Privacy notice

How we handle your data

Plain English. No dark patterns. We collect the minimum we need, store it in the EU, and delete it when we're done with it.

Version 4 · Effective 23 September 2026

1. Who we are

MTMN Digital ("MTMN", "we", "us", "our") is the data controller for personal data submitted through mtmn.ie and its subdomains. We are an independent studio based in Co. Cork, Republic of Ireland.

Contact for data-protection matters: hello@mtmn.ie. Postal address available on request via the same email.

2. What we collect, why, and how long we keep it

Personal data we collect, why we collect it, the lawful basis for processing, and how long we retain it.
DataWhyLawful basisRetention
Name, email, phone, business type, the free-text "anything you'd like us to know" fieldTo respond to your booking request and prepare for the call you've bookedContract / pre-contractual measures (Art. 6(1)(b) GDPR)24 months from submission if you don't become a client; for the lifetime of the engagement plus 7 years for tax records (Revenue requirement) if you do
IP address and basic request metadata (timestamps, user agent)Security: rate-limiting, abuse detection, audit logLegitimate interest (Art. 6(1)(f)), running a service that isn't trivially abused≤ 12 months in audit log; ≤ 24 hours in rate-limit windows
Login email + password hash for staff portal usersOperating the staff dashboardContract / employmentFor the duration of the engagement; account deleted on departure
Google Ads tag (loads only after you click Accept in the cookie bar, then runs on the pages you visit): your IP address, browser user-agent, the Google Ads click identifier (gclid) if you arrived from a Google ad, and the URL of the page are sent to Google. Cookies (_gcl_au, NID) are set in your browser to attribute the booking back to the originating ad clickTo measure which Google Ads spend actually results in booked consultations, so we can stop running ads that don't workConsent (Art. 6(1)(a) GDPR / Reg. 5(3) of the European Communities (Electronic Communications Networks and Services) (Privacy and Electronic Communications) Regulations 2011). The Google tag is not loaded at all until you accept: before that, no request is made to Google, no cookies are set and no identifiers are sent. You can withdraw consent at any time with the Cookie settings button in the footerPer Google's published retention: click-identifier records up to 13 months; the _gcl_au cookie expires 90 days after your last interaction with the site. None of this is stored on MTMN's own servers
Meta Pixel and Conversions API (only after you click Accept in the cookie bar): the Pixel sends your IP address, browser user-agent and the URL of each page you visit to Meta, and sets the _fbp cookie (plus _fbc if you arrived from a Facebook or Instagram ad). If you then send an enquiry from one of our industry pages, our server also tells Meta a lead came in, with your email and phone number hashed (SHA-256) so Meta never receives them in plain text, and the same cookie identifiersTo see which Facebook and Instagram ads actually produce enquiries, so we can stop paying for the ones that don'tConsent (Art. 6(1)(a) GDPR / Reg. 5(3) of the 2011 ePrivacy Regulations). Nothing is loaded from or sent to Meta, by your browser or by our server, unless you have accepted. You can withdraw consent at any time with the Cookie settings button in the footerPer Meta's published retention; the _fbp and _fbc cookies expire 90 days after your last visit. None of this is stored on MTMN's own servers

Other than the Google Ads tag and the Meta Pixel described above, which load only if you accept, this site runs no analytics, no behavioural tracking, and no advertising pixels. We do not sell, rent, or trade personal data to anyone, ever.

3. Who else processes your data on our behalf

Personal data is stored and processed by the following sub-processors. All have been chosen because they are GDPR-compliant. All host data inside the EU/EEA except Google LLC and Meta Platforms, Inc., described below.

4. International transfers

Personal data submitted when you book a call is stored in the European Economic Area (AWS Europe, Ireland) and is not transferred outside the EEA. The exceptions are the Google Ads tag and Meta data described in section 2, collected only if you accept, which are processed by Google LLC and Meta Platforms, Inc. in the United States. Those transfers rely on the EU-US Data Privacy Framework adequacy decision (Art. 45 GDPR, in force since July 2023), in which both companies are certified participants. If we ever introduce another sub-processor outside the EEA we will rely on a Chapter V transfer mechanism (e.g. Standard Contractual Clauses) and update this notice.

5. Your rights

Under the GDPR you have the right to:

To exercise any of these rights, email hello@mtmn.ie. We will respond within one month and won't charge you for it.

Right to complain If you're unhappy with how we handle your data, you can lodge a complaint with the Irish Data Protection Commission at dataprotection.ie. We'd appreciate the chance to fix things first, but it's your right either way.

6. Security

Personal data is encrypted in transit (TLS 1.2+) and at rest (provider-managed encryption). Access to the staff dashboard is protected by hashed passwords (PBKDF2 via werkzeug) and short-lived signed sessions. We rate-limit public endpoints and write an audit log of staff access to records containing personal data.

7. Automated decision-making

None. No decision affecting you is made automatically by this website.

8. Changes to this notice

If we change this notice in any material way, we will publish a new version with an updated effective date and version number at the top of this page. The current version applies to all data we hold; older versions are archived for reference.

9. Contact

Questions, requests, or complaints: hello@mtmn.ie.