Privacy policy
How OTTA uses personal data.
This privacy policy explains what personal data OTTA collects, why it is used, who may receive it, how long it is normally retained and what data protection rights you have.
1. Data controller
Who is responsible for your personal data?
OTTA is the data controller for personal data processed through this website and in connection with OTTA services.
- Business name: OTTA
- Owner: Thomas Thiel
- Business type: Sole trader
- CRO business name number: 790259
- Business address: 460 Aisling Park, Dundalk, County Louth, A91 X4E4, Ireland
- Email: [email protected]
- Website: https://otta.ie/
2. Services covered
This policy covers OTTA website and service activity.
This policy applies to:
- General contact enquiries
- Website project enquiries
- Written setup-check orders
- WooCommerce checkout and payment activity
- Intake forms and submitted files
- Small website projects
- Service-related emails and correspondence
- Website security, technical logs and essential cookies
3. Contact and project enquiries
Enquiry information is used to respond to you.
If you contact OTTA or submit a website project enquiry, OTTA may process information such as:
- Your name
- Your email address
- Your telephone number, if voluntarily provided
- Your business or organisation name
- Your website address
- Your message and project requirements
- Budget, timing or service preferences you choose to provide
- Any files, screenshots or examples submitted with the enquiry
This information is used to reply, determine whether OTTA can provide the requested service, prepare a proposal and keep a reasonable record of the enquiry.
The legal basis is normally taking steps at your request before entering a contract. OTTA may also rely on legitimate interests in responding to genuine business enquiries and maintaining necessary service correspondence.
4. Orders and checkout
WooCommerce processes order information.
When you order a written review, WooCommerce may collect and store:
- Your name
- Email address
- Telephone number
- Billing address and country
- Product ordered
- Order number, date and value
- Order and payment status
- Order notes
- Technical checkout information
Guest checkout is available, so a customer account is not required unless OTTA changes this setting in the future.
Order information is used to conclude and perform the contract, send order communications, deliver the service, deal with cancellations or refunds, and meet accounting and legal obligations.
5. Early service-start consent
The checkout records your service-start request.
For OTTA written reviews, the checkout asks whether you expressly request OTTA to begin the service before the normal 14-day cancellation period has ended.
If you select this checkbox, OTTA stores:
- That consent was given
- The wording shown at checkout
- The date and time of the consent
- The associated WooCommerce order
This record is used to document the contract, your instructions and the handling of applicable cancellation rights.
6. Payment information
Payments are processed by PayPal.
Payments are handled through PayPal or PayPal-supported payment methods. PayPal processes payment data under its own privacy terms.
OTTA normally receives information such as payment status, transaction reference, payer details needed for the order and limited fraud or verification information.
OTTA does not store full payment-card details on this website and will not ask you to send card or bank details by email or through an intake form.
PayPal privacy information: View PayPal’s privacy statement
7. Intake forms and uploads
Setup details are used to prepare your written review.
After ordering, you may submit information through an OTTA intake form, including:
- Your order number and checkout email address
- Descriptions of your website or technical setup
- Website URLs
- Home server, network or Home Assistant information
- Questions, goals and problem descriptions
- Screenshots, images, diagrams or PDF notes
The submitted information is used to verify the order, understand the service requested, prepare the written report and ask reasonable follow-up questions.
Form submissions and uploaded files may be processed in the WordPress website, the form system, server storage, OTTA email mailboxes and normal system backups, depending on the technical settings in use.
Do not submit confidential access credentials
Do not upload or send passwords, API keys, tokens, private keys,
recovery codes, full configuration backups, .env
files, payment details or remote-access credentials.
8. Website project information
Website projects may require additional material.
For an agreed website project, OTTA may process customer-supplied:
- Business contact and company information
- Website text, photographs, logos and branding
- Product or service information
- Staff or customer information included in approved content
- Feedback, revision requests and project approvals
- Domain, hosting or technical information needed for the work
You are responsible for ensuring that you are entitled to provide this material and that any personal data included in it may lawfully be used for the project.
Written reviews do not require remote access. Where limited access is necessary for a separately agreed website project, OTTA will discuss the required access with you. Temporary or separately created access should be used where possible.
9. Email and delivery logs
Service emails are sent through authenticated email systems.
OTTA uses website and email systems to send order confirmations, intake instructions, service correspondence and internal notifications.
Email processing may include:
- Sender and recipient addresses
- Subject line
- Message content
- Order or form information contained in the message
- Uploaded files attached to form notifications
- Delivery status, date, time and technical error information
Website-generated email is sent using FluentSMTP and authenticated OTTA email hosting. Some OTTA addresses may forward messages internally to another designated OTTA mailbox.
Delivery logs are used to confirm that messages were sent, diagnose failures and protect the reliability of the website’s email process.
10. Technical and security data
Technical information helps protect the website.
The website, hosting platform and security services may process:
- IP address
- Browser and device information
- Pages and resources requested
- Date and time of requests
- Login attempts
- Security events and suspected abuse
- Server, application and error logs
This information is used for security, fraud prevention, service availability, troubleshooting, backup integrity and protection against unauthorised access.
The legal basis is OTTA’s legitimate interest in operating and protecting its website, checkout, email and services.
11. Cloudflare and spam protection
Cloudflare helps deliver and protect the website.
OTTA uses Cloudflare services for website delivery, DNS, TLS, security and protection against malicious or automated traffic.
