Document completion notice
Document control
| Document | Privacy Policy |
|---|---|
| Version | 1.2 Draft |
| Effective date | 29th April 2026 |
| Owner | Viamation |
| Review cycle | At least annually and whenever processing activities materially change |
Contents
- 1. Introduction
- 2. Who we are
- 3. Scope of this policy
- 4. Our data protection roles
- 5. Personal data we collect
- 6. How we collect personal data
- 7. Why we use personal data
- 8. Lawful bases
- 9. Customer data processed through the platform
- 10. Sharing personal data
- 11. Service providers and integrations
- 12. International transfers
- 13. Data retention
- 14. Information security
- 15. Your data protection rights
- 16. Exercising your rights
- 17. Direct marketing
- 18. Cookies and similar technologies
- 19. Children's data
- 20. Complaints
- 21. Changes to this policy
- 22. Contact details
- Appendix A - Processing summary
1. Introduction
Viamation is committed to handling personal data lawfully, fairly, transparently and securely. This Privacy Policy explains how we collect, use, share, retain and protect personal data when individuals visit our website, contact us, consider or purchase our services, administer a customer account, or use the Viamation platform. We process personal data in accordance with applicable data protection law, including the General Data Protection Regulation (GDPR) and Irish data protection legislation. This policy should be read with our Cookie Policy, Website Terms of Use, Data Processing Agreement where applicable, and Security & Trust statement.
2. Who we are
Viamation provides operational automation software and related services for organisations. Our services may include the Viamation platform, Workforce, PriceWatch, Communications, Customer Engagement and Operational Intelligence, depending on the customer's agreed configuration. For the purposes of this policy, "Viamation", "we", "us" and "our" refer to Viamation of 57 Main Street, Dundrum, Dublin 14, D14 X0T8, Ireland.
3. Scope of this policy
This policy applies to personal data processed by Viamation for its own business purposes, including information relating to website visitors, prospective customers, customer contacts, authorised platform users, suppliers and other business contacts. It also explains our role where a customer uses the Viamation platform to process personal data about its employees, customers, suppliers or other individuals. In that situation, the customer will usually decide why and how the data is used.
4. Our data protection roles
Viamation acts as a data controller when we decide the purposes and means of processing. This commonly applies to website enquiries, sales activity, account administration, billing contacts, service communications, security administration and our own business records. Viamation generally acts as a data processor when we handle personal data on a customer's documented instructions through the platform. The customer remains responsible for deciding the lawful basis, providing required notices, managing individual rights and ensuring that the data entered into the service is appropriate and lawful. The applicable customer agreement and Data Processing Agreement describe these responsibilities in more detail.
5. Personal data we collect
The personal data we collect depends on how you interact with Viamation. It may include name, job title, organisation, business contact details, account details, correspondence, enquiry information, billing and transaction records, support requests, meeting notes and service preferences. When you use our website or platform, we may collect technical and usage information such as IP address, browser and device information, login and authentication records, timestamps, pages or features used, error logs, security events and cookie preferences. Where a customer configures the platform to process information about its own staff, customers, suppliers or operations, the categories of data are determined by that customer and the services it chooses to use. Viamation does not require customers to provide special category data unless this is expressly agreed and necessary for the service.
6. How we collect personal data
We collect personal data directly when you contact us, complete a form, request information or a demonstration, enter into a contract, create or use an account, communicate with our team, or provide information through the platform. We may also receive information from your employer or organisation, authorised colleagues, business partners, service providers, publicly available business sources, and integrations that a customer chooses to connect to the platform. Technical information may be collected automatically through logs, security tools, cookies and similar technologies, subject to the choices described in our Cookie Policy.
7. Why we use personal data
We use personal data to respond to enquiries, assess customer needs, provide demonstrations and proposals, enter into and manage contracts, configure and deliver services, administer accounts, provide support, issue invoices, maintain records and communicate about service matters. We also use personal data to secure and operate the website and platform, authenticate users, investigate errors or misuse, improve reliability and usability, manage suppliers, comply with legal obligations, establish or defend legal claims, and protect Viamation, customers and users. Where permitted, we may use business contact details to provide relevant information about Viamation services. Individuals can opt out of direct marketing at any time.
8. Lawful bases
We rely on one or more lawful bases depending on the context. These may include taking steps at your request before entering a contract, performing a contract, complying with a legal obligation, pursuing our legitimate interests, or obtaining consent where consent is required. Our legitimate interests may include operating and improving our business and services, securing systems, responding to business enquiries, maintaining customer relationships, preventing misuse and managing legal or commercial risk. We balance these interests against the rights and interests of the individuals concerned. Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect processing that was lawful before consent was withdrawn.
9. Customer data processed through the platform
Customers decide what personal data they place in the Viamation platform and how they use it. Viamation processes that data only to provide, secure, support and improve the contracted service, and as otherwise permitted by the customer agreement and applicable law. We do not use customer data for unrelated advertising, sell it, or determine independent purposes for it unless this is clearly disclosed and legally permitted. Requests concerning customer-controlled data should normally be directed to the relevant customer. We will assist customers with valid requests where required by our Data Processing Agreement.
