☘️ Data sourced from the Companies Registration Office (CRO) of Ireland under Open Data Licence

Privacy Policy & Terms of Service

Effective Date: 26 July 2025  ·  Governed by: Irish Law & GDPR

⚠️ Note: These terms are operative from 26 July 2025. If you make material changes, update the effective date and notify signed-in users by email.

1. Who We Are

CompanyInsights Ireland ("we", "us", "our") is an independent data intelligence platform that provides AI-powered search and analysis of the Irish Companies Registration Office (CRO) public register. Operated by Rajesh Prabhakaran, Ireland.

We are not affiliated with the Companies Registration Office, the Department of Enterprise, Trade and Employment, or any Irish Government body.

2. Data We Collect

Information you provide

DataWhy We Collect ItLegal Basis (GDPR Art. 6)
Email addressTo send a passwordless sign-in link and identify your accountArt. 6(1)(b) — Contractual necessity

Information collected automatically

DataWhy We Collect ItLegal Basis
Hashed IP addressRate-limiting: enforcing the 1 free query per day for anonymous users. Raw IP is never stored — we store a SHA-256 hash combined with today's date only.Art. 6(1)(f) — Legitimate interest
Query textTo process your search via the AI modelArt. 6(1)(b) — Contractual necessity
Query count per dayEnforcing the 10-query daily fair-use limitArt. 6(1)(f) — Legitimate interest
Session timestampsSecurity and abuse detectionArt. 6(1)(f) — Legitimate interest

What we do NOT collect

3. How We Use Your Data

  1. Providing the service — processing queries, enforcing daily quotas, sending sign-in links.
  2. Security & abuse prevention — detecting automated abuse, spam queries, or misuse.
  3. Service improvement — understanding aggregate usage patterns.
  4. Commercial analytics — we may derive, analyse, and commercialise anonymised, aggregated insights (e.g. search trend reports by industry or region). These contain no personal data and cannot identify any individual. See Section 5.

4. Data Sharing & Third-Party Sub-Processors

ProviderRoleCountryPolicy
Google Firebase / FirestoreDatabase, authentication, cloud functionsUSA (EU residency available)Google Privacy Policy
Google Gemini APIAI model that processes query textUSAGoogle Cloud Terms

We do not share your personal data (email, IP hash, or query history linked to your identity) with any third party for their own marketing purposes.

We may disclose your data if required by law, court order, or to protect our rights.

5. Anonymised & Aggregated Data

GDPR does not apply to data that has been genuinely anonymised — i.e., data from which no individual can reasonably be identified. We reserve the right to analyse and commercialise anonymised, aggregated data derived from usage of this service.

6. Data Retention

Data TypeRetention Period
Email address & account recordUntil you delete your account or 2 years of inactivity
Hashed IP quota recordsAuto-deleted after 48 hours
Query logsUp to 90 days for security/abuse review, then deleted
Anonymised aggregated analyticsIndefinite (no personal data)

7. Your GDPR Rights

This service is operated by an individual, not a corporate entity. We want to be transparent about that. You have the following rights under GDPR, and we will handle any request manually and in good faith.

What personal data we actually hold about you: your email address, a daily query counter, and session timestamps. That is the entirety of it.

RightWhat it means in practice for this service
AccessEmail us and we will reply with your email address and query count — that is literally all we have on you.
ErasureWe will delete your account from Firebase Authentication and remove your quota record from our database.
PortabilityWe will send you your data (email + query count) as a simple JSON file.
RectificationIf your email is wrong, please re-register with the correct address and we will delete the old record.
Object / RestrictEmail us. If you object to any processing, the simplest resolution is full account deletion.

To make any request, email prabrajesh@gmail.com. We aim to respond within 30 days, though in practice it is typically much sooner given the small scale of this service.

If you are dissatisfied with our response, you may lodge a complaint with the Data Protection Commission of Ireland: dataprotection.ie

8. Cookies & Local Storage

This service uses browser local storage (not cookies) to track your daily query count on your own device. This data never leaves your browser and is cleared automatically after 24 hours. We do not use tracking cookies, advertising cookies, or third-party analytics cookies.

9. Children

This service is not directed at children under 16. We do not knowingly collect data from children. Contact us immediately if you believe a child's data has been collected.

10. Changes to This Policy

We may update this policy from time to time. For material changes, signed-in users will be notified by email at least 14 days before changes take effect.

Terms of Service

Acceptable Use

You may use CompanyInsights Ireland for personal, research, commercial, or journalistic purposes. You may not:

Disclaimer

All data is sourced from the CRO Open Data dataset and is provided as-is. CRO records may contain errors or outdated information. Nothing on this platform constitutes legal, financial, or investment advice. Always verify critical information directly with the CRO at cro.ie.

Intellectual Property

CRO data is available under the Public Sector Information (PSI) Licence. Our platform design, AI prompt architecture, and codebase are the intellectual property of Rajesh Prabhakaran.

Governing Law

These Terms are governed by the laws of the Republic of Ireland. Disputes are subject to the exclusive jurisdiction of the Irish courts.

Last updated: 26 July 2025  ·  Questions? prabrajesh@gmail.com