Privacy Policy
EU General Data Protection Regulation (GDPR)
Irish Data Protection Act 2018
ePrivacy Directive (as implemented in Ireland)
Business name and trading name
Primary contact name and role
Business address and service areas
Phone number (mobile)
Email address
Business registration number (if applicable)
VAT number (if applicable)
Trade/industry type (plumber, electrician, etc.)
Services offered
Service areas covered
Business hours
Company description and branding materials
Business logo and photos
Website content you provide
Payment is processed through Stripe (www.stripe.com)
We do NOT store credit card details on our servers
We store: billing name, billing address, payment history, invoice records
Stripe processes and securely stores all card information per PCI-DSS standards
Name
Phone number (mobile)
Email address
Service requested
Message/inquiry details
Preferred contact time
Source of inquiry (website form, chat, phone call)
WhatsApp message history
Email correspondence
Call logs (missed calls, connected calls)
AI chatbot conversation transcripts
Customer satisfaction ratings
Google reviews (public)
Private feedback submissions
Testimonials
IP address
Browser type and version
Device type (mobile, desktop, tablet)
Operating system
Pages visited and time spent
Click behavior and navigation paths
Referral source
Geographic location (country/city level)
Session management (keeping you logged in)
Analytics and performance monitoring
Remembering your preferences
We do not collect precise real-time geolocation data
We do not collect sensitive personal data (health, religion, political views, etc.) unless you voluntarily provide it
We do not record phone calls without consent
We do not monitor or track activity outside our Services
Set up and configure your System Setter account
Build and host your multi-page website
Configure AI chatbot, WhatsApp integration, and CRM
Provide technical support and troubleshooting
Process your subscription payments
Send service updates and system notifications
Communicate with you about your account
Respond to your inquiries and support requests
Provide training and onboarding
Send renewal reminders and billing notices
Analye usage patterns to improve our Services
Develop new features and functionality
Conduct internal testing and quality assurance
Comply with Irish and EU legal obligations
Respond to lawful requests from authorities
Enforce our Terms of Service
Protect against fraud and abuse
Performance of contract (providing Services you've subscribed to)
Legitimate interests (improving Services, fraud prevention)
Legal obligation (tax records, responding to authorities)
Consent (where explicitly obtained, e.g., marketing communications)
Store leads in your CRM
Send automated WhatsApp messages
Facilitate communication via email and WhatsApp
Generate and distribute review requests
Track lead pipeline stages
Execute repeat business campaigns
Use your customer data for our own purposes
Share your customer data with third parties (except as outlined in Section 4)
Make decisions about your customers without your instruction
Have a lawful basis to collect and process customer data
Provide customers with your own privacy notice
Obtain consent where required (e.g., marketing communications)
Handle subject access requests from your customers
Report data breaches involving your customer data
Ensure compliance with GDPR for your customer relationships
Platform provider for CRM, websites, automation
Servers located in USA (GDPR-compliant with Standard Contractual Clauses)
Privacy policy: https://www.gohighlevel.com/privacy-policy
Payment processing
We do not store card details; Stripe handles all payment data
Privacy policy: https://stripe.com/privacy
WhatsApp messaging integration
Processes message content and phone numbers
Privacy policy: https://www.whatsapp.com/legal/privacy-policy
Google Analytics (website analytics)
Google Business Profile (review management and local SEO)
Google Cloud (some data storage)
Privacy policy: https://policies.google.com/privacy
Third-party service for directory submissions (60+ platforms)
Shares: business name, address, phone, website URL
No end customer data shared
Are contractually bound to protect your data
Process data only per our instructions
Comply with GDPR requirements
Use appropriate technical and organizational security measures
Required by Irish or EU law
Responding to valid legal process (court order, warrant, subpoena)
Investigating fraud, security threats, or illegal activity
Protecting our rights, property, or safety
Protecting the rights, property, or safety of our users
Sell your personal data to third parties
Rent your data to marketers or advertisers
Use your business name or logo in our marketing without your express consent
Share your customer data with other System Setter clients
Provide your data to competitors
Standard Contractual Clauses (SCCs) approved by the European Commission
Verification that the recipient has adequate data protection measures
Data Processing Agreements with all sub-processors
Encryption in transit (TLS/SSL) and at rest
Secure authentication and access controls
Regular security audits and vulnerability testing
Automated backup systems
Firewall and intrusion detection systems
Secure API connections
Access to data is restricted to authorized personnel only
Staff are trained on data protection obligations
Confidentiality agreements with all personnel
Incident response procedures
Regular review of security practices
Keep your login credentials confidential
Use strong, unique passwords
Log out after using shared devices
Notify us immediately of suspected unauthorized access
Ensure your team members only access data they need
Retained for the duration of your subscription plus 12 months after cancellation
Necessary for: contract performance, support, legal compliance, dispute resolution
Retained for 6 years after your last payment (Irish tax law requirement)
Retained for 3 years for quality assurance and dispute resolution
Retained in your CRM for as long as your account is active
YOU control retention - you can delete leads anytime via the CRM
If you cancel your System Setter subscription, your customer data is deleted within 30 days
You can export your data before cancellation
Backups may retain data for up to 90 days for disaster recovery purposes, then permanently deleted
It's no longer necessary for the purpose collected
You withdraw consent (where consent was the legal basis)
You object to processing and there are no overriding legitimate grounds
The data was unlawfully processed
Required for legal compliance
Email: [email protected]
WhatsApp: 00353 87 185 8207
The tradesperson/business is the Data Controller of your information
System Setter is the Data Processor acting on their behalf
To exercise your rights or make inquiries about your data, contact the business directly
If the business cannot resolve your concern, you may contact us at [email protected] and we will assist
Their own privacy notice
Information about how they use your data
Your rights regarding your data
How to contact them with privacy concerns
We may send you service updates, product announcements, tips, and promotional offers
You can opt out anytime by clicking "unsubscribe" in any email or contacting us
Opt-out does not apply to essential service communications (billing, security alerts, system updates)
Marketing communications sent via our system (WhatsApp, email) are controlled by our business clients
To opt out of their marketing, contact the business directly or reply "STOP" to their messages
We provide unsubscribe mechanisms in all automated campaigns
Session cookies (keep you logged in)
Authentication tokens
Load balancing
Google Analytics (website traffic, user behavior)
GoHighLevel analytics (system usage, feature adoption)
Browser settings: Most browsers allow you to refuse or delete cookies
Opt-out links: Google Analytics: https://tools.google.com/dlpage/gaoptout General opt-out: https://www.youronlinechoices.eu/
Notify the Irish DPC within 72 hours
Notify affected individuals without undue delay
Provide details: nature of breach, data affected, likely consequences, measures taken
If you become aware of a breach involving your customer data through our system, notify us immediately
You must also notify the DPC and affected individuals per GDPR Article 33-34
Our Services
Legal requirements
Industry best practices
Material changes: Email notification to your registered address + prominent website notice 30 days before changes take effect
Minor changes: Updated "Last Updated" date at top of policy
Your continued use after changes constitute acceptance
If you disagree with changes, you may cancel your account before they take effect
We will facilitate data export upon request
Your Role: Data Controller
Our Role: Data Processor
Your Instructions: Via system settings, CRM actions, and support requests
Our Obligations: Process data only per your instructions, implement security measures, assist with GDPR compliance, notify you of breaches
Sub-Processors: We may use approved sub-processors (listed in Section 4.1)
Audits: You may request audit information to verify compliance
Our interests are legitimate (operating a business, improving Services, preventing fraud)
Processing is necessary to achieve those interests
Your interests and rights do not override our legitimate interests
We've implemented safeguards to protect your data