10. Sharing personal data
We may share personal data with authorised Viamation personnel, the organisation you represent, professional advisers, insurers, auditors, payment and banking providers, public authorities where required, and parties involved in a business reorganisation or transaction subject to appropriate safeguards. We disclose only the information reasonably necessary for the relevant purpose. We do not sell personal data.
11. Service providers and integrations
Viamation may use selected service providers for hosting, communications, email, authentication, support, analytics, payment processing, document handling, monitoring and other operational functions. Where providers process personal data on our behalf, we use appropriate contractual and organisational safeguards. A current list of material subprocessors may be provided to customers where required by the applicable agreement. Customers may choose to connect third-party services or integrations. Those providers may process information under their own terms and privacy notices, and customers should assess them before use.
12. International transfers
We seek to process and host personal data within Ireland or the European Economic Area where reasonably practicable. Some service providers or support arrangements may involve access from, or transfers to, countries outside the EEA. Where a restricted transfer occurs, we use an appropriate legal mechanism, such as an adequacy decision, approved standard contractual clauses, or another safeguard permitted by data protection law. Further information may be requested using the contact details below.
13. Data retention
We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, including contractual, operational, security, legal, accounting and dispute-resolution requirements. Retention periods depend on the type of information and the context. Customer data is retained and deleted in accordance with the customer agreement, Data Processing Agreement and platform configuration. Certain records may be kept longer where required by law or where needed to establish, exercise or defend legal claims. When personal data is no longer required, it is deleted, anonymised or securely archived, subject to technical backup cycles and legal obligations.
14. Information security
Viamation uses proportionate technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse, alteration or disclosure. Measures may include controlled access, authentication, encrypted communications, secure hosting, backups, logging, monitoring, supplier controls and incident-response arrangements. No system can guarantee absolute security, but controls are reviewed as our services and risks develop. Additional information is provided in our Security & Trust statement.
15. Your data protection rights
Subject to applicable law, you may have the right to request access to your personal data, correction of inaccurate data, deletion, restriction of processing, objection to certain processing, and receipt or transfer of data in a portable format. Where processing is based on consent, you may withdraw consent. You may also object to direct marketing at any time. These rights are not absolute. We may need to verify your identity, clarify the request, protect the rights of others, or retain information where the law permits or requires us to do so.
16. Exercising your rights
To exercise a right concerning data controlled by Viamation, contact info@viamation.ie and describe the information or processing concerned. Where your request relates to data controlled by a Viamation customer, please contact that organisation directly. If we receive such a request, we may refer it to the relevant customer and assist them as required. We aim to respond within the time required by law. We will explain any lawful extension, refusal or limitation.
17. Direct marketing
We may send relevant business communications to existing or prospective business contacts where permitted by law. Marketing messages will identify Viamation and provide a clear way to opt out. You can unsubscribe by using the link in the message or contacting us. Service, security, billing and contractual communications are not marketing and may still be sent where necessary.
18. Cookies and similar technologies
Our website may use cookies and similar technologies for essential operation, security, preferences and, where consent has been provided, analytics or other optional purposes. Our Cookie Policy explains the categories used, the consent choices available and how to manage preferences.
19. Children's data
Viamation services are intended for organisations and business users, not for children acting in a personal capacity. We do not knowingly collect personal data directly from children through the public website. A customer may use the platform in a context involving information about children only where this is lawful, necessary, appropriately safeguarded and covered by the customer's own notices and responsibilities.
20. Complaints
Please contact us first if you have a concern about how Viamation handles personal data. We will review the matter and respond appropriately. You also have the right to complain to the Data Protection Commission in Ireland or another competent supervisory authority. Contact details for the Data Protection Commission are available on its official website.
21. Changes to this policy
We may update this policy when our services, processing activities, suppliers, legal requirements or regulatory guidance change. The current version will be published with its effective date. Material changes may also be communicated directly where appropriate.
22. Contact details
Data controller: Viamation Postal address: 57 Main Street, Dundrum, Dublin 14, D14 X0T8, Ireland General email: info@viamation.ie
Appendix A - Processing summary
The table below provides a concise summary of Viamation's main processing activities. It should be checked and updated against actual practice before publication.
| Activity | Typical data | Purpose and lawful basis | Typical retention |
|---|---|---|---|
| Website enquiries and sales | Name, role, organisation, contact details and correspondence | Respond to enquiries and manage prospective customer relationships; pre-contract steps and legitimate interests | While the enquiry is active and for a proportionate follow-up period |
| Customer administration | Business contacts, account details, contracts and billing records | Manage contracts, accounts, service delivery and payments; contract, legal obligation and legitimate interests | Contract term plus applicable legal and claims periods |
| Platform users | Identity, login, permissions, activity and support records | Provide, secure and support the service; contract and legitimate interests | Account term plus proportionate security and support retention |
| Customer-controlled platform data | Data selected and uploaded by the customer | Deliver the configured service on customer instructions; customer-determined basis and Viamation acts as processor | As specified in the customer agreement and Data Processing Agreement |
| Security and service logs | IP address, device, authentication, event and error data | Protect systems, investigate incidents and maintain reliability; legitimate interests and legal obligation where applicable | For a proportionate security and operational period |
| Marketing communications | Business contact details and communication preferences | Provide relevant service information; consent or legitimate interests, as applicable | Until opt-out or the contact is no longer relevant |