Privacy Policy
Last updated: 16 September 2026
Loco Digital Limited (“Loco”, “we”, “us”) is a private company limited by shares, registered in Ireland with company number 692576. Our registered office is The Digital Hub, Thomas Street, Dublin 8, D08 TCV4, Ireland (the Digital Hub campus; the Roe Lane building is the same premises). Our VAT number is IE3754721AH. We are the data controller for the personal data described here.
This policy explains what this website does with your personal data, why, and what you can ask us to do about it. It is written to be read, not to be survived. If anything in it is unclear, email hello@loco.ie and you will get a straight answer.
Who to contact
Email hello@loco.ie or call +353 1 554 7325. Post reaches us at Loco Digital Limited, The Digital Hub, Roe Lane, The Liberties, Dublin 8, D08 TCV4.
We are not required to appoint a Data Protection Officer and have not appointed one. Data protection questions are handled by Adam Murphy, Director of Technology, at hello@loco.ie.
What this policy covers
This policy covers loco.ie and the enquiry forms on it. It does not cover the separate contracts we sign with clients, where we usually act as a processor on the client’s instructions, and it does not cover other companies’ websites that we link to.
When you send us an enquiry
The forms on this site ask for your name, email address, phone number (optional), a description of what you want to build, and, on the contact page, whether you would like us to check if grant funding could apply. You choose what to put in the message, so please leave out anything you would not want sitting in an email inbox.
We use it for one thing: to reply to you, and to carry on that conversation if it turns into a project. We do not sell it, rent it, trade it or add it to a marketing list, and we do not use it for automated decision-making or profiling.
The legal basis is our legitimate interest in answering enquiries people have chosen to send us, and, where we go on to work together, taking steps at your request before entering a contract (GDPR Article 6(1)(f) and 6(1)(b)).
When you submit the form, the site sends the contents to our inbox through Brevo, a transactional email service run by Brevo SAS in France. From there it sits in our Google Workspace mailbox, hosted by Google Ireland Limited. Along with what you typed, the email records which page of our site you were on and which button brought you to the form, so we know which page led to the enquiry. It does not record your IP address or device details.
Both forms are protected against automated submissions by Google reCAPTCHA v3, and that is the one part of sending an enquiry that involves your IP address. It is not loaded while you are reading a page: it loads the first time you click or type into a field on a form, and it sets a cookie named _GRECAPTCHA at that point. From then on it looks at how the form is being filled in, and when you press send our server passes the token it produced and your IP address to Google, which returns a score for how likely it is that you are a person. We use that score for one decision, whether to send the message, and we keep no copy of it beyond a line in our log recording that an enquiry was accepted or refused. The legal basis is our legitimate interest in keeping our enquiry forms usable and our inbox free of automated spam (GDPR Article 6(1)(f)). What Google does with the data is set out in Google’s privacy policy and its terms of service. If a score is low enough that we cannot tell you from a bot, the form does not send: it tells you so and gives you our email address and phone number, so a real enquiry is never left with nowhere to go. Since 16 September 2026 the same is true when the check cannot run at all. If your browser has JavaScript switched off, or blocks scripts from google.com, no token is produced, and a submission that arrives without one is refused rather than sent, because in practice almost every one of them is automated. Nothing you have typed is lost when that happens, the page says plainly what went wrong, and it gives you the same two ways to reach us. Email and phone need no scripts and are always open.
We keep enquiry correspondence for as long as we need it to deal with the enquiry and any project that follows, and for no more than 24 months after our last contact with you, unless you become a client and we have to keep records for tax, accounting or contractual reasons for as long as Irish law requires. You can ask us to delete it sooner.
When you are just browsing
The site sets no cookies of its own and asks for nothing until you tell it you are happy with analytics. Reading a page loads nothing from Google, Vimeo or Calendly: the spam check described above starts only once you begin filling in a form. Two things still happen that involve data about you.
Our web server keeps an access log: the IP address the request came from, the page requested, the time, the browser’s user agent string and the referring page. That log is how we find faults and spot attacks. The basis is our legitimate interest in keeping the site running and secure, and we keep it for no more than 30 days.
A copy of an enquiry we could not deliver by email is kept on our server for up to 90 days so that we can still answer it, and is then deleted automatically.
The site runs on a server rented from DigitalOcean in London in the United Kingdom, behind Cloudflare, which serves the site’s files from whichever of its locations is nearest to you. Both act as processors for us under contract.
Fonts are served from our own server, so loading a page makes no request to Google Fonts or any other font service.
Analytics, and only with your consent
We use Google Analytics 4 through Google Tag Manager to count visits and see which pages lead to enquiries. It is loaded in consent mode with everything denied by default, so no analytics cookies are set and no analytics data is sent to Google unless you press Accept in the banner. Press Reject and the analytics tags never run.
