Cookie Consent

We use cookies to enhance your browsing experience, analyze site traffic, and provide personalized content. Essential cookies are required for the website to function. You can customize your preferences or accept all cookies.

By clicking "Accept All", you consent to our use of cookies. See our Privacy Policy for more details.

Privacy Policy

Last Updated: January 17, 2026

1. Introduction

ERD Solutions ("we", "our", or "us") is committed to protecting your privacy and ensuring GDPR compliance. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website erdsolutions.ie and use our services.

2. Data Controller and Data Protection Officer

2.1 Data Controller

ERD Solutions is the data controller responsible for your personal data under GDPR.

Company Name: ERD Solutions

Email: info@erdsolutions.ie

Website: erdsolutions.ie

Address: Ireland

2.2 Data Protection Officer (DPO)

In accordance with GDPR Article 37-39, we have designated a Data Protection Officer to oversee our data protection strategy and ensure compliance with GDPR requirements.

Contact Our Data Protection Officer

For all data protection inquiries, GDPR compliance questions, or to exercise your data subject rights:

DPO Email: privacy@erdsolutions.ie

Alternative Contact: dpo@erdsolutions.ie

Subject Line Format: [DPO Request] - [Your Topic]

Response Time: Within 72 hours for acknowledgment, full response within 30 days

The DPO is responsible for:

  • Monitoring GDPR compliance and data protection practices
  • Advising on data protection impact assessments (DPIAs)
  • Cooperating with the Irish Data Protection Commission
  • Acting as point of contact for data subjects and supervisory authorities
  • Conducting internal audits and staff training on data protection

3. Lawful Basis for Data Processing

We process your personal data under the following lawful bases as per GDPR Article 6:

  • Contract Performance: To provide services you have requested
  • Legitimate Interest: To improve our services and communicate with you
  • Consent: For marketing communications and cookies (you can withdraw at any time)
  • Legal Obligation: To comply with applicable laws and regulations

4. Information We Collect

4.1 Business Information

We collect the following business information from our clients:

  • Company name and business registration details
  • Business contact information (email, phone, address)
  • Project and service information
  • Billing and payment information
  • Communication logs and project documentation

4.2 Website Usage Data

  • IP address and browser type
  • Pages visited and time spent on our website
  • Referring website addresses
  • Cookie data (with your consent)

Important: We do NOT collect or store personal consumer information. We only process business-to-business information necessary for service delivery.

5. How We Use Your Information

  • Provide, operate, and maintain our services
  • Process invoices and payments
  • Communicate about projects and services
  • Send important notices and updates
  • Improve our website and services
  • Respond to inquiries and provide support

6. Data Minimization

We adhere to the principle of data minimization (GDPR Article 5). We only collect and process data that is necessary for the specific purposes outlined in this policy. Data is kept only for as long as necessary to fulfill these purposes or as required by law.

7. Your Rights Under GDPR (Articles 15-22)

As a data subject, you have the following rights under GDPR. We are committed to facilitating the exercise of these rights in accordance with applicable law.

Right to Access (Article 15)

You have the right to request a copy of your personal data we hold.

How to exercise:

  1. Send an email to privacy@erdsolutions.ie with subject "Data Access Request"
  2. Include your full name, email, and company name (if applicable)
  3. Provide proof of identity (copy of ID or passport)
  4. We will provide your data within 30 days in a secure, readable format

Right to Rectification (Article 16)

You can request correction of inaccurate or incomplete data.

How to exercise:

  1. Email privacy@erdsolutions.ie with subject "Data Correction Request"
  2. Specify which information is incorrect and provide the correct information
  3. We will update your data within 30 days and notify you once complete

Right to Erasure (Article 17) - "Right to be Forgotten"

You can request deletion of your data in certain circumstances.

