Privacy Policy

Last updated

July 23, 2026

Address

Penthouse Floor, Rivercourt HQ, River Court Business Centre, Cornmarket Row, Limerick, V94 FVH4, Ireland

Introduction

This Privacy Policy explains how Brainstorm Design, operated by David Curtin, collects, uses, stores, and shares personal information when you visit our website, contact us, or engage our design and digital services. We take privacy seriously and aim to handle your information clearly, proportionately, and lawfully.

Information you provide

Personal Information

When you contact us or work with us, we may collect personal information such as your name, email address, phone number, business name, role, billing details, and payment-related information. We use this information to communicate with you, deliver services, and manage our business relationship.

Project Information

When you contact us, we may collect information about your business, project goals, website, budget, timing, audience, and any files or materials you choose to provide. Please do not submit confidential or special-category information through the enquiry forms.

Information automatically collected

Website Usage

The website and its providers may receive technical information needed to deliver and secure the service, such as IP address, browser and device details, referring page, pages visited, and timestamps. Framer Analytics provides aggregated, cookieless insights. Google Analytics is available only after analytics consent.

Cookies and Tracking

We record your consent choice in local browser storage. After analytics consent, Google Analytics may use cookies to measure site usage. After advertising consent, we may keep an OpenAI ad-click reference (oppref) in session storage long enough to attribute a confirmed enquiry. Optional storage stays off unless you choose it, and Cookie settings remain available on the site.

How we use your information

Service Delivery

We use your information to deliver the services you request, including responding to enquiries, preparing proposals, onboarding projects, managing communications, delivering work, issuing invoices, processing payments via providers, and providing support. This processing is necessary to perform our contract with you or to take steps you request before entering a contract.

Service Improvement

We may review site usage and service interactions to improve our processes, tools, and service quality. This can include diagnosing technical issues, improving site performance, refining our workflows, and developing better client experiences. Where analytics are used, we aim to minimise data and use settings that reduce unnecessary collection where possible.

Communication

We may use your contact details to send project updates, service communications, and administrative messages. If you opt in, we may also send marketing communications such as insights, announcements, or occasional updates about our services. You can unsubscribe at any time using the link provided in emails or by contacting us directly.

Data storage and security

Data storage

We store information using reputable service providers and systems designed to protect confidentiality and integrity. Access is limited to what is reasonably necessary to deliver and administer services. We take practical steps to protect client materials, including secure sharing methods and controlled access where available.

Data retention

We retain personal data for as long as needed to deliver services and meet legal, tax, and operational obligations. Project communications and records may be retained for a reasonable period after completion for reference, support, and the establishment or defence of legal claims. You can request deletion where appropriate, subject to legal requirements and legitimate business needs.

Security Measures

We use reasonable security measures designed to protect information, including encrypted transmission, secure hosting infrastructure, access controls, and account security practices. We apply routine updates and monitoring where available, and we handle client materials with care using trusted storage and sharing tools. No method of transmission or storage is completely secure, but we take security seriously and act promptly when we become aware of a risk or incident.

Information sharing

Third-Party Service Providers

We use service providers including Framer for site hosting and cookieless analytics; MakeForms for enquiry form delivery and EU-hosted response storage; Google reCAPTCHA for form security; Cloudflare for security and a dedicated conversion relay; and OpenAI Ads for conversion measurement. OpenAI receives only a pseudonymous event identifier, event type and time, form-page URL and, where advertising consent exists, the OpenAI ad-click reference. We do not send form names, email addresses, phone numbers or message content to OpenAI.

Legal Requirements

We may disclose information if required to do so by law or where disclosure is reasonably necessary to comply with legal obligations, respond to lawful requests, protect rights and safety, prevent fraud, or enforce agreements. Where legally permitted, we will take reasonable steps to notify you about such disclosures.

Your rights and choices

Access Rights

You may request access to personal information we hold about you, ask for corrections, or request a copy of your information. Where applicable, you may also request restriction of processing, object to certain processing, or request deletion. We will respond within the timeframes required by applicable law.

Control Options

You can opt out of marketing communications at any time and change optional analytics or advertising consent using the Cookie settings control on the site. You can also manage cookies in your browser. If you want us to delete or return project materials or personal data, contact us and we will assess the request in line with legal and operational requirements.

Childrens privacy

Children’s privacy

Our services and website are not intended for children, and we do not knowingly collect personal information from children. If you believe a child has provided personal data to us, please contact us and we will take appropriate steps to remove it.

International data transfers

We may use service providers that process data in different countries, depending on where you are located and which tools are used for delivery and administration. Where international transfers occur, we take reasonable steps to ensure appropriate safeguards are in place, consistent with applicable privacy laws.

Changes to privacy policy

We may update this policy to reflect changes in our practices, technologies, or legal requirements. We will update the “Last updated” date at the top of this page. If changes are material, we will take reasonable steps to provide notice through the website or by email where appropriate.

Specific rights by region

European users (GDPR)

If you are located in the European Economic Area or the United Kingdom, you may have rights including access, rectification, erasure, restriction, portability, objection, and rights relating to automated decision-making where applicable. You also have the right to lodge a complaint with your local data protection authority.

California users (CCPA)

If you are a California resident, you may have rights to know what personal information is collected and disclosed, request access or deletion (subject to exceptions), correct certain information, and opt out of certain data uses where applicable. We do not sell personal information in the ordinary course of business.

Other Regions

We aim to comply with privacy laws that apply to our work and our clients, and we adjust practices where required by local legislation. If you have a region-specific request, contact us and we will respond in line with applicable requirements.

Compliance and Certification

We design our privacy practices around recognised privacy principles, including data minimisation, purpose limitation, and appropriate security. Where GDPR, CCPA/CPRA, or other privacy laws apply, we aim to meet the relevant requirements. If you need further details about our data handling for vendor review purposes, contact us for a summary of the tools and safeguards relevant to your project.