Privacy Policy

    How we protect and process your personal data in compliance with GDPR

    Last updated: July 24th, 2025

    1. Introduction

    This Privacy Policy explains how BL Digital Studio ("we", "us", "our") collects, uses, and protects your personal information when you use our website and services. We specialize in providing website design, hosting, maintenance, and compliance services specifically for Irish solicitors, barristers, and legal professionals.

    We are committed to protecting your privacy and maintaining the highest standards of data protection, particularly given our work with legal professionals who handle sensitive client information. We fully comply with the General Data Protection Regulation (GDPR), Irish Data Protection Act 2018, and all applicable data protection laws.

    Data Controller: BL Digital Studio is the data controller for all personal information collected through our website and services.

    2. Information We Collect

    2.1 Information You Provide Directly

    • Contact Information: Name, email address, phone number, practice address
    • Professional Details: Law firm name, practice areas, professional registration details (when relevant to compliance services)
    • Service Inquiries: Details about your website requirements, compliance needs, hosting preferences
    • Website Audit Information: Current website URL, compliance concerns, technical requirements
    • Booking Information: Consultation preferences, availability, specific service requests
    • Payment Information: Billing details (processed securely through third-party payment processors)

    2.2 Information Collected Automatically

    • Technical Data: IP address, browser type and version, operating system, device information
    • Usage Data: Pages visited, time spent on pages, referral sources, navigation patterns
    • Performance Data: Website loading times, error reports, technical diagnostics
    • Security Data: Login attempts, security events, access logs (for hosted websites)

    2.3 Client Website Data (For Hosting & Maintenance Services)

    • Website Content: Text, images, documents uploaded to hosted websites
    • Form Submissions: Contact forms, consultation requests submitted through client websites
    • Analytics Data: Website traffic patterns, user behavior on client websites (when analytics are enabled)
    • Backup Data: Regular backups of website content and databases for security purposes

    3. How We Use Your Information

    3.1 Service Delivery

    • Providing website design, development, and hosting services
    • Conducting website compliance audits and assessments
    • Performing ongoing website maintenance and technical support
    • Monitoring website performance and security
    • Processing payments and managing billing

    3.2 Communication and Support

    • Responding to your inquiries and consultation requests
    • Scheduling appointments and consultations
    • Providing technical support and troubleshooting
    • Sending service updates and security notifications
    • Sharing relevant legal compliance updates and guidance

    3.3 Business Operations

    • Improving our services and developing new offerings
    • Conducting internal analytics and research
    • Ensuring compliance with LSRA, GDPR, and accessibility standards
    • Managing our business relationships and contracts
    • Protecting against fraud and security threats

    5. Data Sharing and Third-Party Services

    We do not sell your personal information to third parties. We may share your information only in specific circumstances with trusted service providers:

    5.1 Essential Service Providers

    • Web Hosting Services: Secure Irish and EU-based hosting providers for website infrastructure
    • Payment Processors: Stripe and other PCI-compliant payment providers for billing
    • Email Services: Professional email providers for communication and support
    • Backup Services: Secure cloud backup providers for data protection
    • SSL Certificate Providers: For website security and encryption

    5.2 Analytics and Improvement (With Consent)

    • Website Analytics: Google Analytics (when consent is given) for understanding website usage
    • Performance Monitoring: Technical monitoring tools to ensure website uptime and performance

    5.3 Legal and Compliance

    • When required by law or court order
    • To protect our rights, property, or safety
    • In connection with legal proceedings or regulatory investigations
    • With your explicit consent for specific purposes

    6. Cookies and Tracking Technologies

    We use cookies and similar technologies to enhance your browsing experience and provide our services effectively. Our cookie banner allows you to control your preferences.

    6.1 Cookie Categories

    Essential Cookies (Always Active)

    Necessary for website functionality, security, and providing requested services. These include session cookies, security tokens, and preference settings.

    Analytics Cookies (Optional)

    Help us understand how visitors use our website to improve user experience. Includes Google Analytics and performance monitoring cookies.

    Functionality Cookies (Optional)

    Remember your preferences and settings to provide enhanced functionality, such as contact form auto-fill and accessibility settings.

    Marketing Cookies (Optional)

    Track visits across websites to provide relevant content and measure advertising effectiveness. Currently limited to LinkedIn and professional networking platforms.

    You can manage your cookie preferences at any time using our cookie preference center or through your browser settings. Disabling certain cookies may affect website functionality.

    7. Data Retention

    We retain your personal information only for as long as necessary to fulfill our service obligations and comply with legal requirements:

    Contact Inquiries & Consultations

    Retained for 2 years from last contact to provide ongoing support and service follow-up.

    Active Client Data

    Retained for the duration of our service relationship plus 7 years for legal and tax compliance purposes.

    Website Analytics Data

    Automatically deleted after 26 months in accordance with Google Analytics data retention settings.

