How InstaIT Handles Personal Data
Last updated: 7 August 2026
This policy explains how InstaIT collects and uses personal data when you visit instait.ie, send us an enquiry, or engage with us about IT services. It is intended to provide clear information under the General Data Protection Regulation (GDPR) and applicable Irish data-protection law.
1. Who controls your personal data?
InstaIT is the controller of the personal data described in this policy. We are based in Cork, Ireland. Questions or data-protection requests can be sent to [email protected].
2. Personal data we collect
Depending on how you interact with us, we may collect:
- Contact and enquiry information: your name, email address, phone number, subject and message when you use our contact form or contact us directly.
- Business information: your organisation, role, project requirements, locations and other information you choose to provide.
- Service information: correspondence, quotations, instructions, support records, project documentation and details needed to deliver agreed IT services.
- Technical information: IP address, browser/device information, requested pages, timestamps and security events that may be recorded automatically in ordinary web-server logs.
- Administrative information: billing, transaction and supplier/customer records where relevant to a business relationship.
Please do not send passwords, access keys or other sensitive credentials through the public contact form.
3. Why we use personal data and our legal bases
- To respond to enquiries and prepare requested proposals: our legitimate interests in communicating with prospective customers and taking steps requested before a contract.
- To provide IT services and support: performance of a contract and steps necessary to deliver requested work.
- To manage customer and supplier relationships: performance of a contract and our legitimate interests in operating and improving the business.
- To maintain website and system security: our legitimate interests in preventing misuse, diagnosing faults and protecting our services.
- To keep financial and regulatory records: compliance with legal obligations.
- To send marketing communications: only where permitted by law. You may opt out at any time by contacting us or using the unsubscribe method provided.
Where we rely on legitimate interests, we consider the necessity of the processing and its effect on your rights. We do not use personal data from this website for automated decision-making or profiling that produces legal or similarly significant effects.
4. Who receives personal data?
We do not sell personal data. We may share it only where necessary with service providers that support our hosting, email, communications, professional advice, accounting, business administration or delivery of an agreed IT service. These providers may process data only for the relevant service and must protect it appropriately. We may also disclose information where required by law, to protect legal rights, or in connection with a business reorganisation.
If a customer project requires access to systems containing personal data, the responsibilities of InstaIT and the customer should be addressed in the applicable service agreement or data-processing terms.
5. International transfers
Some technology providers may process data outside the European Economic Area. Where this occurs, we will use a lawful transfer mechanism, such as an adequacy decision or approved contractual safeguards, and apply additional protections where appropriate.
6. How long we retain information
- General website enquiries are normally retained for up to 24 months after the last meaningful contact, unless they develop into a customer relationship or must be kept longer for a legal reason.
- Customer, project and support records are kept for the duration of the relationship and afterwards only for as long as reasonably needed for support, warranty, dispute and legal purposes.
- Contracts, invoices and records required for tax or accounting purposes may be retained for the applicable statutory period.
- Web-server and security logs are retained only for a limited operational period unless an event requires longer investigation or preservation.
When deciding a retention period, we consider the purpose, sensitivity, legal requirements and whether the information is needed to establish or defend legal claims.
7. Cookies and similar technologies
We use Google Analytics 4 and Microsoft Clarity to understand how visitors find and use the website, including which pages are viewed, approximate location, device and browser information, general interaction data, and aggregated behaviour such as clicks, scrolling and navigation patterns. These services may use cookies or similar technologies and may process technical identifiers such as IP address information. This information is used to measure website performance, identify usability issues and improve our services; it is not used by InstaIT to identify visitors personally.
Google and Microsoft act as our analytics service providers and process analytics information in accordance with their own privacy terms. Analytics storage is denied by default, and these analytics services are loaded only when a visitor selects “Accept analytics”. Choosing “Reject analytics” keeps them disabled.
Your choice is remembered in local browser storage so it applies across the website on that browser and device. You can withdraw or change your choice at any time using the “Cookie settings” link in the website footer. Clearing your browser data will remove the saved preference and the website will ask again.
Links to third-party websites are governed by those providers' own privacy and cookie policies.
8. Security
We use reasonable technical and organisational measures designed to protect personal data against unauthorised access, loss, alteration or disclosure. No internet or email transmission is completely secure, so confidential credentials should be exchanged only through an agreed secure method.
9. Your data-protection rights
Subject to the GDPR and any applicable restrictions, you may have the right to:
- request access to your personal data;
- ask us to correct inaccurate or incomplete data;
- request deletion or restriction of processing;
- object to processing based on legitimate interests or direct marketing;
- receive certain data in a portable format; and
- withdraw consent where processing is based on consent, without affecting earlier lawful processing.
To exercise a right, email [email protected]. We may ask for information needed to confirm your identity. You also have the right to complain to Ireland's Data Protection Commission at dataprotection.ie.
10. Children
Our website and services are intended for organisations and business users, not children. We do not knowingly collect children's personal data through the website.
11. Changes to this policy
We may update this policy when our services, website or legal obligations change. The latest version will be published on this page with a revised update date.