Legal
Privacy Policy
What we collect when you contact us, why we collect it, how long we keep it, and the rights you have over it.
1. Who we are
Saaim & Co. (“we”, “us”) operates this website. We are the data controller for the personal data described in this policy, which means we decide why and how it is processed.
[Registered postal address required before publication — GDPR Article 13(1)(a).] You can reach us about anything in this policy at info@saaimco.com.
We have not appointed a Data Protection Officer, as we are not required to under Article 37 of the GDPR. Enquiries about data protection go to the address above.
2. What this policy covers
This policy covers personal data we collect through this website and through direct correspondence with us, and personal data we process in the course of providing services to our clients. It does not cover third-party websites we link to; those have their own policies.
3. The personal data we collect
Information you give us
When you complete the contact form on this site, we collect the following:
- Your name — required, so we know who we are replying to.
- Your email address — required, so we can reply.
- Your company name — optional.
- The service you are interested in — optional.
- Your message — required. Please do not include sensitive personal information in it; a project enquiry never needs any.
If you email, message or call us directly instead, we collect whatever you choose to send us in that message.
Information collected automatically
This website does not run analytics, advertising pixels or third-party tracking, and it does not set any non-essential cookies. See our Cookie Policy for detail.
Our web hosting provider keeps standard server access logs (including IP addresses) for security and troubleshooting. This is ordinary infrastructure logging, retained for a short period, and is not used to build a profile of you or to track you across sites.
4. Why we use it, and our legal basis
| What we do | Why | Legal basis (GDPR Art. 6) |
|---|---|---|
| Reply to your enquiry | You asked us to. We cannot answer a question without reading it and replying to you. | Art. 6(1)(b) — steps taken at your request before entering a contract |
| Deliver services you have engaged us for | Performing the work you are paying us for. | Art. 6(1)(b) — performance of a contract |
| Keep records of quotes, projects and correspondence | Running the business, resolving disputes, and meeting tax and accounting obligations. | Art. 6(1)(c) — legal obligation; Art. 6(1)(f) — our legitimate interest in defending claims |
| Protect the site from spam and abuse | Keeping the contact form usable and the site available. | Art. 6(1)(f) — our legitimate interest in the security of our systems |
We do not send marketing emails or newsletters. If that changes, we will ask for your consent first and every message will carry a one-click unsubscribe, as required by the ePrivacy Regulations.
We do not carry out automated decision-making or profiling that produces legal or similarly significant effects on you.
5. How long we keep it
- Enquiries that do not become projects: up to 24 months from your last contact with us, then deleted.
- Client project records: for the duration of the engagement and for 7 years afterwards, which is the retention period Irish tax and company law require for business records.
- Server access logs: as retained by our hosting provider, typically a matter of weeks.
6. Who we share it with
We do not sell your personal data, and we do not share it with third parties for their own marketing. We use a small number of service providers who process data on our behalf, under contract and only on our instructions:
- Web3Forms — processes contact form submissions and forwards them to our email inbox. Your submission passes through their service.
- Our web hosting provider — hosts this website and maintains server logs.
- Our email provider — stores the correspondence between us.
- Our accountant — receives invoicing records where required for tax compliance.
We may also disclose personal data where we are legally required to, for example in response to a valid order from a court or a regulator.
7. Transfers outside the EEA
Some of the providers above may process data outside the European Economic Area. Where that happens, the transfer is protected by an adequacy decision of the European Commission or by Standard Contractual Clauses approved under Article 46 of the GDPR. You can ask us for details of the safeguard applying to any specific transfer.
8. How we protect it
This site is served over HTTPS, so anything you submit is encrypted in transit. Access to enquiry data is limited to the people who need it to reply to you or deliver your project. No system is perfectly secure, but we take measures appropriate to the risk, as Article 32 requires.
9. Your rights
Under the GDPR and the Data Protection Act 2018 you have the right to:
- Access the personal data we hold about you, and receive a copy of it.
- Rectification — have inaccurate data corrected and incomplete data completed.
- Erasure — have your data deleted, where we have no overriding obligation to keep it.
- Restriction — have us pause processing while a dispute about accuracy or legitimate interests is resolved.
- Portability — receive data you gave us in a structured, machine-readable format.
- Object to processing based on legitimate interests, including a general right to object at any time to direct marketing.
- Withdraw consent at any time, where processing is based on consent. Withdrawal does not affect processing already carried out.
To exercise any of these, email info@saaimco.com. We will respond within one month, as required by Article 12(3). Exercising your rights is free of charge, and we will not treat you differently for doing so.
10. Complaints
If you are not satisfied with how we have handled your personal data or your request, please tell us first so we can try to put it right. You also have the right to complain to the Irish supervisory authority at any time:
Data Protection Commission
6 Pembroke Row, Dublin 2, D02 X963, Ireland
dataprotection.ie
If you are based elsewhere in the EU, you may instead complain to the supervisory authority in your own country.
11. Changes to this policy
We update this policy when what we do with data changes — for example if we introduce analytics or a new tool. The date at the top of this page shows when the current version took effect. Where a change materially affects you, we will take reasonable steps to tell you directly.