Privacy Policy

Whelan Web Design
Last updated: 29 August 2026

This policy explains what personal data Whelan Web Design collects through this website and in the course of our work, why we collect it, who we share it with, and what rights you have over it. It is written to meet our obligations under the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and the Irish Data Protection Acts 1988–2018.


1. Who we are

Whelan Web Design (“we”, “us”, “our”) is a web design and digital marketing agency based in Waterford, Ireland. For the personal data described in this policy, we are the data controller unless stated otherwise in Section 9.

Trading nameWhelan Web Design
Registered legal entityCreate For The Web LTD T/A Whelan Web Design
Company registration number551620
AddressUnit 4F, Six Cross Roads Business Park, Waterford City, X91 PY53, Ireland
Email[email protected]
Phone051 325567
Websitehttps://whelanwebdesign.com

We are not required to appoint a Data Protection Officer. Data protection queries should be sent to [email protected] marked for the attention of Riley Barry.


2. The personal data we collect

2.1 When you send us an enquiry

Our contact form asks for your name, email address, phone number, organisation name and the content of your message. All of these fields are required in order to submit the form.

2.2 When you request a quote

Our quote form asks for your name, organisation name, email address, website address, location, a description of your project, your timeline and your budget range.

2.3 When you apply for a job with us

Our careers form collects considerably more information: your name, email address, phone number, portfolio URL, website URL, GitHub URL, a description of yourself, whether you hold the right to work in the EU, what you are looking for in a role, why you are interested in us, your qualifications and experience, your availability, your preferred work location, your salary expectations, the role you are applying for, and how you heard about us (including the name of anyone who referred you).

If you name a person who referred you, we will hold that name as part of your application.

2.4 When you subscribe to our newsletter

Each of our forms includes an optional newsletter opt-in. If you tick it, we add your name and email address to our mailing list, which is managed in FluentCRM running on our own server — the list itself is not held by a third-party marketing platform. The emails are delivered through Postmark. This is separate from your enquiry — you can make an enquiry without subscribing, and you can unsubscribe at any time using the link in every email we send.

2.5 When you become a client

In the course of providing services we hold contact details for you and your staff, billing and payment details, contract and project documentation, and correspondence. Where we host or maintain your website, we also hold access credentials for the systems involved.

2.6 Automatically, when you visit this site

Our web server records standard technical information for every request: IP address, browser type and version, operating system, referring page, pages viewed, and the date and time of access. These logs exist for security and troubleshooting and are not used to build a profile of you.

If you consent to statistics or marketing cookies, we and the third parties named in Section 6 also collect information about how you use the site — pages viewed, scroll depth, time on page, approximate location, and device characteristics.

We do not knowingly collect special category data (health, religion, political opinions, biometrics, etc.) through this website. Please do not include such information in a form message or a job application.


3. Why we use it, and our legal basis

What we doWhyLegal basis (GDPR Art. 6)
Reply to your enquiry and prepare a quoteTo respond to you and, if you go ahead, to scope the workLegitimate interests (Art. 6(1)(f)) — responding to someone who contacted us; or steps prior to a contract (Art. 6(1)(b))
Deliver services we’ve agreedTo perform our contract with youContract (Art. 6(1)(b))
Assess a job applicationTo evaluate your suitability and, if successful, prepare an offerSteps prior to a contract (Art. 6(1)(b)) and legitimate interests (Art. 6(1)(f)) in recruiting
Verify right to work in the EUTo confirm we can lawfully employ youLegal obligation (Art. 6(1)(c))
Send our newsletterTo share updates you asked forConsent (Art. 6(1)(a)) — withdrawable at any time
Invoicing, accounting and tax recordsTo meet Revenue and company law obligationsLegal obligation (Art. 6(1)(c))
Keep the site secure and workingTo detect abuse and diagnose faultsLegitimate interests (Art. 6(1)(f))
Analytics and advertising cookiesTo understand how the site is used and to measure our advertisingConsent (Art. 6(1)(a)) — collected through our cookie banner

Where we rely on legitimate interests, we have considered the impact on you and are satisfied our interest does not override your rights. You can ask us for that assessment.


4. Who we share your data with

We do not sell your personal data. We share it only with the following categories of recipient:

  • Our infrastructure provider — Hosting Ireland (Team Blue Internet Services IE Limited), which supplies and maintains the server our website and email run on.
  • Our email delivery provider — Postmark, which transmits the messages this website sends: enquiry and application notifications to us, and replies and newsletter emails to you.
  • Analytics and advertising providers — Google and Meta, as described in Section 6, but only where you have consented to the relevant cookie category.
  • Our consent management provider — Cookiebot (Usercentrics A/S, Copenhagen), which records your cookie choices and delivers the banner.
  • Our accountants and professional advisers, where needed for tax, audit or legal advice.
  • Public authorities, where we are legally required to disclose.

Each supplier acting on our instructions is bound by a written data processing agreement requiring them to keep your data secure and use it only for the purposes we specify.


5. International transfers

Our website, email and form submissions are held on a server we manage ourselves, supplied by Hosting Ireland and located in Dublin, within the European Economic Area. Hosting Ireland may engage its own sub-processors based outside that country, and is required to put appropriate transfer safeguards in place where it does.

Emails this site sends — replies to your enquiry, notifications of your application, and newsletter messages — are transmitted through Postmark, which operates entirely from the United States and does not offer EU-based servers. That transfer is governed by the Standard Contractual Clauses, which form part of our agreement with them through their terms of service.

