Privacy notice
Last updated: 8 October 2026
The short version. We collect only what we need to deliver our services and meet our legal obligations. Your financial information is used to do the work you asked us to do, nothing else.
We never sell your information or share it for marketing. It is accessed only by our team, the authorities we file with on your behalf, and the systems we use to deliver the service.
1. Who we are
TradesmanBooks is a trading name of OKEENEY Limited, a company registered in Ireland (CRO no. 826806), with its registered office at Corporation Cottages, Killybegs, Co. Donegal. We are the data controller for the personal information described in this notice.
For any question about your information, or to exercise your rights, email daniel.okeeney@tradesmanbooks.com or call +353 87 944 5605.
2. What we collect
- Contact details: your name, business name, phone number, email address and business address.
- Business financial records: bank and credit card statements, invoices, receipts, VAT returns, accounting exports, loan and insurance details, and other records you send us.
- Tax and identity information: your PPS number, tax registration numbers and Revenue details, and the identity documents we are legally required to check before taking you on as a client.
- Information about your employees and subcontractors: where we run payroll or RCT for you, such as names, PPS numbers, pay and tax details.
- Communications: messages, emails and call notes, including WhatsApp messages you send us.
3. Why we use it, and our legal basis
| What we do | Legal basis |
|---|---|
| Carry out your Profit Review or Financial Back Office service: bookkeeping, reports, payroll, VAT, RCT, tax returns and annual compliance | Performing our contract with you |
| File returns with Revenue and the CRO, keep records for the periods required by law, and carry out anti-money laundering checks | Legal obligation |
| Reply to your enquiries, arrange calls, and run and improve our business | Our legitimate interests |
| Send you occasional updates or news, if you have asked for them | Your consent, which you can withdraw at any time |
4. Your employees' and subcontractors' information
When we run payroll or RCT for you, you remain the controller of your employees' and subcontractors' personal information, and we process it on your behalf under the terms of our engagement letter. Please make sure your own staff are told how their information is used.
5. Who we share it with
We share information only where needed to deliver the service or meet a legal requirement:
- Public authorities: the Revenue Commissioners and the Companies Registration Office, when we file on your behalf, and any other authority where the law requires it.
- Our team: our staff and contractors, including our accountant, all bound by confidentiality.
- Service providers we use to deliver the service:
- Xero and Hubdoc (accounting software and document capture)
- SimplePay (payroll software)
- WhatsApp, operated by Meta (messaging)
- Google Drive (secure file storage)
- Notion (client records and status tracking)
- Bitwarden (secure password storage)
- Our email and website hosting providers
- Professional advisers and insurers, where needed to run our business properly.
Each provider handles your information only on our instructions and under a written data processing agreement.
6. Transfers outside the European Economic Area
Some of our providers, and some members of our team, may be based outside the European Economic Area. Where information is transferred outside the EEA, we make sure it is protected by an adequacy decision of the European Commission (such as the EU-US Data Privacy Framework) or by the European Commission's Standard Contractual Clauses, with additional safeguards where needed.
7. How long we keep it
- Client financial and tax records: at least 6 years from the end of the tax year they relate to, as Irish tax law requires.
- Anti-money laundering records: 5 years from the end of our relationship with you.
- Profit Review documents, if you don't go on to become a monthly client: deleted 12 months after your results meeting, unless the law requires us to keep them longer.
- Enquiries that don't lead to work: deleted within 2 years.
When your information is no longer needed, we delete it securely. If you leave us, we hand over your records to you or your new adviser.
8. How we keep it safe
Documents are sent to us through secure upload links rather than ordinary email where possible. Access to client information is limited to the people who need it, accounts are protected with strong passwords and two-factor authentication, and we use reputable providers that encrypt data in transit and at rest. If a data breach ever puts your information at risk, we will tell you and the Data Protection Commission as the law requires.
9. Your rights
Under the GDPR you have the right to:
- access the personal information we hold about you
- have inaccurate information corrected
- have your information deleted, where we are not legally required to keep it
- restrict or object to how we use it
- receive your information in a portable format
- withdraw consent at any time, where we rely on consent
To use any of these rights, email us. We will reply within one month. You also have the right to complain to the Data Protection Commission at www.dataprotection.ie, though we would appreciate the chance to put things right first.
10. Our website
Our website does not use tracking or advertising cookies. It loads fonts from Google Fonts, which means your browser connects to Google's servers. When you message us, you use WhatsApp or your own email provider. Those services have their own privacy policies.
11. Changes to this notice
We may update this notice from time to time. The latest version will always be on this page, with the date it was last updated.
