Privacy Policy
Source: Datafirefly Legal Documentation v1.0 (March 2026). Company: DATAFIREFLY LIMITED, 15A Main Street, Blackrock, Dublin, Ireland, A94T8P8 — CRO 810100. Privacy contact: privacy@datafirefly.com.
Last updated: March 2026 — DATAFIREFLY LIMITED
1.1 Controller
This website and its associated services are operated by DATAFIREFLY LIMITED, an Irish company registered under number 810100, acting as data controller within the meaning of the GDPR.
| Field | Value |
|---|---|
| Company name | DATAFIREFLY LIMITED |
| Registration number (CRO) | 810100 |
| Address | 15A Main Street, Blackrock, Dublin, Ireland, A94T8P8 |
| Privacy email | privacy@datafirefly.com |
| Hosting provider | O2switch, France (EEA) |
1.2 Scope
This policy applies to any person who:
- visits our website
- contacts us by form, email or any other means
- requests a quote, demonstration or information about our services
- subscribes to our services, modules, consulting, training or SaaS subscriptions
- uses our technical support or customer service
- signs up for our newsletter or consents to receive our commercial communications
- is in a professional (B2B) relationship with Datafirefly
1.3 Data collected
1.3.1 Identification and contact data
- Last name, first name
- Company name and role
- Email address and phone number
- Postal address and country
1.3.2 Commercial and contractual data
- Content of your requests, quotes, orders and invoices
- Commercial relationship history
- Information relating to your subscriptions, licenses or subscribed services
1.3.3 Technical and connection data
- IP address, technical logs, date and time of access
- Browser, device type, operating system
1.3.4 Usage data
- Site journey, pages viewed, interactions with our content
- Audience measurement data (via Google Analytics, subject to consent)
1.3.5 Support data
- Content of messages, attachments, screenshots and exchange histories
1.3.6 Payment data
Payment data (card number, expiry date, CVV) are collected and processed directly by our payment provider Stripe Technology Europe Limited. Datafirefly never stores full card details on its servers.
1.4 Purposes and legal bases
In accordance with Articles 13 and 14 of the GDPR, each processing activity is based on an identified legal basis.
| Purpose | Legal basis |
|---|---|
| Responding to your contact, quote or demonstration requests | Pre-contractual measures / Legitimate interest |
| Creation and management of client account | Contract performance |
| Provision of SaaS services, modules, consulting, training | Contract performance |
| Billing, accounting, tax obligations | Legal obligation |
| Customer support and technical maintenance | Contract performance |
| Security, fraud and abuse prevention | Legitimate interest |
| Service improvement and internal statistics | Legitimate interest / Consent |
| Sending newsletters and commercial communications | Consent / ePrivacy rules |
| Lead scoring and customer segmentation (AI) | Legitimate interest — see section 1.9 |
| Defence in court and dispute management | Legitimate interest / Legal obligation |
1.5 Data recipients
Your data are accessible to authorised persons within Datafirefly. They may be transmitted, strictly as necessary, to the following categories of recipients:
- Hosting provider: O2switch (France, EEA)
- Communication and emailing tools: Brevo (formerly Sendinblue), whose servers are in the EEA
- Analytics tools: Google Analytics (see section on transfers outside EEA)
- Advertising networks: Meta Platforms (see section on transfers outside EEA)
- Payment provider: Stripe Technology Europe Limited — direct processing of banking data (see section 1.6)
- Accounting, legal or administrative advisors, under professional secrecy
- Public or judicial authorities, where required by law
1.6 Transfers outside the European Economic Area
Some of our tools involve data transfers to countries outside the EEA, in particular:
| Provider | Country | Legal safeguard |
|---|---|---|
| Google Analytics | United States | Standard Contractual Clauses (SCC) — EU-US adequacy decision applicable |
| Meta Platforms (Pixel) | United States | Standard Contractual Clauses (SCC) |
| Stripe Technology Europe Ltd | Ireland (EEA) / partial US | SCC for residual transfers — Stripe GDPR policy |
| OpenAI / Anthropic / Ollama (if processing) | United States | Standard Contractual Clauses (SCC) |
For further information on these safeguards or a copy of applicable mechanisms, please write to privacy@datafirefly.com.
1.7 Retention periods
Retention periods correspond to the legal maximums allowed for each purpose, in accordance with the storage limitation principle (Art. 5(1)(e) GDPR) and applicable Irish obligations.
| Type of data | Retention period | Legal reference |
|---|---|---|
| Contact requests without commercial follow-up | 3 years after last contact | Irish Statute of Limitations |
| Unconverted prospect data | 3 years after last meaningful contact | Irish Statute of Limitations |
| Client and contractual data | Contract duration + 6 years (archive) | Statute of Limitations Act 1957 (Ireland) |
| Invoices and accounting data | 6 years from end of financial year | Companies Act 2014 & Taxes Consolidation Act 1997 |
| Tax and intra-EU VAT documents | 6 years minimum | Revenue Commissioners Ireland — VAT Act 2010 |
| Technical and security logs | 12 months | GDPR minimisation — security use only |
| Support data / tickets | 3 years after ticket closure | Irish Statute of Limitations |
| Newsletter / marketing consent | 3 years after withdrawal or last interaction | DPC Guidance — ePrivacy Regulations |
| Payment data (transaction reference) | 6 years | Companies Act 2014 — accounting obligations |
| Non-essential cookies and trackers | 13 months maximum | EDPB & DPC guidance on cookies |
| Strictly necessary cookies | Session or 12 months max | ePrivacy Regulations (Ireland) |
| GDPR consent evidence | 3 years after end of relationship | Art. 5(2) GDPR — accountability principle |
1.8 Your rights
In accordance with the GDPR, you have the following rights:
| Right | Description |
|---|---|
| Access | Obtain a copy of data concerning you |
| Rectification | Correct inaccurate or incomplete data |
| Erasure | Request deletion of your data, under conditions |
| Restriction | Request temporary suspension of processing |
| Objection | Object to processing based on legitimate interest |
| Portability | Receive your data in a structured, machine-readable format |
| Withdrawal of consent | Withdraw your consent at any time, without prejudice |
To exercise your rights, contact us at: privacy@datafirefly.com. We may ask you to verify your identity. Any request is processed free of charge within one month, extendable by two months for complex requests.
Right to lodge a complaint with the supervisory authority
You have the right to lodge a complaint with the Data Protection Commission (DPC) of Ireland.
Website: www.dataprotection.ie — Email: info@dataprotection.ie
1.9 Customer scoring and automated processing
Datafirefly uses artificial intelligence tools for lead scoring and customer segmentation. The purpose of such processing is to tailor our commercial offers and prioritise our marketing actions.
Such processing does not constitute automated decisions producing significant legal effects within the meaning of Article 22 GDPR. Scoring is used as an aid to human decision-making and does not automatically determine a contractual decision.
Legal basis: legitimate interest — balanced against your fundamental rights and freedoms.
You may object at any time by writing to privacy@datafirefly.com.
1.10 Data security
Datafirefly implements appropriate technical and organisational measures, including:
- Access control and authentication
- Logging of access to sensitive data
- Regular backups and business continuity plan
- Secure hosting on O2switch infrastructure (France)
- Access restricted to authorised personnel only
- Revocation of access at the end of a service
1.11 Data of minors
Datafirefly services are intended for professional or adult audiences. We do not knowingly collect personal data concerning persons under 18.
1.12 Policy update
This policy may be updated to reflect legal, regulatory or operational developments. The version in force is the one published on the site on the date indicated at the top of the document. In case of substantial modification, we will inform you by email or via a notice on the site.