Cookiebot stores your consent record within the EU/EEA, and its banner is served from Cookiebot’s EU content delivery network. The consent process therefore keeps your data inside the EEA.

Google and Meta may transfer data outside the EEA, including to the United States. Both are certified under the EU–US Data Privacy Framework, and transfers are additionally covered by the European Commission’s Standard Contractual Clauses. These transfers only occur if you consent to the relevant cookie category.


6. Cookies and tracking

No analytics or marketing cookies are set until you consent. When you first visit, our Cookiebot banner asks you to choose. Until you accept a category, the scripts in that category are blocked and no cookies from them are placed. You can change or withdraw your choice at any time via the cookie icon on any page.

One Google tag is the exception, and it is worth explaining. It loads on every page before you choose, but until you consent it runs in a cookieless mode: it sets no cookies, stores nothing on your device and sends no identifier for you. What it does send is a small technical signal — the page address, the referring page, your browser type, and the fact that consent has not been given. Google uses those signals only in aggregate, to estimate overall traffic patterns. If you accept statistics cookies, ordinary analytics measurement begins from that point; if you refuse, it never goes beyond the cookieless signal.

The categories we use

Strictly necessary. One cookie, CookieConsent, set by Cookiebot to remember which categories you accepted. This is set without consent because the site cannot work without it.

Recording your choice also involves Cookiebot processing a limited set of data about the visit: a consent ID, the date and time, your browser’s user agent and referrer, the page address, your language, your IP address and your approximate location. This is how the banner knows which rules apply to you, and it is kept as the record that you were asked.

Statistics. Google Analytics 4, delivered through Google Tag Manager (container GTM-NK9DTXG), with IP anonymisation enabled. Tells us which pages are read and how people move through the site. Cookies in this category are set only after you accept it; before that the tag is limited to the cookieless signal described above. Google’s privacy policy: https://policies.google.com/privacy

Marketing. The Meta pixel, and Google Ads remarketing audiences, which let us measure our advertising and show our ads to you on other sites after you have visited this one. Meta’s privacy policy: https://www.facebook.com/privacy/policy

Full list of cookies

The table below is generated automatically by Cookiebot from a fresh scan of this site, so it always reflects the cookies actually in use, with their exact names, purposes and durations.

You can opt out of Google Analytics entirely at https://tools.google.com/dlpage/gaoptout and manage Meta ad preferences in your Facebook or Instagram settings.


7. How long we keep it

DataRetention
Website enquiries and quote requests that don’t become projects7 years
Client records, contracts and project filesFor the life of the relationship, then 7 years
Invoices and accounting records6 years, as required by Irish tax law
Unsuccessful job applications12 months
Newsletter subscriptionUntil you unsubscribe
Email content passing through our delivery provider45 days, after which the content and its metadata are deleted from their system
Unsubscribes, bounces and spam complaintsKept indefinitely on our delivery provider’s suppression list, so you are not contacted again in error
Web server logs12 months
Cookie dataAs set out in the cookie declaration in Section 6

Form submissions are stored in this website’s database as well as being emailed to us, so deletion means removing both copies.


8. Your rights

Under the GDPR you have the right to:

  • Access the personal data we hold about you, and receive a copy
  • Rectify data that is inaccurate or incomplete
  • Erase your data (“right to be forgotten”), where we have no overriding reason to keep it
  • Restrict how we process it while a query is resolved
  • Object to processing based on our legitimate interests, and to direct marketing at any time
  • Portability — receive data you gave us in a machine-readable format
  • Withdraw consent at any time, where consent is our basis. This does not affect processing already carried out.

To exercise any of these, email [email protected]. We will respond within one month. We do not charge a fee unless a request is manifestly unfounded or excessive.

If you are unhappy with how we have handled your data, you can complain to the Irish supervisory authority:

Data Protection Commission
6 Pembroke Row, Dublin 2, D02 X963
Phone: +353 1 765 0100 / 1800 437 737
www.dataprotection.ie


9. Websites we build and host for clients

Where we host, maintain or support a website for a client, any personal data belonging to that website’s visitors is controlled by our client, not by us. In that relationship we act as a data processor and handle that data only on our client’s documented instructions, under a written data processing agreement. The servers used for that hosting are supplied by Hosting Ireland, which acts as our sub-processor in that arrangement.

If you are a visitor to a website we built and want to exercise your rights over your data, please contact the operator of that website. We will assist them in responding.


10. Security

We protect personal data with SSL/TLS encryption in transit, access controls and role-based permissions, regularly updated software, and restricted administrative access. No system is completely secure, but we take these measures seriously and review them regularly. In the event of a breach affecting your rights, we will notify the Data Protection Commission within 72 hours and inform you where required.


11. Children

This website is aimed at businesses and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child has given us personal data, contact us and we will delete it.


12. Changes to this policy

We review this policy periodically and will update the “last updated” date above whenever it changes. Material changes will be highlighted on this page.


13. Contact

Questions about this policy or how we handle your data:

Whelan Web Design
Unit 4F, Six Cross Roads Business Park, Waterford City, X91 PY53, Ireland
[email protected] · 051 325567

Proudly Irish.
Serving Businesses Nationwide.

From Waterford to Dublin, Cork to Galway — we've helped Irish businesses of every size and sector build a stronger, more profitable digital presence. If you're serious about your next website project, we'd love to hear from you.
Takes 60 seconds — no spam, no hard sell.