SmartRep Privacy Policy
Effective date: 9 September 2026
1. Who provides SmartRep
SmartRep is a software service provided by Robert Treacy, an individual sole trader established in Ireland. Robert Treacy is the supplier and data controller for the business information described in this policy; “SmartRep” is the product name.
Privacy and other enquiries: [email protected] or the monitored website contact form.
Complaints may also be made to the Irish Data Protection Commission at dataprotection.ie.
2. What this policy covers
This policy covers information for which Robert Treacy is controller: SmartRep user accounts, signup security, subscriptions and billing administration, legal-acceptance evidence, sales and support correspondence, bug reports and service-security records.
It does not make SmartRep the controller of an elected representative's constituency casework. The representative or office decides why that data is used and is its controller. Robert Treacy processes it through SmartRep only as a processor under the Data Processing Agreement. Constituents should normally direct questions about their case records to the relevant office.
Eircode-based casework mapping: who handles what
The elected representative or office is the controller of casework. It decides why Eircodes are collected, the lawful basis for using them, who may see the map and how long the information is kept.
SmartRep acts as the office's processor. To create a map point, SmartRep normalises the Eircode, sends the normalised Eircode to the external geocoding providers enabled for the service, and stores the returned latitude and longitude with that office's data. If the first enabled provider cannot find an acceptable point, SmartRep may ask the next enabled provider.
Providers can classify a returned point at different levels of precision. SmartRep stores that classification where supplied for operational diagnostics.
An enabled geocoding provider receives only the normalised Eircode and ordinary request metadata needed to answer and secure the request, such as the SmartRep server's IP address, request time and API-account information. SmartRep never includes a constituent's name, phone number, email address, case notes, case category or case details in a geocoding request. The possible providers are ArcGIS by Esri, HERE and Google. Only providers that are configured and enabled receive requests.
The lookup happens between the SmartRep server and the provider. Opening or zooming the map does not send Eircodes to a geocoding provider, and map dots do not make the stored Eircode or coordinates public.
3. Information we use as controller
Office users and signup
We use names, work email addresses, office and representative type, password hashes, MFA state, recovery-code hashes, session and reset-token records, authentication events, source IP address, browser user agent and signup-abuse checks.
We use this information to create and secure accounts, verify email addresses, authenticate users, prevent abuse, recover access and maintain an evidence record. The bases are performance of the SmartRep contract and our legitimate interests in operating a secure service and demonstrating what was agreed.
Billing
We use office identity, administrator contact details, selected plan, subscription status, invoice references and Stripe customer, Checkout and subscription identifiers. This is necessary to perform the contract, take payment and keep required business records.
Stripe hosts Checkout and the billing portal. SmartRep does not receive full payment card or bank-account details. Stripe may process information as a service provider and for its own payment-security, fraud-prevention and legal purposes under its own privacy information.
Messages, sales and support
We use the sender's contact details and message content submitted by email or the website contact form to answer enquiries, provide support and maintain business correspondence. Please do not send constituent casework through these public channels.
Bug reports
An in-product bug report can include the text the user enters, page address, selected element and its visible text, recent browser-console errors, addresses of recent failed requests and an optional screenshot. A screenshot or diagnostic can contain casework visible on screen. Bug reports are stored with SmartRep on our hosting and are not sent to an external analytics or bug-tracking service.
Website, security and abuse information
SmartRep uses Cloudflare as the HTTPS reverse proxy, content-delivery and security layer in front of the website and application. Cloudflare terminates the user's HTTPS connection and forwards requests to SmartRep over an encrypted connection. It therefore processes request and response content in transit, which can include account and casework information when a user works in the application, together with traffic metadata such as IP address, date and time, requested path, response status and browser user agent. SmartRep and Cloudflare use this processing to deliver and secure the service, diagnose faults and prevent abuse. Cloudflare does not host SmartRep's operational database or uploaded-file store.
Public signup and the website contact form also use Cloudflare Turnstile. Cloudflare receives technical browser and network signals needed to distinguish a person from automated activity. Turnstile does not receive the form contents or casework stored later in SmartRep.
