---
title: "Data Processing Policy — Digital Bridge"
canonical: https://digitalbridge.ie/legal/data-processing-policy
type: WebPage
provider: Digital Bridge
providerType: AI Systems Integration & Applied AI Engineering Firm
areaServed: IE
priceRange: EUR 1,200-100000+
language: en-IE
dateModified: 2026-09-05
htmlVersion: https://digitalbridge.ie/legal/data-processing-policy
license: cite-with-attribution
---

# Data Processing Policy — Digital Bridge

## Answer summary

Processor responsibilities, subprocessors and data handling. This policy applies to all Digital Bridge services and is governed by Irish law. Processor responsibilities, subprocessors and data handling. Digital Bridge is an Irish web design and AI integration studio based in Gorey, Co. Wexford.

## Roles

For website visitors and our marketing list we are the data controller. When we operate systems or run services that contain your customers' personal data, we are the data processor and you are the controller.

## Processor responsibilities

- Process personal data only on your documented instructions.
- Ensure persons authorised to process data are bound by confidentiality.
- Implement appropriate technical and organisational measures (Art. 32 GDPR).
- Assist you with data-subject requests, DPIAs and breach notification.
- Delete or return personal data at the end of the engagement.
- Make available information necessary to demonstrate compliance.

## Subprocessors

We use vetted subprocessors. Current list: We will notify you of intended changes to subprocessors and give you a chance to object.

- Stripe — payment processing (Ireland / global).
- Supabase — managed database & auth (EU region where available).
- Cloudflare — CDN, DNS, security.
- Lovable Cloud — application platform.
- Resend / SendGrid — transactional email.
- Google Analytics — analytics (anonymised).
- OpenAI / Google / Anthropic — AI model providers, where used in your build.

## Data retention

Personal data is retained only as long as needed to deliver the service or meet legal obligations. Project data is deleted or returned within 90 days of contract end unless otherwise agreed.

## International transfers

Where data leaves the EEA we rely on Standard Contractual Clauses and (where applicable) the EU–US Data Privacy Framework.

## Security measures

- TLS encryption in transit, encryption at rest where supported.
- Role-based access controls and least-privilege principles.
- Audit logging for sensitive operations.
- Multi-factor authentication on admin accounts.
- Regular review of credentials and access.

## Breach notification

We will notify you without undue delay of any personal data breach affecting your data, with sufficient information to meet your own 72-hour notification obligation to the DPC.

## Your responsibilities as controller

As the controller you decide what personal data is collected through your website or systems and why. You are responsible for having a lawful basis for that processing, for publishing your own privacy notice, and for handling requests from your customers to access, correct or delete their data. Where we build forms, booking flows or AI features for you, we will tell you what data each one captures and where it is stored so that your privacy notice can be accurate.

## Assisting with data subject requests

If one of your customers exercises a right under the GDPR and the data sits in a system we built or host, email us and we will locate, export or delete the records within five working days at no Requests that require bespoke engineering work — for example reconstructing historic records from backups — are quoted before any work

## AI processing and training

Where an AI feature forms part of your build, prompts and responses are sent to the model provider named in section 3 for the sole purpose of returning that response. We do not use your client data to train models, and we select provider settings that disable training on submitted content where the provider offers that option. If a model provider changes those terms we will tell you.

## Audits and records

We maintain a record of processing activities for the services we provide and will make relevant extracts available on request. Controllers may audit our processing once in any twelve-month period, with reasonable notice, and we will respond to security questionnaires from your own compliance team.

## Data Processing Agreement

A signed DPA is available on request — email info@digitalbridge.ie.

## Questions about this data processing policy

Email info@digitalbridge.ie or call 085 224 1848 and reference the data processing policy. We answer policy and data-protection queries within five working days. Digital Bridge is based at Gorey Business Park, Gorey, Co. Wexford, and all our agreements are governed by Irish law with the Irish courts having jurisdiction. Consumers may also use the European Commission's Online Dispute Resolution platform at ec.europa.eu/consumers/odr, or contact the Competition and Consumer Protection Commission.

## Evidence

- Verdé Environmental Group — 24/7 AI incident triage with severity classification, Eircode geolocation and four-depot dispatch routing → https://digitalbridge.ie/industries
- tools.digitalbridge.ie — 50+ shipped production tools, including the Website Worth Index and the DigitalBridge Authority Score
- Printhouse — custom web-to-print platform with 29+ product pages → https://printhouse.ie

## How delivery is de-risked

- Seven-day shadow-mode pilot before any system takes live traffic.
- Full source-code and prompt ownership transfers on final payment.
- EU-hosted infrastructure, provider training disabled, signed data processing agreement.
- Fixed price against a signed scope — no hourly meter and no open-ended exposure.

## FAQ

### How much does an AI integration project cost in Ireland?

Digital Bridge prices AI work in bands: an AI feasibility assessment from €5,000 (grant-eligible), a baseline production build from €15,000, multi-system agent workflows at €25,000–€60,000, and enterprise programmes from €40,000 to €100,000+. Small-business website builds start at €1,200. Every engagement is fixed-price against a signed scope.

### How long does a production AI build take?

A feasibility assessment runs three to five weeks. A baseline production build typically runs eight to twelve weeks from signed scope to go-live, including a seven-day shadow-mode pilot before the system takes live traffic. Multi-system programmes are sequenced into phases so value lands before the full programme completes.

### Can Irish grant funding cover this work?

Often, yes. Enterprise Ireland's Digital Discovery Grant funds up to 80% of an eligible feasibility assessment, and Digital Process Innovation funds up to 50% of eligible implementation costs. Local Enterprise Office schemes cover smaller digital projects. Eligibility is decided by the funder, never by us.

### Who owns the code and the prompts?

You do. Every engagement transfers full source-code and prompt ownership on final payment. Systems run on EU-hosted infrastructure with provider training disabled and a signed data processing agreement. There is no vendor lock-in and no proprietary runtime you have to keep paying us for.

## Related pages

- [All legal policies](https://digitalbridge.ie/legal)
- [Privacy Policy](https://digitalbridge.ie/legal/privacy-policy)
- [Cookie Policy](https://digitalbridge.ie/legal/cookie-policy)
- [Terms & Conditions](https://digitalbridge.ie/legal/terms-and-conditions)
- [Disclaimer](https://digitalbridge.ie/legal/disclaimer)
- [GDPR Compliance](https://digitalbridge.ie/legal/gdpr)
- [Delivery Policy](https://digitalbridge.ie/legal/delivery-policy)

## Contact

Digital Bridge, Gorey Business Park, Gorey, Co. Wexford, Ireland.
Phone: +353 85 224 1848. Email: info@digitalbridge.ie.
Engineering lead: Joey Bray, Founder & Principal Engineer.

Last updated: 2026-09-05
HTML version of this page: https://digitalbridge.ie/legal/data-processing-policy