How to exercise:

  1. Email privacy@erdsolutions.ie with subject "Data Deletion Request"
  2. State the reason for deletion (e.g., data no longer necessary, withdrawal of consent)
  3. We will assess and process within 30 days

Note: We may retain certain data if required by law (e.g., tax records for 7 years) or to defend legal claims.

Right to Restriction (Article 18)

You can request limitation of data processing in specific situations.

How to exercise:

  1. Email privacy@erdsolutions.ie with subject "Processing Restriction Request"
  2. Explain the grounds for restriction (e.g., contesting accuracy, unlawful processing)
  3. We will mark your data as restricted and only process it in specific circumstances

Right to Data Portability (Article 20)

You can request your data in a structured, machine-readable format (JSON, CSV, XML).

How to exercise:

  1. Email privacy@erdsolutions.ie with subject "Data Portability Request"
  2. Specify your preferred format (JSON, CSV, or XML)
  3. We will provide your data in the requested format within 30 days

Right to Object (Article 21)

You can object to data processing based on legitimate interests or for direct marketing.

How to exercise:

  1. Email privacy@erdsolutions.ie with subject "Processing Objection"
  2. State your grounds for objection
  3. For marketing: We will immediately stop processing; for other objections, we will assess within 30 days

📧 Data Subject Request Contact Information

Primary Contact: privacy@erdsolutions.ie

Alternative Contact: info@erdsolutions.ie

Response Time: Within 30 days (may extend to 60 days for complex requests with notification)

Cost: First request is free; excessive or repeat requests may incur reasonable administrative fees

Identity Verification: We may request proof of identity to protect your data security

Important: When submitting a data subject request, please include:

  • Full name and email address
  • Company name (if applicable)
  • Specific details of your request
  • Proof of identity (for security purposes)

8. Automated Decision-Making and Profiling (Article 22)

✓ Our Commitment: No Automated Legal Decisions

We do NOT use automated decision-making or profiling that would produce legal effects or similarly significantly affect you (as per GDPR Article 22).

What This Means:

  • No Automated Decisions: All significant decisions about your services, pricing, or contract terms are made by humans
  • No Profiling: We do not create automated profiles that would affect your access to services or pricing
  • No Discriminatory Processing: We do not use algorithms that could discriminate or unfairly disadvantage you

AI Tools We Use (With Human Oversight):

  • Content Generation: AI assists with proposal writing, contract drafting, and email templates - always reviewed and approved by our team
  • Chatbot Assistance (Eddy AI): Our chatbot provides information and support but cannot make binding decisions - only humans can approve proposals, contracts, or changes
  • Analytics: We use automated tools to analyze website traffic and user behavior patterns to improve our services - this does not affect individual decisions

Your Right to Human Review (Article 22):

If you believe any automated decision has been made that affects you, you have the right to:

  1. Request human intervention and review of the decision
  2. Express your point of view regarding the decision
  3. Contest the decision and request a manual review

To request human review: Email privacy@erdsolutions.ie with subject "Automated Decision Review Request"

Transparency Commitment:

If we ever introduce automated decision-making that would significantly affect you, we will:

  • Notify you in advance and update this Privacy Policy
  • Explain the logic involved and the significance of such processing
  • Provide information on how to contest automated decisions
  • Obtain your explicit consent where required by law

9. Third-Party Data Processors and Data Sharing

✓ We do NOT sell or rent your personal information to third parties.

We only share data with carefully selected third-party processors who assist in delivering our services. All processors are bound by Data Processing Agreements (DPAs) compliant with GDPR Article 28.

9.1 Third-Party Processors We Use

Stripe, Inc.

