Whelan Web Design
Last updated: 29 August 2026
This policy explains what personal data Whelan Web Design collects through this website and in the course of our work, why we collect it, who we share it with, and what rights you have over it. It is written to meet our obligations under the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and the Irish Data Protection Acts 1988–2018.
1. Who we are
Whelan Web Design (“we”, “us”, “our”) is a web design and digital marketing agency based in Waterford, Ireland. For the personal data described in this policy, we are the data controller unless stated otherwise in Section 9.
| Trading name | Whelan Web Design |
| Registered legal entity | Create For The Web LTD T/A Whelan Web Design |
| Company registration number | 551620 |
| Address | Unit 4F, Six Cross Roads Business Park, Waterford City, X91 PY53, Ireland |
| [email protected] | |
| Phone | 051 325567 |
| Website | https://whelanwebdesign.com |
We are not required to appoint a Data Protection Officer. Data protection queries should be sent to [email protected] marked for the attention of Riley Barry.
2. The personal data we collect
2.1 When you send us an enquiry
Our contact form asks for your name, email address, phone number, organisation name and the content of your message. All of these fields are required in order to submit the form.
2.2 When you request a quote
Our quote form asks for your name, organisation name, email address, website address, location, a description of your project, your timeline and your budget range.
2.3 When you apply for a job with us
Our careers form collects considerably more information: your name, email address, phone number, portfolio URL, website URL, GitHub URL, a description of yourself, whether you hold the right to work in the EU, what you are looking for in a role, why you are interested in us, your qualifications and experience, your availability, your preferred work location, your salary expectations, the role you are applying for, and how you heard about us (including the name of anyone who referred you).
If you name a person who referred you, we will hold that name as part of your application.
2.4 When you subscribe to our newsletter
Each of our forms includes an optional newsletter opt-in. If you tick it, we add your name and email address to our mailing list, which is managed in FluentCRM running on our own server — the list itself is not held by a third-party marketing platform. The emails are delivered through Postmark. This is separate from your enquiry — you can make an enquiry without subscribing, and you can unsubscribe at any time using the link in every email we send.
2.5 When you become a client
In the course of providing services we hold contact details for you and your staff, billing and payment details, contract and project documentation, and correspondence. Where we host or maintain your website, we also hold access credentials for the systems involved.
2.6 Automatically, when you visit this site
Our web server records standard technical information for every request: IP address, browser type and version, operating system, referring page, pages viewed, and the date and time of access. These logs exist for security and troubleshooting and are not used to build a profile of you.
If you consent to statistics or marketing cookies, we and the third parties named in Section 6 also collect information about how you use the site — pages viewed, scroll depth, time on page, approximate location, and device characteristics.
We do not knowingly collect special category data (health, religion, political opinions, biometrics, etc.) through this website. Please do not include such information in a form message or a job application.
3. Why we use it, and our legal basis
| What we do | Why | Legal basis (GDPR Art. 6) |
|---|---|---|
| Reply to your enquiry and prepare a quote | To respond to you and, if you go ahead, to scope the work | Legitimate interests (Art. 6(1)(f)) — responding to someone who contacted us; or steps prior to a contract (Art. 6(1)(b)) |
| Deliver services we’ve agreed | To perform our contract with you | Contract (Art. 6(1)(b)) |
| Assess a job application | To evaluate your suitability and, if successful, prepare an offer | Steps prior to a contract (Art. 6(1)(b)) and legitimate interests (Art. 6(1)(f)) in recruiting |
| Verify right to work in the EU | To confirm we can lawfully employ you | Legal obligation (Art. 6(1)(c)) |
| Send our newsletter | To share updates you asked for | Consent (Art. 6(1)(a)) — withdrawable at any time |
| Invoicing, accounting and tax records | To meet Revenue and company law obligations | Legal obligation (Art. 6(1)(c)) |
| Keep the site secure and working | To detect abuse and diagnose faults | Legitimate interests (Art. 6(1)(f)) |
| Analytics and advertising cookies | To understand how the site is used and to measure our advertising | Consent (Art. 6(1)(a)) — collected through our cookie banner |
Where we rely on legitimate interests, we have considered the impact on you and are satisfied our interest does not override your rights. You can ask us for that assessment.
4. Who we share your data with
We do not sell your personal data. We share it only with the following categories of recipient:
- Our infrastructure provider — Hosting Ireland (Team Blue Internet Services IE Limited), which supplies and maintains the server our website and email run on.
- Our email delivery provider — Postmark, which transmits the messages this website sends: enquiry and application notifications to us, and replies and newsletter emails to you.
- Analytics and advertising providers — Google and Meta, as described in Section 6, but only where you have consented to the relevant cookie category.
- Our consent management provider — Cookiebot (Usercentrics A/S, Copenhagen), which records your cookie choices and delivers the banner.
- Our accountants and professional advisers, where needed for tax, audit or legal advice.
- Public authorities, where we are legally required to disclose.
Each supplier acting on our instructions is bound by a written data processing agreement requiring them to keep your data secure and use it only for the purposes we specify.
5. International transfers
Our website, email and form submissions are held on a server we manage ourselves, supplied by Hosting Ireland and located in Dublin, within the European Economic Area. Hosting Ireland may engage its own sub-processors based outside that country, and is required to put appropriate transfer safeguards in place where it does.
