1. Introduction and company information
This Privacy Policy explains how Celtic Digital Marketing Limited collects, uses, stores, shares, and protects personal data when you visit our website, contact us, use our services, or otherwise interact with us. We are a digital-marketing business and process personal data in connection with marketing campaigns, lead generation, website analytics, advertising, client communications, and related services.
Data controller: Celtic Digital Marketing Limited
Address: Unit 4, Sandyford Business Centre, Blackthorn Road, Sandyford, Dublin 18, D18 VY57, Ireland
Email: [email protected]
Phone: +353 1 524 8796
For the purposes of applicable data protection laws, Celtic Digital Marketing Limited is the controller of the personal data described in this Privacy Policy unless we expressly state otherwise.
2. Data collection and processing
We may collect and process the following categories of personal data:
- Identity data: name, job title, company name.
- Contact data: email address, telephone number, postal address, and other contact details.
- Communication data: messages, enquiry details, correspondence, and call notes.
- Technical data: IP address, device identifiers, browser type and version, time zone setting, operating system, referral source, and website interaction data.
- Usage data: pages visited, time spent on pages, clicks, form submissions, and similar engagement information.
- Marketing and advertising data: campaign responses, preferences, lead-source information, and ad interaction data.
- Client and business data: information provided by clients or prospective clients in the course of our services, including campaign requirements, audience parameters, and performance metrics.
We collect data directly from you when you complete forms, contact us, subscribe to updates, request a quote, or use our services. We also collect data automatically through cookies, analytics tools, and similar technologies. In some cases, we may receive personal data from third parties such as business partners, advertising platforms, analytics providers, lead-generation sources, and publicly available sources where permitted by law.
3. Purpose of data processing
We process personal data for the following purposes:
- to respond to enquiries and provide quotations, proposals, and customer support;
- to deliver digital-marketing services and manage client relationships;
- to manage and optimise marketing campaigns, advertising, and analytics;
- to operate, maintain, and improve our website, services, and user experience;
- to communicate with you about our services, updates, and administrative matters;
- to comply with legal and regulatory obligations;
- to detect, investigate, and prevent fraud, misuse, or security incidents;
- to establish, exercise, or defend legal claims;
- to carry out business operations such as record keeping, reporting, and internal administration.
4. Legal basis for processing
We process personal data only where we have a lawful basis to do so. Depending on the context, our legal bases may include:
- Consent: where you have given clear permission for specific processing, such as certain marketing communications or cookie use.
- Contract: where processing is necessary to enter into or perform a contract with you or your organisation.
- Legal obligation: where processing is required to comply with applicable laws, regulations, or lawful requests.
- Legitimate interests: where processing is necessary for our legitimate business interests, such as running and improving our services, securing our systems, managing client relationships, and promoting our business, provided those interests are not overridden by your rights and freedoms.
Where we process special category data or otherwise sensitive information, we will only do so where permitted by law and subject to appropriate safeguards.
5. Data sharing and third parties
We may share personal data with trusted third parties where necessary for the purposes described in this Privacy Policy. These may include:
- Service providers: hosting providers, email and communication platforms, customer relationship management tools, analytics providers, cloud storage providers, payment processors, and IT support providers;
- Advertising and marketing partners: platforms used to run, measure, and optimise campaigns, including search, social, and display advertising services;
- Professional advisers: lawyers, accountants, auditors, insurers, and consultants;
- Regulatory and public authorities: where required by law, court order, or lawful request;
- Business counterparties: in connection with a merger, acquisition, restructuring, sale of assets, or similar corporate transaction.
We require third parties to handle personal data securely and only in accordance with applicable law and our instructions where they act as processors on our behalf. Some third parties may act as independent controllers of the data they receive; in such cases, their own privacy notices may also apply.
6. Data transfer to third countries
Where necessary, personal data may be transferred to and processed in countries outside Ireland and, where applicable, outside the European Economic Area. This may occur when we use international service providers or when marketing platforms store or process data in other jurisdictions.
When we transfer personal data internationally, we take steps to ensure that appropriate safeguards are in place, such as:
- transfer mechanisms approved by applicable law;
- adequacy decisions where available;
- contractual protections and data processing terms;
- technical and organisational measures to protect the data.
7. Storage duration
We retain personal data only for as long as necessary for the purposes for which it was collected, including to satisfy legal, accounting, reporting, contractual, or operational requirements. Retention periods may vary depending on the type of data and the context of processing.
In determining retention periods, we consider:
- the amount, nature, and sensitivity of the data;
- the risk of harm from unauthorised use or disclosure;
- the purposes of processing and whether those purposes can be achieved by other means;
- legal and regulatory requirements;
- whether a longer retention period is necessary for dispute resolution or enforcement of rights.
When personal data is no longer required, we will delete, anonymise, or securely archive it in accordance with our retention practices and applicable law.
8. User rights
Subject to applicable law, you may have the following rights in relation to your personal data:
- Access: to request confirmation of whether we process your data and obtain a copy of it;
- Rectification: to request correction of inaccurate or incomplete data;
- Erasure: to request deletion of your data in certain circumstances;
- Restriction: to request limitation of processing in certain situations;
- Data portability: to request your data in a structured, commonly used, machine-readable format where applicable;
- Objection: to object to processing based on legitimate interests or to direct marketing at any time;
- Rights related to automated decision-making: where applicable, to request information about any automated decision-making and its effects.
To exercise any of these rights, please contact us using the details below. We may need to verify your identity before responding. We will respond within the timeframe required by applicable law.
9. Withdrawal of consent
Where we rely on your consent to process personal data, you may withdraw that consent at any time. Withdrawing consent will not affect the lawfulness of processing carried out before withdrawal.
You can withdraw consent by contacting us at [email protected] or by using any unsubscribe or preference-management mechanism provided in our communications. If you withdraw consent, we may still process your data where we have another lawful basis to do so.
10. Right to complain
If you have concerns about how we process your personal data, please contact us first so that we can try to resolve the matter. You also have the right to lodge a complaint with the relevant data protection supervisory authority.
In Ireland, the relevant authority is the Data Protection Commission. If you are located in another jurisdiction, you may have the right to contact your local supervisory authority as well.
11. Data security
We take the security of personal data seriously and implement appropriate technical and organisational measures designed to protect against unauthorised access, loss, misuse, alteration, or disclosure. These measures may include:
- access controls and role-based permissions;
- secure passwords and multi-factor authentication where appropriate;
- encryption and secure transmission protocols;
- regular software updates and system monitoring;
- back-up and disaster recovery procedures;
- staff training and confidentiality obligations;
- review of third-party security practices.
While we take reasonable steps to protect your personal data, no system or method of transmission over the internet can be guaranteed to be completely secure.
12. Contact information
If you have any questions about this Privacy Policy, our data practices, or if you wish to exercise your rights, please contact:
Celtic Digital Marketing Limited
Unit 4, Sandyford Business Centre, Blackthorn Road, Sandyford, Dublin 18, D18 VY57, Ireland
Email: [email protected]
Phone: +353 1 524 8796
13. Changes to privacy policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal obligations, or business operations. Any updated version will be posted on this page with a revised effective date where appropriate.
We encourage you to review this Privacy Policy periodically to stay informed about how Celtic Digital Marketing Limited processes personal data.