Privacy Policy

Privacy Policy for Isambard & Associates Ltd

Last Updated: March 12, 2026

Isambard & Associates Ltd (“Isambard”, “we,” “us,” or “our”) is committed to protecting the privacy and security of your personal data. This Privacy Policy explains how we collect, use, disclose, and protect your personal data when you interact with our website ([Your Client’s Website URL]) and use our services, including Net Zero consultancy, FM Procurement, Energy Procurement, Energy Audits, Environmental and Health & Safety Audits, Smart Building Solutions, Acoustic Consultancy & Design (collectively, the “Services”).

We process your personal data in compliance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and the Data Protection Act 2018 (Ireland).

1. Who We Are
Isambard is a consultancy firm based in Ireland, providing specialist services to businesses seeking operational efficiency, sustainability, and compliance.

Contact Details:

Isambard Associates Ltd
109a Kilbroney Road, 
Rostrevor, Newry, Co. Down,
Northern Ireland
BT34 3BN
Phone: +353 (0) 87 737 7193
Email: brianfitzpatrick@isambard.ie
2. Information We Collect
We may collect and process various types of personal data about you, depending on your interaction with us:
2.1 Information You Provide to Us Directly
Contact Information: Name, job title, company name, email address, phone number, and postal address when you fill out forms on our website, subscribe to newsletters, request information, or engage in direct communication (e.g., phone calls, emails).
Service-Related Information: Details necessary to provide our Services, which may include business operational data, energy consumption figures, procurement records, facility layouts, financial information related to projects, and health & safety records. This data may contain personal data of your employees or other individuals, for which you are responsible for obtaining necessary consents.
Communication Data: Records of your correspondence with us, including emails, chat messages, and phone call recordings (if applicable and with prior notice).
Feedback and Survey Data: Information you provide when participating in surveys or giving feedback about our Services.
2.2 Information We Collect Automatically
When you visit our website, we may automatically collect certain information through cookies and similar technologies (please refer to our separate Cookie Policy for more details):
Technical Data: Internet Protocol (IP) address, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access this website.

Usage Data: Information about how you use our website, products, and services, including pages viewed, time spent on pages, navigation paths, and website activity.

3. How We Use Your Information
We use your personal data for the following purposes, based on the legal bases outlined in Section 4:
To Provide and Manage Services: To deliver the consultancy services you have engaged us for, manage our contractual relationship, and fulfil our obligations under any agreement with you.
To Communicate with You: To respond to your enquiries, provide updates on Services, send administrative information, and notify you about changes to our terms or policies.
For Marketing Purposes: To send you information about our Services, news, and events that may be of interest to you, where you have consented or where we have a legitimate interest to do so (you can opt-out at any time).
To Improve Our Website and Services: To understand how our website is used, identify trends, improve user experience, and develop new services.
For Internal Business Operations: For record-keeping, data analysis, auditing, and to ensure the smooth operation of our business.
For Security and Fraud Prevention: To protect our website, systems, and data from unauthorised access, fraud, and other security incidents.

To Comply with Legal Obligations: To meet our legal, regulatory, and compliance requirements, including financial reporting, tax obligations, and responding to lawful requests from public authorities.

4. Legal Basis for Processing (GDPR)
We will only process your personal data where we have a lawful basis to do so. The legal bases we rely on include:
Contractual Necessity: Where processing is necessary for the performance of a contract with you or to take steps at your request before entering into such a contract (e.g., providing our consultancy services).
Legal Obligation: Where processing is necessary to comply with a legal or regulatory obligation (e.g., tax reporting, health & safety regulations).
Legitimate Interests: Where processing is necessary for our legitimate interests (or those of a third party), provided your interests and fundamental rights do not override those interests. This includes improving our services, marketing activities, and ensuring network security. We always balance our legitimate interests against your rights and freedoms.

Consent: Where you have given us clear and explicit consent for a specific purpose (e.g., subscribing to a marketing newsletter). You have the right to withdraw your consent at any time.

5. Sharing Your Information
We may share your personal data with the following categories of recipients:
Service Providers: Third-party vendors and service providers who perform functions on our behalf, such as IT support, hosting, payment processing, analytics, and marketing services. These providers are contractually bound to protect your data and only use it for the purposes for which it was shared.
Professional Advisors: Lawyers, accountants, auditors, and other professional advisors who provide services to us.
Affiliates: Other companies within the Isambard group (if applicable) for internal administrative purposes.
Legal and Regulatory Authorities: When required by law, court order, or governmental regulation, or to protect our rights, property, or safety, or the rights, property, or safety of others.
Business Transfers: In connection with a merger, acquisition, or sale of all or a portion of our assets, your personal data may be transferred to the acquiring entity.

We will not sell or rent your personal data to third parties for their marketing purposes without your explicit consent.

6. Data Retention
We will retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, or reporting requirements.
To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements.
7. Your Data Protection Rights (GDPR)
Under GDPR, you have the following rights regarding your personal data:
Right to Access: You have the right to request a copy of the personal data we hold about you.
Right to Rectification: You have the right to request that we correct any inaccurate or incomplete personal data we hold about you.
Right to Erasure (“Right to be Forgotten”): You have the right to request the deletion of your personal data under certain circumstances.
Right to Restriction of Processing: You have the right to request that we restrict the processing of your personal data under certain conditions.
Right to Data Portability: You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller.
Right to Object: You have the right to object to the processing of your personal data where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground. You also have the right to object where we are processing your personal data for direct marketing purposes.
Rights in relation to Automated Decision-Making and Profiling: You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you.
Right to Withdraw Consent: Where we rely on your consent to process your personal data, you have the right to withdraw that consent at any time.

To exercise any of these rights, please contact us using the details provided in Section 13. We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights).

8. Security Measures
We have implemented appropriate technical and organisational security measures to prevent your personal data from being accidentally lost, used, or accessed in an unauthorised way, altered, or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors, and other third parties who have a business need to know. They will only process your personal data on our instructions and they are subject to a duty of confidentiality.

We have procedures in place to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.

9. International Data Transfers

We store and process your personal data primarily within the European Economic Area (EEA). If we transfer your personal data outside the EEA, we will ensure that appropriate safeguards are in place, such as relying on adequacy decisions, Standard Contractual Clauses (SCCs), or other legally approved mechanisms, to ensure your data receives a similar level of protection.

10. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the “Last Updated” date. We encourage you to review this Privacy Policy periodically.

11. How to Make a Complaint

If you have any concerns about our use of your personal data, you can make a complaint to us using the contact details in Section 1. You also have the right to make a complaint at any time to the Data Protection Commission (DPC), the Irish supervisory authority for data protection issues (www.dataprotection.ie).

12. Contact Us
If you have any questions about this Privacy Policy or our data protection practices, please contact us:

Isambard Associates Ltd

109a Kilbroney Road, 

Rostrevor, Newry,

Co Down 

Northern Ireland 

BT34 3BN

Phone: +353 (0) 87 737 7193

Email: brianfitzpatrick@isambard.ie