Your privacy at Avoura

Privacy Policy

This policy explains how Avoura collects, uses, shares, retains and protects personal data when you visit avoura.ie, contact us, request a proposal, apply for a role, or work with us. It also explains your rights under the EU General Data Protection Regulation (“GDPR”), the Irish Data Protection Act 2018, and applicable Irish ePrivacy rules.

Last updated: 22 June 2026 Applies to avoura.ie and Avoura services Privacy contact: info@avoura.ie

Privacy policy summary

Controller
Avoura Studio, trading as Avoura
77 Camden Street Lower
Dublin 2, D02 XE80, Ireland
Why we use data

To operate and secure our website, respond to enquiries, prepare proposals, deliver services, meet legal duties and improve performance.

Our commitment

We do not sell personal data. We do not use enquiry details for marketing unless there is a separate lawful basis and a clear opt-out.

Your rights

You may request access, correction, deletion, restriction or portability, and may object or withdraw consent where applicable.

01

Who controls your personal data

For the processing described in this policy, the data controller is Avoura Studio, trading as Avoura (“Avoura”, “we”, “us” or “our”), located at 77 Camden Street Lower, Dublin 2, D02 XE80, Ireland. You can contact us about privacy or exercise your rights by emailing info@avoura.ie with the subject “Data Protection Request”.

This policy applies where Avoura decides why and how personal data is used. In some client projects—for example, where we host, maintain, analyse or manage a client’s website, customer database or social media account—Avoura may instead process personal data solely on that client’s documented instructions. In that situation, the client is normally the controller, Avoura is a processor, and the client’s own privacy notice applies to the people concerned.

02

Personal data we collect

Depending on how you interact with us, we may collect the following categories of personal data.

Information you give us

  • Contact details: name, email address, telephone number, organisation, role and preferred contact method.
  • Enquiry and project details: service interest, message, business requirements, objectives, budget, timeline, meeting notes, proposal feedback and correspondence.
  • Client and supplier records: contracts, authorised contacts, project files, approvals, service history, support requests and business relationship records.
  • Billing and compliance records: billing address, invoice details, payment status, tax information and records needed to meet accounting or legal requirements. We do not ask you to send full payment-card details by a general enquiry form.
  • Recruitment data: CV, cover letter, portfolio, work history, education, professional profile, references, interview notes and information required to assess an application.
  • Marketing preferences: any separate opt-in, opt-out, unsubscribe or objection you submit.

Information collected when you use our website or forms

  • Technical and security data: IP address, browser and device information, operating system, user-agent, request date and time, pages requested, security events, form submission ID and bot-verification outcome.
  • Page and attribution data: page URL and title, first landing page, external referrer, UTM campaign parameters, and how you say you heard about Avoura.
  • Cookie and consent data: consent choices, essential session information and, only where permitted, analytics or advertising identifiers and interaction events.
  • Communications data: information contained in emails, calls, video meetings, support requests and social-media messages.

Information from other sources

We may receive business contact information from a colleague who refers you, a professional adviser, a public business website or directory, a social platform, a client or supplier, or another person involved in a project. Where Article 14 GDPR applies, we will provide any additional required information within the applicable timeframe.

Please do not send unnecessary sensitive data. General enquiry forms are not intended for health information, biometric data, political opinions, religious beliefs, trade-union membership, sexual-life information, criminal-offence data, government identifiers, passwords or payment-card numbers. If a project genuinely requires special-category or high-risk data, we will address that processing separately before it begins.

03

Why we process personal data, our legal bases and how long we keep it

We only process personal data where a lawful basis applies. The table below summarises our main processing activities. A right or retention period may vary where law requires a different outcome, a dispute is active, or information must be kept to establish, exercise or defend legal claims.

