Data Processing Policy — Digital Bridge

Processor responsibilities, subprocessors and data handling. This policy applies to all Digital Bridge services and is governed by Irish law.

Roles

For website visitors and our marketing list we are the data controller. When we operate systems or run services that contain your customers' personal data, we are the data processor and you are the controller.

Processor responsibilities

  • Process personal data only on your documented instructions.
  • Ensure persons authorised to process data are bound by confidentiality.
  • Implement appropriate technical and organisational measures (Art. 32 GDPR).
  • Assist you with data-subject requests, DPIAs and breach notification.
  • Delete or return personal data at the end of the engagement.
  • Make available information necessary to demonstrate compliance.

Subprocessors

We use vetted subprocessors. Current list: We will notify you of intended changes to subprocessors and give you a chance to object.

  • Stripe — payment processing (Ireland / global).
  • Supabase — managed database & auth (EU region where available).
  • Cloudflare — CDN, DNS, security.
  • Lovable Cloud — application platform.
  • Resend / SendGrid — transactional email.
  • Google Analytics — analytics (anonymised).
  • OpenAI / Google / Anthropic — AI model providers, where used in your build.

Data retention

Personal data is retained only as long as needed to deliver the service or meet legal obligations. Project data is deleted or returned within 90 days of contract end unless otherwise agreed.

International transfers

Where data leaves the EEA we rely on Standard Contractual Clauses and (where applicable) the EU–US Data Privacy Framework.

Security measures

  • TLS encryption in transit, encryption at rest where supported.
  • Role-based access controls and least-privilege principles.
  • Audit logging for sensitive operations.
  • Multi-factor authentication on admin accounts.
  • Regular review of credentials and access.

Breach notification

We will notify you without undue delay of any personal data breach affecting your data, with sufficient information to meet your own 72-hour notification obligation to the DPC.

Your responsibilities as controller

As the controller you decide what personal data is collected through your website or systems and why. You are responsible for having a lawful basis for that processing, for publishing your own privacy notice, and for handling requests from your customers to access, correct or delete their data. Where we build forms, booking flows or AI features for you, we will tell you what data each one captures and where it is stored so that your privacy notice can be accurate.

Assisting with data subject requests

If one of your customers exercises a right under the GDPR and the data sits in a system we built or host, email us and we will locate, export or delete the records within five working days at no Requests that require bespoke engineering work — for example reconstructing historic records from backups — are quoted before any work

AI processing and training

Where an AI feature forms part of your build, prompts and responses are sent to the model provider named in section 3 for the sole purpose of returning that response. We do not use your client data to train models, and we select provider settings that disable training on submitted content where the provider offers that option. If a model provider changes those terms we will tell you.

Audits and records

We maintain a record of processing activities for the services we provide and will make relevant extracts available on request. Controllers may audit our processing once in any twelve-month period, with reasonable notice, and we will respond to security questionnaires from your own compliance team.

Data Processing Agreement

A signed DPA is available on request — email [email protected].

Questions about this data processing policy

Email [email protected] or call 085 224 1848 and reference the data processing policy. We answer policy and data-protection queries within five working days. Digital Bridge is based at Gorey Business Park, Gorey, Co. Wexford, and all our agreements are governed by Irish law with the Irish courts having jurisdiction. Consumers may also use the European Commission's Online Dispute Resolution platform at ec.europa.eu/consumers/odr, or contact the Competition and Consumer Protection Commission.