Clover Peak Performance Marketing Limited (“we”, “us”, “our”) is committed to protecting your privacy and handling your personal data in a lawful, fair, and transparent manner. This Privacy Policy explains how Clover Peak Performance Marketing Limited collects, uses, discloses, stores, and protects personal data when you interact with our website, services, communications, and related business activities.
1. Introduction and company information
This Privacy Policy applies to personal data processed by Clover Peak Performance Marketing Limited in connection with our performance-marketing services and related operations.
Controller details:
- Company name: Clover Peak Performance Marketing Limited
- Address: 3 The Green, Millennium Business Park, Ballycoolin, Dublin 15, D15 X2R5, Ireland
- Email: [email protected]
- Phone: +353 1 524 8793
For the purposes of applicable privacy laws, Clover Peak Performance Marketing Limited acts as a data controller where we determine the purposes and means of processing personal data. In some cases, we may act as a data processor on behalf of clients, in which case we process personal data only in accordance with contractual instructions and applicable law.
2. Data collection and processing
We may collect and process the following categories of personal data:
- Identity data: name, title, company name, job title.
- Contact data: email address, postal address, phone number.
- Communication data: messages sent to us, correspondence records, meeting notes.
- Technical data: IP address, browser type, device identifiers, operating system, language settings, access times, and referring URLs.
- Usage data: interactions with our website, emails, landing pages, forms, and advertisements.
- Marketing and preference data: consent choices, communication preferences, campaign responses, subscription status.
- Client and business data: information necessary to provide performance-marketing services, including campaign details, account information, reporting data, and audience insights.
- Transaction and billing data: payment-related details, invoicing information, and service records where applicable.
We may collect personal data directly from you, from our clients, from your employer or organization, from publicly available sources, from advertising and analytics platforms, and from service providers or partners acting on our behalf.
Where permitted by law, we may also create or infer data from your interactions with our services to improve campaign performance, audience segmentation, reporting, and service delivery.
3. Purpose of data processing
We process personal data for the following purposes:
- to provide and manage our performance-marketing services;
- to communicate with you and respond to enquiries;
- to create, manage, and optimize advertising campaigns;
- to analyze audience engagement, campaign performance, and conversion metrics;
- to personalize content, advertisements, and user experiences;
- to administer contracts, accounts, invoices, and payments;
- to maintain business records and internal administration;
- to detect and prevent fraud, abuse, security incidents, and unauthorized access;
- to comply with legal and regulatory obligations;
- to establish, exercise, or defend legal claims;
- to send marketing communications, where permitted by law and/or with your consent;
- to improve our website, services, processes, and customer experience.
Where we process personal data for performance-marketing purposes, this may include measuring ad performance, attribution, retargeting, conversion tracking, and audience analysis, subject to applicable legal requirements and your preferences.
4. Legal basis for processing
We process personal data only where we have a lawful basis to do so under applicable law. Depending on the context, our legal bases may include:
- Consent: where you have given clear permission for specific processing activities, such as certain marketing communications or cookies, where required.
- Contract: where processing is necessary to enter into or perform a contract with you or to take steps at your request before entering into a contract.
- Legal obligation: where processing is necessary to comply with legal, tax, accounting, or regulatory obligations.
- Legitimate interests: where processing is necessary for our legitimate business interests, provided those interests are not overridden by your rights and freedoms. These interests may include operating and improving our services, securing our systems, managing business relationships, and conducting limited marketing activities.
- Vital interests: where necessary to protect someone’s life or physical safety in rare circumstances.
Where we rely on legitimate interests, we will assess and balance those interests against your privacy rights. Where consent is the legal basis, you may withdraw consent at any time without affecting the lawfulness of processing before withdrawal.
5. Data sharing and third parties
We may share personal data with third parties where necessary and lawful for the purposes described in this Privacy Policy, including:
- Service providers: hosting providers, cloud infrastructure providers, analytics providers, CRM providers, email service providers, payment processors, IT support, and security providers.
- Advertising and marketing platforms: platforms used to deliver, measure, and optimize campaigns and to manage audience targeting and reporting.
- Professional advisers: lawyers, auditors, accountants, insurers, and consultants.
- Clients and business partners: where needed to deliver services, report on campaigns, or manage commercial relationships.
