Privacy Policy

Effective Date: 10 March 2025
Last Updated: 10 March 2025

B.H Associates  Ltd (“we,” “us,” or “our“) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your personal data when you visit our website (https://bhassociates.ie) or interact with us. It also outlines your rights under the EU General Data Protection Regulation (“GDPR“) and how you can exercise those rights. By using our website or services, you agree to the practices described in this policy.

Types of Data Collected

We collect personal data necessary to provide our services and improve your experience. The types of data we may collect include:

  • Contact Information: Your name, email address, and any other contact details you provide (for example, when filling out a contact form or emailing us). This may also include information you choose to share in messages (such as your organization or phone number, if provided).
  • Technical Information: Your IP address, and other browsing details collected through our analytics tools and cookies (such as browser type, device information, and pages visited on our site). This technical data helps us understand how you use our website.

We do not intentionally collect any sensitive personal data (such as health information, racial or ethnic origin, etc.) through our website. We ask that you refrain from submitting such sensitive information in any contact forms or communications with us.

Data Collection Methods

We collect personal data through the following methods:

  • Directly from You: When you interact with our site or communicate with us, you may provide personal data. For example, you provide your name and email address when filling out a contact form, signing up for updates, or corresponding with us by email or phone. We use this information to respond to your inquiries and provide requested services or information.
  • Automatically Through Website Analytics: When you visit our website, certain data is collected automatically via cookies and similar tracking technologies. We use website analytics tools that gather information about your usage of the site (e.g., pages viewed, time spent on the site, how you navigated to our site). This data may include your IP address and browser information. The collection of this information helps us analyze website traffic and user behavior in order to improve our website and services.

Third-Party Services Used

We utilize trusted third-party services to support our website functionality, analytics, and customer relationship management. These third-party providers collect or process data on our behalf in accordance with our instructions and this Privacy Policy. The key third-party services we use are:

  • Google Analytics: We use Google Analytics to track and report website traffic and user interactions on our site. Google Analytics uses cookies and similar technologies to collect information such as your IP address, browser type, pages visited, and time spent on pages. This information is aggregated and anonymized by Google Analytics (for example, through IP anonymization) to help us understand website usage and improve the user experience. Google acts as a data processor for this information. Please note that Google may process analytics data on servers outside the EU (e.g., in the United States), but we have configured our Google Analytics to comply with GDPR and rely on Google’s data protection commitments. You can learn more in Google’s own Privacy Policy and even opt-out of Google Analytics (see the Cookies section below for opt-out options).
  • HubSpot: We use HubSpot as our Customer Relationship Management (CRM) and marketing platform. If you submit a contact form or sign up for communications, your contact information (like name and email) is stored in HubSpot. HubSpot helps us manage our communications with you, track inquiries, and improve our customer service. HubSpot may also employ cookies on our site to recognize repeat visitors and analyze their interactions (for example, if you have previously filled a form, HubSpot’s cookie can help recall your preferences). Any data collected via HubSpot is used solely for our business purposes (such as responding to your requests or sending you relevant information, only in accordance with your consent or other legal basis). HubSpot, a U.S.-based company, maintains appropriate safeguards for data it processes, including compliance with GDPR requirements. More details can be found in HubSpot’s Privacy Policy on their website.

We have agreements in place with these providers (such as Data Processing Addendums) to ensure they protect your data and only use it for the specific purposes we’ve outlined. These third parties cannot use your personal data for their own marketing or purposes outside of what we instruct. If you would like more information about how these services handle data, please refer to their respective privacy notices.

Purpose of Data Processing

We process the collected personal data for specific and legitimate purposes. The main purposes for which BH Associates uses your data are:

  • Business Communication: To communicate with you in response to your inquiries or requests. For example, if you fill out our contact form or email us, we will use your name and email address to reply and provide the information or support you requested. We may also use your details to discuss our services, schedule meetings, or otherwise manage our business relationship with you.
  • Website Analytics: To analyze how our website is used and to monitor the performance of our site. By understanding which pages are most visited, how users navigate the site, and other usage patterns, we can identify areas for improvement. This helps us ensure our website content is relevant, user-friendly, and functioning properly. Analytics also help us diagnose technical issues and maintain security (for example, using IP addresses to detect and prevent malicious activities).
  • Service Improvement and Development: To improve our services, offerings, and overall user experience. The feedback and data we collect (both directly from you and via analytics) guide us in enhancing our consulting services and website functionality. For instance, we might analyze inquiry trends to develop new services or use website usage data to refine the information and resources we provide online. Our goal is to better tailor our services to our clients’ needs and continuously improve our professional offerings.