What it records is the pages you view and a small number of actions on them: sending the enquiry form, pressing a phone number or an email address, pressing play on a video, and opening or completing a booking in the Calendly panel, each with the page it happened on. A completed booking also carries Calendly’s own reference for that booking, which is a random identifier rather than your name or your email address. Nothing you type into a form or into the booking panel is sent to Google Analytics.
If you accept, Google Analytics sets first-party cookies (_ga and _ga_LHXGHNQEN4) to count one browser separately from another, and the site stores the page and button that brought you to the enquiry form in your browser’s session storage so the attribution described above can be filled in. That session storage is cleared when you close the tab and is only written after you have accepted.
Google Signals and advertising features are switched off. We set no advertising cookies and do no cross-site tracking. User-level analytics data is kept for 14 months.
Your decision is stored on your own device, in local storage under the key loco:consent. Nothing is sent to us when you make it. You can change your mind at any time through “Cookie settings” in the footer, and we ask again after six months. The full list of cookies and storage is in the Cookie Policy.
Third-party embeds
Three case studies and our marketing and video page include videos hosted by Vimeo. Nothing of Vimeo’s is loaded until you press play on the poster. When you do, the player loads from player.vimeo.com with Do Not Track set, which asks Vimeo not to track your viewing, and your IP address and browser details are sent to Vimeo to deliver the video; what Vimeo does with them is covered by Vimeo’s own privacy policy.
The booking panel works the same way. If you press “Book a free 30-minute call”, Calendly’s booking form loads inside the page and sets its own cookies to run it; nothing of Calendly’s is loaded, and nothing is set, unless you press that button. The details you enter into that form go to Calendly LLC to schedule the call and are covered by Calendly’s privacy notice as well as this one.
The panel is Calendly’s software and it brings Calendly’s own suppliers with it. Opening it also loads code from Stripe, which screens bookings for card fraud and sets a device cookie, and from Segment, Sprig and Airbrake, which Calendly uses for its own product analytics, in-app surveys and error reporting. We receive nothing from any of them and we cannot switch them off inside the panel, but none of it loads unless you press the button. The Cookie Policy lists what they set. If you would rather not load any of it, email hello@loco.ie or call +353 1 554 7325 and we will book the call for you.
Who else sees your data
Scroll the table sideways for the full detail
| Who | What they do with it | Where |
|---|---|---|
| Brevo SAS | Delivers the enquiry email to our inbox | France |
| Google Ireland Limited | Our email (Google Workspace) and Google Analytics 4 | Ireland, with support access outside the EU |
| Google Ireland Limited (reCAPTCHA) | Scores a submission to our enquiry forms so we can tell a person from a bot, using your IP address and signals about how you filled the form in. Covered by Google’s privacy policy | Ireland, with processing outside the EU |
| DigitalOcean | Hosts the server and its logs | London, United Kingdom |
| Cloudflare | Serves the site and filters malicious traffic | Global network, including the EU and the United States |
| Calendly LLC | Runs the booking panel and the call it schedules, when you choose to open it. Calendly in turn uses Stripe, Segment, Sprig and Airbrake inside that panel | United States |
| Vimeo.com, Inc. | Serves the video player and the video itself, when you press play | United States |
We share your data with nobody else, except the providers named above, the video player and the booking panel you choose to load, and where we are legally obliged to or have to defend a legal claim.
Data leaving the EU
Our server is in the United Kingdom, which the European Commission has decided offers an adequate level of protection, so no further safeguard is needed for that transfer. Cloudflare and Google may process data outside the EU, and those transfers are covered by the European Commission’s standard contractual clauses, and, for Google’s US entity, by the EU-US Data Privacy Framework. Calendly LLC is in the United States: it is certified under the EU-US Data Privacy Framework, and its data processing terms also carry the standard contractual clauses, so a booking you make is covered by both. Vimeo.com, Inc. is also in the United States, and it receives nothing at all unless you press play on a video. When you do, it is your browser that contacts Vimeo directly rather than us passing anything on, and what Vimeo does with your IP address and browser details is governed by Vimeo’s own privacy policy.
Security
The site is served over HTTPS. Enquiries are never written to a database or to a file inside the public part of the site; they go straight to our mailbox. Access to that mailbox is restricted to the people who need it and protected by two-factor authentication.
Your rights
Under the GDPR you can ask us to give you a copy of the personal data we hold about you, correct it, delete it, restrict what we do with it, or send it to you in a portable format. You can object to processing we carry out on the basis of legitimate interest. Where processing is based on consent, you can withdraw that consent at any time, and withdrawing is as easy as giving it.
Email hello@loco.ie and we will reply within one month. There is no charge.
If you are not happy with how we have handled it, you can complain to the Data Protection Commission, 6 Pembroke Row, Dublin 2, D02 X963, or through www.dataprotection.ie.
Children
This site is for people buying software and websites for their organisations. It is not directed at children, and we do not knowingly collect personal data from anyone under 16. If you think a child has sent us something, email hello@loco.ie and we will delete it.
Changes to this policy
If we change what this site does with personal data, we will update this page and change the date at the top before the change goes live.