Who we are
smarthotspots Ltd, Unit 8A Keypoint, Rosemount Business Park, Dublin, D11 Y77P, Ireland, is responsible for the personal data described in this statement when we decide how and why it is used. In that situation, we act as the data controller.
For privacy enquiries or to exercise your rights, contact us at [email protected] or telephone 01 529 0136.
Who this statement applies to
This statement explains how we handle personal data relating to clients, prospective clients, suppliers, website visitors, support contacts and people who use services we provide. It should be read with any contract, service-specific terms or privacy information supplied by the organisation providing a network or guest WiFi service to you.
When we are a controller or processor
We act as a data controller for our own business administration, website, enquiries, client relationships, billing, security and marketing activities.
When we operate or support a managed network on a client’s documented instructions, we may instead act as that client’s data processor. The client remains responsible for telling its staff, customers or WiFi users how their information is used. Our processing in that role is governed by the relevant service agreement and data-processing terms.
Information we may collect
Depending on your relationship with us, we may collect:
- Contact information, including your name, business, postal address, telephone number and email address.
- Account and billing information needed to set up, administer and charge for services.
- Service and technical information, such as hardware models, serial numbers, software versions, IP addresses, MAC addresses, support records and network diagnostics.
- Usage information generated when our websites, networks or managed services are used.
- Communications you send to us and records of support, sales or service interactions.
Where information comes from
We normally receive information directly from you, your employer or another person acting for your organisation. We may also receive service and technical information from network equipment, connectivity providers, monitoring platforms, support systems and other suppliers used to deliver a contracted service. Limited information may come from public business sources where it is reasonable and lawful to use it.
Purposes and lawful bases
We use personal data only where we have a lawful basis:
- Contract — to prepare, provide, administer and support services requested by you or your organisation.
- Legitimate interests — to respond to business enquiries, manage client and supplier relationships, maintain service quality, secure systems, investigate faults, prevent misuse and operate our business. We consider the impact on individuals before relying on this basis.
- Legal obligation — to meet tax, accounting, regulatory and other legal requirements.
- Consent — for Google Analytics and any optional marketing activity where consent is required. You may withdraw consent at any time.
Where contact, billing or technical information is necessary to enter into or perform a contract, failing to provide it may mean that we cannot quote for, activate or support the requested service.
Who we share information with
Access is limited to authorised smarthotspots personnel and suppliers who need the information to provide agreed services. This can include hosting, connectivity, payment, professional-advice and technical-support providers. We require service providers to protect the information and use it only for the agreed purpose. We may also disclose information where required by law, to protect legal rights, or as part of a business sale or reorganisation.
International transfers
Some suppliers may process personal data outside the European Economic Area. Where that happens, we use a lawful transfer mechanism, such as an adequacy decision or approved Standard Contractual Clauses, together with any additional safeguards considered necessary. You may contact us for information about the safeguards relevant to your data.
Security
We use appropriate organisational and technical measures designed to protect personal data against loss, misuse, unauthorised access, alteration and disclosure. Measures may include access controls, authentication, encryption, firewalls, monitoring, backups, supplier controls and staff procedures. No internet or storage system can be guaranteed completely secure.
How long we keep information
We retain personal data only for as long as reasonably necessary for the purpose for which it was collected. The period depends on the type of record, the service provided and legal, accounting, security and dispute-resolution requirements.
- Enquiry and prospective-client records are reviewed when no continuing business purpose remains.
- Client, billing and contractual records may be retained after the relationship ends where required for tax, accounting or legal claims.
- Support and technical records are retained for the service period and for a reasonable period afterwards to maintain service history, security and accountability.
- Information processed solely on a client’s behalf is returned or deleted in accordance with the applicable agreement, subject to legal obligations.
Cookies and website analytics
We use a privacy-focused, first-party counter for basic website measurement whether or not you accept optional analytics. It records only the date, the page path and an aggregated page-view total. It does not set cookies, create a persistent visitor or session identifier, collect a full IP address, retain query strings or referrers, fingerprint a device, or track anyone across websites. These aggregate counters are automatically removed after 30 days and may be lost sooner when the service restarts.
We use local browser storage only to remember your optional analytics choice. With your consent, Google Analytics helps us understand visits, pages viewed, approximate location, device and browser information, referring websites and interactions with contact links. Google acts as a service provider for this processing.
Google Analytics is disabled until you select “Accept analytics”. If accepted, Google Analytics may set cookies such as _ga and related identifiers. Their lifetime depends on our Analytics configuration and browser restrictions and may be up to two years. Analytics reports may be retained for longer in aggregated form where they no longer identify an individual visitor.
You may reject Google Analytics without losing access to the website. Change your choice at any time using the Cookie settings control. Our Google Analytics measurement ID is G-W3W4FKQ4L2. Further information is available in Google’s Privacy Policy.
Automated decisions
We do not use website or client contact information to make decisions based solely on automated processing that produce legal or similarly significant effects. We do not use Google Analytics to identify individual website visitors.
Your data-protection rights
Subject to applicable law, you may ask us to provide access to your personal data, correct inaccurate information, erase it, restrict its use, object to processing based on legitimate interests, or provide eligible information in a portable format. You may withdraw consent at any time without affecting processing carried out before withdrawal.
We normally respond to valid rights requests within one month. We may need to verify your identity and may extend the response period where a request is particularly complex, as permitted by law.
Complaints
Please contact us first if you have a concern so that we have an opportunity to address it. You also have the right to raise a concern with the Irish Data Protection Commission.
Data Protection Commission
6 Pembroke Row, Dublin 2, D02 X963, Ireland
[email protected]
Changes to this statement
We may update this statement when our services, suppliers or legal obligations change. The latest version will be published here with its revision date.
