Last Updated: December 27, 2025
Your Privacy Matters to Irish Tax Hub
At Irish Tax Hub, safeguarding your personal information is paramount. This Privacy Policy explains how we collect, use, share, and protect your data when you use our website and platform services. For users within the European Economic Area (EEA), your rights under the General Data Protection Regulation (GDPR) are respected and outlined below.
This Policy applies to our website, account services, and our optional "ITH Assistant" (our AI chat for Irish tax).
What Information We Collect
We collect the following types of personal data:
Account Information
When you create an account with Irish Tax Hub, we collect:
- Email address and securely hashed password
- Profile information you provide
- Account preferences and settings
- Authentication tokens and session data
- Account activity and login history
Identification Details
Your name, address, PPS number, date of birth, and similar identifying information required for tax administration and compliance.
Financial Details
Information about your income, expenses, deductions, and other financial data necessary for tax preparation and filing.
Payment and Billing Information
When you purchase services, we collect:
- Payment card details (processed and stored securely by Stripe; we do not store full card numbers on our systems)
- Billing address and contact information
- Purchase history and transaction records
- Subscription status and payment receipts
- Tax/VAT information as required by Irish and EU law
Identity Verification Data
For certain services requiring identity verification, we use Stripe Identity to verify your identity. This may include:
- Government-issued ID documents (passport, driver's license, public services card, etc.)
- Selfie photographs for identity matching purposes
- Verification status and results
This data is processed by Stripe under their own privacy policy and security standards.
Uploaded Documents (Sensitive Data)
When you upload files to our platform for tax preparation services, we may process:
- Payslips containing employment details, income information, and employer data
- Bank statements containing transaction history, account information, and financial patterns
- Other tax-related documents you choose to upload (P60s, P45s, medical receipts, etc.)
These documents may contain special category data under GDPR (e.g., health-related deductions, trade union memberships, charitable donations).
Important: We store these documents securely on EU-based servers (Ireland, EU-West-1 region). We implement encryption at rest and in transit. You can delete your uploaded files at any time through your account settings.
Contact Details
Your email address and phone number, so we can communicate with you regarding your account, services, and tax matters.
Usage Data
Information about how you interact with our website and platform, collected through cookies and similar technologies. See our Cookie Policy for details.
ITH Assistant Inputs (Optional)
If you use the ITH Assistant, any text you type (and files you choose to upload) will be transmitted to our AI providers, OpenAI and Anthropic, to generate a response.
Irish Tax Hub does not store your ITH Assistant prompts or responses on our own systems beyond what is technically necessary to operate the session. The AI providers may process and log your inputs/outputs under their own terms and privacy policies, which we do not control.
Important: Please avoid entering unnecessary personal data and do not share special category or highly sensitive information (such as your PPS number, full financial details, or identifying information about third parties).
How We Use Your Information (Lawful Basis for Processing under GDPR)
We use your personal information based on the following lawful grounds under the GDPR:
Contractual Necessity
We process your data to:
- Create and maintain your account
- Process your tax returns accurately when you request this service
- Provide the services you have purchased or subscribed to
- Store and manage your uploaded documents securely
- Process payments and manage subscriptions
- Communicate with you about your account and services
Legitimate Interests
We process your data to:
- Communicate with you effectively regarding your tax matters
- Enhance and improve the services we offer
- Conduct internal administrative purposes
- Prevent fraud and ensure platform security
- Verify your identity when required for service delivery
- Analyze platform usage to improve user experience (anonymized where possible)
- Monitor errors and performance issues to maintain service quality
These interests are balanced against your rights and do not override your fundamental rights and freedoms.
Legal Obligations
We process your data to:
- Meet our legal and regulatory obligations under Irish and EU law
- Comply with Revenue requirements and tax administration rules
- Maintain records as required by Irish accounting and tax regulations
- Respond to lawful requests from authorities
Consent
Where required for specific processing activities, we will obtain your explicit consent, including:
- Analytics Tracking: Processing usage data via PostHog analytics (see our Cookie Policy)
- Marketing Communications: Sending you promotional materials (where applicable)
- ITH Assistant: Transmitting your queries to AI providers
You have the right to withdraw consent at any time through your account settings or by contacting us.
Analytics & Website Improvement (with Consent)
If you provide your consent via our cookie banner or account settings, we use PostHog to collect information about how visitors use our website. This helps us understand user behavior (e.g., which pages are popular, how long users stay on the site, which features are used) and improve the website's functionality and user experience.
The data collected by PostHog may include pseudonymous identifiers, device type, browser type, pages visited, and interaction patterns. This information is typically aggregated and used for statistical analysis.
