Privacy Policy

Source: Datafirefly Legal Documentation v1.0 (March 2026). Company: DATAFIREFLY LIMITED, 15A Main Street, Blackrock, Dublin, Ireland, A94T8P8 — CRO 810100. Privacy contact: privacy@datafirefly.com.

Last updated: March 2026 — DATAFIREFLY LIMITED

1.1 Controller

This website and its associated services are operated by DATAFIREFLY LIMITED, an Irish company registered under number 810100, acting as data controller within the meaning of the GDPR.

FieldValue
Company nameDATAFIREFLY LIMITED
Registration number (CRO)810100
Address15A Main Street, Blackrock, Dublin, Ireland, A94T8P8
Privacy emailprivacy@datafirefly.com
Hosting providerO2switch, France (EEA)

1.2 Scope

This policy applies to any person who:

  • visits our website
  • contacts us by form, email or any other means
  • requests a quote, demonstration or information about our services
  • subscribes to our services, modules, consulting, training or SaaS subscriptions
  • uses our technical support or customer service
  • signs up for our newsletter or consents to receive our commercial communications
  • is in a professional (B2B) relationship with Datafirefly

1.3 Data collected

1.3.1 Identification and contact data

  • Last name, first name
  • Company name and role
  • Email address and phone number
  • Postal address and country

1.3.2 Commercial and contractual data

  • Content of your requests, quotes, orders and invoices
  • Commercial relationship history
  • Information relating to your subscriptions, licenses or subscribed services

1.3.3 Technical and connection data

  • IP address, technical logs, date and time of access
  • Browser, device type, operating system

1.3.4 Usage data

  • Site journey, pages viewed, interactions with our content
  • Audience measurement data (via Google Analytics, subject to consent)

1.3.5 Support data

  • Content of messages, attachments, screenshots and exchange histories

1.3.6 Payment data

Payment data (card number, expiry date, CVV) are collected and processed directly by our payment provider Stripe Technology Europe Limited. Datafirefly never stores full card details on its servers.

1.4 Purposes and legal bases

In accordance with Articles 13 and 14 of the GDPR, each processing activity is based on an identified legal basis.

PurposeLegal basis
Responding to your contact, quote or demonstration requestsPre-contractual measures / Legitimate interest
Creation and management of client accountContract performance
Provision of SaaS services, modules, consulting, trainingContract performance
Billing, accounting, tax obligationsLegal obligation
Customer support and technical maintenanceContract performance
Security, fraud and abuse preventionLegitimate interest
Service improvement and internal statisticsLegitimate interest / Consent
Sending newsletters and commercial communicationsConsent / ePrivacy rules
Lead scoring and customer segmentation (AI)Legitimate interest — see section 1.9
Defence in court and dispute managementLegitimate interest / Legal obligation

1.5 Data recipients

Your data are accessible to authorised persons within Datafirefly. They may be transmitted, strictly as necessary, to the following categories of recipients:

  • Hosting provider: O2switch (France, EEA)
  • Communication and emailing tools: Brevo (formerly Sendinblue), whose servers are in the EEA
  • Analytics tools: Google Analytics (see section on transfers outside EEA)
  • Advertising networks: Meta Platforms (see section on transfers outside EEA)
  • Payment provider: Stripe Technology Europe Limited — direct processing of banking data (see section 1.6)
  • Accounting, legal or administrative advisors, under professional secrecy
  • Public or judicial authorities, where required by law

1.6 Transfers outside the European Economic Area

Some of our tools involve data transfers to countries outside the EEA, in particular:

ProviderCountryLegal safeguard
Google AnalyticsUnited StatesStandard Contractual Clauses (SCC) — EU-US adequacy decision applicable
Meta Platforms (Pixel)United StatesStandard Contractual Clauses (SCC)
Stripe Technology Europe LtdIreland (EEA) / partial USSCC for residual transfers — Stripe GDPR policy
OpenAI / Anthropic / Ollama (if processing)United StatesStandard Contractual Clauses (SCC)

For further information on these safeguards or a copy of applicable mechanisms, please write to privacy@datafirefly.com.

1.7 Retention periods

Retention periods correspond to the legal maximums allowed for each purpose, in accordance with the storage limitation principle (Art. 5(1)(e) GDPR) and applicable Irish obligations.

Type of dataRetention periodLegal reference
Contact requests without commercial follow-up3 years after last contactIrish Statute of Limitations
Unconverted prospect data3 years after last meaningful contactIrish Statute of Limitations
Client and contractual dataContract duration + 6 years (archive)Statute of Limitations Act 1957 (Ireland)
Invoices and accounting data6 years from end of financial yearCompanies Act 2014 & Taxes Consolidation Act 1997
Tax and intra-EU VAT documents6 years minimumRevenue Commissioners Ireland — VAT Act 2010
Technical and security logs12 monthsGDPR minimisation — security use only
Support data / tickets3 years after ticket closureIrish Statute of Limitations
Newsletter / marketing consent3 years after withdrawal or last interactionDPC Guidance — ePrivacy Regulations
Payment data (transaction reference)6 yearsCompanies Act 2014 — accounting obligations
Non-essential cookies and trackers13 months maximumEDPB & DPC guidance on cookies
Strictly necessary cookiesSession or 12 months maxePrivacy Regulations (Ireland)
GDPR consent evidence3 years after end of relationshipArt. 5(2) GDPR — accountability principle

1.8 Your rights

In accordance with the GDPR, you have the following rights:

RightDescription
AccessObtain a copy of data concerning you
RectificationCorrect inaccurate or incomplete data
ErasureRequest deletion of your data, under conditions
RestrictionRequest temporary suspension of processing
ObjectionObject to processing based on legitimate interest
PortabilityReceive your data in a structured, machine-readable format
Withdrawal of consentWithdraw your consent at any time, without prejudice

To exercise your rights, contact us at: privacy@datafirefly.com. We may ask you to verify your identity. Any request is processed free of charge within one month, extendable by two months for complex requests.

Right to lodge a complaint with the supervisory authority

You have the right to lodge a complaint with the Data Protection Commission (DPC) of Ireland.

Website: www.dataprotection.ie — Email: info@dataprotection.ie

1.9 Customer scoring and automated processing

Datafirefly uses artificial intelligence tools for lead scoring and customer segmentation. The purpose of such processing is to tailor our commercial offers and prioritise our marketing actions.

Such processing does not constitute automated decisions producing significant legal effects within the meaning of Article 22 GDPR. Scoring is used as an aid to human decision-making and does not automatically determine a contractual decision.

Legal basis: legitimate interest — balanced against your fundamental rights and freedoms.

You may object at any time by writing to privacy@datafirefly.com.

1.10 Data security

Datafirefly implements appropriate technical and organisational measures, including:

  • Access control and authentication
  • Logging of access to sensitive data
  • Regular backups and business continuity plan
  • Secure hosting on O2switch infrastructure (France)
  • Access restricted to authorised personnel only
  • Revocation of access at the end of a service

1.11 Data of minors

Datafirefly services are intended for professional or adult audiences. We do not knowingly collect personal data concerning persons under 18.

1.12 Policy update

This policy may be updated to reflect legal, regulatory or operational developments. The version in force is the one published on the site on the date indicated at the top of the document. In case of substantial modification, we will inform you by email or via a notice on the site.