Privacy Policy

Comerford Foley Consultants Limited

Last updated: 14 September 2026

1. Who We Are

This website, comerfordfoley.ie, is operated by Comerford Foley Consultants Limited (“we”, “us”, “our”), a company registered in Ireland.

Registered office: Unit 502, Riverstown Business Park, Tramore, Co. Waterford, Ireland, X91 E8H7

Company (CRO) number: 666720

2. How to Contact Us About Data Protection

If you have any questions about this Privacy Policy or how we handle your personal data, you can contact our Data Protection Contact:

  • Role: Data Protection Contact
  • Email: in**@************ey.ie
  • Post: Data Protection Contact, Comerford Foley Consultants Limited, Unit 502, Riverstown Business Park, Tramore, Co. Waterford, Ireland, X91 E8H7

3. Personal Data We Collect

Depending on how you interact with us, we may collect the following categories of personal data:

  • Identity data: full name, title, date of birth
  • Contact data: postal address, email address, phone number
  • Financial and tax data: PPS number, VAT number, tax reference numbers, bank/financial institution details, accounting records
  • Identity verification (AML) data: copies of passports or driving licences, and proof of address documents (e.g. household bills), collected to meet our anti-money-laundering obligations
  • Business data: company name, company registration/tax numbers, director details
  • Technical data: IP address, browser type, device information, and website usage data collected via cookies (see Section 9)
  • Marketing data: your preferences in relation to receiving marketing communications from us

Where we need to collect personal data by law, or under the terms of a contract we have with you, and you fail to provide that data when requested, we may not be able to perform the contract (for example, we cannot complete AML identity checks or act for you as a client without the required identity documents). In that case, we may have to delay or cancel the service you have requested.

4. Where We Obtain Your Data From

In most cases we collect personal data directly from you — for example, when you fill in a form on our website, contact us by phone or email, or provide documents as part of client onboarding. In some circumstances we may also obtain personal data about you from other sources, including:

  • Publicly available sources, such as the Companies Registration Office (CRO), Revenue, or public company registers — typically company name, registration/tax numbers, director details, and registered business addresses
  • Your employer, business partners, or another individual at your company who refers or introduces you to us — typically your name and business contact details
  • Publicly available information on social media or professional networking platforms such as LinkedIn — typically your name, job title, and business contact details
  • Banks, financial institutions, or other professional advisers involved in delivering a service to you — typically financial and account information relevant to that service

Where we obtain your personal data from a source other than you directly, we will provide the information required by Article 14 GDPR within the applicable timeframe — generally within one month, and where relevant, at the time of our first communication with you or before the data is first disclosed to another recipient.

5. How We Use Your Personal Data and Our Lawful Basis

Under GDPR, we must have a valid lawful basis for each way we use your personal data. The table below sets out our processing activities and the lawful basis relied on for each:

Processing ActivityWhat We DoLawful Basis (GDPR Art. 6)
General enquiries (Start / contact forms)Responding to enquiries submitted via website formsPerformance of a contract / steps prior to entering a contract, where the enquiry concerns engaging our services; otherwise legitimate interest in responding to queries you have raised with us
Client onboarding & engagementCollecting name, contact details, PPS/tax number, DOB, address to set up and deliver accounting/tax servicesPerformance of a contract / steps prior to entering a contract
AML / identity verificationCollecting passport, driver’s licence, and proof of address documentsLegal obligation (Criminal Justice (Money Laundering and Terrorist Financing) Act 2010, as amended)
Ongoing service delivery (tax, bookkeeping, payroll)Processing financial and tax data via Xero and related toolsPerformance of a contract
Email marketing / newsletterSending marketing emails and newslettersConsent (opt-in), withdrawable at any time
Website analyticsGoogle Analytics and similar tools measuring site usageConsent, obtained via the cookie consent banner
Advertising / retargetingFacebook Pixel and similar toolsConsent, obtained via the cookie consent banner
Spam/bot preventionGoogle reCAPTCHA, CleantalkLegitimate interest — protecting the website and users from abuse
Legal & regulatory complianceRetaining records as required by tax, company, and professional regulation lawLegal obligation

6. Anti-Money Laundering (AML) / Identity Verification

As a firm of accountants, we are legally required under Irish anti-money-laundering legislation to verify the identity of our clients before providing services. This means we ask clients to provide a copy of a passport or driving licence, together with a recent utility/household bill as proof of address.

