Ref. Data.Policy

Your Data, Held Under Irish And European Law.

This policy sets out what we collect, why we hold it, what we do with it and how long it stays. It is written to be read rather than skimmed past, because a policy nobody understands protects nobody.

Controller Record

Data Controller

ECSTASY BLISS LIMITED

Registered In

IRELAND

Company Number

822863

Governing Law

GDPR & DPA 2018

Supervisory Authority

DPC, IRELAND

Last Updated

1 SEPT 2026

REF. EB-PRIV-01

VERSION 1.0

01

Who we are

Ecstasy Bliss Limited is an Irish registered company, number 822863, with its registered office at Venture Hub, 136 Capel Street, Dublin, D01 T2C9, Ireland. We build, register, stock and manage ecommerce stores and business websites, and we own and run several trading brands of our own.
For the purposes of the General Data Protection Regulation, Regulation (EU) 2016/679, and the Irish Data Protection Act 2018, Ecstasy Bliss Limited is the data controller for the personal data described here. That means we decide why your data is processed and how, and we carry the responsibility for it.
Where we build or manage a website or store for a client, that client is usually the controller of their own customers’ data and we act as a processor on their instructions. In those cases the client’s own privacy policy governs, and we work to a written agreement with them under Article 28 of the GDPR.
02

What this policy covers

This policy applies to this website, to enquiries you send us, and to the work we carry out for clients and prospective clients. It does not cover other websites we link to, including the sites of our own trading brands, each of which publishes its own policy.
Our trading names are LazarKin, Own Path Course, Fly Safe Flights, Your Next Homes and Glowzy Place. If you bought something from one of those, the policy on that site is the one that applies to your purchase, although Ecstasy Bliss Limited remains the company behind it.
03

What we collect

Only what the work needs. Most people who contact us give us four things: a name, an email address, a business name and a description of what they want built. Everything else is either technical information your browser sends automatically or details that become necessary once a project starts.
We do not ask for special category data, meaning information about health, ethnicity, religion, political views, trade union membership, biometrics or sexual orientation. Please do not send it to us. If it arrives in an enquiry anyway, we delete it.
04

Why we hold it, and on what basis

Under the GDPR every use of personal data needs a lawful basis. Rather than describe ours in paragraphs, here is the whole record in one place, so you can see the purpose, the basis and the retention period side by side.
What we hold
Why we hold it
Lawful basis
Kept for
Enquiry details
To answer your question, quote the work and follow up once if we hear nothing back.
LEGITIMATE INTERESTS
24 MONTHS
Project and client records
To deliver what we agreed, keep a record of decisions, and support the site afterwards.
CONTRACT
6 YEARS
Invoices and payment records
To bill you and to satisfy Irish tax and company law record keeping.
LEGAL OBLIGATION
6 YEARS
Company formation documents
To file with the Companies Registration Office and Revenue on your behalf.
CONTRACT & LEGAL
6 YEARS
Site access credentials
To build, fix or maintain a website or store you have asked us to work on.
CONTRACT
END OF WORK
Marketing list
To send occasional notes about ecommerce, only if you asked to receive them.
CONSENT
UNTIL YOU LEAVE
Website analytics
To see which pages people read and where the site confuses them.
CONSENT
14 MONTHS
Security and server logs
To keep the site up, block abuse and investigate anything that goes wrong.
LEGITIMATE INTERESTS
12 MONTHS
Where we rely on legitimate interests, we have weighed our interest in running the business against your rights and privacy, and we will explain that assessment to you on request. Where we rely on consent, you can withdraw it at any time, and doing so does not make anything we did beforehand unlawful.
05

Where the data comes from

Almost all of it comes directly from you, through a form on this site, an email, a call or a document you send during a project.
06

Cookies and similar technologies

Cookies are small files a website stores on your device. In Ireland their use is governed by the ePrivacy Regulations 2011, which means anything beyond what the site strictly needs to function requires your consent before it is set, not after.
Category
What it does
Consent
Strictly necessary
Keeps the site working: page delivery, security, remembering your cookie choice itself.
Not required
Preference
Remembers small choices you make, so the site behaves the same on your next visit.
Required
Analytics
Counts visits and shows which pages get read, so we can fix the ones that lose people.
Required
Marketing
Measures whether an advert or a campaign brought somebody here.
Required
You can withdraw consent at any time through the cookie controls on this site, and you can block or delete cookies through your browser settings. Blocking the strictly necessary ones will break parts of the site.
07

