Privacy Policy
This policy explains how Comms eCommerce Limited, operating as Insighty, collects, uses, and protects your personal information.
Last updated: April 25, 2026
1. Who We Are
Insighty is a product of Comms eCommerce Limited, a company incorporated under the laws of Ireland, with its principal place of business at 57 Amiens Street, D01YY11 Dublin, Ireland (Company Number: 705310, Tax Number: 3809189MH), represented by director Mario Benić.
In this Privacy Policy, "Insighty," "we," "our," and "us" refer to Comms eCommerce Limited in its capacity as the operator of the Insighty platform. When we process your personal data as described in this policy, we act as the data controller under the General Data Protection Regulation (GDPR) and applicable Irish data protection law.
When a customer uses Insighty to store and manage their own operational data (client records, projects, invoices, etc.), we process that data on behalf of the customer as a data processor. In that context, the customer is the controller. This policy does not govern how customers are required to handle the personal data of their own users or clients.
2. Scope
This Privacy Policy applies to:
- The Insighty web application and platform (insighty.io)
- Our marketing website and landing pages
- Communications with our sales, support, and product teams
- Any contact forms, newsletters, or early access registrations
This policy does not apply to data stored within a customer's Insighty workspace on behalf of that customer's business (governed by our Data Processing Agreement), or to third-party services and integrations that customers connect to Insighty.
3. Information We Collect
3.1 Information You Provide Directly
Account and profile data. When you register or request early access, we collect your name, email address, company name, job title, and any other details you choose to provide.
Payment and billing data. If you subscribe to a paid plan, we collect billing name, address, and payment method details. Full card numbers are processed exclusively by our payment processor (Stripe) and are never stored on our systems.
Communications. When you contact us via email, chat, or support forms, we collect the content of that communication and any attachments you include.
Feedback and surveys. Information you submit through feedback requests, product surveys, or beta programme participation.
3.2 Information We Collect Automatically
Device and connection data. IP address, browser type and version, operating system, device identifiers, screen resolution, and language preferences.
Usage data. Pages visited, features used, session duration, clickstream data, and timestamps when you interact with our website or application.
Log and diagnostic data. Server logs, error reports, and performance data generated automatically during your use of the service.
Cookie data. Information collected through cookies and similar technologies as described in Section 11.
3.3 Information from Third Parties
Third-party sign-in. If you authenticate using Google or another identity provider, we receive the name and email address your provider makes available.
Integrations. If you connect third-party tools (such as Jira or accounting software) to your Insighty account, we receive data from those services as authorised by you.
4. How We Use Your Information
We use the personal data we collect for the following purposes:
- Providing the service. Operating and maintaining the Insighty platform, processing payments, authenticating users, and delivering customer support.
- Improving the service. Analysing usage patterns, fixing bugs, testing new features, and improving performance and user experience.
- Communicating with you. Sending transactional messages (account confirmations, billing receipts, security alerts) and responding to your enquiries.
- Marketing and outreach. With your consent, sending product updates, newsletters, event invitations, and early access information. You may opt out at any time.
- Security and fraud prevention. Detecting and preventing fraudulent activity, security incidents, and violations of our Terms of Service.
- Legal compliance. Meeting our obligations under applicable law, including tax and financial reporting requirements.
5. Legal Bases for Processing
As a company incorporated in Ireland, we are subject to the GDPR directly. We process your personal data only where we have a lawful basis to do so:
Contractual necessity (Article 6(1)(b))
Processing required to perform our contract with you — for example, creating and managing your account, processing subscription payments, and delivering support.
Legitimate interests (Article 6(1)(f))
Processing that serves our legitimate business interests without overriding your fundamental rights — for example, improving the service, preventing fraud, ensuring network security, and marketing to existing users. We conduct balancing assessments before relying on this basis.
Consent (Article 6(1)(a))
Where you have given us explicit, freely given consent — for example, subscribing to our newsletter or requesting early access communications. You may withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal.
Legal obligation (Article 6(1)(c))
Processing required to comply with our legal obligations — for example, retaining financial records for tax purposes or responding to lawful data requests.
