutions.ie
Website: erdsolutions.ie
