Privacy notice
Last updated: 14 September 2026
This notice explains how HDT Software Limited collects and uses personal data when you visit our website, contact us or work with us, and the rights you have under the General Data Protection Regulation (EU) 2016/679 (GDPR) and the Irish Data Protection Acts 1988 to 2018.
Our principles are simple: we collect only what we need, we keep it in the European Union wherever possible, we never sell it, and we delete it when it is no longer needed.
1.Who we are
The controller responsible for your personal data is HDT Software Limited, a company registered in Ireland under number 565919, with its registered office at Building G, West Cork Technology Park, Clonakilty, County Cork, P85 VF62, Ireland.
For any question about this notice or your personal data, contact privacy@hdt-software.com.
Given the nature and scale of our processing, we are not required to appoint a Data Protection Officer under Article 37 GDPR. Our privacy contact is responsible for data protection matters.
2.Scope of this notice
This notice applies to:
- visitors to www.hdt-software.com;
- people who contact us by form, email or phone;
- contacts at our clients, prospects and partners;
- customers of our legacy product ITSM4Outlook;
- contacts at our suppliers.
It does not cover personal data we process on behalf of clients as a processor; see “When we process data on behalf of our clients” below.
3.What we process, why, and on what legal basis
The table below summarises our processing activities.
Visiting this website
- Personal data
- IP address, browser and device information, requested pages, date and time
- Purpose
- Delivering the website, keeping it secure and preventing abuse
- Legal basis (GDPR)
- Legitimate interests, Art. 6(1)(f)
- Retention
- Hosting logs kept for a limited period by Netlify
Contact form and email enquiries
- Personal data
- Name, work email, company, topic, message content, language
- Purpose
- Answering your enquiry and taking steps before a possible contract
- Legal basis (GDPR)
- Steps prior to a contract, Art. 6(1)(b); legitimate interests, Art. 6(1)(f)
- Retention
- Up to 24 months after our last exchange, unless a business relationship follows. Form submissions are deleted from Netlify within 30 days
Client and partner relationships
- Personal data
- Names, job titles, business contact details, correspondence, meeting notes, contract and project records
- Purpose
- Delivering our services and managing the relationship and projects
- Legal basis (GDPR)
- Performance of a contract, Art. 6(1)(b); legitimate interests, Art. 6(1)(f)
- Retention
- Duration of the relationship plus 6 years (Irish limitation period for contract claims)
Invoicing and accounting
- Personal data
- Billing contact details, invoices, payment records, VAT information
- Purpose
- Meeting our accounting and tax obligations
- Legal basis (GDPR)
- Legal obligation, Art. 6(1)(c)
- Retention
- 6 years from the end of the financial year concerned (Irish tax law)
ITSM4Outlook customer support
- Personal data
- Contact details, organisation, licence and version information, support correspondence
- Purpose
- Supporting existing customers of our legacy product
- Legal basis (GDPR)
- Performance of a contract, Art. 6(1)(b)
- Retention
- Duration of the support relationship plus 6 years
Suppliers
- Personal data
- Business contact details, contract and payment records
- Purpose
- Purchasing and managing the services we use
- Legal basis (GDPR)
- Performance of a contract, Art. 6(1)(b); legal obligation, Art. 6(1)(c)
- Retention
- Duration of the contract plus 6 years
Legal claims and compliance
- Personal data
- Records relevant to a dispute or a request from an authority
- Purpose
- Establishing, exercising or defending legal claims; responding to authorities
- Legal basis (GDPR)
- Legal obligation, Art. 6(1)(c); legitimate interests, Art. 6(1)(f)
- Retention
- As long as the matter requires
Where we rely on legitimate interests, we have balanced them against your rights and freedoms. You can ask us for the details of that assessment.
We do not ask for special categories of personal data (such as health data) and ask you not to send them to us. We do not carry out automated decision-making or profiling within the meaning of Article 22 GDPR.
Providing personal data is not a legal or contractual requirement, but without your contact details we cannot reply to your enquiry.
5.Who receives your data
We never sell or rent personal data. We share it only where necessary with:
- Microsoft Ireland Operations Limited, for email, document storage and collaboration (Microsoft 365) and cloud services (Microsoft Azure), acting as our processor;
- Netlify, Inc., for website hosting and processing of contact form submissions, acting as our processor;
- professional advisers such as accountants, auditors and lawyers, who are bound by confidentiality;
- public authorities, courts or regulators, where the law requires it;
- a buyer or successor of our business in the event of a merger or acquisition, subject to equivalent protection.
All processors act under written agreements that meet Article 28 GDPR. The current list is published on our data protection page.
6.International transfers
We store the data we control in the European Union, using Microsoft’s EU Data Boundary for Microsoft 365 and EU regions for Microsoft Azure. Microsoft may make limited transfers outside the EU, for example for security operations, under the EU-U.S. Data Privacy Framework and the European Commission’s Standard Contractual Clauses.
Netlify, Inc. is based in the United States, so website traffic and contact form submissions may be processed there, under the EU-U.S. Data Privacy Framework and the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914). You can ask us for a copy of the relevant safeguards.
7.How we protect your data
We apply appropriate technical and organisational measures, including:
- encryption in transit (TLS) for our website and email, and encryption at rest on the cloud services we use;
- multi-factor authentication and least-privilege access to our systems;
- confidentiality obligations for everyone who handles personal data;
- regular review of access rights, suppliers and this notice.
If a personal data breach occurs, we will notify the Data Protection Commission within 72 hours where required, and inform the people affected without undue delay when the breach is likely to result in a high risk to them.
8.Your rights
Under the GDPR you have the right to:
- access your personal data and receive a copy;
- have inaccurate data corrected;
- have your data erased;
- restrict processing;
- data portability;
- object to processing based on legitimate interests, and object at any time to direct marketing;
- withdraw consent at any time where processing is based on consent, without affecting processing carried out before withdrawal.
To exercise these rights, email privacy@hdt-software.com. We respond within one month, which may be extended by two further months for complex requests; we will tell you if that happens. Requests are free of charge. We may ask you to confirm your identity before acting on a request.
9.Complaints
If you have concerns, please contact us first so we can try to resolve them. You also have the right to lodge a complaint with a supervisory authority, in particular in the EU country where you live, work or where the alleged infringement took place. Our lead authority is the Data Protection Commission, 21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland (www.dataprotection.ie).
10.When we process data on behalf of our clients
When we deliver integration, cloud or AI projects, we may process personal data on behalf of our clients, including EU institutions, bodies, offices and agencies. In those cases the client is the controller and its own privacy notice applies. We act as its processor under Article 28 GDPR or Article 29 of Regulation (EU) 2018/1725, only on its documented instructions. If your data is processed in such a project, please address your request to the client concerned; we will help it respond.
11.Children
Our website and services are intended for businesses and are not directed at children.
12.Changes to this notice
We review this notice regularly and update it when our processing changes. The date at the top shows the latest version, and significant changes will be highlighted on this page.
