GDPR Compliance — Digital Bridge
Your rights under EU GDPR and how to exercise them. This policy applies to all Digital Bridge services and is governed by Irish law.
Our role
For our website visitors and newsletter subscribers, we act as data controller. When delivering services to clients (e.g. processing data stored in your website or CRM on your behalf), we act as data processor.
Lawful bases we rely on
- Contract performance
- Consent (newsletters, marketing cookies)
- Legitimate interest (security, service improvement)
- Legal obligation (tax, accounting)
Your rights under GDPR
- Right of access
- Right to rectification
- Right to erasure ("right to be forgotten")
- Right to restrict processing
- Right to data portability
- Right to object
- Right to withdraw consent at any time
- Right not to be subject to solely automated decision-making
How to make a request
Email [email protected] with "GDPR Request" in the subject line. We will verify identity and respond within 30 days at no
Data Processing Agreement (DPA)
Business clients can request a signed DPA before sharing personal data with us for processing. Contact us to receive our standard DPA.
Subprocessors
We use vetted EU and global subprocessors (hosting, payments, email, analytics). A current list is available on request and in our Data Processing Policy.
International transfers
Where data is transferred outside the EEA, we rely on Standard Contractual Clauses and the EU–US Data Privacy Framework where applicable.
Data breach notification
In the unlikely event of a personal data breach likely to result in risk to your rights, we will notify the Data Protection Commission within 72 hours and affected individuals without undue delay.
Complaints
You have the right to lodge a complaint with the Irish Data Protection Commission — dataprotection.ie.
Retention periods
We keep enquiry and contact-form data for 24 months from last contact, client project records for six years after the engagement ends to meet Revenue and statutory record-keeping obligations, newsletter data until you unsubscribe, and telephone call recordings for six months. Anything outside a defined retention period is deleted rather than archived indefinitely.
Automated decision-making and AI
We do not make decisions producing legal or similarly significant effects about you by automated means. Where an AI system we build for a client processes personal data — an enquiry classifier, a support assistant, a document summariser — we document what the model sees, whether any data leaves the EEA, and whether a human reviews the output before it acts. Under the EU AI Act, transparency obligations for general-purpose and limited-risk systems apply from 2 August 2025 and we design to them by default.
Data minimisation in practice
Our contact forms ask for a name, an email address and the message. Phone number and company are optional. We do not buy contact lists, we do not enrich records with third-party data, and we do not use client production data in demos or training material.
Records of processing
We maintain an Article 30 record of processing activities covering purposes, categories of data and recipients, retention periods and transfer safeguards. Business clients carrying out their own due diligence can request an extract relevant to their engagement.
Questions about this gdpr compliance
Email [email protected] or call 085 224 1848 and reference the gdpr compliance. We answer policy and data-protection queries within five working days. Digital Bridge is based at Gorey Business Park, Gorey, Co. Wexford, and all our agreements are governed by Irish law with the Irish courts having jurisdiction. Consumers may also use the European Commission's Online Dispute Resolution platform at ec.europa.eu/consumers/odr, or contact the Competition and Consumer Protection Commission.