Payment Processing

EU-Based

Data Processed: Payment information, billing details, transaction history

Location: EU/EEA servers

Purpose: Processing online payments and managing subscriptions

Safeguards: GDPR-compliant, PCI DSS Level 1 certified

DPA: Available here

Base44 Platform

Hosting & Database Services

EU-Based

Data Processed: All application data (client information, projects, invoices, communications)

Location: EU/EEA data centers (AWS Frankfurt, Ireland)

Purpose: Application hosting, database management, file storage

Safeguards: GDPR-compliant, ISO 27001 certified, encryption at rest and in transit

DPA: Available here

Google Analytics

Website Analytics (Optional - Requires Consent)

SCCs Applied

Data Processed: Website usage data, IP addresses (anonymized), browser information

Location: USA (with Standard Contractual Clauses)

Purpose: Analyzing website traffic and user behavior to improve services

Safeguards: IP anonymization enabled, Standard Contractual Clauses (SCCs)

DPA: Available here

Email Service Provider

Transactional Emails (Invoices, Notifications)

EU-Based

Data Processed: Email addresses, names, email content

Location: EU/EEA servers

Purpose: Sending transactional emails (invoices, proposals, notifications)

Safeguards: GDPR-compliant, TLS encryption, DPA in place

9.2 Data Processing Agreements (DPAs)

Access to Our Data Processing Agreements

As required by GDPR Article 28, we maintain Data Processing Agreements with all third-party processors. These agreements ensure that processors:

  • Only process data according to our documented instructions
  • Maintain appropriate technical and organizational security measures
  • Maintain confidentiality of personal data
  • Assist with data subject rights requests
  • Delete or return data upon termination of services
  • Allow audits and inspections when necessary

📄 Request DPA Copies:

You can request copies of our Data Processing Agreements by emailing:privacy@erdsolutions.ie with subject "DPA Request"

We will provide summaries or full copies within 30 days, subject to confidentiality provisions.

9.3 Other Data Sharing Scenarios

Legal Requirements & Law Enforcement

We may disclose your data when required by law, court order, or to comply with legal process. We will notify you unless legally prohibited.

Business Transfers (Mergers/Acquisitions)

If we are involved in a merger, acquisition, or sale of assets, your data may be transferred. You will be notified via email and/or prominent notice on our website, with options provided.

With Your Consent

We may share data with third parties when you have provided explicit consent for specific purposes.

10. Data Security

We implement appropriate technical and organizational measures to protect your data, including:

  • Encrypted data transmission (SSL/TLS)
  • Secure data storage with access controls
  • Regular security assessments
  • Staff training on data protection

11. Data Retention

We retain your data only for as long as necessary:

  • Client business data: Duration of service + 7 years (tax/legal requirements)
  • Communication logs: 3 years
  • Website analytics: 26 months
  • Marketing consent: Until withdrawn

12. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to enhance your browsing experience, analyze site traffic, and deliver personalized content. You can manage your cookie preferences through our Cookie Consent Banner.

12.1 Cookie Categories and Specific Cookies Used

Always ActiveEssential Cookies (No Consent Required)

These cookies are strictly necessary for the website to function and cannot be switched off.

cookie_consent

Stores your cookie preferences

Duration: 1 year | Type: First-party

cookie_consent_date

Records when you provided consent

Duration: 1 year | Type: First-party

session_token

Maintains your login session

Duration: Session | Type: First-party | Secure & HttpOnly

client_portal_auth

Client portal authentication

Duration: 7 days | Type: First-party | Secure & HttpOnly

Requires ConsentAnalytics Cookies

These cookies help us understand how visitors interact with our website.

_ga

Google Analytics - Distinguishes unique users

Duration: 2 years | Type: Third-party (Google)

_ga_[container_id]

Google Analytics - Persists session state

Duration: 2 years | Type: Third-party (Google)

_gid

Google Analytics - Distinguishes users

Duration: 24 hours | Type: Third-party (Google)

site_analytics

Base44 Analytics - Page views and interactions

Duration: 1 year | Type: First-party

Requires ConsentMarketing Cookies

These cookies track your online activity to help deliver more relevant advertising.

