GOVIQ-POL-018 · v0.1 (DRAFT)

Privacy Policy

Effective
2026-05-29 (target)
Owner
Liam McDonagh, CEO & acting Data Protection Lead
Review cycle
Annual, or on material change
Contact
privacy@goviq.ie

Statutory references: GDPR (Regulation (EU) 2016/679), Data Protection Act 2018 (Ireland), ePrivacy Regulations 2011 (S.I. No. 336 of 2011).

1.Who we are

Nexum Intelligence Systems Limited is an Irish-incorporated software company providing procurement decision intelligence to organisations operating under the Irish Capital Works Management Framework (CWMF), the Office of Government Procurement (OGP) frameworks, and the Health Service Executive (HSE).

  • Registered office: to be confirmed post-incorporation (STAT-01).
  • CRO number: to be issued by STAT-01.
  • Contact: privacy@goviq.ie

For the purposes of the General Data Protection Regulation (GDPR) and the Data Protection Act 2018, Nexum Intelligence Systems Limited is the data controller for:

  • Visitors to goviq.ie
  • People who contact us via web forms, email, phone, or LinkedIn
  • People who attend our events, demos, or webinars
  • Suppliers, advisors, and contractors who provide services to us
  • Job applicants

Nexum Intelligence Systems Limited acts as a data processor on behalf of its customers (including the HSE) for personal data processed inside the GovIQ platform. That processing is governed separately by the Data Processing Agreement signed between GovIQ and each customer.

2.What personal data we collect

We collect the following categories of personal data about the people listed in section 1.

2.1 Website visitors

  • IP address (for security, abuse prevention, and aggregate analytics)
  • Browser type, operating system, device type
  • Pages viewed, time spent, referring URL
  • Approximate geographic region (country / region only)
  • Cookies and similar technologies — see section 3 and our Cookie Policy

2.2 People who contact us

  • Name, work email, work phone (if voluntarily provided)
  • Job title and organisation (if voluntarily provided)
  • The content of any message you send us
  • Email signature data, where present in email correspondence

2.3 Event and demo attendees

  • The information you provide on registration (typically name, organisation, role, email)
  • Attendance records
  • Recordings of webinars or demos (only if explicitly consented to by all attendees in advance)

2.4 Suppliers, advisors, and contractors

  • Name, contact details, business identifiers
  • Bank account details for payment
  • Contract and engagement records

2.5 Job applicants

  • The information in your application: CV, cover letter, references, interview notes
  • Any information you choose to share about reasonable accommodations during recruitment
  • For successful candidates, this transitions to employment data covered by our internal Privacy Notice for Employees

3.Cookies and similar technologies

GovIQ uses a minimal set of cookies. Specifically:

  • Strictly necessary cookies — for the website to function (no consent required by law)
  • Performance / analytics cookies — only with your consent, via the cookie banner

We do not use marketing or advertising cookies. See our full Cookie Policy for the complete list.

4.Why we collect personal data (lawful basis)

Under GDPR Article 6 we rely on one of the following lawful bases for each processing activity:

ActivityLawful basis
Website operation and securityLegitimate interest (Art. 6(1)(f)) — ensuring the security and proper functioning of our service
Aggregate website analyticsConsent (Art. 6(1)(a)) — captured via the cookie banner
Responding to your enquiryLegitimate interest (Art. 6(1)(f)) — replying to a contact you initiated
Sending you information you requested (e.g., demo follow-up, whitepaper)Consent (Art. 6(1)(a)) — you opted in
Marketing emails to existing business contacts (B2B)Legitimate interest with opt-out (S.I. No. 336 of 2011 reg. 13(5))
Event and webinar attendanceContractual necessity (Art. 6(1)(b)) or consent
Engaging suppliers and contractorsContractual necessity (Art. 6(1)(b))
Paying suppliers and contractorsLegal obligation (Art. 6(1)(c)) — Revenue / accounting
RecruitmentPre-contractual necessity (Art. 6(1)(b)) — steps prior to entering a contract; and legal obligation for record retention

5.How long we keep personal data

CategoryRetention
Website logs90 days
Cookie consent records12 months
Contact form submissions24 months from last contact, then deleted
Marketing list entriesUntil you unsubscribe, plus 30 days
Event and webinar attendance24 months
Supplier and contractor records7 years post-engagement (tax obligation)
Job applications — unsuccessful13 months (employment equality limitation)
Job applications — successfulTransitions to employment record retention

6.Who we share personal data with (sub-processors)

We do not sell personal data. We share it only with the following categories of third party, all of whom act on our behalf under contractual obligations.

