Privacy Policy

David O'Grady Coaching Ltd

Last updated: 29 June 2026 | Version: 1.0


1. Who we are (Data Controller)

This Privacy Policy explains how David O'Grady Coaching Ltd ("we", "us", "our") collects, uses, shares and protects your personal data, and the rights you have over that data.

David O'Grady Coaching Ltd is a private company limited by shares, registered in Ireland (company number 781152, incorporated on 7 February 2025), with its registered office at A21 Bastion Quay, Deerpark Road, Athlone, Co. Westmeath, Ireland. Our VAT number is IE4384428AH. We trade as "David O'Grady Coaching".

For any data-protection question, to exercise your rights, or to make a complaint, you can contact us at:

  • Email: david@davidogradycoaching.com
  • Post: Data Protection, David O'Grady Coaching Ltd, A21 Bastion Quay, Deerpark Road, Athlone, Co. Westmeath, Ireland

We are the data controller for personal data we collect through our website, our customer relationship management (CRM) system, our marketing communications, and our discovery and coaching calls. The position is different for assessment / participant data in some corporate engagements — see Section 9 below.

We are not required by law to appoint a Data Protection Officer, given the nature and scale of our processing. David O'Grady is the named point of contact for all data-protection matters.


2. The personal data we collect

Depending on how you interact with us, we may collect the following categories of personal data:

Category Examples
Identity & contact data First and last name, job title, organisation, email address, phone number, postal address
Enquiry & booking data Information you provide in website enquiry forms, newsletter sign-up, or when you book a discovery / scoping call
Engagement & client data Records relating to coaching, facilitation, certification and accreditation work, including correspondence, scheduling and invoicing details
Meeting / call data Recordings, transcripts and notes of discovery calls and client meetings, where these are made (see Section 5)
Assessment / participant data Responses to and outputs from psychometric and behavioural assessments (e.g. Everything DiSC, The Five Behaviors, Insights Discovery, CliftonStrengths, Hogan) — see Section 9
Website & technical data IP address, browser type, internet service provider, the pages you visit, time spent on pages, and similar analytics data collected via cookies and similar technologies (see our Cookie Policy)
Marketing data Your preferences for receiving our newsletter and other communications, and how you engage with them

We do not operate an online shop or payment checkout, and we do not collect payment-card, billing-address or shipping information through this website. If we add the ability to buy products (such as assessment profiles) in future, we will update this policy to describe the payment processor used, and card data will be handled securely by that PCI-compliant processor — not stored by us.


3. How we use your data, and our legal basis

Under the General Data Protection Regulation (GDPR) and the Irish Data Protection Act 2018, we must have a lawful basis for each way we use your personal data. The table below sets out what we do and why.

What we do Personal data used Lawful basis (GDPR Article 6)
Respond to website enquiries and discovery / scoping-call requests, and follow up Identity, contact, enquiry data Taking steps at your request before entering a contract (Art 6(1)(b)) and/or our legitimate interests in responding to business enquiries (Art 6(1)(f))
Manage our relationship with prospects and clients in our CRM Identity, contact, enquiry, engagement data Our legitimate interests in running and developing our business (Art 6(1)(f)) and/or performance of a contract (Art 6(1)(b))
Deliver coaching, facilitation, certification and accreditation services Identity, contact, engagement, meeting and assessment data Performance of our contract with you or your organisation (Art 6(1)(b))
Record and transcribe discovery and client calls for accurate note-taking and follow-up Meeting / call data Our legitimate interests in keeping accurate records of our discussions (Art 6(1)(f)), where you are told in advance and can ask us not to record (see Section 5)
Send our "HR as Coach" newsletter and marketing communications Identity, contact, marketing data Your consent (Art 6(1)(a)), which you can withdraw at any time
Operate, secure and improve our website (analytics) Website & technical data Your consent for non-essential cookies (Art 6(1)(a)); strictly necessary cookies rely on our legitimate interests (Art 6(1)(f))
Meet legal, tax and accounting obligations Identity, contact, engagement, invoicing data Compliance with a legal obligation (Art 6(1)(c))
Establish, exercise or defend legal claims Any relevant data Our legitimate interests, and compliance with a legal obligation (Art 6(1)(f) / (c))

Where we rely on legitimate interests, we have balanced our interests against your rights and freedoms and are satisfied this processing does not override them. You can ask us for more detail on this assessment at any time.