_fbp

Facebook Pixel - Delivers relevant ads and measures performance

Duration: 3 months | Type: Third-party (Meta)

_gcl_au

Google Ads - Stores conversion data

Duration: 3 months | Type: Third-party (Google)

li_sugr

LinkedIn Insight - Browser identifier for analytics

Duration: 3 months | Type: Third-party (LinkedIn)

12.2 Tracking Scripts and Third-Party Technologies

The following third-party tracking scripts may be loaded on our website when you consent to analytics or marketing cookies:

Google Analytics (gtag.js)

Script URL: https://www.googletagmanager.com/gtag/js

Analytics

Purpose: Website traffic analysis, user behavior tracking, conversion measurement

Data Collected: IP address (anonymized), browser info, pages visited, referrer, device type, session duration

Privacy Controls: IP anonymization enabled, data retention set to 26 months

Google Privacy Policy →

Facebook Pixel

Script URL: https://connect.facebook.net/en_US/fbevents.js

Marketing

Purpose: Ad targeting, conversion tracking, audience building

Data Collected: Page views, button clicks, form submissions, device info, cookie data

Privacy Controls: Limited Data Use mode available for EU users

Meta Privacy Policy →

LinkedIn Insight Tag

Script URL: https://snap.licdn.com/li.lms-analytics/insight.min.js

Marketing

Purpose: Conversion tracking, retargeting, website demographics

Data Collected: LinkedIn member data, URL, referrer, IP address, device info

LinkedIn Privacy Policy →

Base44 Analytics

First-party analytics (self-hosted)

Analytics

Purpose: Track page views, user interactions, form submissions

Data Collected: Page URL, referrer, user actions, timestamps (no personal identifiers)

Privacy: Data stored in EU, no third-party sharing

12.3 Managing Your Cookie Preferences

You can manage your cookie preferences at any time:

  • Our Cookie Banner: Click the cookie icon in the bottom left corner of any page
  • Browser Settings: Most browsers allow you to refuse or delete cookies via settings
  • Opt-Out Tools: Use Google Analytics Opt-out Browser Add-on, Facebook Ad Preferences, LinkedIn Ad Settings
  • Do Not Track: We respect Do Not Track (DNT) browser signals for analytics cookies

Note: Blocking essential cookies may affect website functionality. Blocking analytics/marketing cookies won't affect core features.

13. International Data Transfers (GDPR Chapter V)

Primary Data Storage: Your data is primarily stored within the EU/EEA (Ireland and Germany).

In certain cases, we may transfer data outside the EU/EEA. When we do, we ensure appropriate safeguards are in place as required by GDPR Articles 44-49.

13.1 Transfer Mechanisms & Safeguards

1Adequacy Decisions (Article 45)

We may transfer data to countries recognized by the European Commission as providing adequate data protection:

  • Countries: UK, Switzerland, Canada, Japan, New Zealand, and others with adequacy decisions
  • Safeguard: No additional measures needed - protection equivalent to GDPR

2Standard Contractual Clauses (SCCs) (Article 46)

For transfers to countries without adequacy decisions (e.g., USA), we use Standard Contractual Clauses approved by the European Commission:

  • Legal Basis: Commission Implementing Decision (EU) 2021/914
  • Purpose: Provide contractual guarantees for data protection
  • Applicability: Google Analytics, certain cloud services
  • Transfer Impact Assessment: We conduct TIAs to ensure effective protection

Access SCCs:

View EU Standard Contractual Clauses:Official EU Document

3Data Localization Preference

We prioritize using EU/EEA-based service providers whenever possible to minimize international transfers:

  • Primary servers: AWS Frankfurt (Germany) and Ireland
  • Payment processing: Stripe EU entities
  • Email services: EU-based providers
  • Database: EU/EEA regions only

13.2 Current International Transfers

Service ProviderDestinationTransfer MechanismAdditional Safeguards
Google AnalyticsUSASCCsIP anonymization, data minimization, TIA completed
Base44 PlatformEU/EEA OnlyNo TransferAll data stays in EU (Frankfurt, Ireland)
Stripe PaymentsEU/EEANo TransferEU entity, EU servers

