Privacy Policy

Legal Notice

Protect

Proactive Defense

Detect

Threat Visibility

Recover

Rapid Recovery

Comply

Practical Governance

PRIVACY POLICY

Version 3.0
Last updated: 25 September 2026

1. Introduction and Scope

Digital Synergy Limited (“Digital Synergy”, “we”, “us” or “our”) respects the privacy of individuals who visit our website, contact us, request information about our services or otherwise interact with us.

This Privacy Policy explains how we collect, use, disclose, retain and protect personal data in connection with:

  • the website digital-synergy.eu and its associated pages;
  • general business enquiries;
  • cybersecurity service enquiries and proposal requests;
  • AI security service enquiries and proposal requests;
  • managed IT service enquiries and proposal requests;
  • professional and business communications;
  • website security and abuse-prevention activities;
  • website analytics, where consent has been provided; and
  • other interactions directly connected with this Website.

This Policy applies where Digital Synergy Limited acts as a controller of personal data.

Where Digital Synergy Limited processes personal data on behalf of a customer in the course of providing managed IT, managed security, monitoring, cybersecurity, cloud, backup, security testing or related contracted services, the respective roles and obligations of the parties are governed by the relevant customer agreement, Data Processing Agreement, Statement of Work and documented customer instructions.

2. Controller

The controller responsible for the processing described in this Privacy Policy is:

Digital Synergy Limited
Second Floor, 74 South Mall
Cork, T12 F3FD
Co. Cork
Republic of Ireland

Company / CRO No.: 561118
Irish Tax Registration No.: 3384851DH

General legal and privacy enquiries:
legal@digital-synergy.eu

Cookie-related enquiries:
privacy@digital-synergy.eu

Telephone:
+353 21 203 1280

3. Data Protection Contact

For privacy and data protection matters, you may contact:

dpo@digital-synergy.eu

Postal correspondence may be addressed to:

Digital Synergy Limited
Attn: Data Protection Contact
Second Floor, 74 South Mall
Cork, T12 F3FD
Co. Cork
Republic of Ireland

The above email address is a dedicated privacy and data protection contact point.

Digital Synergy Limited has not designated a Data Protection Officer pursuant to Article 37 of the GDPR.

4. Our Role as Controller and Processor

Digital Synergy Limited generally acts as a controller in relation to:

  • operation and security of this Website;
  • enquiries received through the Website;
  • prospective customer communications;
  • proposal requests;
  • our own business administration;
  • Website analytics;
  • cookie and consent management; and
  • our own lawful business communications.

Digital Synergy Limited may act as a processor where, in the course of providing contracted services, we process personal data solely on behalf of and in accordance with the documented instructions of a customer.

Whether Digital Synergy Limited acts as controller or processor depends on the factual circumstances and the purposes and means of the relevant processing.

5. How We Collect Personal Data

We may collect personal data:

5.1 Directly from you

For example, where you:

  • submit a contact form;
  • submit a cybersecurity service request;
  • submit an AI security service request;
  • submit a managed IT services request;
  • request a quotation or proposal;
  • email us;
  • telephone us;
  • communicate with us in a professional capacity; or
  • otherwise voluntarily provide information to us.

5.2 Automatically through the Website

Limited technical information may be generated when you access or use the Website, including information required to:

  • deliver Website content;
  • operate the Website;
  • maintain security;
  • detect abuse;
  • diagnose technical problems;
  • maintain server logs; and
  • measure Website use where you have consented to analytics.

5.3 From another business contact

In a business-to-business context, we may receive professional contact information from:

  • your employer;
  • your organisation;
  • a colleague;
  • a business partner;
  • a customer;
  • a supplier; or
  • another professional contact.

Where applicable, the transparency requirements described in Section 11 below apply to information obtained indirectly.

6. Categories of Personal Data

Depending on the nature of your interaction with us, we may process the following information.