We only activate PostHog tracking if you explicitly accept analytics cookies through our consent banner or enable it in your account settings.
Controlling Analytics:
- Logged-out users: Click "Accept" or "Decline" in the cookie banner, or click "Manage Cookies" in the footer
- Logged-in users: Visit My Account → Privacy & Consent Preferences to manage your analytics preference
- Your consent is stored and synced across all your devices
For more details, see our Cookie Policy.
ITH Assistant Lawful Basis
When you choose to use the ITH Assistant, we process your inputs to generate a response under our legitimate interests (to provide a fast, searchable interface to public Irish tax materials) and/or your consent (where required) to transmit your query to OpenAI and Anthropic for processing.
Cookies and Similar Technologies
We use cookies and similar technologies for essential functionality, analytics, error monitoring, and security.
Essential Cookies (Strictly Necessary)
These cookies are essential for the platform to function and do not require consent under GDPR:
- Session cookies to keep you logged in and maintain your secure session
- Authentication tokens to verify your identity
- Security cookies to protect against fraud and unauthorized access
- Core functionality cookies to ensure the platform works correctly
Analytics Cookies (Optional - Require Consent)
These cookies help us understand how visitors use our website:
- PostHog analytics to track page views, user behavior, and feature usage
- These are only activated if you explicitly consent via our cookie banner or account settings
Other Technologies
We use additional technologies for error monitoring (Sentry) and payment processing (Stripe). These are necessary to provide and secure our services.
For complete details about cookies, including how to manage your preferences, please see our Cookie Policy.
Who We May Share Your Information With (Data Processors & International Transfers)
We may share your information with the following parties:
Revenue and Other Government Bodies
As legally required for tax administration and compliance with Irish law. These transfers are necessary for compliance with legal obligations.
Payment Processor (Stripe)
We use Stripe to process payments and conduct identity verification:
- Stripe processes payment card details under PCI DSS compliance standards
- Stripe Identity processes identification documents for verification purposes
- Data may be transferred to Stripe servers globally, with appropriate safeguards including EU data residency options and Standard Contractual Clauses
- Review Stripe's Privacy Policy for details on their data practices
Database and Authentication Services
We use secure, GDPR-compliant database and authentication services to store and manage:
- Your account information and authentication data
- Uploaded documents (payslips, bank statements, etc.)
- Application data and settings
- All data is stored on EU-based infrastructure (Ireland, EU-West-1 region), ensuring it remains within the European Economic Area
Analytics Provider (PostHog - with Consent)
If you consent to analytics cookies, we use PostHog to understand website usage:
- Data is processed in accordance with GDPR requirements
- We may configure PostHog to store data within the EU
- Review PostHog's Privacy Policy for details
Error Monitoring (Sentry)
We use Sentry for error tracking and performance monitoring:
- Sentry collects error messages, stack traces, and performance data
- Data may be processed in the United States with appropriate safeguards
- This processing is based on our legitimate interest in maintaining platform security and reliability
- Review Sentry's Privacy Policy for details
AI Providers (OpenAI and Anthropic - ITH Assistant Only)
If you use the ITH Assistant, your prompts and the tool's outputs are sent to OpenAI and Anthropic for processing:
- Data may be processed outside the EEA
- We rely on appropriate safeguards (e.g., Standard Contractual Clauses) used by our providers for international transfers
- Irish Tax Hub is not responsible for the AI providers' independent storage, retention, or security practices
- Review OpenAI's Privacy Policy and Anthropic's Privacy Policy before using the ITH Assistant
Law Enforcement and Legal Authorities
If required by law, court order, or to protect our legal rights and those of our users.
All third-party processors are carefully selected and required to maintain GDPR-compliant data protection standards. Where data is transferred outside the EEA, we ensure appropriate safeguards are in place (Standard Contractual Clauses, adequacy decisions, or equivalent protections).
Where Your Data is Stored
Your personal data is stored on secure servers located in Ireland (EU-West-1 region), ensuring it remains within the European Economic Area. This provides strong data protection under GDPR and Irish data protection law.
Our data infrastructure:
- Primary hosting: Ireland, EU-West-1
- Payment processing: Stripe (global infrastructure with EU data residency options)
- Backups: Stored securely within the EU
- Analytics: PostHog (EU-configurable)
All processors are required to maintain GDPR-compliant data protection standards.
