Skip to content

Legal

Privacy policy

Last updated: 12 August 2026

Who we are

Verity Digital is an independent software consultancy operated by Miroslav Tadej, based in Ireland. For personal data submitted through this website we act as the data controller. You can reach us at info@veritydigital.ie.

What we collect, and why

  • Enquiry and RFP forms — name, organisation, email, optional phone, budget range and your message (procurement enquiries may include a tender reference and estimated contract value). Used solely to respond to your enquiry. Lawful basis: steps taken at your request prior to a contract.
  • Client portal accounts — name, email, organisation and a password stored only as a bcrypt hash. Used to operate your engagements, invoices and appointments. Lawful basis: performance of a contract.
  • Payments — handled by Stripe. Card details never touch our servers; we store only the invoice status and a payment reference.
  • Server logs — standard technical logs (IP address, request path, timestamp) kept briefly for security and reliability. Lawful basis: legitimate interest in operating the service securely.
  • Business prospects — if we identify your organisation as one we may be able to help, we record business-context details only: your name and role, your employer, a work email or phone number, the business problem discussed, and a factual note of any contact between us. We do not collect special-category data, and there is no profiling, scoring or automated decision-making. Lawful basis: legitimate interests (Art. 6(1)(f)) in business-to-business marketing. Where those details did not come from you, we will tell you at first contact where we got them. You can object at any time and we will stop and erase your details — for direct marketing that right is absolute and needs no reason.
  • Accepting a proposal — when you accept a proposal in the portal we record, alongside the acceptance itself, your IP address and browser user-agent string and a fingerprint (a hash) of the exact proposal wording and prices you accepted. This is the evidence that an acceptance happened and of what was accepted, so that neither of us has to rely on memory if the scope is later disputed. It is kept with the proposal. Lawful basis: legitimate interests in holding a reliable record of a contract we are party to.
  • Our internal notes on your engagement — we keep a dated working journal of an engagement: decisions, issues, delivery notes and a record of contact with you. Some entries are marked client-safe and can appear in your reports; the rest are internal — our own working record and candid assessments. To be straightforward with you: internal entries are excluded from the copy of your data you get if you make an access request, because they are our own opinions and working notes rather than a record about you that we hold for your benefit. You can still ask what we hold and challenge anything factual in it. Lawful basis: legitimate interests in keeping a delivery record.
  • Business-customer status — if you contract with us as a business we may record your VAT number and business address, and the date you confirmed you were contracting for business purposes. We ask because consumer-protection law gives extra rights to someone contracting as an individual, and the burden of showing you were not is ours. Lawful basis: compliance with a legal obligation.
  • Account security — if you turn on two-factor authentication we store the secret key your authenticator app uses to generate codes. We also record the date and time you last signed in — a timestamp only, so we can tell an account that is still in use from one that has been abandoned. No IP address, browser or session history is kept against your account for this. Lawful basis: legitimate interests in operating the service securely.
  • Appointments and notifications — a consultation booking records the date, the length and a free-text note, which will hold whatever was written about the meeting. In-app notifications (the bell in the portal) store a short title and message, which may name people. Lawful basis: performance of a contract, or steps taken at your request before one.
  • Files exchanged with us — for a document you upload or a deliverable we send you, we store the file itself plus its original filename, type, size and who uploaded it. Files are held outside the public web root and reached only through an access-checked download. We cannot know what a document contains, so please send only what the engagement needs. Lawful basis: performance of a contract.

We practise data minimisation: forms collect only the fields needed for the stated purpose, and we do not buy, sell or share personal data for marketing.We hold prospect records for the opportunity they relate to. An automatic deletion period for prospects who did not proceed is still being set — see “Retention” below — and we will erase your details on request in the meantime.

Cookies

This site sets essential cookies only: two httpOnly authentication cookies (a short-lived access token and a refresh token), created only when you log in to the client portal and removed on logout. There are no advertising, profiling or third-party tracking cookies, which is why you don't see a cookie banner. Cookies that are strictly necessary to provide a service you asked for are exempt from the consent requirement [S.I. 336/2011, Reg. 5(5)], so there is nothing here for you to consent to or refuse.

Analytics

No analytics are switched on for this site. No analytics script is loaded and no usage data is sent to any third party. The site is built with the ability to enable one — a cookieless, privacy-first service (Plausible: no cookies, nothing stored on or read from your device, no cross-site tracking, only anonymous aggregate counts) — but it is turned off, and turning it on is a deliberate change we would make to this page at the same time. If you are reading this and want to check, the page source loads no third-party script.

Internal business metrics shown to our staff are computed from our own records and are never shared with third parties.

