Cerenos

GDPR Policy

Archived version 2 · Published 30 August 2026 by System (redaction update) · view current version

This GDPR Policy explains, in more detail than our Privacy Policy, how Cerenos meets its obligations under the EU General Data Protection Regulation (GDPR) and equivalent UK and Swiss data protection law. This is version 1 of this policy - see the version history link above for every previous version.

If you are located in the United States, see our US Data Privacy Policy instead - most of the concepts on this page (our EU/UK/Swiss legal bases and the Data Protection Commission's role, in particular) do not directly apply there.

Part 1: General GDPR Core Clauses

(Applies to our users in the European Economic Area, the United Kingdom, and Switzerland.)

Identity of the data controller

Cerenos Limited, a private company limited by shares registered in Ireland under company number 824270, with its registered office at Venture Hub, 136 Capel Street, Dublin, Dublin, D01 T2C9, Ireland, is the data controller directly responsible for the personal data described in our Privacy Policy. Where we process data purely on behalf of a customer organisation using our products (for example, a customer's own client records inside our support/ticketing tools), we act as a data processor on that customer's behalf, and we will enter into a data processing agreement with that customer on request.

Categories of data collected

Lawful bases for processing (Article 6)

Data retention periods

We keep transaction data (invoices, payment records) for a minimum of 6 years, as required by Irish tax law, and analytics data for Google Analytics' own default retention window (currently 14 months) unless you withdraw consent sooner. Our Privacy Policy's "How long we keep your data" section sets out the full retention schedule for every category of data we hold.

Data subject rights

You have the right to:

We do not currently make any decision about you based solely on automated processing (including profiling) that produces a legal or similarly significant effect. To exercise any of these rights, contact [email protected] - this address does not send automated replies, but a member of our team will personally follow up with you once your message is received. We may need to verify your identity before responding, and we will respond within one month as required by the GDPR (extendable by a further two months for complex requests, with notice to you).

Right to lodge a complaint

You have the right to lodge a complaint with your local data protection supervisory authority. As a company registered in Ireland whose servers are hosted in Ireland, our lead supervisory authority is the Data Protection Commission (DPC) of Ireland: https://www.dataprotection.ie/.

Part 2: Specific UK Clause

If you are a resident of the United Kingdom, your data is processed in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Because we host in Ireland, transfers of your data from the UK to Ireland are covered seamlessly by the UK's standard adequacy decision for the European Economic Area - no additional transfer mechanism is needed.

Part 3: Specific Swiss Clause

If you are a resident of Switzerland, your data is processed in compliance with the revised Swiss Federal Act on Data Protection (FADP). We treat Switzerland alongside the EEA for the purposes of every data subject right described above, and you may exercise those rights in exactly the same way, through the same contact address.

International data transfers

Some of our service providers (see our Privacy Policy) are located outside the European Economic Area, including in the United States. Where we transfer personal data outside the EEA, we put in place appropriate safeguards recognised under the GDPR, such as the European Commission's Standard Contractual Clauses, or rely on an applicable adequacy decision.

Data protection by design

We build access controls, encryption for particularly sensitive data stores, and audit logging into our products as standard. New features that introduce a new category of personal data collection are reviewed for their data protection impact before launch.

Breach notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Data Protection Commission within 72 hours of becoming aware of it, and will notify affected individuals directly where the breach is likely to result in a high risk to them, in line with our obligations under the GDPR.

Sub-processors

A current list of the main sub-processors we use is set out in our Privacy Policy's "Who we share data with" section. We will update that list as our vendors change.

Contact us

Questions about this policy, or to exercise your rights, contact [email protected]. This address does not send automated replies - a member of our team will personally follow up with you once your message is received. Our registered office is Venture Hub, 136 Capel Street, Dublin, Dublin, D01 T2C9, Ireland.