4. Who we share your data with

We do not sell, rent or trade your personal data. We share it only with the following categories of recipient, and only as far as necessary:

Service providers (processors) acting on our instructions

  • HubSpot — our website content management system, CRM, web forms, marketing email and website cookies / tracking.
  • Google Workspace — our email, calendar and document storage.
  • Fireflies.ai — transcription of discovery and client calls (see Section 5).

Each of these providers acts under a written data-processing agreement that restricts how they may use your data.

Assessment providers

When we deliver assessment-based work, participant data is processed by the relevant vendor under that vendor's own terms and privacy notice:

  • John Wiley & Sons, Inc. / Wiley — Everything DiSC®, The Five Behaviors®
  • The Insights Group Ltd (Insights Learning and Development) — Insights Discovery®
  • Gallup, Inc. — CliftonStrengths®
  • Hogan Assessment Systems, Inc. — Hogan assessments

Depending on the engagement, these vendors act either as our sub-processors (where we or a client organisation is the controller) or as independent controllers in their own right, under their own privacy notices. We recommend reviewing the relevant vendor's privacy notice when you take part in an assessment. See Section 9 for how participant data is handled.

Others

  • Professional advisers (such as our accountant and solicitor) where needed.
  • Public authorities, regulators or law enforcement where we are legally required to disclose.
  • A successor business, if we ever undergo a merger, acquisition or sale — in which case we will tell you and this policy will continue to protect your data.

5. Recording and transcribing calls

We may record and transcribe discovery calls and client meetings using Fireflies.ai, to support accurate note-taking and follow-up. Where we do this:

  • We will tell you at the start of the call that it is being recorded and transcribed.
  • You can ask us not to record, and we will respect that.
  • You can ask us to delete a recording or transcript at any time.
  • For calls with participants in the United States, we will obtain the agreement of all parties on the call before recording, in line with US "all-party consent" requirements in some states.

Transcripts may contain personal data and, depending on what is discussed, potentially sensitive content. We do not deliberately use these calls to gather special-category data (such as health information); if such information arises incidentally, we treat it with appropriate care and delete it when it is no longer needed. We hold transcripts only as long as needed (see Section 7) and store them under our data-processing arrangements.


6. International data transfers

Some of our service providers and assessment vendors are based in, or process data in, the United States (including HubSpot, Fireflies.ai, Wiley, Gallup and Hogan). Some of our clients are also based in the United States.

Where personal data is transferred outside the European Economic Area (EEA), we rely on appropriate safeguards under Chapter V of the GDPR:

  • the EU–US Data Privacy Framework, where the provider is certified under it (for example, HubSpot is certified); and/or
  • the European Commission's Standard Contractual Clauses, together with any supplementary measures needed to protect your data.

Because the EU–US Data Privacy Framework remains the subject of ongoing legal challenge, we also maintain Standard Contractual Clauses as a fallback safeguard so that transfers stay protected regardless of the Framework's status. You can ask us for a copy of, or more information about, the safeguards we use. If you are a US-based client or participant, please note that your data may also be processed under US law.


7. How long we keep your data

We keep personal data only for as long as we need it, then delete or anonymise it. Our standard retention periods are:

Data Retention period
Enquiry / lead data (held in our CRM) 24 months from your last contact with us, then deleted or anonymised
Client engagement records For the duration of the engagement plus 6 years, to meet Irish tax requirements and the six-year limitation period under the Statute of Limitations 1957
Invoicing and accounting records 6 years, to meet Revenue / tax obligations
Meeting recordings and transcripts 12 months, then deleted
Newsletter / marketing data Until you unsubscribe or withdraw consent
Assessment / participant data In line with the instructions of the client organisation and the relevant assessment vendor's terms; where we are the controller, for the duration of the engagement plus 6 years

8. Your rights

Under the GDPR and the Data Protection Act 2018, you have the right to:

  • Access the personal data we hold about you and receive a copy of it;
  • Rectification — ask us to correct inaccurate or incomplete data;
  • Erasure — ask us to delete your data in certain circumstances;
  • Restriction — ask us to limit how we use your data in certain circumstances;
  • Data portability — receive certain data in a structured, machine-readable format, or have it transferred to another controller;
  • Object to processing based on our legitimate interests, and to object at any time to direct marketing;
  • Withdraw consent at any time, where we rely on consent (this does not affect the lawfulness of processing before you withdrew it); and
  • Rights in relation to automated decision-making (see Section 10).

