Privacy Policy

Paddy Labs (“we,” “us,” or “our”) is committed to protecting the privacy and security of the personal data we process. This Privacy Policy describes how we collect, use, and protect information in compliance with the General Data Protection Regulation (GDPR) and the Data Protection Act 2018 (Ireland).

1. Scope and Our Role

Paddy Labs provides SaaS CRM, billing, and transactional email infrastructure to registered merchant companies (“Merchants”).

  • As a Data Controller: We are responsible for the personal data of our Merchants (e.g., account registration and billing for the Paddy Labs service).
  • As a Data Processor: We process data belonging to the Merchant’s customers at the Merchant’s direction. In these instances, the Merchant is the Data Controller, and their specific privacy policy governs that data.

2. Information We Collect

We collect information necessary to provide our technology platform:

  • Merchant Account Data: Name, business email, job title, and contact details of authorized representatives.
  • Business Information: Registered office address, tax ID, and billing information.
  • Technical Data: IP addresses, login timestamps, browser type, and device identifiers used to access our dashboard for security and performance monitoring.
  • Communication Data: Records of support requests and correspondence sent to info@paddylabs.ie.

3. Legal Basis for Processing

We process data under the following legal frameworks provided by the GDPR:

  • Contractual Necessity: To provide the SaaS platform and support services.
  • Legal Obligation: To comply with Irish Revenue and financial reporting requirements.
  • Legitimate Interests: To maintain platform security, prevent fraudulent use of our billing infrastructure, and improve our services.

4. How We Use Your Information

  • To set up and manage your Merchant account.
  • To facilitate billing and payment for the Paddy Labs platform.
  • To send transactional notifications and platform updates.
  • To provide technical support and troubleshoot infrastructure issues.
  • To prevent, detect, and investigate potentially prohibited or illegal activities.

5. Sharing of Data

We do not sell your personal data. We only share information with third parties who are essential to our operations:

  • Sub-processors: Including cloud hosting providers (e.g., AWS/Google Cloud) and email delivery API providers.
  • Payment Gateways: To process your subscription fees securely.
  • Professional Advisors: Such as auditors or legal counsel as required for business compliance.
  • Law Enforcement: When required by Irish or EU law.

6. International Data Transfers

Paddy Labs is located in Ireland. We store and process data primarily within the European Economic Area (EEA). If we use sub-processors located outside the EEA, we ensure they are bound by European Commission-approved Standard Contractual Clauses (SCCs) to maintain an equivalent level of data protection.

7. Data Retention

We retain personal data for as long as your Merchant account is active. Once an account is closed, we retain certain data (such as invoices and tax records) for 7 years to comply with Irish financial regulations. Technical logs are typically purged after 90 days unless required for an ongoing security investigation.

8. Your Rights

Under the GDPR, you have the following rights:

  • Access: To request a copy of the data we hold about you.
  • Rectification: To correct inaccurate or incomplete data.
  • Erasure: To request the deletion of your data (subject to legal retention requirements).
  • Restriction: To limit how we process your data.
  • Portability: To receive your data in a structured, machine-readable format.
  • Objection: To object to processing based on legitimate interests.

To exercise these rights, please contact our Data Protection lead at info@paddylabs.ie.

9. Security

We implement robust technical and organizational measures to protect data, including:

  • Encryption of data at rest and in transit (TLS/SSL).
  • Strict access controls (Multi-Factor Authentication).
  • Regular security audits of our CRM and billing infrastructure.

10. Contact Information

Paddy Labs, 3 The Place, Dunboyne Castle, Meath, A86 E129, Ireland Email: info@paddylabs.ie