Gorey, Co. Wexfordsupport@novapathdigital.com089 262 6788
Gorey, Co. Wexfordsupport@novapathdigital.com089 262 6788
NovaPath Digital
Legal

Privacy Policy

This policy explains what personal data NovaPath Digital collects, why we collect it, how we use it, and the rights you have under the General Data Protection Regulation (EU) 2016/679 and the Irish Data Protection Act 2018.

Last updated: 10 August 2026

1. Who we are (data controller)

NovaPath Digital (CRO number 777481) is the data controller responsible for the personal data described in this policy.

Address: Gorey, Co. Wexford, Ireland. Email: support@novapathdigital.com. Phone: 089 262 6788.

If you have any question about this policy or how we handle your data, contact us at support@novapathdigital.com and we will respond within 30 days.

2. What personal data we collect

We only collect data that we genuinely need in order to respond to you and deliver our services:

  • Contact and enquiry data: your name, email address, phone number, business name, website address and the content of any message you send us through our contact, quote or website audit forms.
  • Client and project data: information you provide while we design, build, host or support your website, including billing details and any content you supply for your site.
  • Technical and usage data: IP address, browser type and version, device type, referring page, pages viewed and time spent, collected through server logs and: only with your consent, analytics cookies.
  • Communications: emails and messages exchanged with us, kept as a record of the work agreed.

We do not knowingly collect special category data (such as health or biometric data) and we do not collect data from children under 16.

3. Why we use your data and our legal basis

Under Article 6 of the GDPR we rely on the following legal bases:

  • Consent (Art. 6(1)(a)): analytics and non-essential cookies, and any marketing emails you opt in to. You can withdraw consent at any time.
  • Performance of a contract (Art. 6(1)(b)): to provide quotes, design, build, host and support your website, and to invoice you.
  • Legitimate interests (Art. 6(1)(f)): to respond to enquiries, keep our website secure, prevent spam and abuse, and improve our services. We balance these interests against your rights.
  • Legal obligation (Art. 6(1)(c)): to keep accounting and tax records as required by Irish law.

4. Cookies and similar technologies

Our website uses strictly necessary cookies that are required for the site to function and that do not require consent. Any analytics or measurement cookies are only set after you give consent through our cookie banner.

You can accept or reject non-essential cookies at any time using the cookie banner, and you can change your choice later by clearing your browser storage for this site. Full detail is in our Cookie Policy.

5. Who we share data with

We never sell your personal data. We share it only with service providers (processors) who help us run our business, under written data processing terms:

  • Hosting and infrastructure providers (including Cloudflare and Hostinger) that host our website and client sites.
  • Email and communication providers used to send and receive project correspondence.
  • Payment providers (Stripe) for invoicing and payments, we never store your full card details.
  • Analytics providers, only where you have consented to analytics cookies.
  • Professional advisers, accountants and authorities where we are legally required to disclose information.

Some providers may process data outside the European Economic Area. Where that happens, transfers are protected by an adequacy decision or by the European Commission's Standard Contractual Clauses.

6. How long we keep your data

We keep enquiry data for up to 24 months after our last contact, unless you become a client. Client and project records are kept for the duration of the engagement and for 7 years afterwards to meet Irish tax and accounting requirements. Server logs are kept for a short technical period, typically no longer than 12 months. When data is no longer needed it is securely deleted.

7. How we protect your data

All traffic to our website is encrypted with HTTPS. Access to client data is limited to people who need it, protected by strong authentication, and our databases apply row-level access controls. If a personal data breach occurs that is likely to result in a risk to your rights, we will notify the Data Protection Commission within 72 hours and inform affected individuals where required.

8. Your rights under the GDPR

You have the right to:

  • Access the personal data we hold about you and receive a copy.
  • Rectify inaccurate or incomplete data.
  • Erase your data (the 'right to be forgotten') where we no longer have a lawful reason to keep it.
  • Restrict or object to processing, including processing based on legitimate interests.
  • Data portability, receive your data in a structured, commonly used, machine-readable format.
  • Withdraw consent at any time, without affecting processing carried out before withdrawal.
  • Lodge a complaint with the Data Protection Commission (dataprotection.ie), 21 Fitzwilliam Square South, Dublin 2, D02 RD28.

To exercise any of these rights, email support@novapathdigital.com. We will respond within one month and will not charge a fee for reasonable requests.

9. Third-party websites

Our website links to other sites, including client websites and social platforms. We are not responsible for their privacy practices and encourage you to read their policies.

10. Changes to this policy

We may update this policy from time to time. The 'last updated' date above always reflects the current version. Material changes will be highlighted on this page.