Who we share it with

We do not sell personal data, we do not rent it, and we do not pass it to anyone for their own marketing. We do use service providers to run the business, and they process data on our instructions under a written agreement.
If the business is ever sold or restructured, personal data may transfer to the new owner, who would be bound by the same purposes set out here. We would tell you before that happened.
08

Transfers outside the EEA

We prefer suppliers who store data inside the European Economic Area, and for most of what we do that is achievable. Some widely used tools are operated by companies based elsewhere, most often the United States.
Where data leaves the EEA, we rely on one of the transfer mechanisms the GDPR permits: an adequacy decision from the European Commission, the EU to US Data Privacy Framework where the recipient is certified under it, or Standard Contractual Clauses with additional safeguards where neither applies. We do not rely on Privacy Shield, which the Court of Justice invalidated in 2020 and which still appears in a surprising number of privacy policies.
You can ask us which suppliers we use and where they hold data, and we will tell you.
09

How long we keep it

The retention column in the table above is the short answer. The reasoning behind it is that different obligations pull in different directions, so a single blanket period would be either useless or unlawful.
Once a period expires the data is deleted or anonymised so it can no longer identify you.
10

How we protect it

We apply technical and organisational measures proportionate to the risk, which is what Article 32 requires. In practice that means encrypted connections, access limited to the people who need it, separate accounts rather than shared logins, two factor authentication on the systems that support it, and regular backups.
No system is perfectly secure, and anybody who tells you otherwise is selling something. If a breach happens that is likely to risk your rights and freedoms, we will report it to the Data Protection Commission within seventy two hours of becoming aware of it and tell you directly where the risk to you is high.
11

Your rights

These belong to you under the GDPR. They are free to use, and we will not treat you differently for using them.
Article 15

Access

Ask for a copy of the personal data we hold about you, and an explanation of what we do with it.
Article 16

Rectification

Have anything inaccurate corrected, and anything incomplete filled in.
Article 17

Erasure

Ask us to delete data, subject to records we are legally required to retain.
Article 18

Restriction

Have us pause processing while a dispute about accuracy or lawfulness is resolved.
Article 20

Portability

Receive data you gave us in a machine readable format, or have it sent to another provider.
Article 21

Objection

Object to processing based on legitimate interests, and to direct marketing at any time.
Article 7

Withdraw consent

Take back consent whenever you like, without affecting what was lawful before.
Article 77

Complain

Raise it with the Data Protection Commission, whether or not you contacted us first.

Making a request

01
Email us and say which right you want to use. Plain wording is fine, and you do not need to quote an article number.
02
We may ask you to confirm who you are, so that we are not handing your data to somebody else.
03
We respond within one month. If the request is complex we can extend by two further months, and we will tell you why within the first month.
04
If we cannot do what you asked, we explain the reason rather than going quiet, and we tell you how to challenge it.
Send it to

Data requests

ECSTASY BLISS LIMITED
VENTURE HUB
136 CAPEL STREET
DUBLIN, D01 T2C9
IRELAND
PRIVACY@ECSTACYBLISS.COM
12

Marketing

We only send marketing email to people who asked for it, or to existing clients about services similar to the ones we already provided, which is what the ePrivacy Regulations allow. Every message carries an unsubscribe link that works immediately, and unsubscribing does not stop the ordinary emails about work in progress.
13

Children

Our services are sold to businesses and are not directed at children. Ireland sets the digital age of consent at sixteen, and we do not knowingly collect personal data from anyone under that age. If you believe a child has given us data, tell us and we will remove it.
14

Automated decisions

We do not make decisions about you by automated means alone, and we do not profile you in a way that produces legal effects or anything similarly significant. A person reads every enquiry and a person decides whether we take a project on.
15

Changes to this policy

We update this page when what we do changes, when we add a service, or when the law moves. The version number and date at the top of the contents list tell you which one you are reading. Where a change materially affects you, we will say so rather than leaving you to spot it.
Ref. Contact.Data

Ask us first. Then ask the regulator.

If something about your data concerns you, we would rather hear it directly and fix it. You are not obliged to come to us first, and your right to complain to the Data Protection Commission stands either way.
Controller

Ecstasy Bliss Limited

VENTURE HUB, 136 CAPEL STREET
DUBLIN, D01 T2C9, IRELAND
COMPANY NUMBER 822863
PRIVACY@ECSTACYBLISS.COM
Supervisory Authority

Data Protection Commission

6 PEMBROKE ROW
DUBLIN 2, D02 X963
IRELAND
WWW.DATAPROTECTION.IE
IF YOU LIVE IN ANOTHER EU STATE YOU MAY ALSO COMPLAIN TO YOUR OWN NATIONAL AUTHORITY