These documents are stored using a combination of methods: some are held with AML HQ, a cloud-based AML compliance platform, and some are stored directly by us. We retain these documents for a minimum of 5 years, in line with our obligations under applicable anti-money-laundering legislation.

7. Sharing Your Personal Data / Third Parties

We share personal data with a limited number of trusted third parties who help us run our business and deliver our services. Where these providers are based outside the European Economic Area (EEA), we put safeguards in place — such as the European Commission’s Standard Contractual Clauses (SCCs) — to ensure your data continues to receive an equivalent level of protection.

Third PartyPurposeRoleLocation / Transfer Safeguard
XeroCloud accounting software used to manage client bookkeeping and tax recordsProcessorSee Section 8 (International Data Transfers)
AML HQCloud-based AML/identity verification compliance platform, used to store and manage copies of AML identification documentsProcessorSee Section 8 (International Data Transfers)
ZoomVideo consultations with clientsProcessorSee Section 8 (International Data Transfers)
Google AnalyticsWebsite usage analyticsProcessor / independent third partySee Section 8 (International Data Transfers)
Meta / Facebook PixelWebsite advertising and retargetingIndependent third party (Meta acts as a separate controller for its own purposes)See Section 8 (International Data Transfers)
Google reCAPTCHASpam and bot protection on formsProcessorSee Section 8 (International Data Transfers)
CleantalkAnti-spam / bot protectionProcessorSee Section 8 (International Data Transfers)
CookiebotCookie consent management platformProcessorSee Section 8 (International Data Transfers)
MailchimpSending newsletters and marketing emailsProcessorSee Section 8 (International Data Transfers)
Banks / financial institutionsVerifying financial information as part of engagementsIndependent controllerIreland / EEA
Chartered Accountants IrelandProfessional regulatory bodyIndependent controllerIreland

The “Role” classification above reflects our understanding of each provider’s function based on their published terms. Where a provider processes data outside the EEA, the safeguard relied on is addressed generally in Section 8.

Social Media

We maintain pages on social media platforms such as LinkedIn and X (formerly Twitter) to promote our services and engage with clients and the public. Any personal data you share with us through these platforms (for example, by commenting, messaging, or following our page) is processed by us for the purpose of that engagement, and is also subject to the relevant platform’s own privacy policy and cookie practices, which we do not control. We recommend you review each platform’s privacy policy to understand how it handles your data.

8. International Data Transfers

Some of the third parties listed in Section 7 may process personal data outside the EEA (for example, in the United States). Where this happens, we ensure an appropriate safeguard is in place before any transfer occurs, such as:

  • An adequacy decision by the European Commission confirming the destination country provides an adequate level of data protection; or
  • Standard Contractual Clauses (SCCs) approved by the European Commission, incorporated into our agreements with the relevant provider; or
  • For transfers to the United States, certification of the receiving organisation under the EU-U.S. Data Privacy Framework; or
  • Another valid transfer mechanism recognised under GDPR.

You can request further details of the specific safeguard used for any given transfer by contacting us using the details in Section 2.

9. Cookies

Our website uses cookies and similar tracking technologies to operate the site, remember your preferences, measure website usage, and — where you consent — show relevant advertising.

We use Cookiebot, an independent cookie consent management platform, to obtain and record your cookie consent choices and to maintain an up-to-date, itemised list of every cookie used on this website, including its name, purpose, duration, and whether it is a first- or third-party cookie.

