Privacy policy
What Replican does with your data. This website sets no cookies and runs no analytics. What happens when you email us, why we hold it, and your rights under GDPR.
Who is responsible for your data?
Replican is the trading name of Jason Teji, a sole trader established in Ireland and registered for VAT in Ireland. Replican is the data controller for personal data processed through this website and through correspondence with us.
You can reach us about anything on this page at hello@replican.ie or +353 87 0555124. We do not have a statutory obligation to appoint a Data Protection Officer and have not appointed one, so enquiries come to Jason directly.
What does this website collect about you?
Almost nothing, and nothing that identifies you.
This site sets no cookies, runs no analytics, loads no tag manager, embeds no third party scripts, and writes nothing to your browser's local or session storage. There is no tracking pixel, no session identifier and no advertising technology of any kind on any page. You can verify this yourself in your browser's developer tools: the storage panel is empty on every page of the site.
The only data generated by simply reading this site is the ordinary technical record every web server keeps in order to serve a page and defend itself: the IP address the request came from, the page requested, the time, and the browser's user agent string. These records are held by our hosting and network provider, are used only to deliver the site and to block automated abuse, and are not used to build a profile of you or combined with anything else. See the cookie policy for the detail on what is and is not stored on your device.
What happens when you send a brief or an email?
The brief form on the contact page and the brief builder on the homepage do not send anything to us. They assemble a plain text message from what you type and hand it to your own email application, addressed to hello@replican.ie. Nothing you type reaches a Replican server, and nothing is stored, unless you then choose to send that email yourself.
Once you do send it, or if you email or ring us directly, we hold what you sent: your name, your email address or phone number, your business, and whatever you have told us about the work you want done. We use it to reply, to work out whether the job is a good fit, and, if you become a client, to scope, deliver and support the work. A person reads it. It is not fed into an automated qualification system and it is never sold or shared for anyone else's marketing.
What is the lawful basis for holding it?
- Replying to an enquiry you sent us. Legitimate interests: you contacted us about our services, and answering you is the obvious and expected use of what you sent.
- Delivering work once you are a client. Performance of a contract with you, or steps taken at your request before entering one.
- Invoicing, accounts, tax and statutory records. Legal obligation, and our legitimate interests in keeping proper business records.
- Keeping in touch with business contacts about our services. Legitimate interests, as described in the next section.
- Security, abuse prevention and keeping the site available. Legitimate interests in protecting the service and the people using it.
Where we rely on legitimate interests we have considered whether our interest is overridden by your rights, and you can object at any time using the contact details above.
Will you email me about your services?
Possibly, and only if you are a business contact. Where we hold a business email address, we may occasionally send you something relevant to that business: a guide we have written, a change to what we build, or a follow up to a conversation you started. Irish electronic marketing law permits this to an address used mainly for commercial or official activity, where the message relates to that activity, without asking for consent first.
You can stop it at any moment by replying and saying so, or by emailing hello@replican.ie, and we will not send you another one. We do not send marketing to personal email addresses without your consent, and we do not buy, rent or scrape contact lists.
How long do you keep things?
- Anything typed into a brief form and not sent: never held by us at all. It stays on your own device.
- Enquiries that do not become work: up to two years from the last contact, so that if you come back to us we have the context of what we discussed.
- Client correspondence, project records and system documentation: for the life of the engagement and for six years after it ends, matching the period we have to keep the related business records.
- Invoices, accounts and anything else with a tax dimension: six years, as Irish tax law requires.
- Server and security logs held by our hosting provider: short lived, in the ordinary course of operating a website, and not retained by us separately.
Where a shorter period is workable we use it. Where you ask us to delete something earlier and we are not required to keep it, we will.
Who else can see it?
We keep the number of parties involved deliberately small.
- Our hosting and network provider, Cloudflare, which serves this website and handles the technical request records described above.
- Our email provider, which stores and delivers our correspondence.
- Our own accounting system, which Replican built and runs in house on infrastructure we control. Your invoicing and payment records sit there rather than in a third party bookkeeping platform.
- Our accountant and, where required, the Revenue Commissioners, for statutory filings.
- A professional adviser, or a court or regulator, where we are legally required to disclose something or need advice to establish or defend a legal claim.
We do not sell personal data, we do not share it for anyone else's marketing, and we do not use it to train any general purpose AI model.
Is any of it sent outside the EEA?
Some of the providers above are established outside the European Economic Area or operate global infrastructure. Where personal data is transferred outside the EEA, it is done under the safeguards Chapter V of the GDPR allows, which in practice means the European Commission's Standard Contractual Clauses or an adequacy decision covering the country concerned. You can ask us which applies to a particular provider and we will tell you.
What about the data inside an AI employee you built for us?
That is a different arrangement and this policy does not govern it.
When Replican builds and runs an AI employee for a client, the client is the data controller for the personal data that agent touches (their inbox, their customers, their ledger) and Replican acts as a data processor under a separate written data processing agreement. That agreement sets out what we may do with the data, the security measures around it, the sub-processors involved, and what happens to everything at the end. It sits alongside the fact that every deployment runs on infrastructure you own rather than on a shared Replican platform, so the underlying data stays on a server in the client's name.
If you want the fuller picture of how this works in practice, GDPR and AI for Irish businesses covers it in plain terms.
What rights do you have?
Under the General Data Protection Regulation and the Data Protection Act 2018 you can ask us to:
- Give you a copy of the personal data we hold about you, and tell you what we do with it.
- Correct anything inaccurate or incomplete.
- Erase it, where we no longer have a reason to hold it.
- Restrict what we do with it while a question about it is resolved.
- Port it to you or another provider in a machine readable form, where we hold it on the basis of consent or a contract and process it by automated means.
- Object to processing we carry out on the basis of legitimate interests, including any use of your details to tell you about our services.
- Withdraw consent, where we relied on consent, without affecting anything done before you withdrew it.
Email hello@replican.ie and say what you want. We will respond within one month, and we will not charge you for it unless a request is manifestly unfounded or excessive. We may ask you to confirm who you are before we hand over personal data.
There is no automated decision making producing legal or similarly significant effects on this website, and we do not carry out profiling of visitors.
What if you are not happy with how we handled it?
Tell us first, at hello@replican.ie, and we will try to put it right.
You also have the right to complain to the Data Protection Commission, the Irish supervisory authority, at 21 Fitzwilliam Square South, Dublin 2, D02 RD28, or through dataprotection.ie. If you are based elsewhere in the EEA you may complain to your own national supervisory authority instead. If you are in the United Kingdom, the equivalent body is the Information Commissioner's Office.
Does this policy change?
It will, when what we do changes. The date at the top of this page is the date of the current version, and anything material will be reflected here rather than announced separately. This policy sits alongside our terms of use, cookie policy and accessibility statement.
Questions to hello@replican.ie.