Privacy Policy

Last updated: July 2026

1. Controller

The data controller is Data Vision IT Consulting Limited, registered in Ireland. Contact: [email protected].

2. Data We Collect

When you purchase a compliance audit report we collect:

  • Your email address (to deliver the report)
  • The URL you submit for auditing
  • Payment data (processed by Stripe — we do not store card details)

3. Lawful Basis

Processing is necessary for performance of the contract (delivery of the audit report you purchased). Article 6(1)(b) GDPR.

4. Retention

We retain your email and report data for 12 months from the date of purchase, after which it is permanently deleted.

5. Third-Party Processors

  • Stripe Inc (USA) — payment processing. Transfers under SCCs.
  • Sendinblue SAS / Brevo (France) — transactional email delivery.

6. Your Rights

You have the right to access, rectify, and erase your personal data. To exercise any right, email [email protected]. We will respond within 30 days.

7. Complaints

You may lodge a complaint with the Data Protection Commission (Ireland).

8. Data Breach Notification

In the event of a personal data breach, we will:

  • Notify the Data Protection Commission (DPC) within 72 hours of becoming aware of the breach, where it is likely to result in a risk to your rights and freedoms, in accordance with GDPR Article 33.
  • Notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms, in accordance with GDPR Article 34.
  • Maintain an internal record of all breaches, including those not reported to the DPC, as required by GDPR Article 33(5).

To report a suspected data breach or security vulnerability, contact us immediately at [email protected]. We will acknowledge receipt within 24 hours.

9. Cookies

This site uses only essential session cookies required for the checkout flow. No analytics or advertising cookies are used. See our Cookie Policy for full details.