Privacy Policy
Last updated: 3 October 2026
Loco Digital Limited (“Loco”, “we”, “us”) is a private company limited by shares, registered in Ireland with company number 692576. Our registered office is The Digital Hub, Thomas Street, Dublin 8, D08 TCV4, Ireland (the Digital Hub campus; the Roe Lane building is the same premises). Our VAT number is IE3754721AH. We are the data controller for the personal data described here.
This policy explains what this website does with your personal data, why, and what you can ask us to do about it. If anything in it is unclear, email hello@loco.ie and we will answer.
Who to contact
Email hello@loco.ie or call +353 1 554 7325. Post reaches us at Loco Digital Limited, The Digital Hub, Roe Lane, The Liberties, Dublin 8, D08 TCV4.
We are not required to appoint a Data Protection Officer and have not appointed one. Data protection questions are handled by Adam Murphy, Director of Technology, at hello@loco.ie.
What this policy covers
This policy covers loco.ie and the enquiry forms and chat assistant on it. It does not cover the separate contracts we sign with clients, where we usually act as a processor on the client’s instructions, and it does not cover other companies’ websites that we link to.
When you send us an enquiry
The forms on this site, including the short one inside the chat assistant, ask for your name, email address, phone number (optional), a description of what you want to build, and, on the contact page or when funding has come up in the chat, whether you would like us to check if grant funding could apply. You choose what to put in the message, so please leave out anything you would not want sitting in an email inbox.
We use it for one thing: to reply to you, and to carry on that conversation if it turns into a project. We do not sell it, rent it, trade it or add it to a marketing list. Apart from the spam check described below, which decides only whether a message is delivered, we do not use it for automated decision-making or profiling.
The legal basis is our legitimate interest in answering enquiries people have chosen to send us, and, where we go on to work together, taking steps at your request before entering a contract (GDPR Article 6(1)(f) and 6(1)(b)).
When you submit the form, the site sends the contents to our inbox through Brevo, a transactional email service run by Brevo SAS in France. From there it sits in our Google Workspace mailbox, hosted by Google Ireland Limited. We also send you a short automatic acknowledgement from no-replies@loco.ie through Brevo; it does not repeat what you wrote. Along with what you typed, the email records which page of our site you were on and which button brought you to the form, so we know which page led to the enquiry. It does not record your IP address or device details.
The forms are protected against automated submissions by Google reCAPTCHA v3. That check and the rate limit described after it are the only parts of sending an enquiry that use your IP address. reCAPTCHA is not loaded while you are reading a page: it loads the first time you click or type into a field on a form, or when you open the chat assistant, and it may set a cookie named _GRECAPTCHA at that point. From then on it looks at how the form is being filled in, and when you press send our server passes the token it produced and your IP address to Google, which returns a score for how likely it is that you are a person. We use that score for one decision, whether to send the message, and we keep no copy of it beyond a line in our log recording that an enquiry was accepted or refused. The legal basis is our legitimate interest in keeping our enquiry forms usable and our inbox free of automated spam (GDPR Article 6(1)(f)). Google processes this data for us as a processor, under the Google Cloud Data Processing Addendum, to provide the check. If a score is low enough that we cannot tell you from a bot, the form does not send: it tells you so and gives you our email address and phone number, so an enquiry always has somewhere to go. Since 16 September 2026 the same is true when the check cannot run at all. If your browser has JavaScript switched off, or blocks scripts from google.com, no token is produced, and a submission that arrives without one is refused rather than sent, because in practice almost every one of them is automated. Nothing you have typed is lost when that happens, the page says what went wrong, and it gives you the same two ways to reach us. Email and phone need no scripts and are always open.
To stop the forms being abused, our server keeps a one-way code derived from your IP address and another derived from your email address, normally for about a day. They limit how many messages one connection can send and how many acknowledgements one address receives, and they are used for nothing else.
We keep enquiry correspondence for as long as we need it to deal with the enquiry and any project that follows, and for no more than 24 months after our last contact with you, unless you become a client and we have to keep records for tax, accounting or contractual reasons for as long as Irish law requires. You can ask us to delete it sooner.
When you use the chat assistant
The chat assistant on this site, Ask Loco, is an AI system, not a person. It writes its replies with Claude, an AI model made by Anthropic, from what we have written on loco.ie, and it links the page each answer comes from. It can still get things wrong, so please treat what it says as a starting point: Adam or Mark confirm prices, timings and anything else you would rely on, in writing.
