Privacy Policy
Last updated: 25 September 2026
OpenDoorDigital ("we", "us", "our") is committed to protecting your personal data and respecting your privacy. This Privacy Policy explains how we collect, use, store, and protect your personal data when you use our website at opendoordigital.ie or engage our services.
This policy is written in accordance with the General Data Protection Regulation (GDPR) (EU) 2016/679, the Data Protection Acts 1988–2018, and applicable Irish data protection law.
1. Who we are
OpenDoorDigital is a data controller for the purposes of GDPR. Our contact details are:
- Email: hello@opendoordigital.ie
- Website: opendoordigital.ie
2. What personal data we collect
2.1 Data you provide directly
When you request a free homepage check or purchase an audit, we collect:
- Your name
- Your email address
- Your website URL (a business URL, not personal)
- Company name (where provided)
- Any information you include in email correspondence with us
2.2 Data collected automatically
When you visit our website, we may collect standard technical information including:
- Your IP address (anonymised where possible)
- Browser type and version
- Pages visited and time spent on each page
- Referring URL
- Device type and operating system
This data is collected through our hosting provider and our analytics tool, GoatCounter, a privacy-friendly service that uses no cookies, stores no personal data, and does not track you across websites. It is used solely to understand how our website is being used so we can improve it.
2.3 Audit data
When we perform an accessibility audit, we access and crawl the publicly accessible pages of the website URL you provide. We do not collect or store personal data from the websites we audit. Our tools access only the same pages any member of the public could access in a browser, unless you ask us to audit pages behind a login (see 2.4).
2.4 Audits of pages behind a login
If you ask us to audit pages behind a login, we ask you to create a test account for us and to send its details through a secure form: the login page address, the test account's username and password, and any notes. Please do not send us a real person's login. The test account should hold test data only, because the pages we see while signed in are reviewed and screenshots of them appear in your report.
- The password is encrypted before it is stored. If encryption is not available, the form refuses to save it.
- It is used only to sign in to your site for your audit, by our audit software or by our auditor by hand. Each time the password is viewed or copied in our admin system, that is logged.
- While signed in, our software only opens pages by following links. It does not press buttons or submit forms, and it skips links that look like actions, such as sign out, delete, pay or export.
- The signed-in session is held in memory for the length of the audit and is not written to disk on our server.
- The username and password are deleted when your audit finishes, at any time on your request, and in any case after 14 days.
2.5 If we contacted you about your website
We email businesses and organisations whose websites we think we can help with. If we emailed you, this is where your details came from and what we hold:
- Where it came from: the company's entry on the public Companies Registration Office register (company name, registered address and industry code), and the business contact email address published on the company's own website.
- What we hold: the company name, website, the business email address, the town, a short note of something our automated check found on the website's homepage, and the dates we emailed. If you reply, we keep your reply.
- Who we email: businesses and organisations, at an address published for the business, about the business's website. The businesses we find ourselves come from the company register, so they are companies.
- Replies: an automated assistant may read your reply and draft or send an answer to routine questions (prices, what is included, how to order). It says so at the end of any answer it sends. Anything else is answered by a person.
- Stopping it: reply "no thanks" or "unsubscribe" and we will not email you again. To make sure of that we keep only the company name, website, email address and the fact that you opted out.
3. Why we collect your data (legal basis)
We collect and process your personal data on the following legal bases:
- Contract performance: to deliver the audit service you have requested and communicate with you about it.
- Legitimate interests: to respond to your enquiries, improve our service, and send you information directly related to services you have used (where you have not opted out). Also to contact businesses about the accessibility of their website (section 2.5); you can object at any time and we will stop.
- Legal obligation: to comply with applicable law, including tax and accounting obligations.
- Consent: where you have explicitly consented, for example to receive marketing communications.
4. How we use your data
We use your personal data to:
- Deliver your accessibility audit and the associated reports
- Communicate with you about your order or enquiry
- Send you your completed report by email
- Issue invoices and process payments
- Respond to any queries or complaints you raise
- Improve our website and services based on usage patterns
- Send you information about similar services we offer (you can opt out at any time)
5. Who we share your data with
We do not sell, rent, or trade your personal data with any third party. We may share your data with the following categories of processor where necessary to deliver our service:
- Email service providers: to deliver your report and correspondence
- Cloud infrastructure providers: to host and operate our systems (data processed within the EU where possible)
- Payment processors: where you pay by card, your payment details are handled directly by a PCI-DSS compliant payment provider and are not stored by us
- AI service providers: we use AI models (currently Anthropic's Claude) to analyse the content of the pages we audit (public pages, and the test-account pages if you order an audit behind a login), to walk through user journeys on the audited site using made-up test details, and to read and draft answers to replies to our emails, which means the text of your reply is sent to the provider. Login details are never sent to an AI provider
Where any of these processors are located outside the European Economic Area, we ensure appropriate safeguards are in place in accordance with GDPR Chapter V.
6. How long we keep your data
We retain your personal data for as long as is necessary for the purposes described in this policy:
- Customer records (name, email, order details): 7 years, in line with Irish tax law requirements
- Completed audit reports: 2 years, in case you need a copy or we are asked to demonstrate our work
- Test account login details for audits behind a login: deleted when the audit finishes, and never kept longer than 14 days
- Website enquiries that did not result in a purchase: 12 months
- Website analytics data: 26 months (anonymised)
- Businesses we contacted (section 2.5): deleted 2 years after our last contact with you. If you opted out or the email bounced: only the company name, website, email address and that fact, kept so that we never email you again
7. Your rights
Under GDPR, you have the following rights in relation to your personal data:
- Right of access: you can request a copy of the personal data we hold about you
- Right to rectification: you can ask us to correct inaccurate data
- Right to erasure: you can ask us to delete your data in certain circumstances
- Right to restrict processing: you can ask us to stop processing your data in certain circumstances
- Right to data portability: you can request your data in a machine-readable format
- Right to object: you can object to processing based on legitimate interests or for direct marketing purposes
- Right to withdraw consent: where processing is based on consent, you can withdraw it at any time
To exercise any of these rights, please email us at hello@opendoordigital.ie. We will respond within one month of receiving your request.
You also have the right to lodge a complaint with the Data Protection Commission (DPC), the Irish supervisory authority for data protection matters. Their website is www.dataprotection.ie.
8. Cookies
Our website uses only essential cookies necessary for the site to function correctly. Our analytics (GoatCounter) works without cookies, and we do not use any advertising, tracking, or analytics cookies that require your consent. If this changes, we will update this policy and obtain your consent before placing non-essential cookies.
9. Security
We take the security of your personal data seriously. We use appropriate technical and organisational measures to protect your data against unauthorised access, disclosure, alteration, or destruction. Our website is served over HTTPS and access to customer data is restricted to authorised personnel only.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Data Protection Commission within 72 hours of becoming aware of it, and will notify you directly where required by GDPR.
10. Changes to this policy
We may update this Privacy Policy from time to time. Where we make material changes, we will notify you by email (if you are an existing customer) or by posting a notice on our website. The "last updated" date at the top of this page will always reflect the most recent version.
11. Contact us
If you have any questions about this Privacy Policy or how we handle your personal data, please contact us at:
- Email: hello@opendoordigital.ie
We aim to respond to all privacy enquiries within 5 business days.