Your information

Privacy
notice.

This notice explains how SMT Data Analytics handles personal data when you visit this website, use an interactive AI service, complete the readiness checklist, make an enquiry or become a client.

Last updated: 21 August 2026

01

Who we are

SMT Data Analytics is an independent data, AI and automation consultancy based in Cork, Ireland. For the personal data described in this notice, SMT Data Analytics is normally the data controller.

For some client projects, SMT Data Analytics processes personal data only on the client's documented instructions. In that situation, the client is normally the controller and SMT Data Analytics acts as its processor under separate contractual terms.

Questions or requests can be sent to:

Sean Twomey
SMT Data Analytics
Cork, Ireland
sean@smtdataanalytics.com
+353 85 226 3896
02

Personal data we collect

When you contact us

If you email, telephone or connect through LinkedIn, we may receive your name, contact details, organisation, job title, enquiry and other information you choose to provide.

When you use the planned website chatbot

We are preparing to add an AI chatbot to this website. Once it is available, your message will be processed to generate a response. This may include your name, email address and enquiry details. Please do not submit sensitive personal data unless we specifically ask you to use an agreed secure process.

When you attend an online meeting

We may use Read AI as a visible meeting assistant in Zoom, Microsoft Teams or Google Meet. It may process meeting audio and video, participant names and email addresses, calendar details and meeting access information. It produces a transcript, summary, highlights and action items and, depending on our settings, may retain a recording with the report.

When we provide services

For prospective and current clients, we may process business contact details, correspondence, meeting notes, requirements, contracts, invoices and payment records. Project work may involve client-supplied personal data under separate data-processing terms.

When you use this website

Hosting infrastructure may process limited technical information needed to deliver and secure the site, including IP address, browser and device information, requested pages, timestamps and security logs. We do not currently use website accounts, behavioural advertising or analytics tracking.

03

How and why we use personal data

PurposeLegal basis

Respond to enquiries and discuss possible work

Legitimate interests; steps requested before a contract

Deliver projects and manage contracts

Performance of a contract; legitimate interests

Provide the website AI chatbot once launched

Legitimate interests in responding efficiently

Record, transcribe and summarise agreed online meetings

Legitimate interests in accurate notes and follow-up; performance of a contract. We will seek consent where required.

Use appropriately configured AI tools for project work

Performance of a contract; legitimate interests

Process payments, invoices and financial records

Contract; legal obligations; fraud-prevention interests

Operate and protect systems

Legitimate interests in security and reliability

Establish, exercise or defend legal claims

Legitimate interests; legal obligations where applicable

Where consent is relied on, you may withdraw it at any time. Withdrawal does not affect earlier lawful processing.

04

How we use artificial intelligence

Planned website chatbot

We are preparing to add an AI chatbot to this website. Once available, it will process your message to produce a response. The interface will identify that you are interacting with AI. You can contact us directly by email or telephone instead.

AI meeting assistant

We may use Read AI to record, transcribe and summarise online meetings. Read appears as a meeting participant and normally posts an in-meeting notice. You can ask us not to use it, remove it like another participant, or use Read's available opt-out control. We will not use it for a meeting where recording would be inappropriate.

Read AI says meeting content is not used to train its general models unless the account holder explicitly opts in. We do not opt in to that training. Recording, transcript and report retention depends on the account settings used for the meeting. You can ask us to delete a report or recording; where we do not own the report, we will help direct the request to its owner or Read AI.

AI-assisted project work

We may use business or API versions of tools supplied by providers such as Anthropic, OpenAI and Microsoft to support analysis, research, drafting and coding. The exact tools and safeguards depend on the project and agreed client instructions. Personal data is minimised, appropriate contractual terms are used where required, and outputs are reviewed by a person before being relied upon or delivered.

Payment fraud prevention

We use Stripe to process payments. Stripe may use automated fraud-prevention tools to assess transaction and device information. It may act as a processor or an independent controller depending on the activity and its terms.

What we do not do

We do not use AI to make solely automated decisions about website visitors or clients that produce legal or similarly significant effects. We do not intentionally use AI for emotion recognition, biometric categorisation or social scoring. We do not intentionally enter special-category personal data into general-purpose AI tools without an agreed purpose, appropriate safeguards and any required client instruction.

