Privacy policy
Last updated: 30 July 2026
This policy explains what personal data we collect, why we collect it, how long we keep it and what rights you have. It is written to be read rather than to be legally impenetrable. If anything here is unclear, email hello@ovlo.ie and we will explain it.
Who we are
Ovlo is the data controller for the personal data described in this policy.
Ovlo is based in Ireland and works with Irish businesses. Contact for any privacy question or request, including a request for our full registered details: hello@ovlo.ie
What we collect, and why
When you email us
This website has no contact form. There is nothing on this site that collects your details — you email us directly, and we receive whatever you choose to put in that email. Typically that is your name, company, role, email address and something about your card processing.
Why: to respond to your enquiry and, if you go ahead, to carry out and deliver your statement audit.
Lawful basis: taking steps at your request prior to entering into a contract (GDPR Article 6(1)(b)), and our legitimate interest in responding to business enquiries (Article 6(1)(f)).
How long: for two years after our last contact with you, unless you become a client, in which case for the duration of our engagement and six years afterwards to meet Irish tax and accounting record-keeping requirements. You can ask us to delete it sooner.
When you send us card processing statements
Card processing statements are commercial records of your business. They may incidentally contain personal data, such as the name of a contact at your company or a signatory on the account.
Why: solely to carry out the audit you asked for.
Lawful basis: performance of a contract or steps taken at your request prior to one (Article 6(1)(b)).
How we handle them:
- We never ask you to send statements as an email attachment. We reply with a secure upload link.
- We do not share them with any acquirer, payment service provider, terminal supplier or broker.
- We do not share them with any other third party.
- We do not use them as examples, samples or case studies, anonymised or otherwise, without your explicit written permission.
- We store them in access-controlled storage and only for as long as the audit and any resulting engagement requires.
How long: deleted once the audit is complete and delivered, unless you ask us to retain them for an ongoing engagement. Deleted on request at any time.
When you visit the website
We use Plausible Analytics, which is privacy-focused and does not use cookies. It does not collect or store personal data, does not track you across websites, and does not create a persistent identifier for you. It records aggregate information only: page views, referring site, country, and broad device type.
Lawful basis: legitimate interest in understanding how our website is used (Article 6(1)(f)). Because no personal data is processed and no cookies are set, no consent banner is required. Plausible processes and stores this data within the EU.
Cookies
This website sets no cookies.
We do not use Google Analytics, Meta pixels, advertising trackers or any other cross-site tracking technology. Because nothing is stored on your device, there is no cookie banner and nothing for you to consent to or reject.
Who else processes your data
No form processor. We deliberately do not use a third-party form service. Form services of this kind commonly store submissions in the United States without documenting the safeguards that apply to that transfer, and we were not willing to route your enquiry through one. Your email goes directly to us.
Email. Our email is hosted by a commercial email provider, which processes messages you send us in order to deliver them. We will name the provider on request.
Website hosting. The site is hosted on GitHub Pages. GitHub processes server logs including IP addresses for security and abuse prevention. We have no access to those logs.
Analytics. Plausible Analytics, processing within the EU.
We do not sell your data. We do not share it for marketing. We do not add you to a mailing list.
Your rights
Under GDPR you have the right to:
- Access the personal data we hold about you
- Correct anything inaccurate
- Erase your data, subject to any legal retention obligation
- Restrict how we process it
- Portability — receive your data in a machine-readable format
- Object to processing carried out on the basis of legitimate interest
- Withdraw consent at any time, where consent is the basis we relied on
To exercise any of these, email hello@ovlo.ie. We will respond within one month.
If you are unhappy with how we have handled your data, you can complain to the Data Protection Commission, the Irish supervisory authority, at dataprotection.ie.
Security
Statements and enquiries are held in access-controlled storage. Transfers of statements are through a secure upload link rather than email attachment. Access is limited to those who need it to carry out the work.
No system is perfectly secure, and we will not claim otherwise. If a breach occurs that is likely to result in a risk to your rights, we will notify you and the Data Protection Commission as GDPR requires.
Changes to this policy
If we change this policy we will update the date at the top. Material changes affecting how we handle statements or personal data will be notified by email to anyone with an active engagement.
Contact
Questions about this policy, or about any data we hold: hello@ovlo.ie