    Website Backups

    Maintained for 90 days for security and recovery purposes, then automatically deleted unless required for ongoing service delivery.

    Financial Records

    Retained for 7 years in compliance with Irish tax and business record requirements.

    8. Your Data Protection Rights

    Under GDPR and Irish data protection law, you have comprehensive rights regarding your personal data. We are committed to facilitating the exercise of these rights:

    Right of Access

    Request a copy of all personal data we hold about you, including how it's being processed.

    Right to Rectification

    Correct any inaccurate or incomplete personal information we hold about you.

    Right to Erasure

    Request deletion of your personal data (subject to legal retention requirements).

    Right to Data Portability

    Receive your personal data in a structured, machine-readable format.

    Right to Object

    Object to processing based on legitimate interests or for direct marketing purposes.

    Right to Restrict Processing

    Limit how we process your data in certain circumstances.

    How to Exercise Your Rights

    To exercise any of these rights, contact us at privacy@bldigitalstudio.ie or use our contact form. We will respond within 30 days.

    You also have the right to lodge a complaint with the Irish Data Protection Commission if you believe we have not handled your data appropriately.

    9. Data Security Measures

    We implement comprehensive technical and organizational security measures to protect your personal information, reflecting our expertise in legal website security:

    9.1 Technical Security

    • Encryption: All data transmission uses SSL/TLS encryption (minimum 256-bit)
    • Access Controls: Multi-factor authentication and role-based access to client data
    • Data Backup: Automated, encrypted backups with secure off-site storage
    • Infrastructure Security: Firewalls, intrusion detection, and regular security monitoring
    • Vulnerability Management: Regular security assessments and prompt patch management

    9.2 Organizational Security

    • Staff Training: Regular data protection and security awareness training
    • Access Policies: Strict need-to-know access policies for all team members
    • Incident Response: Documented procedures for handling potential data breaches
    • Vendor Management: Due diligence and contractual data protection requirements for all suppliers

    9.3 Professional Standards

    Given our specialization in serving legal professionals, we maintain security standards that recognize the sensitive nature of legal practice data, even though we do not process client-lawyer privileged communications directly.

    10. International Data Transfers

    We prioritize keeping your data within the European Economic Area (EEA) and have structured our operations accordingly:

    Primary Data Processing (Ireland/EU)

    Your personal data is primarily stored and processed on servers located in Ireland and other EU member states, ensuring full GDPR protection.

    Limited Third-Country Transfers

    Some service providers (such as analytics tools) may process data outside the EEA. All such transfers are protected by:

    • European Commission adequacy decisions
    • Standard Contractual Clauses (SCCs)
    • Certification schemes and codes of conduct
    • Your explicit consent where required

    11. Children's Privacy

    Our services are designed for legal professionals and are not directed toward children under 16 years of age. We do not knowingly collect personal information from children under 16.

    If we become aware that we have collected personal information from a child under 16, we will take immediate steps to delete such information from our systems.

    12. Policy Updates and Notifications

    We review and update this Privacy Policy regularly to ensure it remains current with our practices and applicable law. The "Last Updated" date at the top of this policy indicates when the most recent changes were made.

    How We Notify You of Changes

    • Material Changes: Email notification to all active clients and prominent website notice
    • Minor Updates: Website posting with updated date stamp
    • Legal Changes: Direct communication for any changes required by new legislation or regulations

    Continued use of our services after policy updates constitutes acceptance of the revised terms, unless the changes require explicit consent under applicable law.

    13. Contact Information and Complaints

    If you have any questions about this Privacy Policy, wish to exercise your data protection rights, or need to report a privacy concern, please contact us:

    BL Digital Studio - Data Protection Officer

    Email: privacy@bldigitalstudio.ie

    General Contact: info@bldigitalstudio.ie

    Website: www.bldigitalstudio.ie

    Response Time: We aim to respond to all privacy inquiries within 2 business days

    Regulatory Authority

    If you are not satisfied with our response to your privacy concern, you have the right to lodge a complaint with:

    Data Protection Commission (Ireland)
    Website: www.dataprotection.ie
    Phone: +353 57 868 4757
    Email: info@dataprotection.ie

    14. Additional Commitments for Legal Professionals

    Recognizing our specialization in serving Irish solicitors and barristers, we maintain additional privacy and confidentiality commitments:

    Professional Confidentiality

    We understand the importance of client confidentiality in legal practice and ensure our data handling practices support these professional obligations.

    Compliance Expertise

    Our team stays current with LSRA, Law Society, and Bar Council requirements that may affect data processing in legal websites.

    Incident Response

    In the unlikely event of a data breach, we prioritize notification to legal professionals to help them meet their own client notification obligations.

    Cookie Consent

    We use cookies to enhance your experience and analyse site traffic. Essential cookies are always active. Choose your preferences for other cookie types. Read our Cookie Policy.