05

Providers and other recipients

We do not sell personal data. Where relevant, it may be shared with website hosting, CRM, email, calendar, cloud, communications, IT-security, AI and payment providers; professional advisers; project contractors under appropriate terms; authorities where required by law; or a business successor.

Services that may be used

ProviderPurpose and possible data

HighLevel / GoHighLevel

CRM, client management and, where enabled, chatbot services; contact and conversation data

Read AI

Online-meeting recording, transcription and summaries; audio, video, participant and calendar details, transcripts, reports and action items

Anthropic

AI-assisted project work under the applicable account and settings

OpenAI

AI-assisted project and coding work under applicable business or API terms

Microsoft

Azure infrastructure and productivity tools; project data, documents and communications

Google

Workspace services and web fonts; communications and limited technical request data

Stripe

Payments and fraud prevention; billing, transaction, card and device information

This website requests font files from Google Fonts. Google may receive technical request information such as your IP address and browser details. External links are governed by those services' own notices.

06

International transfers

Some providers may process personal data outside the European Economic Area, including in the United States. Where Chapter V of the GDPR applies, we use an appropriate transfer mechanism for the relevant provider and data.

This may include a European Commission adequacy decision, the EU–US Data Privacy Framework for an eligible and currently certified US legal entity, or Standard Contractual Clauses with supplementary safeguards where appropriate. Arrangements are reviewed against the provider, product, legal entity and account terms actually used rather than assumed from a brand name.

You may contact us for further information about the safeguard relevant to your data.

07

How long we keep data

We retain personal data only as long as reasonably necessary for its purpose, including legal, accounting and dispute-resolution requirements.

  • General enquiries and chatbot conversations: normally up to 12 months after the last meaningful contact, unless a longer period is justified.
  • Meeting recordings, transcripts and reports: kept only as long as needed for agreed notes, follow-up or the related client work, then deleted or anonymised unless a legal or contractual reason requires longer retention. Read AI's storage depends on the settings used; its published policy permits some audio/video retention for up to two years, while disabling playback storage deletes the underlying recording after the report is generated.
  • Client and project records: normally for the engagement and up to six years afterwards, subject to contractual, tax, insurance and legal requirements.
  • Invoices and accounting records: for the period required by Irish tax and company law.
  • Technical and security logs: according to the configured provider period and only as long as needed.
  • Checklist answers: stored in your browser until you reset the checklist or clear this site's browser data. We do not receive those answers through the checklist.
08

Security

We use proportionate technical and organisational safeguards designed to protect personal data against accidental loss, unauthorised access, alteration or disclosure. Access is limited to people and providers who need it for legitimate purposes.

Where AI tools process project data, we use account types, settings and contractual protections appropriate to the work. Business/API providers may offer encryption, data-processing terms, retention controls and no model training by default; availability depends on the provider, plan and configuration.

No system is completely secure. If a personal-data breach occurs, we will assess it, document the decision and notify the Data Protection Commission and affected people where the relevant legal thresholds are met.

09

Your data-protection rights

Depending on the circumstances, you may have rights to access, correct, delete, restrict or object to processing; receive certain data in a portable format; withdraw consent; and complain to a supervisory authority.

These rights are not absolute. Email sean@smtdataanalytics.com to exercise a right. We may verify your identity and normally respond without undue delay and within one month, subject to any lawful extension.

Data Protection Commission
6 Pembroke Row, Dublin 2, D02 X963, Ireland
www.dataprotection.ie ↗
10

Cookies and local browser storage

This website does not currently set analytics, advertising or preference cookies and does not use browser storage for behavioural tracking. Hosting may use strictly necessary technical measures.

The AI compliance readiness checklist uses browser local storage to remember the organisation name, answers and notes on that device. These entries are not uploaded or sent to SMT Data Analytics. Remove them with Reset checklist or by clearing this site's browser data. The PDF is generated locally in your browser.

Because no non-essential cookies or tracking are intentionally used, the site does not currently display a consent banner. If that changes, this notice and consent controls will be updated before the technology is enabled.

11

Changes to this notice

We may update this notice when our services, providers or legal obligations change. The latest version will appear here with its effective date. Material changes may also be communicated directly where appropriate.