Privacy Policy
Last updated: 17 September 2026
Website Smith Ltd (“Websitesmith”, “we”, “us”) is the data controller for personal data collected through websitesmith.net. This notice explains what we collect, why, how long we keep it, and the rights you have under the EU General Data Protection Regulation (GDPR), the Irish Data Protection Acts 1988–2018, the ePrivacy Regulations (S.I. No. 336/2011) and applicable US state privacy laws. Our supervisory authority is the Irish Data Protection Commission. Where Irish or EU law and US law set different standards, we apply the Irish standard to every visitor, wherever you are.
1. Data we collect
We only collect data you choose to give us, plus the minimum technical data needed to serve the site securely.
- Demo and enquiry data: business name, email address, legal entity type and registered legal name, together with the estimate options you selected.
- Correspondence: emails you send us and our replies.
- Technical data: server and hosting logs (IP address, timestamp, requested URL, user agent) generated automatically for security, fraud prevention and availability.
We do not knowingly collect special category data, financial account details, or data relating to children under 16 through this website.
2. Why we use it and our legal basis
- To respond to your demo request and prepare a proposal — performance of a contract or steps taken at your request (Art. 6(1)(b) GDPR).
- To keep the site secure and operational — our legitimate interests in protecting our service (Art. 6(1)(f) GDPR).
- To meet legal, accounting and tax obligations — legal obligation (Art. 6(1)(c) GDPR).
- Any optional analytics or marketing cookies — your consent only (Art. 6(1)(a) GDPR), which you can withdraw at any time.
3. No tracking without consent
This website loads no third-party analytics, advertising pixels, session-replay tools or third-party chat widgets on page load. No such script is added to the page, and no request is made to a third-party tracking domain, unless and until you give affirmative consent through our cookie banner.
We honour the Global Privacy Control (GPC) signal. If your browser sends GPC, optional cookies stay off, and we treat it as an opt-out of any sale or sharing of personal information for the purposes of the California Consumer Privacy Act and comparable US state laws.
We do not intercept, record or replay your keystrokes, form inputs or mouse movements, and we do not permit any vendor to do so on our behalf. Form data is transmitted only when you submit the form.
Fonts are served from our own domain. No font, script or style request is made to a third-party content delivery network.
4. Cookies and local storage
We use one strictly necessary local storage entry to remember your cookie choice, so we do not ask again on every page. It contains no identifier and is not shared. Full detail is in our Cookie Policy.
5. Sharing and processors
We never sell or rent personal data. We share it only with service providers who process it on our documented instructions under Art. 28 GDPR:
- Our hosting and database provider, which stores demo requests and serves the site.
- Our email provider, used to reply to you.
- Professional advisers, or authorities, where we are legally required to disclose.
Where a provider processes data outside the European Economic Area, the transfer is covered by the European Commission’s Standard Contractual Clauses or an adequacy decision.
6. Security and retention
Demo request records are protected by row-level database security: submissions can be created by the website form, but cannot be read back by site visitors or by anonymous API access. Data is encrypted in transit.
We keep enquiry data for 24 months from your last contact with us, unless a contract requires us to keep it longer, then delete it. Server logs are retained for up to 30 days.
7. Your rights
You have the right to access, rectify, erase, restrict or object to the processing of your personal data, and the right to data portability. Where processing is based on consent, you may withdraw it at any time without affecting prior processing.
Email websitesmith1@gmail.com to exercise any right. We respond within one month. If you are unhappy, you may complain to the Irish Data Protection Commission (dataprotection.ie). California, Colorado, Connecticut, Virginia and other US state residents may additionally request disclosure, deletion, correction and opt-out of sale or sharing — we apply the same process, free of charge, without discrimination.
8. Irish rules take precedence
We run one compliance standard, not two. Consent for cookies and tracking follows Regulation 5 of S.I. No. 336/2011 and the GDPR affirmative-action test, which is stricter than US notice-and-opt-out practice, so US visitors get the same prior-consent protection as Irish visitors. Where a US rule gives you something Irish law does not — for example a right to opt out of “sale or sharing” — we grant that as well.
We do not operate session replay, keystroke logging or chat-widget interception, which is both an Irish prior-consent requirement and the practice that drives US wiretapping litigation.
9. AI features
Websites we build may include optional AI assistants. Where we deploy one, it is clearly labelled as AI and not a human, in line with the EU AI Act transparency requirements. Conversation data handling is described in the separate agreement for that project, and end clients remain responsible for the notices shown on their own websites.
10. Changes
We update this notice when our practices change and revise the date above. Material changes are highlighted on this page.
Contact us
Website Smith Ltd, Dublin, Ireland · websitesmith1@gmail.com