Last updated: 17 August 2026
This policy explains what personal data One Stop Future Consultants Limited collects, why we hold it, who it is shared with and what rights you have over it.
Who We Are
One Stop Future Consultants Limited is the data controller for the personal data described below.
- Registered in: Ireland, Companies Registration Office, number 725318
- Registered office: Nawab Ali Building, Main Street, Ballaghaderreen, County Roscommon, Ireland
- Data protection contact: [email protected]
As an Irish company, our processing is governed by the EU General Data Protection Regulation and the Data Protection Act 2018, and our supervisory authority is the Data Protection Commission.
Two Different Roles
This distinction decides which rules apply, so it is set out first.
For our own business contacts, enquiries and website visitors we are the controller. We decide what is collected and why, and this policy governs it.
For personal data held inside a client’s own systems that we work on during a project, we are a processor acting on that client’s instructions. That processing is governed by the data processing agreement signed with the client, not by this policy, and the client remains the controller. If your data sits in a system a client of ours asked us to build, your rights are exercised against them and we will support them in answering you.
What We Collect
If you contact us. Your name, email address, employer, and whatever you choose to tell us about your project. If a call follows, our notes from it.
If you become a client. The contact details of the people we deal with, the commercial terms, the billing details, and the correspondence that accumulates over the engagement.
If you visit the site. The pages you view and basic technical information such as approximate location, device and browser. We keep this deliberately minimal. There is no advertising on these sites and no social media tracking embedded in them.
Access credentials. During a project we are often granted access to a client’s systems. Where that involves accounts issued to us, we hold the credentials for the life of the engagement and return or destroy them at the end of it.
We do not collect special category data, and we ask you not to send it to us in an enquiry.
Why We Process It, and the Lawful Basis
| Purpose | Lawful basis |
|---|---|
| Replying to an enquiry and scoping possible work | Legitimate interests, and steps taken at your request before a contract |
| Delivering a project and supporting it afterwards | Performance of a contract |
| Invoicing, accounting and tax records | Legal obligation |
| Keeping records of what was agreed and delivered | Legitimate interests, and legal obligation |
| Understanding how the site is used | Legitimate interests |
Where we rely on legitimate interests, that interest is in operating and improving a consultancy business, and we have weighed it against your rights. You may object at any time using the address above.
Who We Share It With
- Service providers who host our systems, deliver our email and process our accounts, each under a written contract restricting what they may do with the data.
- Professional advisers, such as accountants or solicitors, where genuinely necessary.
- Statutory bodies, including the Revenue Commissioners, where the law requires it.
We do not sell personal data. We do not share it for advertising. We do not name clients publicly without written permission, which is why there are no logos or case studies on this site.
Transfers Outside the EEA
This is set out plainly because it matters.
Our engineering work is delivered from Ireland and Pakistan. Pakistan is not covered by a European Commission adequacy decision, so personal data accessible to our team there is transferred under Standard Contractual Clauses approved by the Commission, supported by a transfer impact assessment. You may request a copy of those safeguards at the address above.
Where a client requires that no personal data leaves the European Union, we can staff and architect the work accordingly. Raise it at the first conversation, because it changes the design rather than the paperwork.
How Long We Keep It
- Enquiries that do not become work: 12 months from the last contact, unless you ask sooner.
- Client records and correspondence: 6 years after the engagement ends, which reflects the period in which a claim could be brought.
- Accounting records: 6 years, as required by Irish tax law.
- Access credentials issued to us: returned or destroyed at the end of the engagement.
- Website analytics: no longer than 14 months.
Your Rights
You have the right to be told what we hold, to receive a copy, to have inaccurate data corrected, to have data erased where there is no continuing reason to hold it, to restrict or object to processing, and to receive certain data in a portable format. Where we rely on consent you may withdraw it at any time.
To exercise any of these, email [email protected]. We respond within one month and there is no charge.
Cookies
We use only what is needed to make the site work. There are no advertising cookies and no social media trackers on any of our sites.
Complaints
Tell us first, so we have a chance to put it right.
You also have the right to complain to the Data Protection Commission, the Irish supervisory authority, at 21 Fitzwilliam Square South, Dublin 2, D02 RD28.
Changes
We update this policy when our processing changes. The date at the top shows the current version. Where a change materially affects you, we will tell you directly rather than rely on you noticing.