Effective portal legal notice
Privacy notice
1. Controller and contact
Frank O Reilly T/A PROFE is the data controller for personal data processed through Plean Ahead for PROFE's own business and professional purposes. Business address: Spiddal Main Street, Ireland. Privacy questions and rights requests: eoin.profe.eng@gmail.com.
A Client or another project participant may separately be a controller for information it supplies or instructs PROFE to process. The parties' roles depend on the engagement and actual processing. Where required, those roles will be addressed in the professional appointment or a separate data-processing arrangement.
2. Scope and information we process
This notice applies to invited portal users and people whose information is included in a Project Record. Depending on role and project, we process:
- Identity and contact details, organisation or household, role and Client reference.
- Invitation, authentication, multi-factor, session, account-recovery and access records. PROFE does not intend to store or view plain-text passwords.
- Project details, locations, stages, target dates, updates and assigned people.
- Drawings, CAD files, PDFs, photographs, reports, revisions, captions and release records.
- Messages, questions, replies, support correspondence and notification preferences.
- IP address, browser or device information, timestamps, audit actions, security events and email delivery records.
- Terms and privacy acknowledgements, any consent genuinely relied upon, rights requests, restrictions and legal holds.
3. Where information comes from
We receive information directly from users; from the Client, household, employer or representative requesting access; from authorised PROFE personnel and other authorised project participants; from uploaded files and messages; from the portal's hosting, authentication, email and security systems; and, where lawful and necessary, from professional advisers, insurers, authorities or public records relevant to the engagement.
If we obtain your information from someone else, we will provide the information required by law within the applicable period unless an exemption applies or you already have it.
4. Purposes and lawful bases
We process account, contact and project information to take requested pre-contract steps, perform and administer the engagement, provide secure project communication, and manage access. We rely on contract where processing is necessary for an agreement with the individual and on our legitimate interests in delivering services, organising project records and communicating securely where contract is not the appropriate basis.
We process authentication, permissions, audit information, file-security results, misuse prevention and incident records for our legitimate interests in protecting users, confidential information and systems, and to meet legal obligations where applicable. We process complaints, regulatory enquiries, rights requests, insurance matters and legal claims to comply with law and to establish, exercise or defend legal claims.
Where we rely on legitimate interests, we assess the necessity of the processing and balance it against the individual's rights. Consent is used only where appropriate; it will be specific, recorded and withdrawable without affecting earlier lawful processing.
5. Required information and consequences
Identity, contact, authority, security and relevant project information are generally required to create and protect an account and to provide project access. If required information is not provided, we may be unable to issue or maintain access or perform the relevant part of the service. Optional fields will be identified where practical.
6. Sensitive information
The portal is not intended for unnecessary health, biometric, criminal-offence, financial-credential or other special-category data. Do not upload such information unless PROFE has confirmed that it is necessary for the engagement and that an appropriate Article 9 condition or other legal basis, access model and retention rule apply. Unexpected sensitive information may be restricted, redacted or deleted where lawful.
7. Recipients and processors
Information is disclosed only where reasonably necessary to authorised PROFE personnel, authorised users assigned to the project, relevant professional advisers and insurers, contracted IT or security support, and public authorities or courts where required or permitted by law.
Service providers currently include Supabase for authentication, database and private file storage; OpenAI Sites and its infrastructure providers for portal hosting; Resend for transactional email; and Cloudmersive for malware scanning of uploaded files. Providers may use approved subprocessors. They are required to act under appropriate terms, apply security measures and handle data only for the relevant service. We do not sell portal personal data or use it for unrelated advertising.
8. International transfers
The primary database is configured in the European Union. Some providers or subprocessors may process limited information outside the European Economic Area. Where Chapter V of the GDPR applies, we use an adequacy decision, approved standard contractual clauses with any required supplementary measures, or another lawful transfer mechanism. Information about the applicable safeguard may be requested from the privacy contact.
9. Retention
We keep personal data only for as long as reasonably necessary for the purpose collected, taking account of contractual, professional, insurance, security and legal requirements. The current operational schedule is:
- Unaccepted invitations: deleted 30 days after expiry.
- Portal accounts: disabled when access ends; the core profile is deleted or anonymised after 90 days unless linked to a retained project, security, acceptance or legal record.
- Project details, files, drawings, site photographs, messages and updates: while active and ordinarily for 7 years after formal project closure; up to 12 years where the engagement is executed as a deed or where a longer professional, insurance or legal period applies.
- Login, access and security logs: ordinarily 24 months after the event.
- Terms, privacy and consent evidence: ordinarily 7 years after account closure or the last relevant reliance.
- Rolling service backups: ordinarily overwritten within 35 days, subject to provider disaster-recovery processes.
10. Legal holds and deletion
A complaint, incident, regulatory enquiry, insurance matter, anticipated claim or legal hold may suspend ordinary deletion for the affected information until the matter is formally closed. We may retain a limited record of a rights request or deletion decision where necessary to demonstrate compliance. Retention periods are reviewed and data is deleted or anonymised when no longer required.
11. Security and personal-data incidents
Measures include individual authentication, mandatory owner multi-factor authentication, server-side role and project checks, database-level tenant isolation, private storage, short-lived authorised download links, controlled client release, audit logging, malware quarantine and account revocation. Provider communications are encrypted in transit. No system is completely secure.
Suspected compromise or accidental disclosure should be reported promptly to eoin.profe.eng@gmail.com. We assess and document personal-data breaches and notify the Data Protection Commission and affected people where the GDPR requires it.
12. Your data-protection rights
Subject to applicable conditions and exemptions, you may request access to your personal data, correction, erasure, restriction, or portability where applicable; object to processing based on legitimate interests; and withdraw consent where consent is the lawful basis. You also have rights concerning solely automated decisions with legal or similarly significant effects.
Send a request to eoin.profe.eng@gmail.com. We may need to verify identity and authority. We normally respond within one month; the GDPR permits an extension of up to two further months for a complex request or multiple requests, and we will explain any extension within the first month.
You may complain to the Irish Data Protection Commission at https://www.dataprotection.ie/ or to another competent supervisory authority. We would appreciate the opportunity to address your concern first, but contacting us is not a condition of making a complaint.
13. Cookies, local storage and email
The portal uses authentication cookies or similar storage that is strictly necessary to sign users in, maintain secure sessions, prevent misuse and remember essential security state. It does not currently use advertising cookies or unrelated behavioural analytics. If optional analytics or marketing technologies are introduced, the notice and consent controls will be updated before use where required.
Transactional emails may include invitations, account recovery, security and project notifications. Delivery and interaction records are used only to provide, secure and troubleshoot those communications.
14. Automated processing and children
The portal does not make decisions that produce legal or similarly significant effects solely by automated means. Automated security and malware controls may quarantine a file or restrict suspicious activity pending human review.
The portal is not intended for independent use by anyone under 18. Where a project concerns a child or represented person, portal access should be held by an authorised adult or representative and only necessary information should be included.
15. Changes to this notice
This notice is identified by version and effective date. Material changes will be brought to users' attention and, where appropriate, a fresh acknowledgement will be requested. Previous versions and acceptance records may be retained where necessary to demonstrate compliance.