Main Avoura processing activities
Activity and purpose Typical data GDPR legal basis Typical retention
Provide and secure the website and forms
Deliver pages, prevent spam and attacks, diagnose faults and protect systems.
IP address, user-agent, request logs, security events, submission ID and bot-verification data. Legitimate interests (Art. 6(1)(f)): website availability, network security, fraud and abuse prevention. Legal obligation where applicable. Form debug logs: up to 14 days. Local rate-limit records: generally up to 24 hours. Token-replay hashes: generally up to 30 minutes. Hosting/security logs follow the provider’s documented schedule.
Respond to enquiries and prepare proposals
Understand your request, contact you, arrange meetings and take steps before a possible contract.
Name, email, phone, company, service interest, message, correspondence and relevant attribution data. Steps at your request before entering a contract (Art. 6(1)(b)); legitimate interests for ordinary B2B administration and follow-up (Art. 6(1)(f)). Normally up to 24 months after the last meaningful contact where no client relationship begins, unless a shorter period is appropriate or a longer period is needed for a claim.
Deliver projects and manage client relationships
Perform contracts, manage work, provide support, maintain records and communicate with authorised contacts.
Contact, contract, project, account, access, communication, deliverable and support data. Contract (Art. 6(1)(b)); legitimate interests in managing business relationships and service quality (Art. 6(1)(f)); legal obligation where relevant. Core contract and project records are generally retained for up to 6 years after the relationship ends, subject to legal, tax, insurance and dispute requirements.
Billing, accounting and tax compliance
Issue invoices, record payments and meet statutory obligations.
Identity, business contact, billing, invoice, payment-status and tax records. Legal obligation (Art. 6(1)(c)); contract (Art. 6(1)(b)); legitimate interests in financial administration (Art. 6(1)(f)). Usually 6 years, or longer where an audit, inquiry, appeal or legal requirement remains open.
Measure enquiry sources and improve services
Understand which pages, campaigns, search engines, AI assistants or referrals produce enquiries.
Landing page, referrer, UTM values, self-reported source, timestamp, submission ID and aggregated performance information. Legitimate interests in measuring business performance (Art. 6(1)(f)); consent (Art. 6(1)(a)) where non-essential cookies or device storage are used. Enquiry-level attribution follows the enquiry retention period. Aggregated or irreversibly anonymised statistics may be kept longer because they no longer identify a person.
Analytics, personalisation or advertising technologies
Understand website use or measure campaigns where such tools are enabled.
Consent record, online identifiers, device/browser data and interaction events. Consent (Art. 6(1)(a)) for non-essential cookies or similar technologies, together with applicable ePrivacy requirements. Until consent is withdrawn or the relevant cookie/identifier expires, as shown in the live cookie-settings panel.
Recruitment
Assess applications, conduct interviews and make hiring decisions.
Application, CV, portfolio, professional history, references and interview notes. Steps before a possible employment contract (Art. 6(1)(b)); legitimate interests in recruitment (Art. 6(1)(f)); legal obligation where applicable. Unsuccessful applications: normally 6 months after the recruitment process ends unless a vacancy notice states otherwise or you separately agree to longer retention. Successful-candidate records move to the personnel file.
Legal claims, compliance and business protection
Respond to lawful requests, enforce agreements and protect rights, safety and property.
Relevant contact, contract, transaction, communication, security and evidential records. Legal obligation (Art. 6(1)(c)); legitimate interests in establishing, exercising or defending legal rights (Art. 6(1)(f)). For as long as the legal duty, limitation period, inquiry, complaint or dispute reasonably requires.

Where we rely on legitimate interests, we consider the purpose, necessity and possible effect on individuals, and use safeguards designed to avoid disproportionate impact. You may object to processing based on legitimate interests as explained below.

04

Enquiry forms, bot protection and SEO/AEO attribution

Submitting an enquiry

Fields marked as required are needed so that we can identify your request and reply. If you do not provide the required information, we may be unable to respond or prepare a proposal. Optional information, such as a telephone number or referral source, can be left blank unless a particular form says otherwise.

The form privacy checkbox is an acknowledgement, not bundled consent. Checking it confirms that you have read this policy and understand how the enquiry will be handled. Our ordinary legal basis for replying is usually Article 6(1)(b) GDPR (steps taken at your request before a possible contract) and, where appropriate, Article 6(1)(f) (legitimate interests). It does not subscribe you to marketing.

Cloudflare Turnstile

We use Cloudflare Turnstile to distinguish genuine visitors from automated abuse and protect our forms. Turnstile may process security signals such as your IP address, TLS fingerprint, user-agent, sitekey and associated website origin. We use it because form security and abuse prevention are necessary for the safe operation of the service. Cloudflare acts as our processor when providing Turnstile website protection and as an independent controller when using limited signals to improve Turnstile’s bot-detection capabilities. Cloudflare’s specific Turnstile information is available in its Turnstile Privacy Addendum.

Lead-source and website-performance reporting

To understand how prospective clients discover Avoura, an enquiry may be associated with its landing page, external referrer, campaign parameters and the source selected by the person submitting the form. Avoura’s handler may classify the source as, for example, a search engine, AI assistant, social platform, referral or direct visit. This helps us measure website and campaign performance; it does not determine whether we respond, the service you receive or the price offered.

