- Controller
- Donncha O'Toole
- Product
- Bronora is a voucher-software product supplied by Donncha O'Toole.
- Address
- Bellevue House, Bellevue Demesne, Delgany, Co. Wicklow, Ireland
- Version
- bronora-privacy-2026-07-29-v2
1. Who is responsible
Bronora is a voucher-software product supplied by Donncha O'Toole. Donncha O'Toole is the controller for information used to run, secure, support and improve the product and to manage merchant relationships. Contact hello@bronora.com, call 083 448 6980, or write to Bellevue House, Bellevue Demesne, Delgany, Co. Wicklow, Ireland.
The business named as issuer in a voucher shop is normally the controller for purchaser, recipient and redeemer information used to sell, deliver, honour and market its vouchers. Donncha O'Toole processes that information for the merchant under the data processing agreement. A merchant may provide additional privacy information for its own purposes. Questions about the merchant’s products, marketing or customer decisions should be directed to that merchant.
2. Information handled
Bronora handles merchant identity, contact and authorised-user details; names, business names, work email addresses and notes sent through a guided setup request; account roles and authentication events; voucher products and terms; order values and payment-provider references; purchaser and recipient names and email addresses; gift messages; delivery, access, redemption, refund and dispute events; consent choices; support correspondence; and security and audit records.
Stripe collects full card numbers and card security codes. Bronora receives payment identifiers, status, value, currency, refund and dispute information but does not need or store full card details. The controller does not intentionally collect special-category personal data. People should not place sensitive information in gift messages or support requests unless it is genuinely necessary.
3. Purposes and legal bases
| Purpose | Information | Legal basis |
|---|---|---|
| Set up and provide merchant accounts | Identity, contact, role, business and account details | Contract; steps requested before a contract |
| Respond to guided setup requests | Name, business, work email address, business type and request note | Steps requested before a contract; legitimate interests in responding to the request |
| Operate voucher delivery, access and records | Order, recipient, message, voucher and activity details | Merchant instructions; contract; legitimate interests in reliable delivery |
| Connect payments and reconcile fees | Stripe account, payment, refund and dispute references | Contract; legal obligations; legitimate interests in accurate accounts and fraud control |
| Secure and support the service | Authentication, audit, device, support and incident records | Contract; legal obligations; legitimate interests in security, support and misuse prevention |
| Meet tax, accounting and legal duties | Merchant, invoice, order, fee and dispute records | Legal obligation; establishment, exercise or defence of legal claims |
| Measure public-site use | Aggregate page, referrer and setup-interest events described below | Legitimate interests in understanding whether the public service is useful |
| Send Bronora marketing | Contact details and recorded choice | Consent, or another lawful business-contact basis where applicable; always subject to opt-out |
Where the controller relies on legitimate interests, it uses the minimum information reasonably needed and weighs those interests against the person’s rights. A person may object as explained below.
4. Transactional messages, marketing and measurement
Transactional account, receipt and voucher-delivery messages are needed to provide the requested service. A voucher can be bought without agreeing to marketing. Merchant marketing and Bronora marketing choices are separate, and consent can be withdrawn at any time without affecting earlier lawful use.
The public site records aggregate page views, campaign labels, referrer hostnames and setup-interest events through a first-party endpoint. It does not use analytics cookies, persistent visitor identifiers or session replay, and it does not store raw IP addresses, user agents, email addresses or customer voucher URLs in those measurement records. These events are deleted after 180 days.
Separately, the site may offer optional product analytics. Only after an active choice, Mixpanel receives limited events such as public paths, campaign labels, button actions and setup steps. The integration starts with tracking off, disables autocapture, page-view automation, session replay and IP-based geolocation, and excludes form contents, names, email addresses, payment data and voucher URLs. It uses a pseudonymous device identifier only to group events after consent; it is not linked to merchant or customer records. The choice can be changed below at any time.
Optional product analytics
No optional product-analytics choice has been made on this device.