We will only use your personal data for the purposes described above or for closely related purposes. If we need to use your data for an unrelated new purpose, we will inform you and explain the legal basis for that new processing, and obtain your consent if required.

Legal Basis for Processing

Under the GDPR, we must have a valid legal basis to process your personal data. BH Associates relies on the following legal grounds:

  • Legitimate Interests (GDPR Article 6(1)(f)): In most cases, we process your data because it is in our legitimate business interests to do so, and we have determined that our processing does not override your privacy rights. For example, when you contact us via the website, it is in our legitimate interest to use your contact information to respond to you and maintain our business correspondence. Similarly, using analytics to improve our website and services is a legitimate interest that generally does not harm your rights or freedoms (especially since such data is often aggregated or anonymized). We always consider your rights and interests before relying on legitimate interests and will not use your data for activities where your rights take precedence.
  • Consent (GDPR Article 6(1)(a)): In certain situations, we will ask for your consent to process your personal data. For instance, if we use non-essential cookies (like Google Analytics or HubSpot tracking cookies) or if we ever send you marketing or newsletter emails, we will do so based on your consent (e.g., through our cookie consent banner or an opt-in form). Where consent is our legal basis, you have the right to withdraw that consent at any time. Withdrawing consent will not affect the lawfulness of processing done before the withdrawal. For example, you can opt out of analytics cookies or unsubscribe from a mailing list at any time, and we will stop processing your data for that purpose going forward.

In addition to the above, if we ever need to process personal data to comply with a legal obligation (Article 6(1)(c)) or to perform a contract or pre-contractual steps (Article 6(1)(b)), we will do so. For instance, if you become a client, processing your data might be necessary to fulfill our consulting contract with you. We will always identify the appropriate legal basis for processing your data and ensure we meet the conditions of that basis.

Data Retention

We will retain your personal data only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, or to comply with legal and contractual obligations. How long we keep data depends on the type of information and the purpose for which we collected it:

  • Contact and Communication Data: If you contact us (for example, via a form or email), we will retain your information and our response for as long as needed to address your inquiry and any follow-up issues. If you become a client or engage our services, we may retain your data for the duration of our business relationship and for a reasonable period thereafter (for instance, to maintain records of our communications or projects, or as required by law for accounting and tax purposes). If you do not become a client, we will periodically review and securely delete personal data from inquiries that are no longer needed.
  • Analytics Data: Data collected via Google Analytics, HubSpot, and cookies is typically retained for a specific retention period configured within those tools. For example, Google Analytics allows us to set a retention period (often 14 months or as adjusted by us) for user-level and event-level data. After the retention period, the data may be automatically deleted or anonymized. We use analytics data in aggregate form, and we do not maintain personally identifiable analytics information longer than necessary.
  • Legal Retention Requirements: In some cases we may need to keep certain data for a longer period if required by applicable laws or regulations. For example, business records, invoices, or contractual agreements might be retained for a number of years under Irish law. During such retention, your data will continue to be protected in accordance with this Privacy Policy.

When the retention period for personal data expires, or if you request erasure and we have no lawful basis to retain it, we will either delete your data securely or anonymize it (so that it can no longer be associated with you). If it is not feasible to delete data (for example, because it is stored in secure backups), we will ensure that appropriate measures are in place to prevent any further active processing of that data until deletion is possible.

Your Rights Under GDPR

As an individual in the European Union (or in a jurisdiction with similar data protection laws), you have specific rights regarding your personal data. BH Associates is committed to respecting your rights and facilitating your exercise of them. Under the GDPR, you have the following rights:

  • Right of Access: You have the right to request confirmation of whether we process personal data about you, and if so, to request a copy of the personal data we hold about you. We will provide you with a copy of your data, along with information about how we use it, in a transparent and easily understandable format.

  • Right to Rectification: If any of the personal data we have about you is inaccurate or incomplete, you have the right to request that we correct or update it. We encourage you to contact us to keep your information up to date (for example, if you change your email address).

  • Right to Erasure: Also known as the “right to be forgotten,” this right allows you to request that we delete your personal data. You can ask us to erase your data, for instance, if it is no longer necessary for the purposes for which it was collected, if you have withdrawn your consent (where consent was the basis), or if you believe our processing is unlawful. We will honor valid erasure requests, provided we do not have a compelling legal reason to retain the data (e.g., a legal obligation or the establishment, exercise, or defense of legal claims).