6.1 Website and technical information

This may include:

  • IP address;
  • date and time of access;
  • requested URL;
  • referring page;
  • browser type and version;
  • operating system;
  • device information;
  • HTTP request information;
  • User-Agent information;
  • security events;
  • server access logs;
  • error logs; and
  • diagnostic information.

6.2 Website security information

Where security or anti-abuse technologies are used, information may include:

  • IP address;
  • timestamp;
  • browser and device characteristics;
  • User-Agent header;
  • TLS-related technical signals;
  • request characteristics;
  • hostname or origin;
  • security identifiers;
  • bot-detection signals; and
  • other limited technical information necessary to identify malicious or automated traffic.

6.3 Contact information

This may include:

  • name;
  • business email address;
  • telephone number;
  • company or organisation;
  • job title or professional function;
  • country;
  • subject of the enquiry;
  • message content; and
  • subsequent correspondence.

6.4 Cybersecurity and AI security proposal information

Depending on the relevant form or enquiry, this may include:

  • name;
  • business email address;
  • organisation;
  • country;
  • approximate organisation or infrastructure size;
  • number of devices or endpoints;
  • security service interests;
  • requested project or service scope;
  • preferred start date or timeline;
  • information entered in free-text fields; and
  • subsequent communications relating to the proposal.

6.5 Managed IT proposal information

This may include:

  • name;
  • business email address;
  • organisation;
  • country;
  • number of users;
  • selected service requirements;
  • support requirements;
  • information entered in free-text fields; and
  • subsequent communications.

6.6 Analytics information

Where analytics consent has been provided, we may process pseudonymous information such as:

  • analytics identifiers;
  • session information;
  • page views;
  • Website events;
  • approximate device information;
  • browser information;
  • referring source;
  • general Website usage information; and
  • consent status.

We do not use Website analytics to make decisions producing legal or similarly significant effects about individual Website visitors.

7. Sensitive Information and Security Information

Please do not submit through ordinary Website forms:

  • passwords;
  • private cryptographic keys;
  • API keys;
  • authentication tokens;
  • administrator credentials;
  • production credentials;
  • confidential vulnerability data that is not necessary for the initial enquiry;
  • special-category personal data;
  • criminal-offence data; or
  • other information requiring a higher-security communication channel.

Where sensitive technical or security information is required for a professional engagement, an appropriate secure communication method will be agreed separately.

8. Purposes, Legal Bases and Retention

8.1 Website operation

Purpose

To operate, deliver and maintain the Website and provide functionality requested by visitors.

Legal basis

Article 6(1)(f) GDPR — our legitimate interests in operating a secure, reliable and functional business Website.

Retention

Server access and error logs are normally retained for up to 90 days, unless longer retention is reasonably necessary in connection with:

  • a technical investigation;
  • security incident;
  • suspected abuse;
  • legal claim; or
  • regulatory matter.

8.2 Website security and abuse prevention

Purpose

To protect the Website, infrastructure and online forms against:

  • malicious requests;
  • bots;
  • spam;
  • automated abuse;
  • unauthorised access;
  • attacks;
  • fraud; and
  • other security threats.

Legal basis

Article 6(1)(f) GDPR — our legitimate interests in protecting the confidentiality, integrity, availability and security of our Website and information systems.

Where processing is specifically required by an applicable legal obligation, Article 6(1)(c) GDPR may also apply.

Retention

Technical and security logs controlled by Digital Synergy Limited are normally retained for up to 180 days.

Relevant records may be retained longer where reasonably necessary in connection with a security incident, investigation, complaint, legal claim or regulatory matter.

8.3 General enquiries

Purpose

To receive, evaluate, manage and respond to enquiries and professional communications.

Legal basis

Article 6(1)(f) GDPR — our legitimate interests in communicating with prospective customers, customers, suppliers, professional contacts and other persons who contact us.

Where an individual contacts us in their own name to take steps before entering into a contract with that individual, Article 6(1)(b) GDPR may apply.

