Privacy Policy

Privacy Policy

Privacy Policy

Last updated: August 2026

This Privacy Policy explains how Nootrol Limited trading as Threadable collects, uses and protects personal data when you visit our website, contact us or work with us.

About Threadable

Nootrol Limited trading as Threadable is registered in Ireland under company number 474985, with offices at 3 Lanesville Mews, Monkstown, Dublin, Ireland. Threadable helps operationally complex businesses modernise systems, workflows, data and delivery capability. For more information about our services, visit our How We Help page.

We understand that your privacy is important to you and that you care about how your personal data is used. We respect and value the privacy of everyone who interacts with us, and we only collect and use personal data in the ways described in this policy, consistent with our obligations and your rights under the General Data Protection Regulation (EU Regulation 2016/679) (the “GDPR”).

What This Privacy Policy Covers

This Privacy Policy describes how Threadable collects, uses, stores and discloses personal data from visitors to our website, customers, prospective customers, employees and job candidates, and in other situations where Threadable acts as a data controller. It also explains your rights under data protection law.

“Personal data” is defined by the GDPR as any information relating to an identifiable person who can be directly or indirectly identified. If you have any questions about our use of your personal data, please contact us using the details at the end of this policy.

Personal Data We Collect

We collect personal data relating to our clients, prospective clients, suppliers, business contacts, website users, employees and job applicants. Where we collect data not listed in this policy, we will give you appropriate notice of what is collected and how it is used where required by law.

When you use the contact form on our website, we may collect your name, email address, company, the area you would like to discuss, your website or URL, your phone number where provided, your message and any context you share, and technical or source information such as UTM parameters where captured.

  • Personal and contact details provided when you correspond with us, register for events or request information.

  • Education history, professional information and related documents provided for recruitment purposes, including CVs, references and interview notes.

  • Financial information, such as banking details, needed for payroll, benefits or invoicing where we do business with you.

Cookies and Analytics

Our website is built and published using Framer. Framer may use essential technologies needed to operate the website securely and provides aggregated, privacy-friendly analytics that do not identify individual visitors.

We do not use Google Analytics, LinkedIn Insight Tag, HubSpot website analytics, advertising pixels or other non-essential marketing cookies on this website. If this changes, we will update this Privacy Policy and, where required, obtain consent before such technologies are used.

How We Use Personal Data

  • To respond to enquiries submitted through our website or by email, and to have an initial conversation about how we may be able to help.

  • To provide, manage and improve our services, and to meet our contractual obligations to clients.

  • To operate and manage our business, including administration, security and record keeping.

  • To assess applications from prospective employees.

  • To send relevant information about our services where you have consented or where we have a legitimate interest in contacting you.

Legal Basis for Processing

Under the GDPR we must always have a lawful basis for using your personal data:

  • Performance of a contract — engaging and delivering our services and managing our contractual obligations.

  • Consent — marketing communications, web forms, newsletters and recruitment applications.

  • Legitimate interests — communicating with business contacts, improving and securing our services, and operating our business, where those interests are not overridden by your rights and freedoms.

  • Legal obligation — legally required reporting and responding to legal process.

Threadable does not knowingly collect personal data from children under the age of 18. We do not provide services to children, nor do we market to children.

Marketing

With your permission and/or where permitted by law, we may use your personal data for marketing purposes, including contacting you by email or telephone with information and news about our services. You will not be sent unlawful marketing or spam, and you will always have the opportunity to opt out.

Most of the personal data we use for marketing relates to individuals employed by our clients and other companies we work with. We may also obtain contact information from public sources, including content made public on social media, to make an initial contact with a relevant individual.

Sharing Personal Data

We may share personal data with third parties that provide services to us, such as website hosting and publishing (including Framer), form handling, analytics, email processing, CRM, security and business operations. In some cases these providers require access to some or all of your data to supply their services.

We only share the information necessary for the purposes described, and any third party who receives personal data is bound by a contract with Threadable setting out its obligations in relation to your data, as required by Article 28 of the GDPR.

Where you submit an enquiry, we may use HubSpot as our customer relationship management system to store and manage the information you provide and our subsequent communications with you. HubSpot does not receive browsing data from this website through website-tracking scripts.

International Transfers

Unless stated otherwise, transfers of personal data from within the European Economic Area (EEA) to third parties outside the EEA are based on an adequacy decision or are governed by the European Commission’s standard contractual clauses. Any other transfers of your personal data take place in accordance with appropriate international data transfer mechanisms and safeguards.

Retention

We retain personal data only for as long as necessary for the purposes described in this policy, to comply with our legal obligations, resolve disputes and enforce our agreements.

  • Enquiry data is kept for as long as needed to respond to and follow up on your enquiry.

  • Client and supplier data is kept for the duration of our relationship and for any period required by law, such as tax and accounting rules.

  • Recruitment data is kept for the duration of the recruitment process and, with your consent, for consideration for future roles.

Security

We are committed to keeping your information secure with us and with any third parties who act on our behalf. Our security approach is governed by a mature IT framework aligned with ISO/IEC 27001 certification standards, and information is transmitted using SSL/TLS encryption wherever possible.

  • Access to personal data is limited to employees, agents, contractors and other third parties with a legitimate need to know, subject to duties of confidentiality.

  • We maintain procedures for dealing with data breaches, including notifying you and/or the Data Protection Commission where we are legally required to do so.

  • All staff receive training on our data protection policies and procedures.

As no communication over the internet is completely secure, we cannot guarantee the security of information you send to us over your internet connection.

Your Rights

Under the GDPR you have the following rights, which we will always work to uphold:

  • The right to be informed about our collection and use of your personal data.

  • The right to access the personal data we hold about you.

  • The right to rectification if any personal data we hold is inaccurate or incomplete.

  • The right to erasure — asking us to delete or otherwise dispose of personal data we hold.

  • The right to restrict the processing of your personal data.

  • The right to object to us using your personal data for a particular purpose.

  • The right to data portability where you provided the data directly, we use it with your consent or for the performance of a contract, and it is processed by automated means.

  • Rights relating to automated decision-making and profiling — we do not use your personal data in this way.

Subject Access Requests

If you want to know what personal data we hold about you, you can ask us for details and for a copy of it. This is known as a subject access request. All subject access requests should be made in writing to the email address below.

There is normally no charge for a subject access request. If your request is manifestly unfounded or excessive — for example, if you make repetitive requests — a fee may be charged to cover our administrative costs. We will respond within one month of receiving your request. For more complex requests, up to three months may be required, and we will keep you fully informed of our progress.

Complaints

If you have any cause for complaint about our use of your personal data, you have the right to lodge a complaint with the Data Protection Commission, the supervisory authority for data protection in Ireland.

Contact

To contact us about anything to do with your personal data and data protection, including to make a subject access request, please email dpo@threadable.io.