The authenticated map requests visible map tiles directly from the OpenStreetMap Foundation. The Foundation can receive the user's IP address, browser information, referring page, time and requested map area. SmartRep does not put constituent names, contact details, Eircodes or case notes into those requests.
Our separate Cookie and device-storage notice explains the exact browser storage used by login, offline capture and the PWA. SmartRep uses no advertising cookies, tracking pixels or product-analytics SDK.
4. Recipients and locations
We use the following providers for the business-side processing described here:
| Provider | Purpose | Relevant information |
|---|---|---|
| Hetzner Online GmbH | Hosting in Helsinki, Finland (hel1-dc2), European Union, for the application, database and uploaded files | Information stored in SmartRep |
| Stripe | Hosted Checkout, subscriptions, invoices and billing portal | Office, billing and payment information; no casework |
| Proton AG | Transactional and human business email | Recipient address, office/user name, verification or reset link and billing-alert information; no casework unless a sender puts it in an email |
| Cloudflare | HTTPS reverse proxy, content delivery, traffic security and Turnstile public-form abuse prevention | Request and response content in transit, which can include account and casework information; IP address, request metadata and browser or network security signals |
| OpenStreetMap Foundation | Direct delivery of map tiles | User IP, browser request and map area; no case record content |
| ArcGIS by Esri | Eircode geocoding, only when configured and enabled | Normalised Eircode and ordinary server request metadata; no names, contact details or case notes |
| HERE | Eircode geocoding, only when configured and enabled | Normalised Eircode and ordinary server request metadata; no names, contact details or case notes |
| Eircode geocoding, only when configured and enabled | Normalised Eircode and ordinary server request metadata; no names, contact details or case notes |
Customer casework stored in SmartRep's operational database and uploaded-file store is hosted in the European Union. Cloudflare operates a global network and may process web traffic and traffic metadata outside the EEA. Proton is based in Switzerland, for which the European Commission has adopted an adequacy decision. Where a provider processes personal data outside the EEA, we rely on its applicable contractual and organisational transfer safeguards.
We may disclose information where required by law or where reasonably necessary to establish, exercise or defend legal rights.
5. Retention
Retention is applied according to the type of record and why it is needed:
| Information | Current retention approach |
|---|---|
| Operational Customer Data after cancellation | Read-only/export-only, then manually deleted within 90 days unless the office resubscribes or requests earlier deletion |
| User and office account records | Subscription and closure period; limited identity and security records may then be retained with contract evidence |
| Billing and tax records | Up to six years where required for business, tax or contract records |
| Legal-acceptance and contract evidence | Up to six years after the contract ends |
| Signup-abuse counters | Seven days |
| Support and sales correspondence | Normally up to 24 months after the last contact, unless needed for an active matter or legal record |
| Bug reports and diagnostics | Until manually removed or the related office's operational data is erased |
| Server and security logs | Kept only for a proportionate operational and security period under the hosting configuration |
Deletion from the live service does not selectively edit an existing backup. Any backup that exists ages out through its normal operational cycle. A deletion request continues to apply if a backup is restored.
6. Security
Current safeguards include application-level organisation scoping, individual user accounts, administrator and staff roles, restricted-case access, per-user MFA, password hashing, session revocation, TLS in transit, rate limits and application audit records.
No internet service can promise absolute security. Users should protect their devices, use individual accounts and promptly report suspected compromise.
7. Your rights
Depending on the circumstances, a person may ask us for access to their personal data, correction, erasure, restriction, portability, or object to processing based on legitimate interests. They may also complain to the Data Protection Commission.
These rights are not absolute and may be limited where information must be retained by law or for legal claims. To exercise a right relating to a SmartRep account, billing, support or another record covered by this policy, email [email protected]. We may need to verify identity.
For constituent casework, contact the elected representative or office that controls the record. If a casework request reaches us, we will normally refer it to that office.
8. Automated decisions and reuse
SmartRep does not make decisions producing legal or similarly significant effects about individuals. Reports, matching and maps are decision-support tools reviewed by office users.
SmartRep does not use Customer Data for advertising, behavioural profiling, product analytics, cross-customer benchmarking, model training or a provider-owned dataset.
9. Changes
We will publish material changes as a new version and update the effective date. Where a change materially affects existing users, we will provide reasonable notice through the service or by email.