Until you open the chat, it stores nothing on your device and sends nothing about you to us. On some pages a short suggestion may appear beside its button while you read. It is picked in your browser from the page you are on and how you are reading it during this visit, for example reaching the prices or opening two of the questions on a page. None of that is stored, and none of it reaches us unless you open the chat. If you have accepted analytics, Google Analytics also counts when a suggestion is shown and whether it was opened, dismissed or ignored, as described under Analytics. When you open the chat, your browser fetches the suggested questions for that page from our server and loads Google’s reCAPTCHA v3, the spam check described above.
When you send a message, we receive what you type and what the assistant replies, the page you were on when you sent each message, the time of each message, and how you opened the chat: with its button, from a suggestion beside it, or by choosing one of its suggested questions. Each conversation gets a random reference beginning “LOCO-”, which the chat’s menu shows you. We also note whether the conversation led to an enquiry, a request to talk to Adam or Mark or a booked call, and technical details of each reply, such as how long it took. Before a message is stored or passed to Anthropic, our server removes any email address or phone number it finds in it, and any other long number such as a card or account number, so please use the chat’s enquiry form for contact details. We do not keep your IP address with the conversation, and nothing you write in the chat is sent to Google Analytics.
To stop the chat being abused, our server keeps a one-way code made from your IP address and the date, using a secret only the server holds. It counts how many chats one connection starts in a day and what answering them has cost, it is deleted within two days, and it is used for nothing else.
We use the conversation for three things: to answer you; to pass on a real enquiry, when you send one, so that Adam or Mark can reply; and to find answers the assistant got wrong or could not give, so that we can fix the pages and the information it answers from. The assistant does not score you or your project, and nothing it concludes stops you reaching us: our email address and phone number are always available in the chat. Neither we nor Anthropic use your conversations to train AI models.
The legal basis is our legitimate interest in answering the questions people choose to ask us, in making those answers better and in keeping the chat free of abuse, and, where you ask for a quote, a proposal or a call, taking steps at your request before entering a contract (GDPR Article 6(1)(f) and 6(1)(b)).
You can object to us keeping a conversation to improve the assistant. Choose “Don’t keep this chat to improve the assistant” in the chat’s menu and we will not use it for that, and will delete it 24 hours after your last message; or email hello@loco.ie with its reference and we will delete it. “Delete this chat transcript” in the same menu deletes the conversation from our systems at once. Some things stay: an enquiry or booking you already sent from it; Anthropic’s copy, described below; our server backups, for up to 7 days; and, for 30 days, a note of the conversation’s reference and when it was deleted, as a record of the deletion.
Otherwise we keep a conversation for 90 days after your last message, so that we can follow up and check the answers, and then delete it automatically. If you send an enquiry from the chat, the enquiry is kept as described above. Conversations are left out of our server’s nightly backup archive, and a deleted conversation leaves the server’s daily backups within 7 days. Our server’s error log also keeps a line about each reply, such as how long it took, with nothing that was written in the chat, for up to 9 weeks.
Anthropic produces the replies for us as our processor, under Anthropic’s Commercial Terms and Data Processing Addendum, which we have with Anthropic Ireland, Limited. For each reply it receives the conversation so far, with the removals described above, and the page you are on, but not your IP address or anything you put into the chat’s enquiry form. Anthropic, PBC processes it in the United States, where Anthropic stores it, and Anthropic’s service may produce a reply in any country where it runs; the standard contractual clauses in the Data Processing Addendum cover those transfers. Anthropic does not use it to train its models. It deletes it within 30 days, except content its automated safety systems flag, which it may keep for up to 2 years, and it cannot delete a single conversation sooner at our request.
The chat’s suggested questions work without the spam check. Before the assistant answers the first question you type, our server passes the check’s token and your IP address to Google, as it does for the forms, and keeps the result and the score with the conversation. If the score is low, the chat allows fewer and shorter messages. If your browser cannot run the check, or the check fails, the assistant does not answer typed questions, and it gives you our email address, phone number and booking link instead. If Google cannot be reached at that moment, the assistant answers and the conversation is recorded as unchecked.
If you send an enquiry from the chat, what you put into its form reaches us by email, as described above, and is not added to the conversation. The email also carries the chat’s reference and the short summary the chat suggested for your message, which you see in the form before you send it.
If you book a call from the chat, it first shows you the note it will pass to Calendly, with the chat’s reference, and lets you change it. When you open the booking form, that note, and your name and email address if you entered them, go to Calendly so that the form arrives filled in, even if you then decide not to book. We record in the chat that you opened the booking form and whether a call was booked, but not the booking’s details. Otherwise the booking panel works as described under Third-party embeds.
