Privacy Notice

Last Updated: 24 August 2026

Incorpro Limited (registered in Ireland, company number 654276)
Unit 2
2 Bridge Street
Athlone, Westmeath
N37 V8N7, Ireland
info@incorpro.ie

Incorpro Limited is the data controller for the personal data described in this notice. We have not appointed a Data Protection Officer; however, we have nominated a Head of Privacy who is responsible for our compliance with data protection law. You can contact our Head of Privacy by email at info@incorpro.ie or by post at the address above, marked for the attention of the Head of Privacy.

1. How we process personal data

For people who contact us through our website

We use the personal data you have provided to us to respond to your queries when you contact us. Our legal basis for this processing is our legitimate interest in responding to your enquiry, maintaining records of professional communications, and operating our professional services business. If you become a client, your personal data will become part of your file with us. If you do not become a client, we will delete your personal data 12 months after your last contact with us. Providing your contact details is not a legal requirement, but we cannot respond to your query without them.

For people who visit our website from an online advertisement

If you come to our website by clicking one of our online advertisements, the web address carries labels describing the advertisement you clicked: which campaign it was, which of the keywords we bid on matched your search, and which version of the advertisement you saw. We choose what those labels contain. On their own, they do not identify you.

We only record these labels if you accept cookies. If you do, we store them in two cookies on your device for 90 days, so that if you return later we can still tell which advertisement first brought you to us. Our legal basis for this processing is your consent. You can withdraw it at any time by opening the "Manage Cookies" link in our footer and choosing "Reject All", which deletes both cookies. Our Cookie Policy lists them individually with their purpose and duration. If you do not accept cookies, we do not store these labels.

If you submit a company-registration form, we copy the labels onto that submission, whether or not you go on to complete the purchase. This lets us see which of our advertisements bring in customers, so that we can spend our advertising budget on the ones that work. We do not use these labels to make any decision about you, to set your price, to build a profile of you, or to send you advertising. We do not store on your record the click identifier that Google and other advertising platforms attach to advertisement links.

We keep the labels on your submission for 12 months, and then delete them. Your order itself is retained separately, under the periods set out below. We do not share these labels with any third party for that party's own purposes; the IT and AI service providers listed in section 2 may process them on our behalf and on our instructions. Separately, our website uses Google Analytics, which receives the web address you arrive on and therefore these labels; our Cookie Policy explains that processing and the transfer to Google.

Everything above concerns the campaign labels. The following is different, because it involves the contact details you type into our forms.

If you accept cookies and then complete a form on our website, our advertising measurement sends some of those contact details to Google, so that Google can confirm which advertisement led to your enquiry or your order. This can include your name, email address, telephone number and address. We do not choose which fields are collected: Google's own tag detects contact details in the form itself. Google states that the details are converted into a scrambled code before they are sent. That code is not anonymous — Google compares it with details it already holds, so Google can recognise you if it holds the same details, and that comparison is how the measurement works.

Google processes these details as our processor for the measurement itself, and separately uses event data from these measurements for the general benefit of advertisers, for example to improve automated bidding and to detect invalid activity. We keep no copy of the scrambled code ourselves, as it is sent at the moment of the measurement, and Google's retention of it is governed by the Google Ads data protection terms. The contact details you gave us are retained as described elsewhere in this notice.

Our legal basis for this processing is your consent. This measurement is entirely optional: we have configured our tags so that nothing is sent unless you accept cookies, and rejecting them does not affect your order or the services we provide to you. You can withdraw your consent at any time using the "Manage Cookies" link in our footer or the cookie settings button shown on every page.

You can ask us to delete these labels from your records at any time by emailing us at info@incorpro.ie. We will action it and confirm within one month, and doing so will not affect your order or the services we provide to you. To stop us recording them in future, use the "Manage Cookies" link in our footer and choose "Reject All". If you ask us to erase your personal data, we will also instruct Google to delete the contact details we sent for advertising measurement. We cannot retrieve those details ourselves once they have been sent, and we cannot guarantee how quickly Google will act.