6.1 Our sub-processors (data processors acting for us)

Sub-processorWhat they doLocation
Microsoft Ireland Operations LtdEmail, calendar, sign-in (Entra ID); Microsoft Graph / SharePoint only where a customer connects its own Microsoft 365 tenantEU Data Boundary (Ireland)
Convex Inc. (US parent)Managed database and serverless runtime for the GovIQ applicationAWS eu-west-1 — Dublin, Ireland
Vercel Inc. (US parent)Web application hosting (Next.js)Server functions pinned to Dublin, Ireland (dub1) from our next production deployment; until then Washington DC, US (iad1). Static assets from Vercel's global edge network
Resend, Inc. (US parent)Transactional email — recipient name and address, subject and message content; open and click tracking offAWS eu-west-1 (Amazon SES) — Dublin, Ireland
Cloudflare, Inc. (US)DNS resolution only — no customer personal dataGlobal anycast network (no EU region)
Google (Google Analytics 4)Consent-gated analytics for goviq.ie website visitors only — never customer or tenant data, and not used in the GovIQ applicationTO CONFIRM

No AI or large-language-model service processes customer data. The GovIQ product makes no AI / LLM calls, and no customer data is sent to any AI provider. Amazon Web Services acts as a sub-processor to Convex and Resend, not directly to GovIQ.

A live, dated version of this list is maintained at goviq.ie/trust (Sub-Processor Register).

6.2 Service providers

  • Our accountant — for payroll and statutory filings
  • Our solicitor — for contractual and legal advice
  • Our insurance broker — for the procurement of cover

6.3 Authorities and regulators

We may disclose personal data to comply with a legal obligation (e.g., a valid court order, Garda investigation, Data Protection Commission inquiry). We do not disclose personal data voluntarily to authorities outside formal legal process.

7.International transfers

GovIQ application data is stored in Ireland (Convex, AWS eu-west-1, Dublin). Several of our sub-processors have US parent companies, so personal data can be accessed or processed outside the European Economic Area (EEA). Where that happens, we rely on one of the following GDPR Chapter V mechanisms:

  • Adequacy decision (where the European Commission has determined the receiving country provides adequate protection)
  • Standard Contractual Clauses (SCCs) — in the Data Processing Agreements with our US-parented sub-processors (Convex, Vercel, Resend and Cloudflare)
  • Supplementary measures — encryption and access restrictions

Specific situations:

  • Vercel — server functions are pinned to Dublin (dub1) from our next production deployment; until then application requests are processed in Washington DC, US (iad1), under SCCs. Static assets are served from Vercel's global edge network.
  • Cloudflare — DNS resolution only, on Cloudflare's global anycast network (no EU region); no customer personal data.
  • AI services — none. No AI or large-language-model service processes customer data.

8.Your rights under GDPR

You have the following rights in respect of personal data we hold about you:

RightWhat it means
Access (Art. 15)Ask for a copy of the personal data we hold about you
Rectification (Art. 16)Ask us to correct inaccurate or incomplete data
Erasure (Art. 17)Ask us to delete your personal data, subject to certain exceptions (e.g., legal obligations)
Restriction (Art. 18)Ask us to limit processing while a query is resolved
Portability (Art. 20)Ask us to provide your data in a structured, machine-readable format and / or transfer it to another controller
Object (Art. 21)Object to processing based on legitimate interest, including direct marketing — for marketing, this objection is absolute
Withdraw consent (Art. 7(3))Withdraw any consent you have given; this does not affect processing already carried out
Not to be subject to automated decision-making (Art. 22)We do not currently make solely automated decisions about you that have legal or similarly significant effects

To exercise any of these rights, contact us at privacy@goviq.ie. We will respond within one month of receiving your request (extendable by two months for complex requests, with notification to you within the first month).

We may ask you to verify your identity before responding, to protect your data from unauthorised disclosure.

9.How to contact us

TopicEmail
Privacy enquiries and rights requestsprivacy@goviq.ie
Security concerns or reportssecurity@goviq.ie
General contactinfo@goviq.ie

Acting Data Protection Lead: Liam McDonagh, CEO. GovIQ does not currently require a formal Data Protection Officer under GDPR Article 37, but we may appoint one if our processing scale increases.

10.Complaints

You have the right to lodge a complaint with the Data Protection Commission (DPC):

  • Web: www.dataprotection.ie
  • Phone: +353 (0)761 104 800
  • Post: 21 Fitzwilliam Square South, Dublin 2, D02 RD28

We would prefer to address your concern directly first — please contact privacy@goviq.ie and we will take your concern seriously and respond promptly.

11.Changes to this policy

We may update this policy:

  • Annually, as part of our policy review cycle
  • When we add or change a sub-processor
  • When we change the categories of data we process or the purposes
  • On any material legal change

Any material change is reflected:

  • Here, with a new version number and effective date
  • At goviq.ie/privacy, immediately
  • For people on our marketing list, by email notification 14 days before the change takes effect (where the change affects them)

The version history of this policy is preserved in the company repository.