Emails this site sends — replies to your enquiry, notifications of your application, and newsletter messages — are transmitted through Postmark, which operates entirely from the United States and does not offer EU-based servers. That transfer is governed by the Standard Contractual Clauses, which form part of our agreement with them through their terms of service.
Cookiebot stores your consent record within the EU/EEA, and its banner is served from Cookiebot’s EU content delivery network. The consent process therefore keeps your data inside the EEA.
Google and Meta may transfer data outside the EEA, including to the United States. Both are certified under the EU–US Data Privacy Framework, and transfers are additionally covered by the European Commission’s Standard Contractual Clauses. These transfers only occur if you consent to the relevant cookie category.
6. Cookies and tracking
No analytics or marketing cookies are set until you consent. When you first visit, our Cookiebot banner asks you to choose. Until you accept a category, the scripts in that category are blocked and no cookies from them are placed. You can change or withdraw your choice at any time via the cookie icon on any page.
One Google tag is the exception, and it is worth explaining. It loads on every page before you choose, but until you consent it runs in a cookieless mode: it sets no cookies, stores nothing on your device and sends no identifier for you. What it does send is a small technical signal — the page address, the referring page, your browser type, and the fact that consent has not been given. Google uses those signals only in aggregate, to estimate overall traffic patterns. If you accept statistics cookies, ordinary analytics measurement begins from that point; if you refuse, it never goes beyond the cookieless signal.
The categories we use
Strictly necessary. One cookie, CookieConsent, set by Cookiebot to remember which categories you accepted. This is set without consent because the site cannot work without it.
Recording your choice also involves Cookiebot processing a limited set of data about the visit: a consent ID, the date and time, your browser’s user agent and referrer, the page address, your language, your IP address and your approximate location. This is how the banner knows which rules apply to you, and it is kept as the record that you were asked.
Statistics. Google Analytics 4, delivered through Google Tag Manager (container GTM-NK9DTXG), with IP anonymisation enabled. Tells us which pages are read and how people move through the site. Cookies in this category are set only after you accept it; before that the tag is limited to the cookieless signal described above. Google’s privacy policy: https://policies.google.com/privacy
Marketing. The Meta pixel, and Google Ads remarketing audiences, which let us measure our advertising and show our ads to you on other sites after you have visited this one. Meta’s privacy policy: https://www.facebook.com/privacy/policy
Full list of cookies
The table below is generated automatically by Cookiebot from a fresh scan of this site, so it always reflects the cookies actually in use, with their exact names, purposes and durations.
You can opt out of Google Analytics entirely at https://tools.google.com/dlpage/gaoptout and manage Meta ad preferences in your Facebook or Instagram settings.
7. How long we keep it
| Data | Retention |
|---|---|
| Website enquiries and quote requests that don’t become projects | 7 years |
| Client records, contracts and project files | For the life of the relationship, then 7 years |
| Invoices and accounting records | 6 years, as required by Irish tax law |
| Unsuccessful job applications | 12 months |
| Newsletter subscription | Until you unsubscribe |
| Email content passing through our delivery provider | 45 days, after which the content and its metadata are deleted from their system |
| Unsubscribes, bounces and spam complaints | Kept indefinitely on our delivery provider’s suppression list, so you are not contacted again in error |
| Web server logs | 12 months |
| Cookie data | As set out in the cookie declaration in Section 6 |
Form submissions are stored in this website’s database as well as being emailed to us, so deletion means removing both copies.
8. Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you, and receive a copy
- Rectify data that is inaccurate or incomplete
- Erase your data (“right to be forgotten”), where we have no overriding reason to keep it
- Restrict how we process it while a query is resolved
- Object to processing based on our legitimate interests, and to direct marketing at any time
- Portability — receive data you gave us in a machine-readable format
- Withdraw consent at any time, where consent is our basis. This does not affect processing already carried out.
To exercise any of these, email [email protected]. We will respond within one month. We do not charge a fee unless a request is manifestly unfounded or excessive.
If you are unhappy with how we have handled your data, you can complain to the Irish supervisory authority:
Data Protection Commission
6 Pembroke Row, Dublin 2, D02 X963
Phone: +353 1 765 0100 / 1800 437 737
www.dataprotection.ie
9. Websites we build and host for clients
Where we host, maintain or support a website for a client, any personal data belonging to that website’s visitors is controlled by our client, not by us. In that relationship we act as a data processor and handle that data only on our client’s documented instructions, under a written data processing agreement. The servers used for that hosting are supplied by Hosting Ireland, which acts as our sub-processor in that arrangement.
If you are a visitor to a website we built and want to exercise your rights over your data, please contact the operator of that website. We will assist them in responding.
10. Security
We protect personal data with SSL/TLS encryption in transit, access controls and role-based permissions, regularly updated software, and restricted administrative access. No system is completely secure, but we take these measures seriously and review them regularly. In the event of a breach affecting your rights, we will notify the Data Protection Commission within 72 hours and inform you where required.
11. Children
This website is aimed at businesses and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child has given us personal data, contact us and we will delete it.
12. Changes to this policy
We review this policy periodically and will update the “last updated” date above whenever it changes. Material changes will be highlighted on this page.
13. Contact
Questions about this policy or how we handle your data:
Whelan Web Design
Unit 4F, Six Cross Roads Business Park, Waterford City, X91 PY53, Ireland
[email protected] · 051 325567