Retention

Normally up to 12 months from our last substantive interaction, unless:

  • the enquiry results in a contractual relationship;
  • a longer period is required by law; or
  • retention is reasonably necessary for the establishment, exercise or defence of legal claims.

8.4 Cybersecurity, AI security and managed IT proposal requests

Purpose

To:

  • understand your organisation’s requirements;
  • assess the requested scope;
  • communicate with relevant business contacts;
  • evaluate whether we can provide the requested service;
  • prepare or discuss a proposal; and
  • manage prospective customer communications.

Legal basis

Article 6(1)(f) GDPR — our legitimate interests in responding to B2B service enquiries, assessing requirements and preparing requested commercial proposals.

Article 6(1)(b) GDPR may apply where an individual acts in their own name and requests pre-contractual steps relating to a contract with that individual.

Retention

Normally up to 12 months from our last substantive interaction, unless:

  • the proposal results in a customer relationship;
  • longer retention is required by law; or
  • longer retention is reasonably necessary in connection with a legal claim.

8.5 Website analytics

We use Google Analytics 4 only where analytics consent has been provided through our cookie consent mechanism.

Purpose

To:

  • understand Website usage;
  • assess Website performance;
  • identify frequently visited content;
  • improve navigation and usability; and
  • improve Website content.

Legal basis

Article 6(1)(a) GDPR — consent.

Analytics is not activated until the required consent has been provided.

You may withdraw analytics consent at any time by using the “Change cookie settings” control available on the Website.

Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.

Google Analytics event data is configured for retention for up to 14 months, subject to the relevant service configuration and provider processes.

8.6 Cookie and consent preferences

Purpose

To:

  • remember your cookie preference;
  • apply your consent decision;
  • record whether optional technologies may operate;
  • demonstrate consent or rejection where required; and
  • record subsequent changes or withdrawal.

Legal basis

Depending on the particular record:

  • Article 6(1)(c) GDPR — compliance with applicable legal obligations; and/or
  • Article 6(1)(f) GDPR — our legitimate interests in administering and evidencing Website privacy choices.

Consent and preference records may be retained for up to 24 months, subject to applicable requirements.

8.7 Compliance, disputes and legal claims

We may retain or otherwise process relevant personal data where reasonably necessary to:

  • comply with applicable law;
  • respond to a court or regulator;
  • investigate suspected misuse;
  • manage a complaint;
  • maintain required business records;
  • protect our rights;
  • establish legal claims;
  • exercise legal claims; or
  • defend legal claims.

The legal basis may include Article 6(1)(c) or Article 6(1)(f) GDPR, depending on the circumstances.

9. Required Information

Certain fields in our forms may be marked as required.

We request required information only where it is reasonably necessary to:

  • receive your request;
  • identify how to respond;
  • understand the relevant service requirement; or
  • assess a requested proposal.

If required information is not provided, we may be unable to process or respond to the request.

Submitting a form does not itself create a contract with Digital Synergy Limited.

10. Electronic Direct Marketing

Submission of an enquiry, contact form or proposal request does not constitute consent to receive unrelated electronic direct marketing.

Where prior consent is required by Irish law for electronic direct marketing, we will obtain such consent through a separate and affirmative opt-in mechanism.

Where an applicable statutory exception permits electronic marketing without separate consent, we will rely on that exception only within its legal scope and subject to the applicable conditions.

Every electronic direct marketing communication sent by us will provide an appropriate method to object or unsubscribe where required.

You may object to the processing of your personal data for direct marketing purposes at any time.

Where you unsubscribe or object, we may retain limited suppression information necessary to ensure that your preference continues to be respected.

11. Information Obtained from Other Sources

In some B2B circumstances, another person may provide us with your professional contact information.

For example, a colleague may identify you as the appropriate technical, commercial or management contact for a project or service enquiry.

Where Article 14 GDPR applies and you have not already received the relevant information, we will provide the required privacy information within the period prescribed by applicable law, normally no later than:

  • one month after obtaining your personal data;
  • the time of our first communication with you, where the information is used to communicate with you; or
  • the first disclosure to another recipient, where applicable,

whichever occurs first.