13.3 Your Rights Regarding International Transfers

You have the right to:

  • Be Informed: Receive information about international transfers affecting your data
  • Object: Object to transfers if you believe they don't provide adequate protection
  • Request Copies: Obtain copies of the safeguards in place (SCCs, BCRs, etc.)
  • Access Transfer Documentation: Request details about transfer impact assessments

To exercise these rights or request transfer documentation:
Email: privacy@erdsolutions.ie with subject "International Transfer Inquiry"

Transparency Commitment:

We continuously monitor legal developments (including adequacy decisions, Schrems II rulings, and new transfer mechanisms) and will update our practices accordingly. Any material changes to international transfers will be communicated to affected clients.

14. Children's Privacy

Our services are not directed to individuals under 18. We do not knowingly collect data from children.

15. Changes to This Policy

We may update this policy periodically. We will notify you of significant changes via email or website notice. Continued use of our services after changes constitutes acceptance.

16. Right to Lodge a Complaint

If you believe we have not handled your data properly, you have the right to lodge a complaint with the Irish Data Protection Commission:

Data Protection Commission

21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland

Phone: +353 (0)761 104 800

Email: info@dataprotection.ie

17. Record of Processing Activities (GDPR Article 30)

In compliance with GDPR Article 30, we maintain a Record of Processing Activities (RoPA) that documents all data processing operations. This record is available to the supervisory authority upon request.

Summary of Processing Activities

1. Client Relationship Management

Purpose: Managing client accounts, projects, and communications

Legal Basis: Contract performance (GDPR Art. 6(1)(b))

Data Categories: Business contact info, project details, communication logs

Data Subjects: Business clients and their representatives

Recipients: Internal staff, Base44 hosting (DPA in place)

Retention: Duration of relationship + 7 years (legal obligation)

Security Measures: Encryption, access controls, audit logs

2. Invoicing and Payment Processing

Purpose: Processing payments and maintaining financial records

Legal Basis: Contract performance + Legal obligation (tax law)

Data Categories: Billing information, payment details, invoices

Data Subjects: Business clients

Recipients: Stripe (payment processor with DPA), accounting staff

Retention: 7 years (tax and accounting regulations)

Security Measures: PCI DSS compliance, encrypted transmission

3. Website Analytics

Purpose: Analyzing website traffic and improving user experience

Legal Basis: Consent (GDPR Art. 6(1)(a))

Data Categories: IP address (anonymized), browser info, page views

Data Subjects: Website visitors

Recipients: Google Analytics (SCCs), internal analytics team

Retention: 26 months

Security Measures: IP anonymization, data minimization

4. Marketing Communications

Purpose: Sending promotional emails and service updates

Legal Basis: Legitimate interest (existing clients) + Consent (prospects)

Data Categories: Email, name, company, communication preferences

Data Subjects: Clients and business prospects

Recipients: Email service provider (DPA), marketing team

Retention: Until consent withdrawn or 3 years inactivity

Security Measures: Secure transmission, list segmentation

5. Contact Form Inquiries

Purpose: Responding to service inquiries and quote requests

Legal Basis: Legitimate interest (pre-contractual)

Data Categories: Name, email, phone, company, inquiry details

Data Subjects: Prospective clients

Recipients: Sales team, Base44 storage (DPA)

Retention: 3 years from last contact

Security Measures: Encrypted storage, access restrictions

Request Full RoPA Documentation

The complete Record of Processing Activities (RoPA) is available to supervisory authorities and can be provided to data subjects upon legitimate request. To request a copy:

Email: privacy@erdsolutions.ie with subject "RoPA Request"

18. Contact Us

For any privacy-related questions or to exercise your rights:

Primary: privacy@erdsolutions.ie

General Inquiries: info@erdsolutions.ie

Website: erdsolutions.ie