We also advertise on ChatGPT. That measurement works the same way in outline, but the legal position differs in one respect that affects your rights, so we set it out separately rather than folding it in above.

If you accept cookies and then place an order, our advertising measurement tells OpenAI that the order happened and what it was worth, so that OpenAI can confirm which advertisement led to it. OpenAI's own tag may also detect contact details in our forms — this can include your email address and telephone number — and send them in a scrambled form for the same purpose. As with Google, we do not choose which fields are collected, and that scrambled code is not anonymous: OpenAI compares it with details it already holds, and that comparison is how the measurement works.

OpenAI does not act as our processor for this. Under the OpenAI Ad Tools Data Processing Addendum that we have accepted, OpenAI is an independent data controller and decides its own purposes for the data we send it. The practical consequence for you is that we cannot instruct OpenAI to delete it. If you ask us to erase your personal data we will stop sending anything further about you to OpenAI — that addendum obliges us to do so — but we cannot procure deletion of what has already been sent, and we will not tell you otherwise. You can exercise your rights against OpenAI directly at privacy@openai.com.

Our legal basis for this processing is your consent, on the same terms as above: nothing is sent unless you accept cookies, this measurement is entirely optional, and rejecting cookies does not affect your order or the services we provide to you.

For people who sign up for our newsletter

We use the contact information you have provided us to send you our newsletter and other updates. Our legal basis for this processing is the consent that you provided when you signed up. Signing up is entirely voluntary. We always include an unsubscribe option in our marketing communications, so you can opt out of receiving such communications at any time by clicking the unsubscribe link included in every newsletter, or by contacting us at info@incorpro.ie — you have an absolute right to object to receiving direct marketing and we will act on any such objection immediately. We retain your contact information for as long as you remain subscribed. If you unsubscribe or object, we will stop using it for marketing; we will then delete it unless we have another lawful basis to retain it (for example, if you are also a client and we hold the data for tax, AML, or engagement-record purposes set out below).

For clients and prospective clients

We process personal data about you in order to provide our professional services, including accounts preparation, tax compliance, payroll, and company secretarial services. Our legal bases for this processing are performance of a contract, compliance with our legal obligations, and our legitimate interest in fulfilling our professional and regulatory obligations as a firm of Chartered Accountants. Providing your personal data is necessary for us to provide services to you. In many cases it is also a legal requirement — for example, the Criminal Justice (Money Laundering and Terrorist Financing) Act 2010 requires us to verify your identity and retain records before we can act for you, and the Companies Act 2014 requires the filing of certain personal data (such as director and secretary details) with the Companies Registration Office. If you do not provide the required data, we may be unable to take you on as a client or to continue providing services to you.

We retain client engagement records for the following periods, determined by the applicable statutory obligation:

  • Anti-Money Laundering / Customer Due Diligence records — 5 years from the end of the business relationship, as required by the Criminal Justice (Money Laundering and Terrorist Financing) Act 2010.
  • Tax and accounts records — 6 years from the end of the relevant tax year, as required by Revenue Ireland.
  • Payroll records — 6 years from the end of the relevant payroll period, as required by Revenue Ireland.
  • Other client engagement records — 7 years from the completion of the engagement, in line with professional indemnity and contractual limitation periods.
For people whose information we received from one of our clients

If you are an employee, contractor, customer, supplier, or family member of one of our clients, we receive and process your personal data as part of our engagement with that client. That personal data may include your name, contact information, and financial information such as salary or payments. We will only process your data in order to provide our accounting, tax, audit or other services to our client. Our legal basis for this processing is our legitimate interest in fulfilling our professional and contractual obligations to our clients, and in many cases a legal obligation (for example, payroll reporting obligations to Revenue). We retain this data in accordance with the same retention periods set out above. You were not required to provide this data to us directly — it was provided to us by our client.