Where required, we will also provide information about the source from which the personal data originated.

Applicable Article 14 exemptions may apply in limited circumstances.

12. Cloudflare Turnstile

We use Cloudflare Turnstile, provided by Cloudflare, Inc., on Website pages containing online forms.

Turnstile is used for:

  • bot detection;
  • spam prevention;
  • protection against automated submissions;
  • malicious request detection; and
  • Website and form security.

Turnstile may process limited technical security signals, including:

  • IP address;
  • TLS-related technical information;
  • User-Agent information;
  • browser characteristics;
  • device characteristics;
  • Turnstile sitekey;
  • hostname or origin; and
  • other technical signals required for bot or abuse detection.

Digital Synergy Limited does not use Turnstile for:

  • behavioural advertising;
  • advertising profiling;
  • marketing attribution; or
  • audience analytics.

Cloudflare may act as a processor in relation to certain processing carried out on our behalf to provide the service and may separately process certain technical security signals for its own legitimate security purposes in accordance with its applicable documentation.

13. Recipients and Service Providers

We disclose personal data only where reasonably necessary for the purposes described in this Privacy Policy.

Relevant recipients may include:

Hetzner Online GmbH

Germany.

Hetzner provides infrastructure and hosting services supporting the Website and associated systems.

Where Hetzner processes personal data on our behalf, appropriate contractual data protection arrangements are maintained.

Cloudflare, Inc.

United States.

Cloudflare provides Turnstile security and bot-detection functionality on Website pages containing protected online forms.

Google Ireland Limited and relevant Google group companies

Google Analytics 4 is used only where the Website visitor has provided analytics consent.

Google Analytics Measurement ID:

G-5MB58K74J8

Professional advisers

Where necessary, information may also be disclosed to:

  • legal advisers;
  • accountants;
  • auditors;
  • insurers;
  • information security professionals; and
  • other professional advisers.

Public authorities

Information may be disclosed to:

  • courts;
  • regulators;
  • law-enforcement bodies; or
  • other competent authorities

where disclosure is required or permitted by applicable law.

We do not sell personal data.

We do not disclose Website visitor personal data to unrelated third parties for their own independent advertising purposes.

14. International Data Transfers

We seek to process personal data within the European Economic Area where reasonably practicable.

Certain providers may process or access limited personal data outside the EEA, including in the United States.

Where Chapter V of the GDPR applies, an appropriate transfer mechanism will be used.

Depending on the circumstances, this may include:

  • a European Commission adequacy decision;
  • the EU-U.S. Data Privacy Framework where the relevant recipient maintains a valid certification covering the relevant processing;
  • European Commission Standard Contractual Clauses; and
  • supplementary contractual, organisational or technical safeguards where required.

Where Standard Contractual Clauses or another Article 46 safeguard is used, you may request further information about the relevant safeguards by contacting:

legal@digital-synergy.eu

Any copy or information provided may be subject to appropriate redactions necessary to protect confidential, security-sensitive or third-party information.

15. Cookies and Similar Technologies

We use:

  • strictly necessary technologies;
  • user-requested preference functionality;
  • Website security technologies; and
  • optional analytics technologies.

Optional analytics technologies are not activated until the required consent has been provided.

Further information, including relevant technologies, purposes and durations, is available in our Cookie Policy.

Cookie preferences may be changed through the “Change cookie settings” control available on the Website.

16. Data Security

We implement technical and organisational measures designed to protect personal data against:

  • accidental loss;
  • unlawful destruction;
  • unauthorised access;
  • unauthorised disclosure;
  • alteration;
  • misuse; and
  • other unlawful processing.

Measures are selected having regard to:

  • the nature of the information;
  • the scope and context of the processing;
  • the purposes of the processing;
  • available technology;
  • implementation costs; and
  • the risks to individuals.

Security measures are reviewed and adjusted as reasonably appropriate.