To support website performance, search visibility and enquiry-source reporting, we may use trusted technology, analytics, marketing and professional service partners based in Ireland, elsewhere in the EEA, or in other countries. We limit any disclosure or access to what is reasonably necessary for the relevant service and require appropriate confidentiality, security and data-protection obligations.

Where this involves a transfer of personal data outside the EEA, we use an applicable lawful transfer mechanism and safeguards as described below. You may contact us for further information about the relevant categories of recipients and safeguards.

05

Cookies and similar technologies

Cookies are small text files stored on a device. Similar technologies include local storage, session storage, pixels, tags, SDKs and scripts that read or store information on a device. We distinguish between the following categories.

  • Strictly necessary technologies: used for core page delivery, security, load balancing, consent preferences, form operation and bot prevention. These do not require consent where they are genuinely necessary to provide the service requested.
  • Preference technologies: remember optional choices or settings. We request consent where the law requires it.
  • Analytics technologies: measure visits, interactions and campaign performance. These are blocked until you opt in where they are not strictly necessary.
  • Advertising or embedded-media technologies: support campaign measurement, remarketing or third-party media. These are blocked until you opt in where required.

Where non-essential technologies are used, our cookie banner or settings panel provides the current provider, purpose, category and lifespan for each technology and offers a genuine choice before activation. Rejecting non-essential technologies is as easy as accepting them. You can withdraw or change your choice at any time through the website’s cookie settings; withdrawal does not affect processing that was lawful before withdrawal.

Attribution storage is covered too. First-touch campaign data stored in localStorage or sessionStorage is a similar technology. Avoura does not write or read that non-essential attribution data until the visitor has given the relevant consent. Current-page values may still be processed at form submission where a separate lawful basis applies and no non-essential device storage is used.

06

Who receives personal data

We disclose personal data only where necessary and proportionate. Recipients may include:

  • Website, hosting and security providers, including infrastructure, backup, monitoring and bot-protection services.
  • Email, communications and collaboration providers used to receive enquiries, arrange meetings and manage work.
  • CRM, project-management, file-storage and support providers where used for client or enquiry administration.
  • Analytics, consent and campaign-measurement providers, but only where the required consent or other lawful basis exists.
  • Trusted service providers and partners in Ireland and elsewhere, including technology, analytics, search, marketing, development and specialist support providers where necessary to operate, measure or improve our website and services.
  • Professional advisers and business service providers, such as accountants, legal advisers, insurers, payment providers and auditors.
  • Approved contractors or specialist partners involved in delivering a project, under confidentiality and data-protection obligations appropriate to their role.
  • Public authorities, regulators, courts or law-enforcement bodies where disclosure is required by law or necessary to protect legal rights, safety or security.
  • A purchaser, investor or successor organisation in connection with a genuine business reorganisation, merger or sale, subject to confidentiality and applicable law.

Where a supplier acts as our processor, we require a contract addressing Article 28 GDPR, confidentiality, security, assistance with rights and breaches, deletion or return of data, audit rights and sub-processors. Some recipients—such as professional advisers, banks, tax authorities or social platforms—may act as independent controllers for their own purposes.

Avoura does not sell personal data or provide enquiry lists to data brokers.

07

Transfers outside the European Economic Area

We use service providers and partners in Ireland and may also work with providers elsewhere in the European Economic Area (“EEA”) or in other countries. A transfer within the EEA remains subject to the GDPR framework. Where personal data is transferred to, stored in, or accessed from a country outside the EEA, we do so only where an applicable lawful transfer mechanism and appropriate safeguards are in place.

  • An adequacy decision adopted by the European Commission;
  • European Commission Standard Contractual Clauses, together with a transfer-impact assessment and supplementary safeguards where required;
  • another valid mechanism under Chapter V GDPR; or
  • an Article 49 derogation only in the limited circumstances in which the GDPR permits it.

You may request further information about the relevant transfer locations and safeguards, including how to obtain a copy of an applicable safeguard, by contacting us. We may redact confidential or commercially sensitive information where permitted, while still providing a meaningful explanation of the protection used.

08

Security, accuracy and data minimisation

We use organisational and technical measures appropriate to the nature and risk of the processing. These may include HTTPS, access controls, least-privilege permissions, password and account protections, software updates, backups, anti-bot controls, rate limiting, logging, vendor due diligence, confidentiality commitments and staff or contractor access restrictions.

