Legal
Privacy Policy
Effective date: 9.08.2026
Last updated: 9 August 2026
This Privacy Policy explains how Mateusz Kania, trading as SiteForge ("SiteForge", "we", "us", "our"), collects, uses, stores and protects personal data when you visit SiteForge.ie, contact us, purchase or use our services, access our client systems, or otherwise interact with us.
1. Data Controller and Business Identity
For personal data processed for SiteForge's own business purposes, the data controller is:
- Proprietor: Mateusz Kania
- Trading name: SiteForge
- Business address: Bridge Street, Skibbereen, Co. Cork
- CRO Business Name Registration No.:
- Email: [email protected]
- General contact: [email protected]
- Telephone: 089 948 6328
SiteForge provides website design and development, WordPress and WooCommerce services, hosting, domain and email services, website care and maintenance, malware removal, SEO, website analytics, branding, marketing and visual design, and related technical and digital services.
2. When SiteForge Is a Controller and When It Is a Processor
SiteForge acts as a data controller when we decide why and how personal data is processed for our own business activities, including enquiries, quotations, client administration, billing, security, service management and operation of SiteForge.ie.
For some client services, such as managed hosting, website maintenance, email hosting, cloud storage, backups, website analytics or technical support, SiteForge may process personal data on behalf of a client. In those circumstances, the client will normally be the data controller and SiteForge will act as a data processor. Such processing is governed by our Data Processing Agreement ("DPA") and the client's documented instructions.
3. Personal Data We Collect
3.1 Contact and identity data
- Name and surname.
- Email address and telephone number.
- Business or organisation name, role and business contact details.
- Postal or billing address where required.
3.2 Enquiry, project and service data
- Information submitted through contact, quote, support and onboarding forms.
- Project requirements, business information, website content, files, images and materials supplied by you.
- Communications, approvals, change requests, support tickets and service history.
- Website, domain, hosting, mailbox and technical configuration details.
3.3 Account and authentication data
- Client account identifiers and account settings.
- Authentication and security information, such as login events, password-reset records and 2FA status.
- Access logs and records needed to operate and secure myAccount, myPanel, myCloud, myWebmail and related services.
3.4 Billing and transaction data
- Orders, invoices, payment status, renewal dates and transaction references.
- Billing information required for accounting and tax records.
- Full payment-card details are normally processed directly by the relevant payment provider and are not intended to be stored by SiteForge.
3.5 Technical, security and usage data
- IP address, browser type, device type, operating system and approximate location derived from IP.
- Pages viewed, referrer, timestamps, interaction events and performance information.
- Server, firewall, anti-abuse, login, email and security logs.
- Information used to diagnose errors, investigate abuse and protect our systems and customers.
3.6 Analytics and session interaction data
Where analytics or behaviour-measurement tools are enabled, we may process page views, traffic sources, campaign parameters, click and scroll activity, entry and exit paths, device/browser information, performance data, heatmaps and session-replay information. Where required by law, non-essential tracking is activated only after valid consent.
We do not intentionally use session-recording tools to capture passwords, full payment-card details or other sensitive form fields. Fields are masked or excluded where the relevant technology supports this.
3.7 Live chat and AI-assisted support
SiteForge may use live-chat and AI-assisted support tools. Messages you send may be processed by the relevant chat or AI service provider in order to generate or assist with a response. Do not submit passwords, payment-card details, special-category personal data or other information that is not necessary for your support request.
4. How We Obtain Personal Data
We obtain personal data:
- Directly from you when you contact us, place an order, create an account or use a service.
- From a client or authorised representative when they provide information needed for a project or service.
- Automatically through website, server, security and analytics technologies.
- From payment providers, domain registrars, hosting or technology providers where this is necessary to administer a service or transaction.
- From publicly available business sources where reasonably necessary to respond to or verify a business enquiry.
5. Purposes and Lawful Bases for Processing
5.1 Enquiries, quotations and pre-contract steps
Purpose: To respond to enquiries, assess projects, prepare quotations and take steps requested before entering a contract.
Lawful basis: Article 6(1)(b) GDPR and, where appropriate, Article 6(1)(f) GDPR.
5.2 Providing contracted services
Purpose: To deliver websites, ecommerce systems, hosting, domains, email, maintenance, support, SEO, analytics, design and related services.
Lawful basis: Article 6(1)(b) GDPR.
5.3 Accounts, billing and payments
Purpose: To administer accounts, orders, invoices, payments, renewals and accounting records.
Lawful basis: Article 6(1)(b) GDPR, Article 6(1)(c) GDPR and, where appropriate, Article 6(1)(f) GDPR.
5.4 Security, fraud prevention and service integrity
Purpose: To protect websites, accounts, networks and infrastructure, prevent abuse, investigate incidents, enforce service rules and maintain reliable services.
Lawful basis: Article 6(1)(f) GDPR and, where a legal obligation applies, Article 6(1)(c) GDPR.
5.5 Service communications
Purpose: To send essential operational messages such as service notices, renewal reminders, security alerts, support replies and project communications.
Lawful basis: Article 6(1)(b) GDPR and/or Article 6(1)(f) GDPR.
5.6 Analytics and improvement
Purpose: To understand how SiteForge.ie and our services are used, diagnose performance problems and improve usability, security and marketing effectiveness.
Lawful basis: Article 6(1)(a) GDPR where consent is required; otherwise Article 6(1)(f) GDPR only where the relevant processing can lawfully rely on legitimate interests.
5.7 Marketing
Purpose: To send marketing communications where you have requested them or where another lawful basis clearly applies.
Lawful basis: Article 6(1)(a) GDPR or another lawful basis permitted by applicable law.
5.8 Legal, regulatory and dispute matters
Purpose: To comply with tax, accounting, legal and regulatory obligations and to establish, exercise or defend legal claims.