- Authorities and regulators: where required by law, court order, or lawful request.
- Corporate transactions: in connection with a merger, acquisition, restructuring, sale of assets, financing, or similar transaction, subject to appropriate safeguards.
We require third parties to handle personal data securely and only for specified purposes consistent with our instructions and applicable law. Some recipients may act as independent controllers, while others act as processors under contract.
6. Data transfer to third countries
As a performance-marketing business, we may transfer personal data to countries outside Ireland, the European Economic Area (EEA), or other jurisdictions with equivalent data protection standards, depending on the location of our service providers, clients, and advertising platforms.
Where personal data is transferred internationally, we will ensure that appropriate safeguards are in place, which may include:
- an adequacy decision by the relevant authority;
- standard contractual clauses or equivalent contractual protections;
- supplementary technical and organizational measures where necessary;
- other lawful transfer mechanisms permitted by applicable privacy law.
You may contact us for more information about international transfers and the safeguards we rely on, subject to confidentiality and legal limitations.
7. Storage duration
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including to satisfy legal, accounting, reporting, contractual, and legitimate business requirements.
Retention periods vary depending on the type of data and the context of processing. In general:
- client and service records are retained for the duration of the relationship and for a reasonable period thereafter;
- financial and tax-related records are retained for the period required by law;
- marketing preference records are retained until they are no longer needed or until you withdraw consent or object where applicable;
- technical logs and security records are retained for a limited period unless a longer retention period is required for security, legal, or investigative reasons.
When personal data is no longer required, we will delete, anonymize, or securely archive it in accordance with our retention practices and applicable law.
8. User rights
Subject to applicable law, you may have the following rights regarding your personal data:
- Access: to request confirmation of whether we process your personal data and to obtain a copy of it.
- Rectification: to request correction of inaccurate or incomplete personal data.
- Erasure: to request deletion of personal data in certain circumstances.
- Restriction: to request that we limit processing in certain situations.
- Data portability: to request a copy of certain personal data in a structured, commonly used, machine-readable format and, where technically feasible, to have it transmitted to another controller.
- Objection: to object to processing based on legitimate interests or to direct marketing at any time.
You may also have rights relating to automated decision-making, including profiling, where applicable under law. We do not make decisions based solely on automated processing that produce legal or similarly significant effects unless permitted by law and subject to appropriate safeguards.
To exercise your rights, please contact us using the details below. We may need to verify your identity before responding. We will respond within the time limits required by applicable law.
9. Withdrawal of consent
Where we rely on your consent to process personal data, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.
You may withdraw consent by using the unsubscribe link in marketing emails, adjusting cookie settings where available, or contacting us directly using the details in this policy. If you withdraw consent, we may still process your personal data where another lawful basis applies.
10. Right to complain
If you have concerns about how we handle your personal data, we encourage you to contact us first so we can attempt to resolve the issue.
You may also have the right to lodge a complaint with your local data protection supervisory authority. In Ireland, this is typically the Data Protection Commission, or any other competent authority depending on your location and applicable law.
11. Data security
We implement appropriate technical and organizational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. These measures may include:
- access controls and authentication measures;
- role-based permissions and least-privilege access;
- encryption in transit and, where appropriate, at rest;
- firewalls, monitoring, logging, and intrusion detection;
- staff confidentiality obligations and security training;
- vendor risk assessment and contractual safeguards;
- regular review of security procedures and incident response planning.
While we take reasonable steps to protect personal data, no method of transmission over the internet or electronic storage is completely secure. We cannot guarantee absolute security, but we continually work to improve our protections.
12. Contact information
If you have questions, requests, or concerns about this Privacy Policy or our processing of personal data, please contact:
- Clover Peak Performance Marketing Limited
- Address: 3 The Green, Millennium Business Park, Ballycoolin, Dublin 15, D15 X2R5, Ireland
- Email: [email protected]
- Phone: +353 1 524 8793
Please include sufficient detail in your message so that we can understand and respond to your request effectively.
13. Changes to privacy policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or business operations. Any changes will be effective when posted on our website or otherwise communicated to you, unless a different effective date is stated.
We encourage you to review this Privacy Policy periodically to stay informed about how Clover Peak Performance Marketing Limited processes personal data.
Effective date: 27 August 2026