Who is responsible
HUMANEDGE PLUS LIMITED (company number 806759), 118/119 Custom House Quay, Waterford, Ireland, X91 C429, is the controller for personal information submitted through its public website. In a client Discovery engagement, responsibilities for information supplied by the client or its staff depend on the agreed engagement and the purpose of that processing.
For questions about this notice or a privacy request, email hello@humanedgeplus.ie.
Information we receive
The information depends on the route you use. It may include your name, work email, role, organisation, enquiry and communications with us. The Snapshot also asks about the organisation and its stated AI use. Protected Discovery asks different questions for Leadership, Management and Staff participants.
Please do not include unnecessary confidential, sensitive, employee, customer or client information in public form fields. The Snapshot asks for categories and context, not underlying records, and has no file upload.
Business AI Snapshot
The Snapshot asks for your organisation’s name, sector and approximate size; your name, role and work email; and answers about current or planned AI use, how people access AI, information categories, management visibility, guidance, decisions, desired outcomes, what prompted you to take the Snapshot and a preferred next step. Some answers may include short free text.
We use a submitted Snapshot to understand the context you describe, consider whether a conversation may be useful, and respond to you. A person reviews the submission. There is no automated scoring, automated compliance decision or automatic service recommendation.
Our lawful basis is legitimate interests under Article 6(1)(f) GDPR: understanding enquiries about AI governance and deciding how to respond. When online submission is available, Snapshot information is sent through a dedicated service in Google Cloud/Firebase; the browser does not write directly to the submission database.
General enquiries
The Contact form asks for your name, work email, reason for contact and message. Organisation is optional. We use the information to receive, assess and respond to business enquiries, collaboration enquiries and existing-client matters. Our lawful basis is legitimate interests under Article 6(1)(f) GDPR: receiving and responding to those communications. Sending a Contact message or Snapshot is not an agreement to receive unrelated marketing.
At present, Contact form submissions are sent to Formspree, a form service provider, to handle delivery of the message.
Discovery and client work
Protected Discovery is available only through an access code for an agreed organisation. Leadership and Management participants may provide their name, role or function and role-specific answers. The Staff route does not ask for a name or work email; Staff responses are intended to be used as aggregate organisational evidence, with controls to reduce identification risk. Optional free text can still contain identifying information, so participants should avoid adding it unnecessarily.
Discovery responses and related engagement records are held in the protected Google Cloud/Firebase environment. The client organisation’s and HumanEdge+’s data-protection roles depend on the particular engagement and its agreed terms.
Website and security data
Firebase Hosting and connected Google Cloud services deliver and protect this website and its protected services. Those services may process connection and security information, including IP addresses and request metadata. Snapshot application records are designed not to retain raw client IP addresses; this does not mean connection infrastructure never processes them.
Service providers and transfers
Google Cloud/Firebase provides website hosting and protected data services. Formspree currently handles the Contact form. Business email and communication providers may be used to respond to enquiries and deliver operational notifications.
Resend is used to send transactional or operational email notifications associated with relevant HumanEdge+ submission workflows. Information needed for those notifications may be processed by Resend for that purpose.
A European database location does not mean all provider processing stays within the EEA. Provider support, infrastructure and subprocessors may involve other countries. Where personal information is transferred outside the EEA, we use applicable transfer mechanisms, such as an adequacy decision where applicable, or Standard Contractual Clauses or other appropriate safeguards where applicable, and can provide information about relevant safeguards on request.
The Client Portal link opens a separate service. Its own privacy information should be read when you use that service.
How long information is kept
Non-client Contact enquiries are normally kept for 12 months from enquiry closure. If a person becomes a client, information needed for that engagement may form part of the controlled client record under the applicable client retention rule; an enquiry does not automatically become a client record.
Snapshot submissions from organisations that do not convert to clients are normally kept for 12 months from the authoritative server receipt. If an organisation becomes a client, only information genuinely needed for that engagement may be retained separately in its controlled client record. Conversion does not automatically retain the full Snapshot as a long-term client record.
Completed raw Discovery responses are normally retained for 24 months after the engagement closes.
Material final client engagement records are normally retained for 6 years, subject to applicable legal, accounting, contractual or legal-hold requirements.
A complaint, dispute or legal requirement may require a particular record to be kept longer.
Your rights and complaints
Depending on the circumstances, you may have rights to access your personal data, correct it, request erasure or restriction, object to processing, and receive portable data. Where processing is based on consent, you may withdraw that consent. These rights can have conditions or exceptions.
Contact hello@humanedgeplus.ie to make a request. You can also raise a concern with Ireland’s Data Protection Commission.
For a general enquiry, use the Contact page. For information about our work, return to the .