To exercise any of these rights, contact us at david@davidogradycoaching.com. We will respond free of charge and within one month. We may need to verify your identity before acting on a request.


9. Assessment and participant data

Much of our work involves psychometric and behavioural assessments (such as Everything DiSC, The Five Behaviors, Insights Discovery, CliftonStrengths and Hogan). These produce personal profiles of the individuals who take part.

  • When we deliver assessments for an organisation (for example, a team or leadership programme), that organisation is usually the data controller for its participants' data, and we act as a processor on its behalf, with the assessment vendor as a sub-processor or independent controller. In these cases a separate data-processing agreement governs how participant data is handled, and participants should also refer to the assessment vendor's own privacy notice.
  • When you engage us directly as an individual, we act as the controller for your assessment data.

If you are a participant taking an assessment as part of your employer's programme, your employer will normally be your first point of contact for your data rights, but you can also contact us using the details in Section 1 and we will direct your request appropriately.

Assessment results are developmental indicators interpreted by a qualified facilitator or coach — they are not clinical diagnoses and are not used to make automated decisions about you (see Section 10).


10. Automated decision-making and profiling

We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing.

Our CRM (HubSpot) may carry out lead scoring and analytics to help us prioritise and tailor our communications, and assessment tools generate individual profiles. In all cases, any decision affecting you involves human judgement — assessment outputs are interpreted by a facilitator or coach, not applied automatically.


11. Cookies and similar technologies

Our website uses cookies and similar technologies. Strictly necessary cookies are set automatically; all other cookies (such as analytics and functional cookies) are set only with your prior consent, given through our cookie consent banner, in line with the ePrivacy Regulations (S.I. 336/2011) and Data Protection Commission guidance.

Full details of the cookies we use, their purposes and durations, and how to change or withdraw your consent at any time, are set out in our separate Cookie Policy.


12. Children's data

Our services are for businesses and professionals. We do not knowingly collect personal data from children under 16 (the digital age of consent in Ireland under section 31 of the Data Protection Act 2018). If you believe a child has provided us with personal data, please contact us and we will delete it.


13. How we protect your data

We take appropriate technical and organisational measures to protect your personal data, including:

  • holding data in access-controlled, reputable cloud systems (such as HubSpot and Google Workspace) under data-processing agreements;
  • limiting access to David O'Grady and authorised service providers on a need-to-know basis;
  • using encryption in transit; and
  • reviewing our security arrangements periodically.

No method of transmission over the internet or electronic storage is completely secure, but we work to protect your data using appropriate safeguards.


14. Links to other websites

Our website may contain links to other websites that we do not operate or control. This Privacy Policy does not apply to those websites, and we are not responsible for their content or privacy practices. We encourage you to read the privacy policy of any website you visit.


15. Your right to complain

We would always ask you to contact us first so we can try to resolve any concern. You also have the right to lodge a complaint with the Irish supervisory authority:

Data Protection Commission 6 Pembroke Row, Dublin 2, D02 X963, Ireland Website: www.dataprotection.ie (online complaint form available) Email: info@dataprotection.ie Telephone: +353 (0)1 765 0100


16. For visitors and clients in the United States

We welcome clients in the United States. Where US state privacy laws (such as the California Consumer Privacy Act / CPRA) apply to you, please note:

  • We do not sell your personal information.
  • We do not share your personal information for cross-context behavioural advertising.
  • Where supported by our platform, we honour recognised opt-out preference signals, including Global Privacy Control (GPC).
  • You may have rights to know what personal information we hold, to request its deletion, and to correct it.
  • To exercise any such rights, contact us using the details in Section 1, and we will not discriminate against you for doing so.

17. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. When we do, we will change the "Last updated" date at the top, and where changes are significant we will take reasonable steps to bring them to your attention.


18. Contact us

If you have any questions about this Privacy Policy or how we handle your personal data, please contact:

David O'Grady Coaching Ltd A21 Bastion Quay, Deerpark Road, Athlone, Co. Westmeath, Ireland david@davidogradycoaching.com