privacy

Privacy Policy

This policy explains how Plexa Solutions Limited collects, uses and protects personal data when you visit our website, contact us, or work with us as a client. We've kept it as plain as we can.

Last updated: June 2026

01Who we are

Plexa Solutions Limited ("Plexa", "we", "us") is a private limited company registered in Ireland. We are the data controller responsible for the personal data described in this policy when you visit our website or contact us directly.

When we deliver services to clients, the picture is slightly different — we typically act as a data processor on behalf of the client. We explain that separation below.

If you have any questions about this policy, contact us at hello@plexasolutions.ie.

02What data we collect, and why

When you visit the website

Our website is hosted on Netlify. Like any hosted site, Netlify automatically records basic information about visitors — IP address, browser type, pages viewed, and approximate location. We use this only to keep the site running securely and to understand basic traffic patterns.

We use Google Analytics to understand how visitors use our website — which pages are viewed, how people navigate the site, and general traffic patterns. Google Analytics only runs after you provide consent via the cookie banner shown when you first visit. It sets cookies and processes data including your IP address, which is transferred to and processed by Google in the United States under the EU-US Data Privacy Framework. You can withdraw consent at any time by clearing your browser's cookies for this site, which will show the consent banner again on your next visit. We do not use advertising or marketing trackers.

When you book a call or send us an email

If you book a call through our website, our scheduling provider (Calendly) collects your name, email address, company name, and anything you choose to write in the booking form. We use this to prepare for and hold the meeting with you.

If you email us directly, we receive whatever you write, including your email address, name, and the contents of your message. We use this to respond and, if appropriate, to follow up.

Our legal basis for processing this information is our legitimate interest in responding to genuine business enquiries, and your consent in choosing to contact us.

When you become a client

If you engage us for services, we process whatever personal data is necessary to deliver the work — typically the contact details of your team, and any data your project requires us to handle on your behalf. In that scenario you are the data controller and we are your processor, governed by a separate Data Processing Agreement we will sign with you.

03Who else processes data on our behalf

We use a small number of trusted service providers to run the business. These are our sub-processors:

Netlify
Website hosting (US-based, GDPR-compliant data processing terms in place)
Google Analytics
Website usage analytics — only runs after you give consent via our cookie banner. US-based, processed under the EU-US Data Privacy Framework
Calendly
Meeting scheduling for visitors who book a call
GoDaddy
Domain registration and email hosting
INT (engineering partner)
When you engage us for client work, our engineering partner may process project data as our sub-processor, under Standard Contractual Clauses for transfers outside the EEA

For each provider, we rely on contractual safeguards (data processing agreements and, where required, EU Standard Contractual Clauses) to ensure your data is handled to GDPR standards.

04International transfers

Some of our service providers are located outside the European Economic Area (EEA) — for example, Netlify and Calendly in the United States, and our engineering delivery partner in India.

For all such transfers, we rely on the European Commission's Standard Contractual Clauses as the legal basis. We assess each provider's safeguards and only use those that maintain protections equivalent to GDPR.

When client engagements involve transfers to our engineering partner, this is covered explicitly in the Data Processing Agreement we sign with the client.

05How long we keep your data

  • Enquiries and website contacts — up to 24 months from your last interaction, unless we become a client of yours, in which case retention follows the contract.
  • Calendly booking data — retained per Calendly's own policy and deleted from our systems within 12 months of the meeting.
  • Email correspondence — retained for the duration of any active discussion and for a reasonable period afterwards (typically 24 months) for legal, tax and reference purposes.
  • Client engagement data — retained per the relevant client contract, then deleted or returned in line with that agreement.

06Your rights

Under GDPR you have the following rights regarding your personal data:

  • Access — request a copy of the personal data we hold about you.
  • Rectification — ask us to correct anything that is inaccurate or incomplete.
  • Erasure — ask us to delete your personal data, in certain circumstances.
  • Restriction — ask us to stop processing your data while a query is resolved.
  • Objection — object to processing we carry out on the basis of legitimate interest.
  • Data portability — receive your data in a structured, machine-readable format.
  • Withdraw consent — where we rely on consent, you can withdraw it at any time.

To exercise any of these rights, email us at hello@plexasolutions.ie. We will respond within 30 days.

07Cookies

Our website uses essential cookies necessary for the site to function, plus Google Analytics cookies that only activate once you accept them via the consent banner shown on your first visit. We do not set any marketing or advertising cookies. If you decline, only essential cookies are used and no analytics data is collected about your visit.

08Security

We take reasonable technical and organisational measures to protect personal data — including encrypted transmission (HTTPS across the website), access controls on our systems, and contracts requiring our service providers to maintain equivalent standards. No system is perfectly secure, but we work to reduce risk to a level appropriate to the data involved.

09Complaints and supervisory authority

If you have a concern about how we handle your data, please contact us first at hello@plexasolutions.ie — we'd rather hear and address it than not.

You also have the right to lodge a complaint with the Irish supervisory authority, the Data Protection Commission (DPC):

Authority
Data Protection Commission

Web
www.dataprotection.ie

Address
21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland

10Changes to this policy

We may update this policy from time to time to reflect changes in how we operate or in the law. The "last updated" date at the top of this page will always show when it was last revised. Significant changes will be communicated directly to active clients.

11Contact

Controller
Plexa Solutions Limited

Email
hello@plexasolutions.ie

Registered office
45 Hawkins Wood Avenue, Greystones, Co. Wicklow, A63 X9C4, Ireland