How Long We Keep Your Data (Data Retention)
We retain your personal information only as long as necessary for the purposes outlined in this policy:
Data Category
Retention Period
Legal Basis
Account information
While your account is active, plus 7 years after account closureIrish tax record requirements and legal obligations
Tax return files and financial documents
Minimum 6 years from the end of the tax yearRevenue requirement and legal obligation
Uploaded documents (payslips, bank statements)Until you delete them, or 6 years minimum if used for tax returnsRevenue requirement and contractual necessity
Payment and billing records
7 years after transactionIrish accounting and legal requirements
Communication records
3-7 years depending on natureLegal obligations and legitimate interests
Identity verification records
As determined by Stripe's retention policy
Legal obligation and fraud prevention
Analytics dataUp to 12 months
PostHog retention configuration
ITH Assistant logs
Determined by OpenAI and Anthropic policies; not stored by Irish Tax Hub beyond session
AI provider terms
Session and authentication logs
90 days
Security and fraud prevention
Error monitoring logs
90 daysLegitimate interest (debugging and security)
Important Notes:
- You can request deletion of your data subject to our legal obligations
- Some data must be retained for compliance purposes even after account deletion (e.g., payment records for tax authorities)
- When legally required retention periods expire, we will securely delete or anonymize your data
- You can delete uploaded documents at any time through your account, subject to legal retention requirements
Keeping Your Data Secure
We take data security seriously and employ industry-standard security measures to protect your personal information from unauthorized access, use, disclosure, alteration, or destruction.
Security Measures Include:
- Encryption: Data encrypted in transit (TLS/SSL) and at rest on our servers
- Secure Authentication: Passwords are hashed using industry-standard algorithms (never stored in plain text)
- Access Controls: Strict access controls limiting who within Irish Tax Hub can access your data
- EU-Based Hosting: Data stored on GDPR-compliant servers in Ireland
- Regular Security Audits: Ongoing monitoring and security assessments
- Secure Backups: Regular encrypted backups stored securely within the EU
- Infrastructure Security: Firewalls, intrusion detection, and DDoS protection
- Employee Training: Staff trained on data protection and security best practices
- Error Monitoring: Automated error detection to identify and fix security issues promptly
Your Responsibilities:
- Choose a strong, unique password for your account
- Keep your login credentials confidential
- Log out of your account when using shared devices
- Enable two-factor authentication if available
- Report any suspected security incidents to us immediately
Please remember: No online transmission or electronic storage is entirely foolproof. While we implement robust security measures, we cannot guarantee absolute security.
Special Note on ITH Assistant:
Because ITH Assistant prompts may be processed by third-party systems (OpenAI and Anthropic), do not include personal information; remove or mask directly identifying details (e.g., PPSN, account numbers, exact addresses, full names).
Your Rights Regarding Your Data (Under GDPR)
If you are located in the EEA, you have the following rights under the GDPR:
Right to Access
You have the right to request a copy of the personal data we hold about you. You can request this by contacting us at contact@irishtaxhub.ie.
Right to Rectification
You have the right to request correction of inaccurate or incomplete personal data. You can update most information directly through your account settings.
Right to Erasure ("Right to be Forgotten")
You have the right to request deletion of your personal data in certain circumstances.
To delete your account: Contact us at contact@irishtaxhub.ie with your deletion request.
When you delete your account:
- Your profile and account information will be permanently deleted
- Your uploaded documents (payslips, bank statements, etc.) will be permanently deleted from our systems
- Your payment history will be anonymized but retained for legal compliance (7 years as required by Irish law)
- Some data may be retained where we have a legal obligation to do so (e.g., tax records, accounting records)
Please note: Deletion is permanent and cannot be reversed. You may wish to download your data before requesting deletion (see Right to Data Portability below).
Right to Restriction of Processing
You have the right to request restriction of processing your personal data in certain circumstances (e.g., while we verify accuracy of disputed data).
Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller. Contact us to request a copy of your data.
Right to Object
You have the right to object to processing based on legitimate interests or for direct marketing purposes. We will cease processing unless we have compelling legitimate grounds.
Right Not to Be Subject to Automated Decision-Making
We do not use automated decision-making or profiling that produces legal effects concerning you or similarly significantly affects you, except where necessary to prevent fraud (e.g., payment verification through Stripe).
The ITH Assistant provides informational responses only and does not make decisions with legal effect about you.
Right to Withdraw Consent
Where processing is based on consent (e.g., analytics cookies, marketing), you have the right to withdraw consent at any time:
- Analytics: Visit My Account → Privacy & Consent Preferences or click "Manage Cookies" in the footer
- Marketing: Unsubscribe from emails or update preferences in your account
- ITH Assistant: Simply stop using the service
This does not affect the lawfulness of processing based on consent before its withdrawal.
How to Exercise Your Rights
To exercise any of these rights, please contact us at contact@irishtaxhub.ie. We will respond to your request within one month (extendable by two months for complex requests).