Note that having a lawful basis under Article 6 GDPR for a processing activity (such as legitimate interest in preventing spam or abuse) is separate from the ePrivacy consent requirement for storing or accessing information on your device. Tools such as reCAPTCHA and our anti-spam service may set cookies or access device information that require your consent unless a narrow exemption applies. Where consent is required, these technologies will only be used after you have given it through Cookiebot.

The following Cookiebot declaration script is embedded on this page and automatically displays the full, up-to-date list of cookies used on this website:

You can change or withdraw your cookie consent at any time using the cookie settings link in the website footer.

10. How Long We Keep Your Data

We do not keep personal data for longer than necessary. Retention periods depend on the type of data and the purpose for which it was collected:

Data CategoryRetention Period
Client engagement & financial records7 years from the end of the engagement, in line with our records-retention policy, and for any additional period necessary to establish, exercise, or defend legal claims. Certain records, such as signed contracts and agreements, may be retained for a longer period
AML identity documents (passport, licence, proof of address)A minimum of 5 years, in line with applicable anti-money-laundering legislation
Marketing consent / newsletter subscriptionUntil you withdraw consent or unsubscribe, at which point we retain only a minimal suppression record to ensure we respect your opt-out and do not contact you again
Website enquiry form submissions (not converted to clients)24 months
CookiesSee Cookiebot cookie declaration. Retention periods vary depending on the individual cookie.

11. Your Rights Under GDPR

You have the following rights in relation to your personal data:

  • The right to be informed about how your data is used
  • The right of access to the personal data we hold about you
  • The right to rectification of inaccurate or incomplete data
  • The right to erasure (“right to be forgotten”), in certain circumstances
  • The right to restrict processing, in certain circumstances
  • The right to data portability
  • The right to object to processing based on legitimate interest or for direct marketing purposes
  • Rights related to automated decision-making and profiling (see Section 12)

Where we process your personal data on the basis of your consent (for example, marketing, analytics, or advertising cookies), you have the right to withdraw that consent at any time. Withdrawing consent does not affect the lawfulness of any processing carried out before the withdrawal.

To exercise any of these rights, please contact us using the details in Section 2. We will respond without undue delay and normally within one month, in accordance with GDPR. Where a request is complex or we have received a number of requests, we may extend this by a further two months, and we will explain why if we do.

12. Automated Decision-Making

We do not use your personal data to make any decisions about you solely through automated means (i.e. without human involvement) that would produce legal or similarly significant effects on you.

13. Data Security

We use appropriate technical and organisational measures to protect the personal data we hold from unauthorised access, alteration, disclosure, or destruction, including secure cloud storage, access controls, and staff data protection training.

Where a personal data breach is likely to result in a risk to the rights and freedoms of individuals, we will notify the Data Protection Commission without undue delay and, where feasible, within 72 hours of becoming aware of it. Where a breach is likely to result in a high risk to affected individuals, we will also inform those individuals directly without undue delay.

14. Children’s Data

Our website and services are directed at businesses and adults and are not intended for children under 16.

If you are a parent or guardian and believe that a child has provided us with personal data without your consent, please contact us using the details in Section 2 so that we can investigate and, where appropriate, delete that data.

15. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. The “last updated” date at the top of this page shows when it was last revised. We encourage you to review this page periodically.

16. How to Complain

If you are unhappy with how we have handled your personal data, please contact us in the first instance using the details in Section 2 so we can try to resolve your concern.

You also have the right to lodge a complaint with the Irish Data Protection Commission. Complaints should be submitted through their online contact form, which is the fastest and most reliable route:

  • Online: www.dataprotection.ie (“Contact Us” / complaint form)
  • Postal address: Data Protection Commission, 6 Pembroke Row, Dublin 2, D02 X963, Ireland
  • Phone (general queries only — complaints must be submitted online or in writing): (01) 765 0100 / 1800 437 737