2. Whom we share data with

We share your personal data with the following service providers, who process it on our behalf in delivering our services to you: ID-Pal Limited (identity verification), Google Ireland Limited (cloud infrastructure, document processing, analytics, and advertising measurement), OpenAI (document analysis and AI assistance), Anthropic (AI assistance), Anysphere, Inc. (Cursor — staff software and AI assistance), xAI (staff AI assistance via Grok / Grok Bot, as Anysphere's sub-processor), Mailgun (Sinch) (email delivery), Revolut Bank UAB (Irish Branch) (payment processing), Yapily Limited (UK) (open-banking transaction data, with your consent), Calendly (meeting scheduling), WhatsApp Ireland Ltd (client messaging), OpenAI OpCo, LLC (advertising measurement for our advertising on ChatGPT), Sentry (application error monitoring — error reports may incidentally include personal data that appears in stack traces or log context). These providers are not permitted to use this data except on our behalf, with two exceptions: Google also uses event data from our advertising measurement for its own purposes, and OpenAI receives the data we send for our ChatGPT advertising measurement as an independent controller rather than on our behalf, deciding its own purposes for it. Both are described in section 1 above. The categories of personal data shared with each provider depend on the service they deliver to us. We update this list when our service providers change. We may also share your personal data with our professional advisors (such as our solicitors, auditors and tax advisors), who are subject to rules of confidentiality, and we may be obliged to provide access to your personal data to regulators including the Data Protection Commission, the Companies Registration Office, Revenue, and our professional body Chartered Accountants Ireland.

Where you subscribe to a recurring service (such as the Nominee Company Secretary or Registered Address service), your payment card is securely stored by our payment provider, Revolut Bank UAB (Irish Branch), so that the annual renewal fee can be charged automatically. We do not store full card numbers on our own systems; we retain only a payment-provider reference to the stored card. The card is used solely to collect amounts you owe for the services you have subscribed to, and storage continues until the subscription is cancelled.

In addition, we obtain information about company directors, secretaries, shareholders and beneficial owners from independent data sources — including the Companies Registration Office, the Revenue Online Service, EU VIES (for VAT validation), and Vision-Net. These bodies act as independent data controllers in their own right; we receive data from them rather than sharing data with them.

If we received your personal data from one of our clients, then we also share your personal data with that client.

We will not share your personal data with any other third parties, unless we have a legal or professional duty to do so.

For information about the cookies we set on our website, please see our Cookie Policy.

3. Transfers of data outside the European Economic Area

Some of the providers listed above are based in the United States. OpenAI, Anthropic, Mailgun (Sinch) and Sentry are US-based; transfers of personal data to these providers are governed by the 2021 Standard Contractual Clauses approved by the European Commission. Calendly is US-based and is certified under the EU-US Data Privacy Framework; the 2021 Standard Contractual Clauses incorporated in Calendly's Data Processing Addendum act as a fallback safeguard for any transfer not covered by that certification. Anysphere, Inc. (the provider of Cursor) and xAI are US-based. Transfers of personal data to Anysphere are governed by the 2021 Standard Contractual Clauses incorporated in Anysphere's Data Processing Addendum (cursor.com/terms/dpa). xAI processes personal data as Anysphere's sub-processor when we use Grok / Grok Bot through Cursor.

Google Ireland Limited and WhatsApp Ireland Ltd are based within the EEA, and the contracting entity for our agreement is the EEA entity. Personal data is onward-transferred to the relevant US-based parent or affiliate (Google LLC for Google Analytics, Google Workspace, Google Cloud storage and Google Ads; Meta Platforms Inc. for WhatsApp Business). For Google Analytics, Google Workspace and Google Cloud storage, the onward transfer is governed by the 2021 EU Standard Contractual Clauses, which are incorporated into the Google Cloud Data Processing Addendum that we have accepted with Google Ireland Limited. For Google Ads, which we use for advertising measurement, the onward transfer is governed by the 2021 EU Standard Contractual Clauses incorporated into the Google Ads data protection terms that we have accepted with Google Ireland Limited. For WhatsApp/Meta, the onward transfer takes place under the EU-US Data Privacy Framework, with the 2021 Standard Contractual Clauses incorporated as a fallback in the underlying processor terms (the WhatsApp Business Data Processing Terms).