Cloudflare Turnstile may be used on forms to distinguish genuine submissions from automated abuse. Cloudflare may process technical data such as IP address, browser characteristics and request information for these purposes.
Cloudflare privacy information: View Cloudflare’s privacy policy
12. Cookies
Essential cookies help the site function.
The website may use essential cookies or similar local-storage technologies for:
- Shopping basket and checkout functions
- Payment processing
- Security and abuse prevention
- Login and administrative functions
- Remembering necessary website states
These technologies are used where necessary to provide the website, checkout or service requested.
If optional analytics, advertising or non-essential tracking is introduced, OTTA will update this policy and implement appropriate consent controls where required.
13. Purposes and legal bases
Why OTTA processes personal data.
| Purpose | Typical legal basis |
|---|---|
| Responding to enquiries and preparing proposals | Steps requested before entering a contract and legitimate interests |
| Processing orders and delivering services | Performance of a contract |
| Recording early service-start consent | Contract administration, legal obligations and legitimate interests |
| Processing payments and refunds | Performance of a contract and legal obligations |
| Keeping accounting and tax records | Legal obligation |
| Website, email and checkout security | Legitimate interests |
| Handling disputes or legal claims | Legal obligations and legitimate interests |
| Optional marketing or non-essential cookies | Consent, where used |
14. Data recipients
Data is shared only where reasonably necessary.
Depending on the service and transaction, limited personal data may be processed by or disclosed to:
- OTTA’s website-hosting and email provider
- WooCommerce and associated checkout systems
- PayPal and supported payment providers
- Cloudflare and website-security providers
- Form, backup and email-delivery systems
- Professional advisers such as an accountant or legal adviser
- Public authorities where disclosure is required by law or needed to protect legal rights
OTTA does not sell personal data and does not provide customer data to advertisers.
15. International transfers
Some service providers operate internationally.
Some providers used for payments, website protection, software or technical infrastructure may process personal data outside Ireland or the European Economic Area.
Where such a transfer occurs, it should be covered by an applicable legal safeguard, such as an adequacy decision, approved contractual safeguards or another transfer mechanism recognised under data protection law.
Further information about provider transfers is available in the relevant provider’s privacy statement.
16. Data retention
Data is not kept indefinitely.
- Enquiries that do not become an order: normally retained for up to 24 months after the last meaningful contact, unless there is a reason to keep them longer.
- Order, invoice and accounting records: generally retained for at least six years, or longer where required by tax law, an audit, dispute or legal proceeding.
- Early service-start consent records: retained with the associated order record.
- Intake uploads and working material: normally retained for up to 12 months after delivery, unless needed for clarification, a dispute, a legal obligation or an ongoing service.
- Final written reports and relevant correspondence: may be kept with the service record where reasonably needed to show what was ordered and delivered.
- Website-project working files: normally retained for up to 12 months after project completion, unless otherwise agreed or needed for ongoing work.
- Email-delivery and technical logs: retained for the operational period configured in the relevant system and periodically deleted unless needed to investigate a problem.
- Security logs: retained only for an operational security period unless an event requires longer investigation.
Deleted information may remain in normal system backups until the relevant backup-rotation period has completed.
17. Your data protection rights
You may have rights over your personal data.
Depending on the circumstances, you may have the right to:
- Request access to your personal data
- Ask for inaccurate information to be corrected
- Request deletion where there is no lawful reason to retain it
- Ask for processing to be restricted
- Object to processing based on legitimate interests
- Receive certain information in a structured, commonly used machine-readable format
- Withdraw consent where processing is based on consent
- Complain to the Irish Data Protection Commission
Withdrawing consent does not affect processing that was lawful before the withdrawal.
To make a privacy request, email [email protected].
OTTA may need to verify your identity before releasing or changing personal data.
Irish Data Protection Commission: www.dataprotection.ie
18. Required and optional information
Some information is needed to provide the service.
Information marked as required during checkout or in an intake form is normally needed to process the order, verify the customer or prepare the requested service.
If required information is not provided, OTTA may be unable to accept an order, begin work or complete the service.
Fields marked optional may be left blank.
19. Automated decisions
OTTA does not use automated decision-making.
OTTA does not currently use personal data to make decisions that have legal or similarly significant effects solely through automated processing.
Automated security systems may block or challenge suspicious website activity, but service proposals and written reviews are handled by a person.
20. Children
OTTA services are intended for adults and businesses.
OTTA services are not directed at children, and OTTA does not knowingly seek personal data from children through its enquiry, checkout or intake processes.
21. Security
Reasonable safeguards are used.
OTTA uses reasonable technical and organisational measures intended to protect personal data, including controlled website access, encrypted connections, authenticated email delivery, security services and backups.
No internet service, email system or storage method can guarantee absolute security. Customers should avoid sending unnecessary confidential information.
22. Changes to this policy
This privacy policy may be updated.
OTTA may update this policy when services, forms, hosting, payments, email systems, security tools or legal requirements change.
The current version will be published on this page with an updated date.
Last updated
27 July 2026
This version reflects OTTA’s current written reviews, website project enquiries, WooCommerce checkout, PayPal payments, intake forms and file uploads, FluentSMTP email delivery, Cloudflare protection and related website systems.
Clear services with clear data handling.
Choose a written review or contact OTTA about a small website project.