Source-access requests

If you request access to a private source repository, we ask for your name, email, organisation and (optionally) your role, plus your explicit consent to us storing those details and contacting you about the request. We collect only these fields — no phone number, no tracking. The details are stored securely, are accessible only to the site administrator, are never sold or shared, and are used solely to respond to you. You can ask us to delete them at any time using the contact details below.

We previously offered a CV download that captured the same details under the same consent. That download has been withdrawn, no records were captured while it ran, and the store it wrote to has been removed. There is nothing held from it.

Testimonials

If you provide a testimonial, we display it publicly only with your explicit consent and only show what you agreed to — typically your name, company, role and the words you wrote. We record that consent and never publish a testimonial without it. You can withdraw consent at any time by emailing info@veritydigital.ie. You do not have to give a reason, and we will not ask for one — the testimonial is unpublished and the consent record updated. We do not display more than you consented to, and we never publish invented or anonymous reviews.

Email

We send transactional email only — confirmations and notifications related to your enquiry or engagement, delivered via a GDPR-compliant transactional email provider. We do not send marketing email.

Retention

We keep each category for as long as its purpose requires, and no longer. We would rather tell you exactly where we have got to than quote periods we are not yet applying, so this section separates the two.

Deleted automatically today

  • Spent authentication tokens — used or expired sign-in, password-reset and invitation tokens are purged 30 days after they die. These are dead cryptographic values that can no longer sign anyone in; the record of what happened stays in the audit log.

Kept, with a reason

  • Financial and contractual records — invoices, engagements and the contracts behind them are kept for six years. Irish tax law requires business records to be kept for six years, and the same period is the limitation period for a simple contract claim under the Statute of Limitations 1957. Because of this, a closed account is anonymised rather than deleted where invoices are attached to it: your name, email and login are removed and the financial record survives without identifying you.
  • Security and audit records — the append-only log of privileged actions is retained as evidence of how the platform is operated. It records IP addresses. We have built the ability to anonymise those addresses after a set age, but it is not currently switched on, so audit-log IP addresses are retained for now.

Periods still being set

For the remaining categories — enquiries and prospect records, prospects who did not proceed, dormant portal accounts, and audit-log IP addresses — the right period is a legal judgement rather than a technical one, and we are taking professional advice before fixing it. Until each period is set, data in these categories is retained rather than deleted on a schedule. We will update this policy with the periods once they are decided. This does not affect your right to ask us to erase your data at any time — see “Your rights” below — and we act on those requests whatever the schedule says.

Our Data Protection Policy sets out our wider approach. Where it and this page differ on a period, this page is the current position.

Sub-processors and transfers

We use a small number of carefully selected service providers, each under GDPR-appropriate terms:

  • Amazon Web Services — cloud hosting. All application data and backups are stored in the EU (Ireland, eu-west-1).
  • Stripe — payment processing. Card details never touch our servers. Stripe may transfer data outside the EEA under its GDPR transfer safeguards.
  • Resend — transactional email delivery (recipient address and message content). A US provider; transfers are covered by GDPR transfer safeguards (Standard Contractual Clauses).
  • Anthropic — AI-assisted drafting of engagement reports (see “AI-assisted reports” below). Limited engagement data, which can include your name and project notes, is processed in the United States under GDPR transfer safeguards (Standard Contractual Clauses). Anthropic does not use this data to train models.

Beyond these, personal data is kept within the EU/EEA. These four are the only third-party processors that receive personal data. (The analytics service named above would be a fifth if it were switched on; it is not, and this list would be updated before it was.)

AI-assisted reports

Some client-facing engagement reports are drafted with the assistance of AI (Anthropic's Claude). Drafting uses the minimum data needed — your name and business-level engagement records such as milestones, deliverables and progress notes; never your contact details, credentials or payment data. Every AI-drafted report is reviewed and approved by a human before it is released to you.

Where we produce a downloadable project report document, that document carries a notice on its first page recording that it is AI-assisted and should be verified before it is relied on. Engagement reports are not currently issued as generated documents and so carry no such stamp: they are drafted with AI assistance and reviewed by a person before anything is released to you. We state that here rather than marking a file that does not exist. If we begin issuing engagement reports as documents, we will mark them and update this policy.

Your rights

You may request access, rectification, erasure, restriction, portability or object to processing at any time by emailing info@veritydigital.ie. We respond within one month. You also have the right to lodge a complaint with the Irish Data Protection Commission.

How this data is protected

The technical controls protecting your data — parameterized SQL, httpOnly cookie authentication with refresh rotation, role-based access control, rate limiting, locked-down CORS — are documented openly on our How this site is built page and in our Information Security Policy.