OpenAI is different from the providers above, because we do not contract with an EEA entity. The data we send for our ChatGPT advertising measurement goes directly to OpenAI OpCo, LLC, 1455 3rd Street, San Francisco, California 94158, United States, which is the data importer named in the OpenAI Ad Tools Data Processing Addendum that we have accepted. That transfer is governed by the standard contractual clauses incorporated into that addendum, under which we are the data exporter.

ID-Pal Limited and Revolut (Revolut Bank UAB Irish Branch) are EEA-based and personal data shared with them remains within the EEA.

Yapily Limited is based in the United Kingdom; transfers of personal data to Yapily are made on the basis of the European Commission's adequacy decision for the United Kingdom, originally adopted on 28 June 2021 and renewed in June 2025 (currently in force until June 2027).

The categories of personal data transferred to each provider are determined by the service that provider delivers to us, as described in Section 2 above. A copy of the Standard Contractual Clauses and other safeguards described above is available on request from our Head of Privacy at info@incorpro.ie.

4. Automated Decision-Making, AI Assistance, and Profiling

We do not use automated decision-making or profiling that produces legal or similarly significant effects about you. However, we provide IncorproChat, an AI-powered chatbot that draws on a knowledge base of employee-produced content to assist with general queries.

IncorproChat disclaimer

IncorproChat provides general information drawn from a knowledge base of employee-produced content. It does not constitute accounting, tax, legal, or professional advice. Responses are not always up to date, complete, or applicable to your specific situation. Consult our team before making any decisions based on IncorproChat's responses. We accept no liability for any errors, omissions, or reliance on the information provided.

Please do not share confidential, personal, or sensitive information in IncorproChat. Conversation logs may be reviewed by our staff to identify quality regressions and to inform updates to the knowledge base; our legal basis for this is our legitimate interest in maintaining the accuracy of the service. Conversation logs are retained for up to 12 months from the date of the conversation, after which they are deleted; where a conversation forms part of a client engagement record, the retention periods set out in section 1 above apply instead.

5. Your rights

You have the following rights under the GDPR in relation to your personal data. Where a particular right applies only in certain circumstances or is subject to specific conditions, we explain those conditions in the relevant entry below.

  • Right to be informed — you have the right to be told how we use your personal data, which this notice fulfils.
  • Right to access — you have the right to request a copy of the personal data that we hold about you, together with other information about our processing of that personal data.
  • Right to rectification — you have the right to request that any inaccurate data that is held about you is corrected, or if we have incomplete information you may request that we update the information such that it is complete.
  • Right to erasure — you have the right to request us to delete personal data that we hold about you. This is sometimes referred to as the right to be forgotten. Note that this right does not apply where we are required by law to retain the data (for example, tax or AML records).
  • Right to restrict processing — you have the right to request that we restrict our processing of your personal data in certain circumstances, for example while the accuracy of data is contested.
  • Right to object — you have the right to object to our processing of your personal data where we rely on legitimate interests as our legal basis. Where you object to processing for direct marketing purposes, this right is absolute — we must stop processing immediately and without any balancing assessment.
  • Right to data portability — you have the right to request us to provide you, or a third party, with a copy of your personal data in a structured, commonly used, machine-readable format, where the processing is based on consent or contract.
  • Right to withdraw consent — if we are processing personal data based on your consent, you may withdraw that consent at any time. Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal.

In order to exercise any of the rights set out above, or if you have questions or concerns about how we process your data, please contact us at info@incorpro.ie or by post at Incorpro Limited, Unit 2, 2 Bridge Street, Athlone, Westmeath, N37 V8N7, Ireland. You also have the right to lodge a complaint with the Data Protection Commission, whose contact details are as follows:

Data Protection Commission
Canal House,
Station Road,
Portarlington,
Co. Laois,
R32 AP23,
Ireland.

Telephone: +353 (0)761 104 800
Website: www.dataprotection.ie
Email: info@dataprotection.ie

Incorpro

We typically reply instantly

For guidelines on using this chat, please refer to our privacy policy.