7. International Data Transfers
Comms eCommerce Limited is based in Ireland and operates within the European Economic Area. However, some of our service providers and sub-processors are located outside the EEA, including in the United States.
Where we transfer personal data outside the EEA, we do so using appropriate safeguards as required by Chapter V of the GDPR — including Standard Contractual Clauses (SCCs) approved by the European Commission, adequacy decisions, or other lawful transfer mechanisms. You may request details of the specific transfer mechanisms we use by contacting us at the address in Section 15.
8. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes described in this policy, unless a longer retention period is required by law.
- Account data. Retained for the duration of your account, plus a reasonable period afterwards to fulfil backup, legal, and dispute resolution obligations.
- Payment and billing data. Retained for seven years to satisfy Irish tax and financial reporting requirements.
- Support communications. Retained for the duration of your account or until the matter is resolved, plus any legally required period.
- Usage and analytics data. Raw logs retained for up to 12 months; aggregated analytics retained indefinitely.
- Marketing data. Retained until you unsubscribe or request deletion, whichever is earlier.
When personal data is no longer required, we securely delete or anonymise it in accordance with our data management procedures.
9. Data Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, destruction, or alteration. These measures include:
- Encryption of data in transit using TLS/SSL and at rest
- Role-based access controls and least-privilege principles for internal systems
- Regular security reviews and vulnerability assessments
- Confidentiality obligations for all personnel with access to personal data
- Incident detection, logging, and response procedures
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Irish Data Protection Commission within 72 hours of becoming aware of the breach and, where required, notify you directly without undue delay.
You are responsible for maintaining the confidentiality of your account credentials and for securing the devices you use to access Insighty.
10. Your Rights
Under the GDPR, you have the following rights regarding your personal data:
- Right of access (Article 15). Request a copy of the personal data we hold about you.
- Right to rectification (Article 16). Request correction of inaccurate or incomplete personal data.
- Right to erasure (Article 17). Request deletion of your personal data where no compelling reason for continued processing exists.
- Right to restriction (Article 18). Request that we restrict processing of your data in certain circumstances.
- Right to data portability (Article 20). Receive a copy of your data in a structured, commonly used, machine-readable format.
- Right to object (Article 21). Object to processing based on legitimate interests, including for direct marketing purposes.
- Right to withdraw consent. Where processing is based on consent, withdraw it at any time without affecting prior lawful processing.
- Right to lodge a complaint. Lodge a complaint with the Irish Data Protection Commission (dataprotection.ie) or the supervisory authority in your EU member state of habitual residence.
To exercise any of these rights, contact us at privacy@insighty.io. We will respond within 30 days. We may ask you to verify your identity before processing your request. We will not discriminate against you for exercising your rights.
12. Children
The Insighty platform is a business-to-business service and is not directed at children under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected data from a person under 16, we will delete it promptly. If you believe a child has provided us with their data, please contact us at privacy@insighty.io.
13. Third-Party Services
The Insighty platform supports integrations with third-party services such as Jira, accounting software, and other business tools. When you connect a third-party service to your Insighty account, data shared with that integration is governed by that third party's own privacy policy. We are not responsible for the privacy practices of third-party services. We recommend reviewing their policies before enabling any integration.
Our website may also contain links to external websites. Following those links takes you outside our service and this policy does not apply to those destinations.
14. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. When we make material changes, we will update the "Last updated" date at the top of this page, notify registered users by email, and, where applicable, display an in-product notification.
We encourage you to review this policy periodically. Your continued use of the service after the effective date of any changes constitutes acceptance of the updated policy.
15. Contact Us
If you have questions, concerns, or requests relating to this Privacy Policy or our data protection practices, please contact us:
Comms eCommerce Limited (Insighty)
57 Amiens Street
D01YY11 Dublin, Ireland
Company Number: 705310
Data protection enquiries: privacy@insighty.io
General enquiries: insighty.io/contact
You also have the right to lodge a complaint with the Irish Data Protection Commission (dataprotection.ie) if you believe we have processed your personal data in a manner inconsistent with applicable data protection law.