  • Right to Restrict Processing: You have the right to request that we restrict or suspend the processing of your personal data under certain circumstances. This might apply if you contest the accuracy of your data (while we verify it), or if you object to our processing and we are considering your request. During the restriction period, we will store your data securely and not use it (except to the extent allowed by GDPR, such as to protect rights or comply with legal obligations).

  • Right to Data Portability: For data you provided to us and which we process by automated means based on your consent or a contract, you have the right to request a copy in a structured, commonly used, machine-readable format (for example, a CSV file). You can also ask us to transmit this data directly to another data controller where technically feasible. This right is designed to make it easier for you to transfer your personal data between service providers.

  • Right to Object: You have the right to object to our processing of your personal data when such processing is based on legitimate interests. If you object, we will review the reasons for your objection and will stop processing the data in question unless we have an overriding legitimate ground to continue or it is needed for legal claims. Specifically, you have the absolute right to object to processing of your data for direct marketing purposes at any time. If we ever send you marketing emails or newsletters, you can opt out easily (for example, via an “unsubscribe” link or by contacting us), and we will stop all such communications.

  • Right to Withdraw Consent: (If applicable) Where we rely on your consent to process your data (for example, for certain cookies or optional communications), you have the right to withdraw that consent at any time. Withdrawing consent will not affect any processing already carried out, but it will stop that processing going forward. You can withdraw consent by adjusting your cookie settings or contacting us to opt out of specific uses.

  • Right to Lodge a Complaint: If you believe that we have infringed your data protection rights or GDPR obligations, you have the right to file a complaint with a supervisory authority. BH Associates is based in Ireland, so our lead supervisory authority is the Irish Data Protection Commission (DPC). You can contact the DPC or your local EU data protection authority for guidance or to lodge a complaint. We encourage you to contact us first with any concerns, and we will do our best to resolve them to your satisfaction.

To exercise any of your rights, please contact us using the contact details provided in the “Contact Information” section below. We will respond to your request as soon as possible, and in any event within the GDPR’s required timeframe (generally one month). Please note that we may need to verify your identity before fulfilling certain requests, to ensure that we protect your data from unauthorized access.

Cookies and Tracking

Our website uses cookies and similar tracking technologies to enhance user experience and analyze website performance. Cookies are small text files that are stored on your device when you visit a website. They serve various functions, from keeping you logged in to remembering your preferences and collecting analytics data. Here’s how we use cookies and how you can manage them:

  • Types of Cookies We Use:

    • Essential Cookies: These cookies are necessary for the website to function correctly. They might include preferences or session cookies that enable core features like security, network management, and accessibility. We do not require your consent for essential cookies, as the site cannot properly operate without them.
    • Analytics and Performance Cookies: We use cookies for analytics purposes, primarily through Google Analytics and HubSpot, as mentioned above. These cookies collect information about how visitors use our site (for example, which pages are visited most, or if users get error messages on certain pages). The data is aggregated and helps us improve how our website works. For instance, Google Analytics cookies (_ga, _gid, etc.) help distinguish unique users and throttle request rates, and HubSpot cookies (like _hstc, hubspotutk) track a visitor’s identity and sessions. We treat these as non-essential cookies, which means we may ask for your consent before setting them, depending on applicable law.
    • Functional Cookies: If any are used, these would help enhance functionality and personalization, such as by remembering your preferences. (At present, our site’s primary cookies are analytics-related, but if we use any functionality cookies, we will disclose their purpose here.)
  • Cookie Consent & Control: When you first visit our website, you may see a cookie consent banner or notice. We use this to inform you about our use of cookies and, where required by law, to obtain your consent for placing non-essential cookies (like analytics cookies) on your device. You have the right to accept or reject non-essential cookies. If you opt out or decline analytics cookies, those cookies will not be set and our tracking tools will be limited or disabled for your visit.
    Regardless of the banner, you can also control cookies through your browser settings. Most web browsers allow you to refuse new cookies, delete existing cookies, or notify you when new cookies are being set. Please note that blocking all cookies (including essential ones) might impact your experience of our site—some features might not work as intended if cookies are disabled entirely. If you delete cookies, any preferences controlled by those cookies (including opting out of cookies) will be reset.
    For analytics specifically, Google offers an Opt-Out Browser Add-on that, once installed, prevents Google Analytics from collecting information on your visits to any site that uses it. Similarly, HubSpot provides options to disable tracking if you have previously submitted information. You can find these tools on their respective websites. Using these opt-outs will not affect basic browsing functionality.

Our Cookie Policy (if provided separately) contains more details about the specific cookies we use and their purposes. By continuing to use our website with cookies enabled, you are agreeing to our use of cookies as described here. You can change your cookie preferences at any time by adjusting your browser settings or, if available, through our site’s cookie settings tool.