No internet transmission or storage method is completely risk-free. If we become aware of a personal-data breach, we will assess it promptly, contain and remediate it, document the outcome, and notify the Data Protection Commission and affected individuals where the GDPR requires notification.

We ask you to provide accurate, relevant information and to tell us if important details change. We seek to collect only the data reasonably needed for the stated purpose, and we delete or anonymise information when it is no longer required, subject to legal obligations, dispute holds and limited backup cycles.

09

Your data protection rights

Your rights depend on the circumstances and are subject to the conditions and exemptions in applicable law.

Access

Ask whether we process your personal data and request a copy together with required information about the processing.

Rectification

Ask us to correct inaccurate data or complete information that is incomplete.

Erasure

Ask us to delete personal data where a legal ground for erasure applies.

Restriction

Ask us to limit processing in circumstances set out in Article 18 GDPR.

Data portability

Receive certain data you provided in a structured, commonly used, machine-readable format where the right applies.

Object

Object to processing based on legitimate interests. We will stop unless compelling legitimate grounds or legal claims justify continuation.

Withdraw consent

Withdraw consent at any time where consent is the basis. Withdrawal does not affect earlier lawful processing.

Object to direct marketing

Object at any time to direct marketing, including related profiling. We must stop using your data for that purpose.

How to make a request

Email info@avoura.ie and describe the right you wish to exercise. To protect personal data, we may ask for proportionate information to verify identity or authority. We normally respond without undue delay and within one month. Where a request is complex or numerous, the GDPR may allow an extension of up to two further months; if so, we will explain this within the first month. Requests are normally free, but the GDPR permits a reasonable fee or refusal where a request is manifestly unfounded or excessive.

Right to complain

Please contact us first so we have an opportunity to address the concern. You also have the right to complain to the Irish Data Protection Commission (“DPC”) or, where applicable, another EEA supervisory authority in the country where you live, work or believe an infringement occurred.

Data Protection Commission
6 Pembroke Row
Dublin 2, D02 X963, Ireland
Email: info@dataprotection.ie
Website: dataprotection.ie
10

Marketing communications

Sending a project enquiry does not automatically subscribe you to newsletters or promotional emails. Where electronic direct marketing requires consent, we use a separate, clear opt-in and keep a record of the choice. We may rely on the limited existing-customer exception only where every condition in Irish ePrivacy law is satisfied, including marketing only our own similar services and providing a simple opportunity to object when details are collected and in every message.

You may unsubscribe through the link in a marketing email or contact us at any time. After an opt-out, we may keep the minimum information needed on a suppression list so that we can respect the request and avoid sending further marketing. Service messages, proposal correspondence and replies to an enquiry are not marketing where they are limited to the requested transaction or relationship.

11

Automated decisions and profiling

Avoura does not currently make decisions based solely on automated processing that produce legal effects or similarly significant effects on website visitors, enquirers or clients. Automated security tools may assess whether a request is likely to be generated by a bot, and source-attribution logic may classify an enquiry for performance reporting. These operations do not determine eligibility for services, contractual terms or pricing. If this changes, we will provide the information and safeguards required by Articles 13, 14 and 22 GDPR before the relevant processing begins.

12

Children

Avoura’s website and business services are directed primarily to organisations and adults and are not intended for children under 16. We do not knowingly use the website to collect a child’s personal data for marketing. If you believe a child has provided personal data without appropriate authority, contact us so we can review and delete it where required. A specific project involving children will be subject to separate privacy, consent and safeguarding arrangements appropriate to that project.

13

Third-party websites, embeds and social media

Our website may link to external websites or social platforms such as LinkedIn, Instagram, Facebook, YouTube or Pinterest. Those organisations control their own processing when you visit their services, use an embedded feature or interact with an Avoura social account. Their privacy notices apply to their processing. Where an embedded video, map, social feed or similar feature is not strictly necessary and can place or read information on your device, we keep it blocked until the relevant consent is given.

A link to another website does not mean that Avoura endorses its privacy practices. Review the third party’s notice and settings before providing personal data.

14

Changes to this policy and how to contact us

We review this policy when our services, suppliers, forms, cookies or legal obligations change. The “Last updated” date at the top shows when this version was issued. Where a change materially affects how we use existing personal data, we will provide additional notice or seek consent where the law requires it.

Contact Avoura about privacy

Email: info@avoura.ie

Avoura Studio, trading as Avoura
77 Camden Street Lower
Dublin 2, D02 XE80, Ireland

Please use the subject line “Data Protection Request” so the request can be routed promptly.

↑ Back to top