Privacy Policy — Ireland
How Cerrax handles personal data under the GDPR, in plain terms.
1. Who we are
Cerrax Ltd ("Cerrax", "we") provides a pricing engine for the removals industry. We are a company registered in England and Wales and we are not established in the European Union. This policy explains what personal data we handle for firms in Ireland and the people they quote, why, and your rights. Questions: hello@cerrax.io.
We have not yet designated a representative in the EU under Article 27 of the GDPR. While our processing of data about people in the EU is occasional and small in scale we rely on Article 27(2); we will appoint one as that changes, and will name them here. In the meantime, contact us directly at the address above — we answer as the controller or processor ourselves.
2. Two different roles
Our role under the GDPR depends on whose data it is:
- Your data (the removal firm using Cerrax). For account holders' own details, we are the controller.
- Your customers' data. When a firm uses Cerrax to price a job, any personal data about that firm's customers (names, addresses, Eircodes) is handled by us as a processor, on the firm's instructions. The firm is the controller; our processing is governed by the data processing agreement between us.
- Website visitors. We are the controller for the limited data you give us directly (e.g. a waitlist or contact form).
3. What we collect
From firms using Cerrax: account and contact details (name, company, email, phone, VAT number if you give it), and the job inputs you enter to produce a price. Within job data: addresses and job details, which may be personal data of your customers — processed only to produce and explain a price and record the outcome you tell us. From the job itself: where your crew use Cerrax on the day, photographs they take of the property, its access and any damage found; if you ask your customer to sign the inventory, the name they give and the signature they draw; and, if you invite it and your customer chooses to, a video of their home that they send you to be quoted from. These are held as the record of the job, on your instructions, and are used for nothing else: they never affect a price and are never shared with another firm. From website visitors: what you submit in a waitlist, demo or contact form. We do not record your browsing sessions or track behaviour for advertising.
4. Cookies
We use only the cookies needed to make the site and service work (for example, keeping you signed in). We don't use advertising or cross-site tracking cookies, so no cookie consent banner is needed. If we ever add analytics or other non-essential cookies, we'll ask for consent first, as the ePrivacy Regulations (S.I. 336/2011) require.
We measure how many people visit these pages using Vercel Web Analytics, which is privacy-preserving by design: it sets no cookie, stores no identifier, and cannot follow you between sites or sessions. It tells us page counts, referring sites and countries — never who you are.
5. Why we use it, and our lawful bases
- To provide the service — performance of our contract with you (Article 6(1)(b)).
- To improve the pricing engine — our legitimate interest in calibrating prices (Article 6(1)(f)), using de-identified data (see §7).
- To meet legal obligations — e.g. accounting, responding to lawful requests (Article 6(1)(c)).
6. Automated pricing
Cerrax produces a price automatically from the inputs and settings provided. This is a tool for the firm: the firm decides what to charge its customer (see our Terms). The automated price is not a decision Cerrax makes about a customer that produces a legal or similarly significant effect on them within the meaning of Article 22 of the GDPR.
7. The learning corpus (important)
Cerrax gets more accurate as it sees real outcomes. To do that we retain de-identified pricing and outcome data — the shape of a job and what it cost, stripped of the people involved. We erase the person and keep the anonymised job. Aggregated, anonymised insight may inform regional benchmarks; we never expose an individual firm's prices or any customer's identity. We only treat data as de-identified once it can no longer be linked to a person, and we hold it to that standard before it enters the corpus.
8. Who we share it with
We don't sell personal data. We use a small set of service providers (sub-processors) under contract, currently including: cloud hosting and database (Google Cloud, London region) and geocoding (Google Maps, for distance between addresses). Where the optional spreadsheet-import or narrative-capture features are used, those inputs are processed by an AI provider (Anthropic, United States). Our website is hosted by Vercel, which also provides the cookieless visitor analytics described in §4. Email we send you is delivered by Amazon Web Services (SES, EU region). Payments are taken by Stripe. We keep this sub-processor list current and reflect only services actually in use.
9. Where your data is stored
Your data is held in the United Kingdom, in London. For a firm in Ireland that is a transfer of personal data out of the European Union, and it is lawful because the European Commission has decided that the United Kingdom provides an adequate level of protection (Decision (EU) 2021/1772, extended in 2025). Where a provider processes data outside the EU and the UK — AI processing in the United States is the case today — we rely on the EU standard contractual clauses. We don't move personal data anywhere without a valid transfer mechanism.
As things stand today: every Cerrax account is in the United Kingdom or Ireland, and the data behind every one of them is held in London. That is a statement of fact on the date at the top of this page rather than a promise about the future — if you need it in writing for a particular account, or want to know where a specific service processes data, ask us at hello@cerrax.io and we will tell you.
10. How long we keep it
Account and customer personal data: for as long as your account is active and for up to six years after it closes, to meet our legal, accounting, and tax obligations — unless the law requires us to keep it longer. Job records — a quote, its booking and outcome, the crew's sheets, and any survey or damage photographs attached to them — for six years after the move (or after the quote, if the job did not go ahead), unless a claim or dispute about that job is still open. Photographs have no separate clock: they are kept for as long as the job record they belong to and are deleted with it. A customer's video is deleted 90 days after the job's last date unless the customer has separately agreed to its longer use. De-identified outcome data: retained for the learning corpus. You can ask us to erase personal data (§12); committed pricing records are never silently altered, but personal identifiers within them can be redacted.
11. Marketing and communications
We'll send you service messages needed to run your account. If you ask for a demo or sign up, we may contact you about Cerrax; you can opt out of marketing at any time via the unsubscribe link or by emailing us. We follow the ePrivacy Regulations (S.I. 336/2011) for any electronic marketing.
12. Your rights
Under the GDPR you can request access, correction, erasure, restriction, portability, and object to certain processing. For your customers' data (where we are processor), direct requests to the firm as controller; we assist them. To exercise a right, contact hello@cerrax.io. We answer within one month.
13. Children
Cerrax is a tool for businesses and is not directed at children. We don't knowingly collect data from children.
14. Complaints
If you're unhappy with how we handle your data, tell us at hello@cerrax.io — we will acknowledge your complaint within 30 days and work to resolve it. You can also complain to the Data Protection Commission (dataprotection.ie), which is the supervisory authority in Ireland.
15. Security
We protect data with access controls, encryption in transit and at rest via our cloud provider, and audited administrative actions. No system is perfectly secure, but we take reasonable measures appropriate to the data.
If a personal data breach occurs, we act promptly: where we are the controller we notify the Data Protection Commission within 72 hours where required, and affected individuals where required; where we are a processor we notify the affected firm without undue delay so they can meet their own obligations.
16. Changes
We may update this policy; we'll post the new version here with a revised effective date.
17. Contact
Cerrax Ltd, 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. hello@cerrax.io.