Legal
Privacy Policy
Last updated: September 2026
Bradán Accountants is committed to protecting your privacy and handling your personal data securely and in compliance with the General Data Protection Regulation (GDPR), the Irish Data Protection Act 2018, and other applicable laws.
1. Introduction and Data Controller
Bradán Accountants ("we", "our", or "us") is committed to protecting your privacy and handling your personal data securely and lawfully. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you engage with us through our website, by email, by phone, or in person.
- •Bradán Accountants
- •Suite 2, Cathedral Buildings, Middle Street, Galway, H91 ERD1, Ireland
- •Email: [email protected]
- •Phone: (091) 450 705
2. Information We Collect
We may collect and process the following categories of personal data:
Contact and Identification Data
- •Full name, address, phone number, and email address
- •Government-issued identification documents where legally required
- •Personal Public Service (PPS) number and tax identification numbers
Business and Financial Data
- •Accounting records, ledgers, and financial statements
- •Tax returns, income information, and deductions
- •Payroll information and employee details
- •Invoices, receipts, and payment details
- •Bank account information
Technical and Website Data
- •IP address, browser type, and device information
- •Pages visited and time spent on our website
- •Cookies and similar tracking technologies
Communication Data
- •Email correspondence and records
- •Phone call records and notes
- •Information you provide in queries, forms, or feedback
3. How We Use Your Information
We process your personal data for the following purposes:
- •Providing accounting, tax, payroll, bookkeeping, and company secretarial services
- •Responding to enquiries, providing quotes, and managing client relationships
- •Complying with legal and regulatory obligations, including Revenue requirements and anti-money laundering law
- •Internal administration, billing, and record-keeping
- •Improving our website and services through analytics and feedback
- •Sending marketing communications (only where you have consented)
- •Detecting and preventing fraud and protecting the security of our systems
4. Legal Basis for Processing
Under the GDPR, we only process your personal data where we have a lawful basis to do so:
Consent
- •You have given clear, informed consent (for example, marketing communications)
Contract
- •Processing is necessary to perform our contract with you or to take steps before entering a contract
Legal Obligation
- •Processing is necessary to comply with Irish and EU tax law, Revenue requirements, and anti-money laundering regulations
Legitimate Interests
- •Processing is necessary for our legitimate business interests, provided your rights do not override those interests
5. Sharing Your Data
We may share your personal data with the following categories of recipients:
Government and Tax Authorities
- •Revenue Commissioners
- •Companies Registration Office
- •Other regulatory bodies where legally required
Service Providers
- •Cloud accounting software providers (for example, Xero and Hubdoc)
- •IT service providers and hosting companies
- •Payment processors and banking partners
Professional Advisers
- •External auditors
- •Legal advisers
- •Insurance providers
We never sell your personal data to third parties.
6. International Transfers
Your personal data is primarily stored within Ireland and the European Economic Area (EEA).
- •Where we transfer data outside the EEA, we rely on European Commission adequacy decisions
- •Standard contractual clauses and equivalent safeguards are used where appropriate
- •All transfers are carried out in full compliance with the GDPR
7. Data Retention
We retain your personal data only as long as necessary to fulfil the purposes for which it was collected and to meet legal, tax, and regulatory requirements.
- •Tax records: minimum 6 years from the end of the relevant tax year
- •Accounting records: minimum 6 years (statutory requirement)
- •Company documents: minimum 10 years
- •Payroll records: minimum 3 years
- •Website analytics: up to 26 months
- •Email communications: up to 6 years after the client relationship ends
- •Marketing data: until you withdraw consent or opt out
After these periods, your data will be securely deleted or anonymised.
8. Your Data Protection Rights
Under the GDPR and the Irish Data Protection Act 2018, you have the following rights:
- •Right of access - request a copy of your personal data
- •Right of rectification - correct inaccurate or incomplete data
- •Right of erasure - request deletion of your data ("right to be forgotten")
- •Right to restriction of processing - limit how we use your data
- •Right to data portability - receive your data in a machine-readable format
- •Right to object - object to processing, including for direct marketing
- •Right to withdraw consent - withdraw consent at any time
To exercise these rights, contact [email protected]. We will respond within one month.
9. Data Security
We implement appropriate technical and organisational measures to safeguard your personal data:
- •Encryption of data in transit (SSL/TLS) and at rest
- •Secure, password-protected access to our systems
- •Regular security updates and patches
- •Firewalls and intrusion detection systems
- •Strict access controls and staff training on data protection
- •Secure backup and disaster recovery procedures
While we take all reasonable steps, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
11. Marketing Communications
We may contact you with news, updates, and information about our services, but only where you have opted in.
- •Email newsletters and service updates
- •Information about new services and industry news
- •You can unsubscribe at any time by contacting us or using the unsubscribe link
12. Children's Data
Our services are directed at businesses and adults.
We do not knowingly collect personal data from children under the age of 16. If you believe a child has provided us with personal data, please contact us and we will delete it.
13. Third-Party Links
Our website may contain links to third-party websites.
We are not responsible for the privacy practices of linked websites. Please review their privacy policies before providing any information.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time.
Updates will be posted on our website with a revised "Last updated" date. Continued use of our services after changes are posted constitutes acceptance of the updated policy.
15. Contact Us and the Data Protection Commission
If you have questions about this Privacy Policy or how we handle your personal data, please contact us:
- •Bradán Accountants
- •Suite 2, Cathedral Buildings, Middle Street, Galway, H91 ERD1, Ireland
- •Email: [email protected]
- •Phone: (091) 450 705
You also have the right to lodge a complaint with the Irish Data Protection Commission (www.dataprotection.ie).
Effective Date: September 2026. This Privacy Policy applies to all interactions with Bradán Accountants through our website and services. We remain committed to protecting your privacy and ensuring transparency in how we handle your personal data in accordance with all applicable laws and regulations.