Please do not put health, financial or other sensitive personal details into the chat. The assistant does not need them and is told never to ask for them or repeat them. If you share them anyway, delete the chat from its menu or tell us the reference and we will delete it, and if we come across such details when we read conversations, we delete that conversation. The assistant is meant for people asking about work for their organisations, not for children: see Children below.
When you are only browsing
The site sets no cookies of its own and asks for nothing until you tell it you are happy with analytics. Reading a page loads nothing from Google, Vimeo or Calendly: the spam check described above starts only once you begin filling in a form or open the chat assistant, and the chat assistant stores and sends nothing until you open it. Two things still happen that involve data about you.
Our web server keeps an access log: the IP address the request came from, the page requested, the time, the browser’s user agent string and the referring page. That log is how we find faults and spot attacks. The basis is our legitimate interest in keeping the site running and secure, and we keep it for no more than 30 days.
A copy of an enquiry we could not deliver by email is kept on our server for up to 90 days so that we can still answer it, and is then deleted automatically. It drops out of our server backups within a further 23 days.
The site runs on a server in London, in the United Kingdom, rented from DigitalOcean, LLC, a company based in the United States. It sits behind Cloudflare, which serves the site’s files from whichever of its locations is nearest to you. Both act as processors for us under contract.
Fonts are served from our own server, so loading a page makes no request to Google Fonts or any other font service. The one exception is reCAPTCHA, which fetches a font of its own from Google once it has loaded on a form or in the chat assistant.
Analytics, and only with your consent
We use Google Analytics 4 through Google Tag Manager to count visits and see which pages lead to enquiries. It is loaded in consent mode with everything denied by default, so no analytics cookies are set and no analytics data is sent to Google unless you press Accept in the banner. Press Reject and the analytics tags never run.
What it records is the pages you view and a small number of actions on them: sending the enquiry form, pressing a phone number or an email address, pressing play on a video, opening or completing a booking in the Calendly panel, and how the chat assistant is used, such as opening it, choosing a suggested question or sending a message, each with the page it happened on. A completed booking also carries Calendly’s own reference for that booking, which is a random identifier rather than your name or your email address. Nothing you type into a form, the chat assistant or the booking panel is sent to Google Analytics, and neither is a chat’s reference.
If you accept, Google Analytics sets first-party cookies (_ga and _ga_LHXGHNQEN4) to count one browser separately from another, and the site stores the page and button that brought you to the enquiry form in your browser’s session storage so the attribution described above can be filled in. That session storage is cleared when you close the tab and is only written after you have accepted.
Google Signals and advertising features are switched off. We set no advertising cookies and do no cross-site tracking. User-level analytics data is kept for 14 months.
Your decision is stored on your own device, in local storage under the key loco:consent. Nothing is sent to us when you make it. You can change your mind at any time through “Cookie settings” in the footer, and we ask again after six months. The full list of cookies and storage is in the Cookie Policy.
Third-party embeds
Some case studies and our marketing and video page include videos hosted by Vimeo. Nothing of Vimeo’s is loaded until you press play on the poster. When you do, the player loads from player.vimeo.com with Do Not Track set, which asks Vimeo not to track your viewing, and your IP address and browser details are sent to Vimeo to deliver the video; what Vimeo does with them is covered by Vimeo’s own privacy policy.
The booking panel works the same way. If you press “Book a free 30-minute call”, Calendly’s booking form loads inside the page and sets its own cookies to run it; nothing of Calendly’s is loaded, and nothing is set, unless you press that button. The details you enter into that form go to Calendly LLC to schedule the call and are covered by Calendly’s privacy notice as well as this one.
The panel is Calendly’s software and it brings Calendly’s own suppliers with it. Opening it also loads code from Stripe, which screens bookings for card fraud and sets a device cookie, and from Segment, Sprig and Airbrake, which Calendly uses for its own product analytics, in-app surveys and error reporting. We receive nothing from any of them and we cannot switch them off inside the panel, but none of it loads unless you press the button. The Cookie Policy lists what they set. If you would rather not load any of it, email hello@loco.ie or call +353 1 554 7325 and we will book the call for you.
We load the video player and the booking panel only when you ask for them, on the basis of our legitimate interest in showing our work and letting you book a call (GDPR Article 6(1)(f)). For that moment of loading, we and Vimeo or Calendly are joint controllers. After it, each of them is responsible for what it does with your data.