5. Recipients and service providers
| Recipient | Purpose and location | Legal role and safeguard |
|---|---|---|
| DigitalOcean, LLC | Application, database and encrypted backup hosting in London, United Kingdom | Processor; UK adequacy decision and DigitalOcean data processing terms |
| Amazon Web Services EMEA SARL | Transactional email through Amazon SES in Ireland, with limited global support access possible | Processor; AWS data processing terms, adequacy or contractual transfer safeguards as applicable |
| Stripe Payments Europe, Limited and Stripe group providers | Merchant-connected payments, application fees, refunds, disputes and compliance | Stripe acts under its agreement with the merchant and its own legal duties; its DPA and transfer safeguards apply where it acts as processor |
| Mixpanel, Inc. (optional) | Limited product analytics for public-site journeys after an active choice, using an EU data-residency project | Processor; Mixpanel DPA and project data-residency safeguards |
Authorised Bronora personnel and professional advisers may receive information only where needed and subject to confidentiality. Data may also be disclosed where law requires it, to protect people or the service, or as part of a genuine business transfer with appropriate protections. The controller does not sell personal data.
6. International transfers
The primary database is hosted in the United Kingdom, which is covered by an EU adequacy decision. Providers may make limited transfers elsewhere for support, security or service delivery. The controller relies on an adequacy decision, the European Commission’s standard contractual clauses or another lawful safeguard where one is required. A copy or summary of the relevant safeguard can be requested from hello@bronora.com.
7. Retention
| Record | Normal retention rule |
|---|---|
| Abandoned merchant setup | Expired, unused setup links are eligible for cleanup after 7 days; inactive draft account details are closed and de-identified after 30 days |
| Guided setup requests and related correspondence | Normally 2 years after closure, or longer when linked to an active account, transaction, incident or legal claim |
| Merchant contract, fee, tax and invoice records | During the account and normally 6 years afterwards |
| Order, voucher, refund, dispute and audit records | While needed for voucher liability, then normally 6 years after the later of the relevant transaction, final redemption or expiry, refund, or dispute resolution |
| Recipient details and gift messages | While needed for delivery, secure access, support and voucher liability; deleted or de-identified when they can be separated from records that must be retained |
| Support records | Normally 2 years after closure, or longer when linked to an active account, transaction, incident or legal claim |
| Consent and objection records | While the choice is current and afterwards as reasonably needed to prove or honour it; suppression records may be retained to prevent unwanted contact |
| Public-site measurement | 180 days |
| Optional product-analytics events | Subject to the Mixpanel project retention settings; withdrawal stops future events |
| Rate-limit and temporary security records | Normally 7 days; audit and confirmed incident records are kept longer where needed for security or claims |
| Database backups | 14 days, after which they are automatically removed |
A record may be kept longer where required by law, an unresolved voucher, dispute, fraud review or legal claim. It may be removed sooner when no longer necessary. Provider copies are also subject to the provider’s lawful retention duties.
8. Security
Bronora uses encrypted network connections, encrypted sensitive fields, protected credentials, role and tenant controls, multi-factor authentication for merchant owners, restricted service accounts, audit and financial ledgers, monitored services, daily backups and restoration checks. No internet service is risk-free. Suspected misuse or an exposed voucher link should be reported promptly to hello@bronora.com.
9. Rights
Depending on the circumstances, a person may request access, correction, deletion, restriction or portability, object to processing, or withdraw consent. Rights can be limited where the controller must keep a record by law or for an active voucher, fraud review or legal claim. Requests can be sent to hello@bronora.com. The controller may need proportionate information to verify identity and normally responds within one month.
For information controlled by a voucher issuer, the controller may pass the request to that merchant and help it respond. A person may complain to the Irish Data Protection Commission at dataprotection.ie and may also contact the supervisory authority where they live or work.
10. Changes
The controller will update the version and effective date when this notice materially changes and will give account holders appropriate notice. Earlier versions will remain identifiable in transaction and consent records where relevant.