Lawful basis: Article 6(1)(c) GDPR and/or Article 6(1)(f) GDPR.
6. Legitimate Interests
Where we rely on legitimate interests, those interests may include operating and improving our business, securing our infrastructure, preventing fraud and abuse, maintaining service records, managing business relationships, protecting legal rights and responding to ordinary business enquiries. We consider whether those interests are necessary and balanced against the rights and interests of the affected individual.
7. Payments
Payments may be processed by third-party payment providers such as Stripe or PayPal. Those providers may process payment and anti-fraud information under their own privacy terms. SiteForge receives transaction status and reference information needed to administer your purchase, but we do not intend to receive or store your full card number or card security code.
8. Hosting, Domains, Email, Cloud and Client Website Data
When you use SiteForge hosting, email, cloud, backup, analytics or maintenance services, our systems may contain personal data belonging to your own customers, staff, website visitors or other users. Where we process that information only on your behalf, you are responsible for determining the lawful basis, providing required privacy information, responding to data-subject requests and giving SiteForge lawful documented instructions. SiteForge's processor obligations are set out in the DPA.
Domain registration and management may require registrant information to be shared with the applicable registrar, registry or other domain-service provider where necessary to register, maintain, transfer or renew a domain.
10. Recipients and Service Providers
We share personal data only where reasonably necessary. Depending on the service, recipients may include:
- Hosting, server, backup, cloud and infrastructure providers.
- Content-delivery, DNS, anti-DDoS, firewall and security providers, including Cloudflare where enabled.
- Payment providers such as Stripe and PayPal.
- Account, invoicing and service-management platforms used to administer SiteForge services.
- Consent-management providers such as CookieYes.
- Analytics providers such as Google Analytics and Microsoft Clarity where enabled.
- Live-chat, communication and AI-assistance providers where enabled.
- Email delivery and mailbox infrastructure providers.
- Domain registrars and registries.
- Contractors and specialist freelancers who need access to information to perform work for SiteForge, subject to appropriate confidentiality and data-protection obligations.
- Professional advisers, insurers, accountants, legal advisers and public authorities where legally necessary.
We do not sell personal data.
11. International Transfers
We aim to use European Economic Area ("EEA") infrastructure where practical. Some third-party providers may process or make personal data accessible outside the EEA. Where Chapter V GDPR applies, we use an appropriate transfer mechanism, such as an applicable European Commission adequacy decision, Standard Contractual Clauses or another lawful safeguard, together with supplementary measures where required.
12. Data Retention
We keep personal data only for as long as necessary for the purpose for which it was collected, including legal, accounting, security and dispute-resolution requirements. Our normal retention approach is:
- Enquiries that do not become a client relationship: normally up to 24 months after the last meaningful contact, unless a shorter period is appropriate or a legal reason requires longer retention.
- Client, project, support and contractual records: for the duration of the relationship and normally for up to 6 years afterwards where needed for tax, accounting or legal-claims purposes.
- Invoices, transaction and accounting records: normally at least 6 years where required by Irish tax and accounting rules.
- Security and technical logs: for the period reasonably necessary for security, troubleshooting, abuse prevention and incident investigation; longer where a specific incident or legal requirement justifies it.
- Hosted client content, mailboxes, cloud files and backups: for the active service period and then deleted or returned in accordance with the service termination process, subject to normal backup-rotation cycles and any legal retention requirement.
- Consent records: for as long as reasonably necessary to demonstrate the consent status and comply with legal accountability obligations.
13. Security
We use technical and organisational measures appropriate to the nature and risk of the processing. Measures may include TLS encryption in transit, access controls, strong authentication and 2FA where supported, firewall and anti-abuse protections, backups, monitoring, logging, malware protection, software updates, least-privilege access and incident-response procedures.
No online system can be guaranteed to be completely secure. If we become aware of a personal-data breach, we will assess it and take the notification and mitigation steps required by applicable data-protection law.
14. Your Data Protection Rights
Subject to the conditions and exceptions in applicable law, you may have the right to:
- Request access to your personal data.
- Request correction of inaccurate or incomplete personal data.
- Request erasure of personal data.
- Request restriction of processing.
- Object to processing based on legitimate interests.
- Object to direct marketing at any time.
- Receive certain personal data in a portable format.
- Withdraw consent at any time where processing is based on consent, without affecting prior lawful processing.
- Lodge a complaint with the Irish Data Protection Commission or another competent supervisory authority.
To exercise a right, email [email protected]. We may need to verify your identity before acting on a request. We normally respond within the timeframe required by GDPR.
15. Complaints
You may complain to the Irish Data Protection Commission ("DPC") if you believe your personal data has been processed unlawfully. You can find current contact and complaint information on the DPC's official website: dataprotection.ie.
We would appreciate the opportunity to address a concern directly first, but contacting us is not a condition of your right to complain to a supervisory authority.
16. Children
SiteForge services are directed primarily to businesses and adults. We do not intentionally collect personal data directly from children for the purpose of creating ordinary SiteForge client accounts or purchasing business services. If a client website processes children's data, the client remains responsible for determining the appropriate legal basis and safeguards, while SiteForge will process data in accordance with the DPA and documented instructions where acting as processor.
17. Third-Party Websites and Services
SiteForge.ie may link to third-party websites or services. Their processing of personal data is governed by their own privacy information. We are not responsible for the privacy practices of independent third parties.
18. Changes to This Privacy Policy
We may update this Privacy Policy when our services, processing activities or legal obligations change. The current version and its last-updated date will be published on this page. Where a change materially affects how existing personal data is processed, we will provide additional notice where required by law.
19. Contact
Privacy questions and data-protection requests should be sent to [email protected].