No Internet-connected system can be represented as completely secure, and no Website or security control can guarantee the prevention of every possible incident.

17. Your Data Protection Rights

Subject to the conditions, limitations and exemptions provided by applicable law, you may have the following rights.

Right of access

You may request confirmation as to whether we process personal data concerning you and obtain access to that information.

Right to rectification

You may request correction of inaccurate personal data or completion of incomplete personal data.

Right to erasure

You may request deletion of personal data where the applicable legal conditions are satisfied.

Right to restriction

You may request restriction of processing in the circumstances provided by the GDPR.

Right to data portability

Where the relevant legal conditions apply, you may request certain personal data in a structured, commonly used and machine-readable format.

Right to withdraw consent

Where processing is based on consent, you may withdraw consent at any time.

Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

Right to object

Where we process personal data on the basis of Article 6(1)(f) GDPR, you may object to that processing on grounds relating to your particular situation.

Where personal data are processed for direct marketing, you may object to such processing at any time.

Right to lodge a complaint

You have the right to lodge a complaint with the Irish Data Protection Commission or another competent supervisory authority.

18. Exercising Your Rights

You may submit a privacy or data-protection request by contacting:

legal@digital-synergy.eu

or:

dpo@digital-synergy.eu

You may also write to:

Digital Synergy Limited
Attn: Data Protection Contact
Second Floor, 74 South Mall
Cork, T12 F3FD
Co. Cork
Republic of Ireland

Please provide sufficient information to allow us to identify and understand your request.

Where we have reasonable doubts concerning identity, we may request proportionate additional information necessary to verify the identity of the person making the request.

We will not routinely request excessive identity documentation.

We will respond without undue delay and normally within one month, subject to the GDPR.

Where permitted because of the complexity or number of requests, this period may be extended by up to two additional months. Where an extension is required, we will inform you within the initial one-month period.

Requests are normally handled free of charge. The GDPR permits a reasonable fee or refusal to act in limited circumstances involving manifestly unfounded or excessive requests.

19. Complaints to the Data Protection Commission

The Irish supervisory authority is:

Data Protection Commission
6 Pembroke Row
Dublin 2
D02 X963
Ireland

Website: www.dataprotection.ie

You are entitled to contact the Data Protection Commission directly.

20. Automated Decision-Making

Digital Synergy Limited does not use personal data collected through this Website to make decisions based solely on automated processing that produce legal effects or similarly significant effects concerning Website visitors within the meaning of Article 22 GDPR.

If this changes, this Privacy Policy will be updated as required.

21. Children

The Website and services promoted through it are directed primarily at businesses, organisations and professional users.

They are not intended or designed as services directed at children.

We do not knowingly use this Website to solicit children’s personal data for behavioural advertising or profiling.

If you believe that personal data concerning a child has been submitted to us in circumstances requiring attention, please contact:

legal@digital-synergy.eu

22. Third-Party Websites

The Website may contain links to websites or services operated by independent third parties.

Digital Synergy Limited does not control those third parties and is not responsible for their independent privacy practices.

Visitors should review the privacy information applicable to any external service they choose to use.

23. Changes to this Privacy Policy

We may amend this Privacy Policy where:

  • our Website changes;
  • our processing activities change;
  • providers change;
  • technologies change;
  • applicable law or regulatory guidance changes; or
  • clarification is otherwise appropriate.

The current version and date will be displayed at the top of this Policy.

Where a material change affects an existing consent choice, additional notice or renewed consent will be obtained where required.

24. Contact

General privacy and legal enquiries
legal@digital-synergy.eu

Cookie-related enquiries
privacy@digital-synergy.eu

Data Protection Contact
dpo@digital-synergy.eu

Digital Synergy Limited
Second Floor, 74 South Mall
Cork, T12 F3FD
Co. Cork
Republic of Ireland

Telephone: +353 21 203 1280

Company / CRO No.: 561118
Irish Tax Registration No.: 3384851DH

digital synergy
digital synergy
digital synergy
digital synergy
digital synergy