Last updated: 17 August 2026
This policy explains what personal data One Stop Future Consultants Limited collects, why we hold it, who it is shared with and what rights you have over it.
Who We Are
One Stop Future Consultants Limited is the data controller for the personal data described below.
- Registered in: Ireland, Companies Registration Office, number 725318
- Registered office: Nawab Ali Building, Main Street, Ballaghaderreen, County Roscommon, Ireland
- Data protection contact: [email protected]
We are an Irish company working with clients internationally. Our processing is governed by the EU General Data Protection Regulation and the Irish Data Protection Act 2018, and this applies to the personal data of every visitor to this site regardless of where you are. Where United States state privacy law also gives you rights, those are set out further down.
Two Different Roles
This distinction decides which rules apply, so it comes first.
For our own business contacts, enquiries and website visitors we are the controller. We decide what is collected and why, and this policy governs it.
For personal data held inside a client’s own systems that we work on during a project, we are a processor acting on that client’s written instructions. That processing is governed by the data processing agreement signed with the client, and the client remains the controller. If your data sits in a system one of our clients asked us to build, your rights are exercised against them, and we will assist them in answering you.
What We Collect
If you contact us. Your name, email address, employer, and whatever you choose to tell us about your project. If a call follows, our notes from it.
If you become a client. The contact details of the people we deal with, commercial terms, billing details, and the correspondence that accumulates over an engagement.
If you visit this site. The pages viewed and basic technical information such as approximate location, device and browser. We keep this deliberately minimal. There is no advertising on this site and no social media tracking embedded in it.
Access credentials. Projects usually require access to a client’s systems. Where accounts are issued to us, we hold those credentials for the life of the engagement and return or destroy them at the end.
We do not collect special category or sensitive personal information, and we ask that you do not send any to us in an enquiry.
Why We Process It, and the Lawful Basis
| Purpose | Lawful basis |
|---|---|
| Replying to an enquiry and scoping possible work | Legitimate interests, and steps taken at your request before a contract |
| Delivering a project and supporting it afterwards | Performance of a contract |
| Invoicing, accounting and tax records | Legal obligation |
| Keeping records of what was agreed and delivered | Legitimate interests, and legal obligation |
| Understanding how the site is used | Legitimate interests |
Where we rely on legitimate interests, that interest is in operating and improving a consultancy business, and we have weighed it against your rights. You may object at any time using the address above.
Who We Share It With
- Service providers who host our systems, deliver our email and process our accounts, each under a written contract restricting what they may do with the data.
- Professional advisers, such as accountants or solicitors, where genuinely necessary.
- Statutory bodies, where the law requires it.
We do not sell personal data and we have never sold it. We do not share it for advertising or for cross-context behavioural advertising. We do not name clients publicly without written permission, which is why this site carries no logos and no case studies.
International Transfers
Set out plainly, because it matters.
Our engineering work is delivered from Ireland and Pakistan. Pakistan is not covered by a European Commission adequacy decision, so personal data accessible to our team there is transferred under Standard Contractual Clauses approved by the Commission, supported by a transfer impact assessment. You may request a copy of those safeguards at the address above.
Some of our service providers are established in the United States. Transfers to them are made under Standard Contractual Clauses or, where the provider is certified, under the EU-US Data Privacy Framework.
Where a client requires that no personal data leaves a particular jurisdiction, we can staff and architect the work accordingly. Raise it at the first conversation, because it changes the design rather than the paperwork.
How Long We Keep It
- Enquiries that do not become work: 12 months from the last contact, unless you ask sooner.
- Client records and correspondence: 6 years after the engagement ends, reflecting the period in which a claim could be brought.
- Accounting records: 6 years.
- Access credentials issued to us: returned or destroyed at the end of the engagement.
- Website analytics: no longer than 14 months.
Your Rights Under the GDPR
You have the right to be told what we hold, to receive a copy of it, to have inaccurate data corrected, to have data erased where there is no continuing reason to hold it, to restrict or object to processing, and to receive certain data in a portable format. Where we rely on consent you may withdraw it at any time.
If You Are in the United States
Several states, including California, Colorado, Connecticut, Virginia and Texas, give residents rights over their personal information. Where those laws apply to you, you may ask us to confirm what we hold, provide a copy, correct it, or delete it, and you may not be treated differently for asking.
Two points specific to those laws. We do not sell personal information and we do not share it for cross-context behavioural advertising, so there is nothing for an opt-out to switch off. And we do not use personal information for automated decision-making or profiling of any kind.
Making a Request
Whichever set of rights applies, email [email protected]. We respond within one month and there is no charge. We may ask for enough information to confirm who you are, and we will not use what you send for that purpose for anything else.
Cookies
We use only what is needed to make the site work. There are no advertising cookies and no social media trackers.
Complaints
Tell us first, so we have a chance to put it right.
You also have the right to complain to a supervisory authority. As we are established in Ireland, that is the Data Protection Commission. In the United Kingdom it is the Information Commissioner’s Office. If you are in California, you may also contact the California Privacy Protection Agency or the state Attorney General.
Changes
We update this policy when our processing changes. The date at the top shows the current version. Where a change materially affects you, we will tell you directly rather than rely on you noticing.