Right to Lodge a Complaint
You have the right to lodge a complaint with a supervisory authority:
- Irish Data Protection Commission: www.dataprotection.ie
- Or the supervisory authority in your country of residence, place of work, or where an alleged infringement occurred
Age Requirements
Our services are intended for individuals aged 16 years or older (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal information from individuals under this age.
If you believe we have collected information from a minor, please contact us immediately at contact@irishtaxhub.ie, and we will take prompt steps to delete such information.
Automated Decision-Making and Profiling
Irish Tax Hub does not engage in automated decision-making or profiling that produces legal effects concerning you or similarly significantly affects you.
Exception: We may use automated fraud prevention systems (via Stripe) to protect against fraudulent transactions. These systems help ensure platform security and protect all users.
Data Breach Notification
In the unlikely event of a data breach that poses a risk to your rights and freedoms, we will:
- Notify the Irish Data Protection Commission within 72 hours as required by GDPR
- Notify you without undue delay if the breach is likely to result in a high risk to your rights and freedoms
- Provide information about the nature of the breach and steps we are taking to address it
Important Notice about the ITH Assistant (Not Professional Advice & No Liability)
The ITH Assistant is an informational resource and is not a substitute for professional tax advice.
You should be aware:
- Outputs may be incomplete, outdated, or inaccurate
- The ITH Assistant does not take account of your full personal circumstances
- No professional–client relationship is created by using the ITH Assistant
- Irish Tax Hub provides ITH Assistant outputs "as is" without warranties (express or implied) as to accuracy, completeness, or fitness for a particular purpose
- Irish Tax Hub bears no responsibility or liability for actions taken or not taken based on ITH Assistant outputs
You should always seek professional advice from a qualified tax advisor before making tax decisions or taking action based on ITH Assistant outputs.
Acceptable Use & Rate Limiting (ITH Assistant)
We reserve full discretion to protect the service and ensure fair access for all users.
We may rate-limit, throttle, suspend, or block access to the ITH Assistant for behavior that we consider:
- Abusive, harmful, unlawful, or disruptive
- Automated scraping or high-volume requests designed to extract data
- Attempts to reverse engineer or circumvent technical safeguards
- Submission of prohibited content (illegal content, malware, spam, etc.)
- Misuse that degrades service quality for other users
International Users
While Irish Tax Hub is primarily designed for Irish residents and users within the EEA, users from other jurisdictions may access our website and services.
If you are outside the EEA:
- Your data may be transferred to and processed within the EEA (Ireland)
- You may not have the same data protection rights as EEA residents
- By using our services, you consent to the transfer of your data to Ireland
Third-Party Links
Our website may contain links to third-party websites (e.g., Revenue.ie, Citizens Information, survey platforms). We are not responsible for the privacy practices of these external sites. We encourage you to review their privacy policies before providing any personal information.
Updates to This Policy
We may update this Privacy Policy periodically to reflect changes in our practices, services, legal requirements, or for other operational reasons.
When we make significant changes:
- We will update the "Last Updated" date at the top of this policy
- We will notify you via email (if you have an account) or through a prominent notice on our website
- For material changes, we may seek your renewed consent where required by law
We encourage you to review this Privacy Policy periodically. Your continued use of our services after changes are posted constitutes acceptance of the updated policy.
Get in Touch
If you have any questions about this Privacy Policy, wish to exercise your GDPR rights, or have concerns about our data handling practices:
Email: contact@irishtaxhub.ie
For Data Protection Inquiries: Please mark your email subject line "Data Protection Inquiry" or "GDPR Request"
To Lodge a Complaint: Irish Data Protection Commission: www.dataprotection.ie
We aim to respond to all inquiries within 5 business days and formal GDPR requests within one month.
Consent and Agreement
By using our website and services, you acknowledge that:
✓ You have read and understood this Privacy Policy
✓ You agree to the collection and use of your personal information as described here
✓ You understand your rights under GDPR and how to exercise them
By creating an account, you additionally acknowledge that:
✓ You consent to us storing your account information and any documents you upload
✓ You understand that payment information will be processed by Stripe
✓ You agree to our data retention periods as outlined above
By using the ITH Assistant, you additionally acknowledge that:
✓ Your inputs may be processed by OpenAI and Anthropic
✓ Such processing may involve international transfers subject to appropriate safeguards
✓ You should avoid sharing unnecessary or sensitive personal data
✓ The ITH Assistant is not a substitute for professional tax advice
Irish Tax Hub
Empowering you to take control of your tax affairs
Tax Agent Number: 81592L
Related Policies
- Cookie Policy - Detailed information about how we use cookies
- Terms of Service - Our terms and conditions for using the service
This privacy policy is effective as of the "Last Updated" date above. Previous versions of this policy can be requested by contacting us at contact@irishtaxhub.ie.