Data Sharing and Disclosure

We treat your personal data with care and confidentiality. We do not sell or rent your personal information to third parties for their own marketing or other purposes. However, we may share your data in certain circumstances, as outlined below:

  • Service Providers and Partners: We share personal data with third-party service providers that perform services on our behalf, as necessary for them to carry out their work. This includes the providers mentioned earlier, such as Google Analytics (for website analytics) and HubSpot (for CRM and communications management). It may also include our website hosting provider, email service provider, IT support, or similar vendors. These companies are given access only to the information they need to perform their specific services, and they are contractually obliged to protect your data and use it only for our specified purposes. We ensure that all our processors are bound by data protection agreements (including Standard Contractual Clauses for international data transfers, if applicable) to safeguard your information.

  • Legal Requirements and Protection: We may disclose personal data when required to do so by law or in response to valid requests by public authorities (for example, a court order, subpoena, or law enforcement demand). We may also share information if we believe in good faith that such action is necessary to comply with a legal obligation, to protect and defend our rights or property, to prevent fraud, or to protect the safety of our website users, clients, or others. Any such disclosure will be done in a controlled manner and only what is necessary will be shared.

  • Business Transfers: In the unlikely event that BH Associates undergoes a business transaction such as a merger, acquisition, or sale of assets, personal data we hold may be transferred to the new owner as part of that deal. If such a transfer occurs, we will ensure the confidentiality of your personal data is maintained and provide notice before your personal data is transferred and becomes subject to a different privacy policy.

Aside from the situations above, we will not share your personal data with third parties unless we have your explicit consent to do so. For example, if we ever wanted to use a testimonial you provided or refer you to one of our partner organizations, we would ask for your permission before sharing any identifying information.

Please note that our website may contain links to third-party websites or services (for example, links to articles or partner sites). Clicking on those links may allow third parties to collect or share data about you. We are not responsible for the privacy practices of those external sites. We encourage you to read the privacy policies of any external websites you visit.

Security Measures

We take security seriously and implement a variety of technical and organizational measures to protect your personal data from unauthorized access, alteration, disclosure, or destruction. These measures include:

  • Data Encryption: Our website is secured via industry-standard SSL/TLS encryption. This means that any data transmitted between your browser and our website (for example, information you enter into a contact form) is encrypted in transit and cannot be easily intercepted by third parties. We also employ encryption and secure protocols when transferring or storing sensitive data in our systems or with our service providers.
  • Access Controls: We limit access to personal data to those employees, contractors, and service providers who have a business need to know such information. All personnel who handle personal data are subject to confidentiality obligations and are trained in data protection best practices. We use password protection, two-factor authentication, and other access control mechanisms to prevent unauthorized access to our systems and accounts.
  • Secure Infrastructure: We host our website and data with reputable hosting providers that maintain robust security standards (including firewalls, intrusion detection systems, and regular security audits). Our third-party service providers (like HubSpot) likewise use secure data centers and undergo security certifications and audits. We keep our software, website platform, and plugins up-to-date to protect against vulnerabilities.
  • Monitoring and Testing: We monitor our systems for potential vulnerabilities and attacks. We employ anti-malware tools and regularly review our security policies. In addition, we have procedures in place to handle any suspected data breach, including notifying users and authorities as required by law.

Despite our efforts, it’s important to note that no method of transmission over the internet, or method of electronic storage, is 100% secure. While we strive to protect your personal data with commercially acceptable means, we cannot guarantee absolute security. However, we continuously update and improve our security practices to meet or exceed industry standards and to address emerging threats.

Contact Information

If you have any questions, concerns, or requests regarding this Privacy Policy or how we handle your personal data, please do not hesitate to contact us. We are here to help and address any issues you may have.

Data Controller: B.H Associates Ltd
Email: sales@bhassociates.ie (You may also use sales@bhassociates.ie for general inquiries.)

We will respond to inquiries or requests as soon as reasonably possible, and no later than the timeframe required by applicable law. If you’re contacting us to exercise a GDPR right, please provide enough information to verify your identity (to ensure we don’t disclose your data to someone else).


Changes to This Privacy Policy: We may update this Privacy Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons. If we make significant changes, we will post the updated policy on this page with a new “Last Updated” date, and we may notify you by other means (for example, via email if you have provided one, or through a notice on our homepage). We encourage you to review this policy periodically to stay informed about how we are protecting your information.

By continuing to use our website or services after any changes to this Privacy Policy are posted, you acknowledge and agree to the updated terms. This Privacy Policy is effective as of the date listed at the top.