Who else sees your data
Scroll the table sideways for the full detail
| Who | What they do with it | Where |
|---|---|---|
| Brevo SAS | Delivers the enquiry email to our inbox and the automatic acknowledgement to you | France |
| Google Ireland Limited | Our email (Google Workspace) and Google Analytics 4 | Ireland, with support access outside the EU |
| Google Cloud EMEA Limited (reCAPTCHA) | Scores a submission to our enquiry forms, and the first question you type into the chat assistant, so we can tell a person from a bot, using your IP address and signals about how you used the form or the chat, as our processor under the Google Cloud Data Processing Addendum | Ireland, with processing outside the EU |
| Anthropic Ireland, Limited, and Anthropic, PBC | Produces the chat assistant’s replies from what you write to it, as our processor under Anthropic’s Commercial Terms and Data Processing Addendum. It does not train its models on it, and deletes it within 30 days unless its safety systems flag it | United States, where it is stored, and any country where Anthropic runs its service, under standard contractual clauses |
| DigitalOcean, LLC | Hosts the server, the chat assistant’s conversations, its logs and its backups | Server in London, United Kingdom. The company is in the United States |
| Cloudflare | Serves the site and filters malicious traffic | Global network, including the EU and the United States |
| Calendly LLC | Runs the booking panel and the call it schedules, when you choose to open it, including the note the chat assistant shows you first if you book from the chat. Calendly in turn uses Stripe, Segment, Sprig and Airbrake inside that panel | United States |
| Vimeo.com, Inc. | Serves the video player and the video itself, when you press play | United States |
We share your data with nobody else, except the providers named above, the video player and the booking panel you choose to load, and where we are legally obliged to or have to defend a legal claim.
Data leaving the EU
Our server is in the United Kingdom, which the European Commission has decided offers an adequate level of protection; it renewed that decision in December 2025. The company we rent the server from, DigitalOcean, LLC, is in the United States, and any access to the server from there is covered by the standard contractual clauses in its data processing agreement. Cloudflare and Google may process data outside the EU, and those transfers are covered by the European Commission’s standard contractual clauses, and, for Google’s US entity, by the EU-US Data Privacy Framework. Calendly LLC is in the United States: it is certified under the EU-US Data Privacy Framework, and its data processing terms also carry the standard contractual clauses, so a booking you make is covered by both. Vimeo.com, Inc. is also in the United States, and it receives nothing at all unless you press play on a video. When you do, it is your browser that contacts Vimeo directly rather than us passing anything on, and what Vimeo does with your IP address and browser details is governed by Vimeo’s own privacy policy. The chat assistant’s replies are produced by Anthropic. We contract with Anthropic Ireland, Limited; Anthropic, PBC processes the conversation in the United States, where it is stored, and Anthropic’s service may produce a reply in any country where it runs. Those transfers are covered by the standard contractual clauses in Anthropic’s Data Processing Addendum.
Security
The site is served over HTTPS. Enquiries are not stored on the web server; they go to our mailbox, and access to that mailbox is restricted to the people who need it and protected by two-factor authentication. The only exception is the copy of an undelivered message described above. The chat assistant’s conversations are kept on the server, without IP addresses, for the times given under When you use the chat assistant, and only the site itself and Loco can read them.
Your rights
Under the GDPR you can ask us to give you a copy of the personal data we hold about you, correct it, delete it, restrict what we do with it, or send it to you in a portable format. You can object to processing we carry out on the basis of legitimate interest. Where processing is based on consent, you can withdraw that consent at any time, and withdrawing is as easy as giving it.
Email hello@loco.ie and we will reply within one month. There is no charge.
For a conversation with the chat assistant, you can delete it, or ask us not to keep it, from the chat’s own menu while it is open. After that, email us its reference, which the chat’s menu shows, or the email address you used if you sent us an enquiry from the chat. We do not store conversations with names, email addresses or IP addresses, so without one of those we may not be able to find yours. Before we send you a copy of a conversation, we check that it is yours.
If you are not happy with how we have handled it, you can complain to the Data Protection Commission, 6 Pembroke Row, Dublin 2, D02 X963, or through www.dataprotection.ie.
Children
This site is for people buying software and websites for their organisations. It is not directed at children, and we do not knowingly collect personal data from anyone under 16. If someone tells the chat assistant they are under 16, it gives general information only, stops offering its enquiry form and booking, and asks for no contact details. If you think a child has sent us something, email hello@loco.ie and we will delete it.
Changes to this policy
If we change what this site does with personal data, we will update this page and change the date at the top before the change goes live.